Incident response retainer.com

Standby contract · SLA · onboarding

What an incident response retainer actually buys

A retainer is a contract signed before the incident: a named team, a response-time commitment, and in most models hours or funds paid in advance. This page sets out what goes into one, which variables move the price, and the wording the SLA needs in order to mean anything.

  • Primary sources only
  • No price quotes
  • Reviewed September 2026
Standby card · statutory clocks

Standby: no incident open

DORA initial notification From classification as major, and no later than 24 hours from becoming aware
04hours
NIS2 early warning From becoming aware of a significant incident
24hours
GDPR Article 33 From becoming aware of a personal data breach
72hours

Three clocks, three different starting points, one act of triage feeding all of them. A retainer is the arrangement that decides who produces the facts each clock needs, and how quickly.

Live incident

Is something running right now?

Then stop reading and do these three things. The rest of this page is written for the day before, which is the only day a retainer can be bought.

  1. Write down the time

    Every deadline on this page runs from a moment you will have to name in writing. Record when you became aware, who noticed it, and through what. That timestamp is the first line of the notification and the last thing anyone remembers accurately.

  2. Contain without destroying the account

    Isolate hosts and revoke sessions, but capture volatile evidence before you rebuild, and never rebuild the only copy. NIST is explicit that every response strategy has trade-offs: recovering quickly and investigating properly pull in opposite directions, and somebody has to decide which one wins.

  3. Get someone on it who does this weekly

    If you have a retainer, declare on the agreed channel now, because the clock in your contract starts at declaration. If you do not, call anyway. OffSeq incident response takes calls from organisations it has never met.

Nothing on this page is legal advice or a substitute for your own incident response plan. If you are an essential or important entity under NIS2, a financial entity under DORA, or a controller under the GDPR, your notification duties are running from the moment you became aware, whether or not anyone has been engaged yet.

Definition

What a retainer is, and what it is not

The word covers three different commercial arrangements. What they share is the part that gets discussed least and matters most: the contract exists before the incident does.

An incident response retainer is an agreement, signed in advance, under which a specialist team will help you handle a cyber incident. Every retainer contains at least three things: a pre-negotiated contract, a stated response target, and a queue position ahead of walk-in work. Most also contain prepaid hours or funds, and some contain onboarding and exercises.

The reason the pre-negotiated contract is first on that list is procurement latency. Without a retainer, day one of a ransomware event is spent agreeing a master services agreement, a data processing agreement, a liability cap and an hourly rate, with your lawyers and theirs, while systems are encrypted. Palo Alto Networks describes exactly this in its own terms: a retainer gives “priority access to experienced responders with pre-defined SLA’s before a crisis occurs” and “removes the delays of finding a provider and negotiating terms during an attack”.

The second component is the response-time commitment. It is the number every provider advertises and the term buyers most often misread, because the figure says nothing about what has to have happened by then. A one-hour target to acknowledge a call and a one-hour target to begin containment are different products at different prices, and the difference is usually not written down anywhere the buyer reads. The SLA section takes that apart.

The third is the money. A retainer is priced like insurance with a service attached: you are buying the removal of procurement latency, a queue position, and a discount against the same provider’s walk-in emergency rate. That discount is the actual financial product, and it is the number to ask for. The three models distribute that risk differently.

None of this is a legal requirement. NIS2 and DORA both require an incident handling capability, not a retainer. A retainer is one lawful way to hold part of that capability under contract instead of on payroll, and buying one creates a supplier you then have to assess in its own right.

Components

The six things a retainer is made of

No standard exists, so scope varies more than price does. These are the components that recur across published provider descriptions, and the question that decides whether each one is real.

  1. C-01

    The contract, signed early

    Master terms, liability position, data processing agreement, rate card and notice periods, all agreed while nobody is under pressure. Mandiant lists it as a headline feature of its retainer: “pre-negotiated terms and pre-paid funds for proactive services, training, and incident response”.

    Ask How long does your onboarding and contracting take from signature to a working agreement, and what do you need from us to finish it?

