Incident Response Retainer
On-call DFIR team with a 1-hour response SLA
What this engagement covers
The service
When something goes wrong, you do not want to be shopping for an IR firm. Our retainer gets you a pre-contracted, pre-onboarded DFIR team with a 1-hour response SLA, 24/7/365.
What we test
Full DFIR scope - ransomware, BEC, insider threats, cloud intrusions, supply chain compromise, nation-state activity. Containment, eradication, forensic analysis, and recovery.
How we run it
Pre-engagement onboarding so we know your environment before the crisis. On-call DFIR leads, coordinated communications support, and hands-on containment authorized to our agreed scope.
Onboarding and environment discovery
Communications and escalation planning
Immediate containment on activation
Forensic collection and analysis
Eradication and recovery
Post-incident retrospective
What you receive
Findings land in your tracker as you go, not only in a PDF at the end. Retest is in scope, not a change order.
- Pre-negotiated MSA and statement of work
- 1-hour response SLA, 24/7/365
- Dedicated DFIR lead on retainer
- Quarterly tabletop exercise
- Annual IR plan review
- Post-incident report and root cause analysis
- Executive and board-level communications support
What we usually find
The issues this engagement surfaces most often. Yours will differ, but this is the shape of it.
Who this is for
Findings are mapped to SOC 2, HIPAA, PCI-DSS, NIST CSF, GDPR, NIS2, so the report drops into an audit package rather than needing to be translated first. If you need the readiness work behind one of those, that is a separate engagement.
Scope it in one call
Tell us what is in scope and we come back with a fixed price and a start date. No discovery-call maze, no hourly estimate that moves.