Skip to main content
Home/Services/Incident Response Retainer
Security Testing

Incident Response Retainer

On-call DFIR team with a 1-hour response SLA

SOC 2 HIPAA PCI-DSS NIST CSF GDPR NIS2
engagement log Incident Response Retainer testing
day 01scopetargets confirmed · rules of engagement signedagreed
day 01reconattack surface mappedcomplete
day 02findingRansomware detonation and spreadcritical
day 03findingBusiness email compromisehigh
day 04triagereviewed and countersigned by a Lorikeet pentesterpublished
day 04delivertickets opened in your tracker201
afterretestfixes verified · included in scopeno charge
retest included human countersigned report your auditor accepts
Annual retainer + incident-based engagementtypical duration $18,000/year retainerfixed scope, from 7deliverables 6methodology stages
Scope

What this engagement covers

The service

When something goes wrong, you do not want to be shopping for an IR firm. Our retainer gets you a pre-contracted, pre-onboarded DFIR team with a 1-hour response SLA, 24/7/365.

What we test

Full DFIR scope - ransomware, BEC, insider threats, cloud intrusions, supply chain compromise, nation-state activity. Containment, eradication, forensic analysis, and recovery.

Method

How we run it

Pre-engagement onboarding so we know your environment before the crisis. On-call DFIR leads, coordinated communications support, and hands-on containment authorized to our agreed scope.

01

Onboarding and environment discovery

02

Communications and escalation planning

03

Immediate containment on activation

04

Forensic collection and analysis

05

Eradication and recovery

06

Post-incident retrospective

Deliverables

What you receive

Findings land in your tracker as you go, not only in a PDF at the end. Retest is in scope, not a change order.

  • Pre-negotiated MSA and statement of work
  • 1-hour response SLA, 24/7/365
  • Dedicated DFIR lead on retainer
  • Quarterly tabletop exercise
  • Annual IR plan review
  • Post-incident report and root cause analysis
  • Executive and board-level communications support
Typical results

What we usually find

The issues this engagement surfaces most often. Yours will differ, but this is the shape of it.

Ransomware detonation and spread Business email compromise Credential-based lateral movement Data exfiltration via cloud storage Persistence mechanisms in cloud tenants Insider threat activity
Fit

Who this is for

Organizations without an internal DFIR team
Companies with cyber insurance requirements
Regulated industries (finance, healthcare)
Any business where downtime has real cost
Standards this supports

Findings are mapped to SOC 2, HIPAA, PCI-DSS, NIST CSF, GDPR, NIS2, so the report drops into an audit package rather than needing to be translated first. If you need the readiness work behind one of those, that is a separate engagement.

Next

Scope it in one call

Tell us what is in scope and we come back with a fixed price and a start date. No discovery-call maze, no hourly estimate that moves.

Lory waving

Hi, I'm Lory! Need help finding the right service? Click to chat!