  2. C-02

    A response-time target, in tiers

    Published commitments run from one hour to one business day and are sold as service levels, so the number is a function of the tier you buy rather than a property of the provider. Unit 42 states plainly that its “response SLAs range from 24 hours to two hours, based on your selected retainer and service level”.

    Ask By the target, what exactly must have happened: an acknowledgement, a named lead, a responder on a bridge, or containment under way?

  3. C-03

    Prepaid hours or funds

    A block bought up front and drawn down. The block is only good value if it can be spent on readiness in a quiet year, which is why Mandiant’s prepaid funds are described as covering proactive services and training as well as response.

    Ask Can unused hours be spent on plan review, threat hunting or an exercise, and do they roll over at renewal or expire?

  4. C-04

    Onboarding before the first call

    Network and identity context, logging coverage, an agreed access method, a severity scheme and the escalation chart. NIST treats supplier involvement in incident planning as an outcome in its own right, subcategory GV.SC-08, and Arctic Wolf bundles “IR planning and a tabletop exercise” into the retainer itself.

    Ask What onboarding is included, when does it happen, and what documents exist at the end of it?

  5. C-05

    Named contacts and an escalation path

    A declaration channel that starts the clock, an out-of-band fallback for when your own email is down, and named people with authority on both sides. NCSC asks even a basic plan to carry key contacts, escalation criteria and “at least one conference number” that is always available.

    Ask Who answers at 03:00 on 1 January, and what is the fallback if our email and telephony are the thing that is down?

  6. C-06

    A written scope of work

    The FIRST CSIRT Services Framework names the parts: report acceptance, incident analysis, artifact and forensic evidence analysis, mitigation and recovery, incident coordination, and crisis management support. A retainer that covers analysis but not recovery is a different product from one that covers both.

    Ask Which of those six are in scope, is rebuild work included, and who talks to the regulator and the insurer?

Every provider quoted here publishes these commitments on its own public service pages. None of them publishes a price, an hourly rate or an hour count, which is why this site describes structure and never quotes figures. Sources are linked in each guide.

Scoping tool

Work out the retainer shape you need

Five answers about your estate, your obligations and what you expect the provider to do first. The tool returns a retainer shape, the wording your SLA needs, the onboarding that has to happen before an incident, and the clauses to insist on. It never returns a price, because no provider publishes one.

Intake

Answer as the organisation actually is at three in the morning, not as the target operating model says it will be.

Environment size

Roughly how many endpoints, servers and cloud instances a responder would have to work across.

How the estate is spread

Geography and technology decide travel, timezone cover and who is allowed to touch what.

Regulatory position

Select every regime that applies. NIS2 and DORA can both apply to the same group.

In-house capability

What exists on your side at three in the morning, not on the org chart.

What you expect the provider to do first

This is the single question that moves the price most, and the one buyers answer last.

Shape: Prepaid block with readiness built in. Regulatory position: NIS2 important entity, Personal data at scale. 10 onboarding items and 9 contract clauses apply.

Retainer shape

Prepaid block with readiness built in

Model A: prepaid hours or funds, drawn down

The estate is large or spread enough that a responder arriving cold would spend the first day learning it. Buy a block of hours or funds up front and require that part of it is spent before any incident, on onboarding and at least one exercise. Mandiant publishes exactly this structure: pre-negotiated terms and pre-paid funds for proactive services, training and incident response.

  • A signed contract before the incident. Master terms, liability position, data processing agreement and rates agreed while nobody is under pressure. This is the component every retainer has, and the one that removes the most hours from day one.
  • A place in the queue. A stated response target and priority over walk-in work. ENISA describes the same logic from the responder side: contracted customers are served at the highest priority, everyone else gets best effort.
  • A discount against the emergency rate. The gap between your retained rate and the same provider’s walk-in rate is the actual financial product. Ask for both numbers and compare them.
  • Pre-incident work you actually consume. Plan review, an exercise with the provider in the room, and a documented access method. NIST flags supplier participation in incident planning and exercises as a distinct outcome, GV.SC-08 and ID.IM-02.

