About incidentresponseretainer.com
incidentresponseretainer.com explains one purchase: the agreement an organisation signs before an incident so that qualified responders arrive on known terms. Readers here sign that contract, defend it to a board, and answer to a supervisory authority afterwards, so the provenance of the guidance is set out below.
Publisher
The site is published by SEQ SIA (reg. No. 40203410806), Lastādijas iela 12 k-3, Riga, LV-1050, Latvia, trading as OffSeq, a provider of incident response and security assessment services. Contact: support@offseq.com.
incidentresponseretainer.com is not affiliated with the European Commission, ENISA, NIST, FIRST, the UK NCSC, any national CSIRT, any insurer or any of the providers whose published commitments are quoted here, and nothing on the site is an official interpretation of any instrument it describes.
Authorship
SEQ SIA (OffSeq) is responsible for publishing, maintaining and updating this site. Articles use team attribution. Every regulatory statement carries a source so a reader can check the basis for it against the instrument itself.
How the guidance is sourced
- Legal statements cite the instrument: Directive (EU) 2022/2555, Commission Implementing Regulation (EU) 2024/2690, Regulation (EU) 2022/2554, Commission Delegated Regulation (EU) 2025/301 and Regulation (EU) 2016/679. Where a text is quoted, it is quoted from the published version on EUR-Lex.
- Framework statements cite the publisher: NIST for SP 800-61r3, ENISA for the Good Practice Guide for Incident Management, FIRST for the CSIRT Services Framework, and the UK NCSC for its incident management and cyber insurance guidance.
- Market statements about response times and retainer structure are quoted from the providers’ own public service pages, with the date they were checked. We do not paraphrase what a provider has not published.
- We publish no prices, no hourly rates and no hour counts, because no provider publishes them. Where a figure would have to be invented, the text gives the question to ask instead.
- We publish no breach-cost, dwell-time or ransomware-frequency statistics on this site. If a number is not in a named, dated, linked source, it is not here.
- The “Updated” date only moves when the text changes; an automated content-hash ledger reverts unearned bumps.
Commercial interest
We sell incident response, including retainers. That is a direct interest in you concluding that you need one, and it should colour how you read every recommendation here.
- Links to OffSeq are our own service links, not a market comparison. We do not rank, score or recommend competing providers.
- The comparison table of published response-time commitments exists because those figures are public and buyers ask for them. It is not an endorsement of, or an attack on, any provider listed.
- No vendor, insurer, broker or certification scheme pays for a mention. There is no advertising and no affiliate revenue.
- Where a retainer is the wrong purchase, the site says so. The scoping tool returns “buy monitoring first” for organisations whose real constraint is that nobody is watching.
Scope limits
This site covers the commercial and contractual side of incident response: what a retainer contains, how it is priced, what the SLA has to say, and how it meets duties under NIS2, DORA and the GDPR. It is not a technical incident handling manual, and it is not a substitute for your own incident response plan.
It is also not legal advice on whether a given instrument applies to your organisation, and it is not advice on insurance coverage. Cyber policy wordings differ; questions about what your policy permits belong with your broker in writing.
Corrections
Send corrections to support@offseq.com, ideally with the instrument and article, or the provider page, you think we have misread. Substantive changes are made and re-dated in the open.