What Is an Incident Response Retainer?

Also called: IR retainer

Related problems: Not knowing who to call when we get breached; Our cyber insurer asks whether we have an incident response firm lined up; Our MDR provider can isolate a laptop but can't run a full investigation; Losing days to contracts and onboarding in the middle of an attack

An incident response retainer is a contract you sign with an incident response firm before anything goes wrong, so that when a serious security incident happens you can call them and have experienced responders working on it within an agreed time. It settles the terms, rates, access and contacts in advance, which removes the slowest part of most breach responses: finding a firm, negotiating a contract and explaining your environment while the attacker is still inside.

At a glance

  • It is a contract for on-call outside responders, not a monitoring service; it activates when you call.
  • The core terms are guaranteed response times, hourly rates, a block of prepaid hours (or none) and what unused hours can be used for.
  • It covers the deep work after detection: forensic investigation, scoping, eradication, recovery guidance and reporting.
  • Cyber insurers and larger customers increasingly ask whether you have one, and insurers may require their approved firms.
  • It complements an internal incident response plan and an MDR service; it does not replace either.

What problem it solves

Most mid-sized companies don’t employ forensic investigators. When ransomware hits or an attacker is found in email or a cloud tenant, they need people who do this every week. Without a retainer, the first hours go to finding a firm, checking whether it is approved by the insurer, agreeing rates, signing a contract, granting access and briefing responders on a network they have never seen. Those are the hours when containment matters most.

A retainer moves that work to a calm day. The firm has already reviewed your environment, knows who your decision-makers are, and has committed to start within a set time. It also answers a growing question on cyber insurance applications and customer security questionnaires: “Who will help you respond to an incident?”

How it works

Onboarding. After signing, the provider typically runs an onboarding session: key contacts, network and cloud overview, which security tools you run, where logs are kept, and how responders will get access. Good providers set up dedicated, auditable credentials for their team rather than asking for shared admin accounts mid-incident.

Activation. When you suspect an incident, you call a hotline or open an emergency case. The provider commits to a first response, usually a call with an experienced responder within a set number of hours, and to mobilizing a team remotely or on site within a longer window. These times vary by provider and tier, so read them carefully.

The engagement. Responders work with your IT team, your managed detection provider if you have one, and often your breach counsel and insurer. Typical work includes triage, collecting evidence and preserving its integrity, working out how the attacker got in and what they touched, removing their access, and advising on safe recovery. The engagement ends with a report that legal, insurance and leadership can rely on.

Commercial models. Common structures are prepaid hours at a discounted rate, a subscription with a fixed annual fee, or a zero-dollar retainer that guarantees rates and response times with nothing prepaid. Many providers let you spend unused hours on proactive work such as tabletop exercises, plan reviews, or a compromise assessment that looks for signs an attacker is already present.

When it matters for buyers

  • At cyber insurance renewal. Find out whether your policy requires a panel firm, then choose a retainer provider your insurer will pay for.
  • When a peer or competitor is breached. That is often when leadership asks what would happen here. A retainer is a concrete answer.
  • When you buy or renew MDR. Check what “response” the MDR contract actually includes and where it stops. Many providers bundle a small number of retainer hours; decide whether that is enough.
  • When customers or auditors ask. Supplier security questionnaires often ask about incident response capability and outside support.
  • Before an incident, never during. Retainers bought mid-incident are just emergency engagements at emergency rates.

Questions to ask vendors

  • What are your guaranteed times for first contact and for responders actively working the case, and do they apply around the clock?
  • Are you on our cyber insurer’s approved panel, and will you coordinate with breach counsel?
  • How many hours are prepaid, at what rate, and what happens to unused hours at the end of the term?
  • Can unused hours be used for tabletop exercises, plan reviews or compromise assessments?
  • What does onboarding cover, and what access and tools will you need in place before an incident?
  • Do you handle ransomware, business email compromise and cloud or SaaS incidents in-house, or subcontract any of them?
  • What does your final report include, and can it be prepared under legal privilege when counsel directs the work?

How it differs from incident response and MDR

Incident response (IR) is the discipline itself: the plan, roles and steps your organization follows when something goes wrong. A retainer is one way to staff the hardest parts of that plan with outside experts. Managed detection and response (MDR) is a continuous, 24/7 service that watches your systems and responds to threats, taking quick containment actions like isolating a device where you have authorized it, or guiding your team to. An incident response retainer is called on demand for the deeper investigation and recovery that follows a serious incident. If you already use MDR, ask whether its response stops at containment; if it does, a retainer fills the gap. See our incident response services overview and our article on why an incident response retainer saves time.

Frequently Asked Questions

Is an incident response retainer the same as MDR?
No. Managed detection and response (MDR) is a continuous service that watches your environment around the clock and responds to threats, either taking first containment steps such as isolating a laptop where you have authorized it, or telling your team what to do. A retainer is an agreement for a deeper investigation and recovery team you call when an incident goes beyond that. Many MDR providers sell a retainer as an add-on, but the two are scoped and priced separately.
Do we need a retainer if we already have an incident response plan?
A plan says who does what inside your company. Unless you have experienced forensic investigators on staff, the plan usually includes calling outside help, and a retainer means that call goes to a firm that already knows your environment and has agreed terms, rather than a cold search during the crisis.
Does our cyber insurance policy affect which firm we can use?
Often, yes. Many policies require or encourage you to use incident response firms from the insurer's approved panel, and costs from a firm outside the panel may not be covered. Check your policy, and ask any provider you're considering whether they are on your insurer's panel before you sign.
What happens to unused retainer hours?
It depends on the contract. Some providers let unused prepaid hours expire at the end of the term, some roll them over, and many let you convert them into proactive work such as tabletop exercises, plan reviews or compromise assessments. Negotiate this up front.
Are there retainers that cost nothing up front?
Some providers offer zero-dollar or low-cost retainers that lock in response times and rates with no prepaid hours; you pay only if you call them. They are cheaper to hold but may come with slower guaranteed response times and less onboarding than a paid retainer.

You Don’t Need Another Sales Call. You Need an Answer.

30 minutes. No pitch. Just an honest conversation about where you are, what you need, and whether working together makes sense.

We use your details to set up and prepare for the call, and send the newsletter only if you ask for it. Privacy policy.