Trade-off A block you cannot spend on readiness is a write-off in a quiet year. Make rollover and proactive use explicit terms, not goodwill.

What the SLA should say

The verb
By the target, the provider must have a named lead assigned and a responder working with your team on a bridge. “Respond” on its own is not a commitment.
What starts the clock
Your declaration on the agreed channel, not the provider accepting that the event qualifies. Otherwise the provider controls its own clock.
The target
Ask for the two-hour end of the published range. Published commitments run from one hour to twenty-four, and the number is a function of the tier you buy.
Coverage
The target applies 24 hours a day, every day of the year, with the same target at 03:00 on 1 January as at 10:00 on a Tuesday.
Severity threshold
One written definition of the severity that triggers the target, applicable by your duty manager at 03:00 without a debate.
Remedy
A miss produces a service credit and a written miss report, so a missed target produces a record rather than an apology.
Capacity
What happens when a widespread event puts many of the provider’s customers in the queue at once, and whether your tier guarantees a position.

Draft clause to negotiate from

Within the two-hour end of the published range of the Customer declaring an incident on the agreed channel, the Provider shall have a named lead assigned and a responder working with your team on a bridge. The target is measured from the time of declaration and not from the Provider’s acceptance of it, applies 24 hours a day, every day of the year, with the same target at 03:00 on 1 January as at 10:00 on a Tuesday, and a failure to meet it entitles the Customer to a service credit and a written miss report, so a missed target produces a record rather than an apology.

Before the first incident

  1. Escalation chart and contact list, both sides. Named people with the authority to decide, deputies, and what each is allowed to approve. NCSC is explicit that the people escalated to must have the authority to make critical decisions, and Implementing Regulation (EU) 2024/2690 lists escalation charts and contact lists among the documents an incident handling policy has to produce.
  2. A declaration channel and an out-of-band fallback. One number or address that starts the clock, and a way to run the incident when your own email and telephony are the thing that is down. NCSC asks for at least one always-available conference number.
  3. An access method agreed and tested. How the provider reaches your systems, under whose account, with what approval, tested once while nothing is wrong. This is the step most often discovered missing on day one.
  4. A severity and categorisation scheme. Predefined criteria and a triage rule, so prioritisation of containment and eradication is decided in advance rather than argued about live. Reg. 2024/2690 point 3.4.2(a) requires exactly that.
  5. The data processing agreement, signed. A responder handling images and mailbox exports is a processor. GDPR Article 28(3) sets what the contract has to say, and Article 28(2) means sub-processors need authorisation before, not during.
  6. One exercise with the provider in the room. A tabletop that runs your escalation chart and the provider’s intake together. NIST ID.IM-02 treats exercises done in coordination with suppliers and third parties as a distinct improvement outcome.
  7. Logging and endpoint coverage confirmed. A responder cannot investigate what was never recorded. Establish what is logged, for how long, and where the gaps are, before the retainer is tested against them.
  8. Notification drafts and who signs them. The NIS2 early warning is due within 24 hours of awareness and has to say whether malicious action is suspected and whether there is cross-border impact. Draft the template, and agree whether the provider writes it or reviews it.
  9. The 72-hour drafting responsibility. Article 33 gives the controller 72 hours from awareness. Decide now whether the provider supplies the facts, drafts the notification, or neither, and who holds the pen when the facts are still moving.
  10. Asset, identity and network handover. A current inventory, the identity provider topology and a network diagram that a stranger can read. NIST treats asset inventories as directly useful to responders for scoping and prioritisation.

