An incident response retainer is a contract you sign with an incident response firm before anything goes wrong, so that when a serious security incident happens you can call them and have experienced responders working on it within an agreed time. It settles the terms, rates, access and contacts in advance, which removes the slowest part of most breach responses: finding a firm, negotiating a contract and explaining your environment while the attacker is still inside.
At a glance
- It is a contract for on-call outside responders, not a monitoring service; it activates when you call.
- The core terms are guaranteed response times, hourly rates, a block of prepaid hours (or none) and what unused hours can be used for.
- It covers the deep work after detection: forensic investigation, scoping, eradication, recovery guidance and reporting.
- Cyber insurers and larger customers increasingly ask whether you have one, and insurers may require their approved firms.
- It complements an internal incident response plan and an MDR service; it does not replace either.
What problem it solves
Most mid-sized companies don’t employ forensic investigators. When ransomware hits or an attacker is found in email or a cloud tenant, they need people who do this every week. Without a retainer, the first hours go to finding a firm, checking whether it is approved by the insurer, agreeing rates, signing a contract, granting access and briefing responders on a network they have never seen. Those are the hours when containment matters most.
A retainer moves that work to a calm day. The firm has already reviewed your environment, knows who your decision-makers are, and has committed to start within a set time. It also answers a growing question on cyber insurance applications and customer security questionnaires: “Who will help you respond to an incident?”
How it works
Onboarding. After signing, the provider typically runs an onboarding session: key contacts, network and cloud overview, which security tools you run, where logs are kept, and how responders will get access. Good providers set up dedicated, auditable credentials for their team rather than asking for shared admin accounts mid-incident.
Activation. When you suspect an incident, you call a hotline or open an emergency case. The provider commits to a first response, usually a call with an experienced responder within a set number of hours, and to mobilizing a team remotely or on site within a longer window. These times vary by provider and tier, so read them carefully.
The engagement. Responders work with your IT team, your managed detection provider if you have one, and often your breach counsel and insurer. Typical work includes triage, collecting evidence and preserving its integrity, working out how the attacker got in and what they touched, removing their access, and advising on safe recovery. The engagement ends with a report that legal, insurance and leadership can rely on.
Commercial models. Common structures are prepaid hours at a discounted rate, a subscription with a fixed annual fee, or a zero-dollar retainer that guarantees rates and response times with nothing prepaid. Many providers let you spend unused hours on proactive work such as tabletop exercises, plan reviews, or a compromise assessment that looks for signs an attacker is already present.
When it matters for buyers
- At cyber insurance renewal. Find out whether your policy requires a panel firm, then choose a retainer provider your insurer will pay for.
- When a peer or competitor is breached. That is often when leadership asks what would happen here. A retainer is a concrete answer.
- When you buy or renew MDR. Check what “response” the MDR contract actually includes and where it stops. Many providers bundle a small number of retainer hours; decide whether that is enough.
- When customers or auditors ask. Supplier security questionnaires often ask about incident response capability and outside support.
- Before an incident, never during. Retainers bought mid-incident are just emergency engagements at emergency rates.
Questions to ask vendors
- What are your guaranteed times for first contact and for responders actively working the case, and do they apply around the clock?
- Are you on our cyber insurer’s approved panel, and will you coordinate with breach counsel?
- How many hours are prepaid, at what rate, and what happens to unused hours at the end of the term?
- Can unused hours be used for tabletop exercises, plan reviews or compromise assessments?
- What does onboarding cover, and what access and tools will you need in place before an incident?
- Do you handle ransomware, business email compromise and cloud or SaaS incidents in-house, or subcontract any of them?
- What does your final report include, and can it be prepared under legal privilege when counsel directs the work?
How it differs from incident response and MDR
Incident response (IR) is the discipline itself: the plan, roles and steps your organization follows when something goes wrong. A retainer is one way to staff the hardest parts of that plan with outside experts. Managed detection and response (MDR) is a continuous, 24/7 service that watches your systems and responds to threats, taking quick containment actions like isolating a device where you have authorized it, or guiding your team to. An incident response retainer is called on demand for the deeper investigation and recovery that follows a serious incident. If you already use MDR, ask whether its response stops at containment; if it does, a retainer fills the gap. See our incident response services overview and our article on why an incident response retainer saves time.
