All services

Incident Response Retainer

An agreement signed before an incident, not during one: a known environment, a direct line and terms already settled, so the first hour goes into handling the incident rather than into procurement.

What a retainer removes

  • Finding a provider, agreeing scope and signing takes days. An incident does not wait for them.
  • A provider meeting your environment for the first time during an incident spends the first hours learning it.
  • Access, permissions and contacts have to be arranged under pressure, by the people already handling the incident.
  • Commercial terms negotiated mid-incident are negotiated from the weakest position you will ever be in.

What is agreed in advance

The environment, known in advance

We map the systems, the identities and the critical dependencies before anything happens, so an incident starts from knowledge rather than from questions.

A direct line

A named route to reach us, agreed in advance, rather than a general contact address answered in business hours.

Access already arranged

Permissions, contacts and escalation paths settled while there is time to settle them properly.

Terms settled in advance

Scope, availability and commercial terms are agreed in the retainer, so none of them is being negotiated while an incident is running.

Scope, hours of availability, response levels and pricing are defined in the agreement itself, per client. Nothing on this page is a commitment to a particular service level.

Questions management usually asks

Who decides on a retainer?

It is usually not an IT decision. A retainer is a commitment about how the organisation will behave in its worst week, which makes it a management question about risk ownership rather than a technical purchase.

What does it cost, and how fast is the response?

Both are set in the agreement itself, because both depend on the scope: which systems are covered, what availability is required and how the organisation is structured. We do not publish a single figure that would not be true for every client.

What if we never have an incident?

Then the mapping, the access work and the agreed escalation paths remain, and they are the same groundwork a risk assessment produces. The retainer is not only insurance; it is preparation that holds value on its own.

Do we still need it if we have an IT provider?

An IT provider keeps the environment running. Incident response is a different discipline with a different objective — establishing what happened, containing it and preserving evidence — and the two are usually needed at the same moment.

// next step

Not sure what the right next step is?

Use the short assessment to identify the areas worth reviewing, or tell us what changed and we will start from there.

Do not send passwords, credentials, API keys, logs or sensitive incident material through the web form.