Put this in the contract

  • The SLA verb and the clock start. Write both into the contract, not the sales deck. A target with no stated verb is unenforceable, and a target the provider starts itself is not a target.
  • Scope, item by item. Which services are in: report acceptance, analysis, forensic artifact analysis, mitigation and recovery, coordination, crisis management support. The FIRST CSIRT Services Framework names them; a retainer that covers analysis but not recovery is a different product at a different price.
  • Rates, rollover and the out-of-hours multiplier. The drawdown rate, the rate after the block is exhausted, the out-of-hours rate, whether unused balance rolls over, and whether it can be spent on readiness work.
  • Authority to act, and its limits. Whether the provider may isolate a host, disable an account or take a service offline without your sign-off. NIST calls this out specifically as a restriction to write down, alongside restrictions on sharing sanitised incident information with other customers.
  • Jurisdiction of processing and sub-processors. Where responders sit, where forensic data is processed and stored, who the sub-processors are, and that changing any of it requires notice to you in advance.
  • Retention, deletion and the evidence standard. How long images and telemetry are kept, how they are returned or destroyed, and whether chain of custody and hashing are handled to a standard that survives litigation or a criminal referral.
  • Insurer compatibility. Confirm with your broker in writing that engaging this provider will not prejudice a claim. Insurers maintain their own panels and the selection is normally made at the point a claim is filed.
  • The provider is now part of your supply chain. NIS2 Article 21(2)(d) makes supplier security a measure in its own right, and Article 21(3) requires you to take into account the vulnerabilities specific to each direct service provider. Buying a retainer creates a supplier you have to assess, with privileged access to everything.
  • Article 28(3) processor terms. Documented instructions only, confidentiality commitments, Article 32 measures, assistance with Articles 32 to 36, and deletion or return of all personal data at the end of the engagement, at your choice.

Bands and wording only. Actual pricing depends on the estate, the tier and the provider, and every output here is a position to negotiate from rather than an answer. Nothing on this page is legal advice.

Have OffSeq scope this against your estate

Interactive mode is not available. You can read the full reference content below. No answers are assessed and no result is calculated.

The interactive scoping tool needs JavaScript. The full reference it works from is below: the five questions it asks, what each answer changes, and the four outputs it produces.

  • Q1 · Environment size

    Roughly how many endpoints, servers and cloud instances a responder would have to work across.

    Under 100: One office estate, a handful of servers or a single cloud account. 100 to 500: A single mid-sized business with an identity provider and some SaaS. 500 to 2,000: Several business units, mixed on-premises and cloud, real change volume. Over 2,000: Enterprise estate: multiple domains, tenants and platform teams.

  • Q2 · How the estate is spread

    Geography and technology decide travel, timezone cover and who is allowed to touch what.

    One site, one country: A single office and one cloud tenant. Several sites, one country: Branches or plants under one legal entity and one regulator. Several countries: More than one jurisdiction, language and supervisory authority. Industrial or OT systems present: Production, control or medical systems where a containment action can stop or endanger something physical.

  • Q3 · Regulatory position

    Select every regime that applies. NIS2 and DORA can both apply to the same group.

    NIS2 essential entity: Article 21 measures plus the Article 23 reporting sequence, under ex ante supervision. NIS2 important entity: The same Article 21 and 23 duties, supervised ex post. DORA financial entity: Articles 11 and 17, and Article 30 governs the retainer contract itself. Personal data at scale: A breach is likely to trigger the Article 33 notification duty.

  • Q4 · In-house capability

    What exists on your side at three in the morning, not on the org chart.

    No dedicated security staff: IT is outsourced or fully occupied with operations. IT team with security duties: Competent generalists; incident response is not their day job. Security team, business hours: Named security staff, no formal out-of-hours rota. Round-the-clock monitoring: Your own SOC or a managed detection service already watching.

  • Q5 · What you expect the provider to do first

    This is the single question that moves the price most, and the one buyers answer last.

    Answer by the next working day: You can hold the first night yourself and want expertise afterwards. Be working with us within hours: A responder on the bridge, triaging with your team, the same shift. Start containing immediately: Authorised to isolate hosts and disable accounts on your behalf.

  • What the tool returns

    Four outputs, never a price. Retainer shape: which of the three commercial models fits, what the fee actually buys, and the trade-off you are accepting. SLA wording: the verb the target attaches to, what starts the clock, the coverage hours, the severity threshold and the remedy for a miss. Onboarding: the artefacts that have to exist before an incident. Contract: the clauses to insist on.

    The three models are a prepaid block drawn down against hours or funds; a standby agreement at a low or nominal fee with response billed at pre-agreed rates; and a subscription with a fixed recurring fee for a defined scope, often bundled with monitoring.

  • The published response-time range

    Providers publish commitments between one hour and one business day, sold as tiers. Palo Alto Networks states that Unit 42 response SLAs range from 24 hours to two hours depending on the retainer and service level; Mandiant publishes a two-hour response time; Arctic Wolf publishes one hour. None of them publishes a price, which is why this tool produces bands and wording rather than figures.

  • The default position shown here

    A 500 to 2,000 endpoint estate on several sites in one country, a NIS2 important entity holding personal data at scale, an IT team with security duties and no out-of-hours rota, expecting a responder to be working with them within hours. That combination points at a prepaid block with readiness built in, a two-hour target measured from declaration, ten onboarding items and nine contract clauses.

Bands and wording only. Actual pricing depends on the estate, the tier and the provider, and every output here is a position to negotiate from rather than an answer. Nothing on this page is legal advice.

The commitment

What the response-time SLA has to say

The advertised number is the least interesting part of a response-time commitment. Six terms decide whether it is enforceable, and providers rarely publish any of them.

The verb
What must have happened by the target: an acknowledgement, a named incident lead assigned, a responder on a bridge with your team, or containment actions under way. Respond on its own commits to nothing. NIST defines the underlying act precisely enough to borrow: a preliminary review that verifies an incident occurred, then an estimate of its severity and the urgency needed.
What starts the clock
Your declaration on the agreed channel, or the provider accepting that the event qualifies? If it is the second, the provider controls its own clock and the target is decorative. Fix the trigger to your act, and name the channel.
Triage or containment
A target to triage buys you an informed opinion. A target to contain buys you an action on your systems, which means pre-authorisation, credentials and an access method that were arranged months earlier. These are different products and the price gap between them is real.
Coverage and calendar
Does the same figure apply at 03:00 on 1 January as at 10:00 on a Tuesday, in which timezone, and against whose public holidays? Providers who advertise 24/7 availability do not always attach the same numeric target to it.
The severity threshold
Below which severity does the clock not start at all, and can your duty manager apply that definition at three in the morning without a debate? Implementing Regulation (EU) 2024/2690 requires assessment against predefined criteria laid down in advance, with triage deciding the priority of containment and eradication.
The remedy, and the capacity
What happens when the target is missed, and what happens when a widespread event puts many of the provider’s customers in the queue at once. For DORA-regulated buyers this is not optional: Article 30(3)(a) requires precise quantitative and qualitative performance targets that allow corrective action without undue delay when the level is not met.
Response-time commitments published by providers
ProviderPublished commitmentWhere
Arctic Wolf 1 hour arcticwolf.com
Mandiant 2 hours cloud.google.com
Unit 42 2 to 24 hours paloaltonetworks.com
CrowdStrike No figure published crowdstrike.com

Checked 13 September 2026. Mandiant is part of Google Cloud and Unit 42 is part of Palo Alto Networks. The published range is one hour to one business day, sold as tiers. None of these pages states what the responder must have done by the target, and none publishes a price. Treat the figure as the start of the conversation, not the end of it.

Cost

How retainers are priced

No major provider publishes a price, a rate or an hour count on its public pages. What can be described honestly is the structure of the deal: three models, each transferring a different risk, and the variables that move any of them.

  1. Prepaid block, drawn down

    How it works
    You buy a quantity of hours or a fund up front and draw against it. Mandiant publishes this structure directly: pre-negotiated terms and pre-paid funds covering proactive services, training and incident response.
    Fits when
    A complex or regulated estate where a responder arriving cold would spend the first day learning it, and where readiness work needs a budget line that cannot be deferred.
    Where it hurts
    A block you cannot spend on readiness is a write-off in a quiet year. The negotiable terms are the drawdown rate, the out-of-hours rate, rollover, and whether proactive use is permitted.
  2. Standby, at a low or nominal fee

    How it works
    A small annual fee, sometimes bundled with another product, buys the pre-negotiated contract and the response target. The response itself is billed at pre-agreed rates when it happens.
    Fits when
    Organisations that can hold the first hours themselves and want the procurement delay removed at close to zero carrying cost, keeping the cash in the business until something happens.
    Where it hurts
    Nothing is prepaid, so nothing was spent on making the provider familiar with your estate. Budget onboarding and one exercise separately or the agreement buys paperwork and a phone number.
  3. Subscription, scope defined

    How it works
    A fixed recurring fee covers a stated scope, frequently bundled with managed detection so that the team which detects also responds.
    Fits when
    Organisations with no out-of-hours capability of their own, where the binding constraint is nobody noticing rather than nobody answering.
    Where it hurts
    Easy to budget, hard to compare. Get the response scope written separately from the monitoring scope, or you will not learn what you bought until you need it.

The one figure worth extracting is the gap between your retained rate and the same provider’s walk-in emergency rate. Arctic Wolf frames the value of its retainer in exactly those terms, advertising a saving of up to 70 per cent against a standalone emergency engagement. Ask both providers you shortlist for both numbers, and compare the gap rather than the headline fee. The cost guide works through the calculation.

Regulatory position

What the law asks for, and where a retainer fits

No EU instrument requires an incident response retainer. Several require a capability that most organisations cannot staff alone, and one of them regulates the retainer contract itself.

Incident response duties and their effect on a retainer
InstrumentWhat it requiresWhat that means for the retainer
NIS2Art. 21(2)(b), (c), (d) Appropriate and proportionate measures on an all-hazards basis, including incident handling, business continuity and crisis management, and supply chain security covering direct suppliers and service providers. The capability must exist; how you hold it is your choice. Buying it from a provider engages point (d), so the responder becomes a supplier you assess, with privileged access to everything.
NIS2 technical rulesReg. (EU) 2024/2690, Annex pt. 3 An incident handling policy setting out roles, responsibilities and procedures for detecting, analysing, containing, recovering, documenting and reporting; a categorisation system; escalation charts, contact lists and templates; triage against predefined criteria; response covering containment, eradication and recovery; logged activity and recorded evidence; tested procedures; post-incident review with root cause. This is the most concrete published statement of what adequate looks like, and it doubles as the onboarding checklist. Directly binding only on the digital-infrastructure and digital-provider entity types it lists.
NIS2 reportingArt. 23(4) Early warning within 24 hours of awareness, indicating whether unlawful or malicious acts are suspected and whether there could be cross-border impact; incident notification within 72 hours with an initial assessment and indicators of compromise; a final report within one month. The 24-hour statement is a triage output, and it is the clearest argument for a target measured in hours rather than days. Agree in advance who drafts it.
DORAArt. 11 and 17 Documented arrangements to respond to and resolve ICT incidents while prioritising resumption; plans activating containment without delay; response and recovery plans audited internally; testing at least yearly including cyber-attack scenarios; a crisis management function; readily accessible records of activity during disruption; early warning indicators, classification, and assigned roles per incident type. A retainer can supply the response arrangements, but not the policy, the classification scheme or the crisis function. Those stay with the financial entity, and the provider has to fit them.
DORA contractsArt. 30(1), (2), (3) The full contract must include the service level agreements in one written document; state the countries where services are provided and data is processed; oblige the provider to assist during an ICT incident at no additional cost or a cost determined ex ante; and, for critical or important functions, carry precise quantitative and qualitative performance targets and rights of access, inspection and audit. For a financial entity, a retainer sold with a vague target is not merely weak, it fails Article 30(3)(a). Processing location and sub-contracting become contract terms rather than details.
DORA reportingDel. Reg. (EU) 2025/301 Initial notification within four hours of classifying an incident as major and no later than 24 hours from becoming aware of it; intermediate report within 72 hours of the initial notification; final report within one month. The clock starts at classification, which is an analytic act. Four hours is survivable only if the criteria and the person authorised to apply them were agreed beforehand.
GDPRArt. 28 and 33 A processor may be used only under a contract meeting Article 28(3), including documented instructions, confidentiality, sub-processor authorisation and deletion or return of data; the controller must notify a personal data breach without undue delay and where feasible within 72 hours of awareness. A responder taking memory images and mailbox exports is a processor. The data processing agreement and the authorised sub-processor list are onboarding tasks, not incident tasks.

Quotations are from the published texts on EUR-Lex. The regime table is a summary for orientation, not legal advice on whether a given instrument applies to your organisation. The NIS2 and DORA guide works through each article.

Escalation

Who decides what, at three in the morning

A response target is worthless if the person it reaches cannot authorise anything. NIST separates the two moves people confuse: escalation adds resources or time, elevation involves a higher level of management.

  1. Whoever notices

    Decides Whether this is an event or an incident, and whether to declare.

    Needs one written definition of what constitutes a declarable incident and one channel to declare on. The commonest failure is a competent person waiting until morning to avoid waking someone.

  2. Duty manager or on-call lead

    Decides Severity, and whether the retainer is invoked.

    This is the rung that starts your contractual clock, so the criteria have to be applicable without a discussion. Reg. (EU) 2024/2690 requires exactly that: predefined criteria and a triage that sets the priority of containment.

  3. Incident lead, yours and theirs

    Decides Containment strategy and the investigation-versus-recovery trade-off.

    Two named people, one on each side, with the provider’s lead assigned by name rather than by rota. ENISA treats assignment to a named handler as the closing step of triage for a reason.

  4. CISO or CIO

    Decides Actions with business impact: taking a service offline, forcing a password reset across the estate.

    NCSC is blunt that the people escalated to must have the authority to make critical decisions, and that a high or critical incident is likely to reach board level.

  5. Executive or management body

    Decides Regulatory notification, customer communication, law enforcement, ransom position.

    Under NIS2 Article 20, the management body approves the risk-management measures, oversees implementation and can be held liable for infringements. This rung cannot be delegated to the provider.

Comparison

A retainer is not your insurer’s panel

Both put responders in front of you. They start at different moments, are chosen by different people and are paid by different parties, and confusing them is expensive during a claim.

Incident response retainer compared with a cyber-insurance panel provider
RetainerInsurance panel
Who contracts You contract the responder directly, on terms you negotiated. The insurer approves the list and normally pays the responder from the policy.
When it starts Before the incident. That is the entire point of it. Generally at the point a claim is filed. Coalition describes its own response arm as one of several vendors policyholders may engage “at the time a claim is filed”.
Who chooses You, on capability, jurisdiction and cultural fit. You, from the insurer’s list.
Knowledge of your estate Whatever onboarding you bought and used. Usually none before the call.
The response target Whatever you negotiated, with a remedy if it is missed. Set by the insurer’s arrangement with the vendor, not by you.
Who pays You, from the retainer or at pre-agreed rates. The policy, subject to limits, deductible and coverage terms.
The failure mode You pay for a year in which nothing happens. Your preferred responder is not on the panel, or costs incurred before notification are contested.

They are complements, not substitutes. NCSC notes that some insurers supply services useful during or immediately after an incident, such as IT forensic services, legal assistance or public relations support, and is equally clear that insurance “will not prevent a cyber breach/attack”. The practical rule: put the insurer notification step in the runbook, and get written confirmation from your broker that engaging your retained provider will not prejudice a claim. Policy wordings differ, so ask rather than assume.

Questions

What buyers actually ask

Answers here are deliberately structural. Where a figure would be invented, the question is answered with the question to put to the provider instead.

What does an incident response retainer cost?
No major provider publishes a price, an hourly rate or an hour count on its public service pages, so any figure quoted online is either one customer’s contract or an estimate. What is knowable is the structure: a prepaid block drawn down against hours or funds, a standby agreement at a low or nominal fee with response billed when used, or a fixed subscription for a defined scope. The variables that move any of them are estate size and complexity, the number of jurisdictions, the service tier bought, on-site attendance, out-of-hours coverage, whether forensics must be evidentiary, and how much readiness work is bundled in. The single most useful number to request is the gap between your retained rate and the same provider’s walk-in emergency rate, because that gap is the financial product you are buying.
Is a retainer required by NIS2 or DORA?
No. Neither instrument mentions retainers. NIS2 Article 21(2)(b) requires incident handling as one of the minimum risk-management measures, and DORA Articles 11 and 17 require documented response and recovery arrangements and an ICT-related incident management process. Both require a capability. A retainer is one lawful way to hold part of that capability under contract rather than on payroll. Buying one also engages NIS2 Article 21(2)(d) on supply chain security, because the responder becomes a direct service provider with privileged access.
What response time should I ask for?
Published commitments run from one hour to one business day and are sold as tiers, so the honest answer is that the target follows the tier you are willing to buy. Choose it from what you must be able to do inside the first statutory window rather than from the vendor’s brochure: DORA gives four hours from classifying an incident as major, NIS2 gives 24 hours from awareness for the early warning, and the GDPR gives 72 hours from awareness of a personal data breach. If any of those apply, a next-business-day target is difficult to defend.
Does the SLA cover triage or containment?
That is the question, and the answer is rarely on the website. A target to triage means somebody qualified will have formed and communicated a view of what is happening. A target to contain means somebody will be taking action on your systems, which requires pre-authorisation, credentials and a tested access method that were arranged long before. Ask which verb the target attaches to, and get the answer written into the contract.
What starts the clock?
Insist that it starts when you declare an incident on the agreed channel. If it starts when the provider accepts that the event qualifies, the provider controls its own clock and the commitment is unenforceable in practice. Also settle the severity threshold below which the target does not apply at all, and confirm that your duty manager can apply that definition at three in the morning without a debate.
Do unused retainer hours roll over?
Sometimes, and it is a negotiable term rather than a market standard. None of the major providers publishes its rollover policy. What some do publish is that prepaid funds may be spent on proactive services and training as well as incident response, which is usually more valuable than rollover: in a year with no incident, hours spent on a plan review, a threat hunt or a tabletop exercise return something, while a lapsed balance returns nothing.
Can we just rely on our cyber insurance panel?
You can, and many organisations do, but understand what you are choosing. The panel is selected by the insurer and normally engaged at the point a claim is filed, so the responder starts cold and the response target is the insurer’s arrangement rather than yours. A retainer starts the relationship before the incident and lets you negotiate the target yourself. The two work together as long as you check, in writing and before renewal, that engaging your retained provider will not prejudice a claim.
What has to be ready before the retainer is any use?
An escalation chart and contact list on both sides with named people who hold real authority, a declaration channel that starts the clock plus an out-of-band fallback, an access method that has been tested while nothing was wrong, a severity and categorisation scheme with predefined criteria, a signed data processing agreement with the sub-processor list authorised in advance, and at least one exercise run with the provider in the room. Commission Implementing Regulation (EU) 2024/2690 lists most of those artefacts explicitly, including incident response manuals, escalation charts, contact lists and templates.
Where will our data be processed during an incident?
Ask before you sign, because it is a contract term rather than an operational detail. Under the GDPR, a responder handling images and mailbox exports is a processor, and Article 28(3)(a) limits transfers to documented instructions from you, while Article 28(2) means sub-processors need authorisation in advance. For financial entities, DORA Article 30(2)(b) requires the contract to name the countries where services are provided and data is processed, and to require advance notice of any change.
What happens if a widespread event hits many of the provider’s customers at once?
Ask exactly that, and get the answer in writing. A mass-exploitation event against a widely deployed product will put a large share of a provider’s customer base into the queue on the same morning. Establish whether your tier guarantees a position, what surge capacity exists, and whether the provider will tell you honestly that it cannot start when it cannot. ENISA describes the underlying reality from the responder side: contracted customers receive the highest priority and everyone else receives best effort.