Incident response retainer.com

What does an incident response retainer cost?

Updated 7 min read

Search for the cost of an incident response retainer and you will find ranges. None of them comes from a provider. This guide explains why the figure is not published, what is actually knowable about the price, and how to compare two quotes without pretending the headline fee is the comparison.

Start with the verified negative

On 13 September 2026 we checked the public service pages of four providers that sell incident response retainers: Mandiant through Google Cloud, Unit 42 at Palo Alto Networks, CrowdStrike and Arctic Wolf. Between them those pages publish response times, service descriptions and, in two cases, what prepaid funds may be spent on. None of them publishes a price, an hourly rate or an hour count. Every page routes a buyer to a contact form.

That is not evasion, it is the shape of the product. A retainer is priced against a specific estate, a specific service tier and a specific set of obligations, and the same provider will quote two organisations of identical headcount very differently. Any figure you find online is therefore either one customer’s contract, repeated out of context, or an estimate somebody assembled from the same absence of data you are looking at.

You are buying three things, and only one of them is labour

It helps to separate the fee from the work. A retainer fee buys three distinct things, and understanding which of them you actually need is what decides the model.

  • Removal of procurement latency. The contract, the data processing agreement, the liability position and the rate card already exist when the incident starts. This is the component every retainer includes and the one that is impossible to buy after the fact.
  • A queue position. Retained customers are served first. ENISA describes the same arrangement from the responder’s side in its incident management guidance: contracted customers get priority one service, and the rest of the constituency gets a good-effort service.
  • A discount against the emergency rate. Arctic Wolf frames the value of its retainer in exactly these terms, advertising a saving of up to 70 per cent against a standalone emergency incident response engagement. Whatever the number is for your shortlist, that gap is the financial product.

Labour is the fourth thing, and in two of the three models you have not bought any of it yet.

The three models, and what each one costs you when nothing happens

Retainer pricing models compared
ModelWhat the fee coversA year with no incidentThe term to negotiate hardest
Prepaid blockHours or funds bought up front, drawn down at an agreed rateThe balance is either spent on readiness, rolled over, or lostWhether unused balance can be spent on proactive work, and whether it rolls over
StandbyThe contract and the response target; response billed when usedA small fee, and no provider familiarity gainedThe rate that applies when it is used, including the out-of-hours rate
SubscriptionA defined scope, often bundled with monitoringThe monitoring was consumed; the response scope was notExactly where the covered scope ends and billable work begins
Hybrids are common: a small block plus a subscription, or a standby agreement with a bundled tabletop. The question that identifies the real model is what happens to your money in a quiet year.

Prepaid block

You buy a quantity of hours or a fund and draw against it. Mandiant publishes this structure openly: pre-negotiated terms and pre-paid funds for proactive services, training and incident response. Note the order of that list. The prepaid pot is described first as a way to buy readiness, and only third as a way to buy response.

The buyer risk is straightforward: buy too little and the block is exhausted in the first week of a real incident, at which point the post-block rate governs everything; buy too much and you have prepaid for work you will not do. Sizing advice that does not know your estate is worthless, but one principle holds: size the block against your worst realistic week, not your average month, and then make sure the balance is spendable on readiness so that a quiet year still returns something.

Standby

A small or nominal annual fee, sometimes folded into another product, buys the contract and the response target. The response itself is billed at pre-agreed rates. The cash stays in the business until something happens, and the procurement latency is still gone.

The catch is that a standby agreement funds no onboarding. A provider that has never seen your network, does not know which identity provider you use and has no tested access method will spend the first hours of your incident doing discovery you could have paid for in advance at a calmer rate. If you choose this model, budget one onboarding session and one exercise as separate line items.

Subscription

A fixed recurring fee for a stated scope. Frequently the response sits alongside managed detection, on the sensible logic that the team that sees the alert should be the team that acts on it.

Subscriptions are the easiest to budget and the hardest to compare, because the scope boundary is doing all the work. Ask for the definition of a covered incident, the hour cap if there is one, and what specifically becomes billable extra. Then ask the same of the second vendor and compare those two definitions rather than the two monthly figures.

What legitimately moves the number

A provider pricing a retainer is estimating two things: how much work it would take to become useful to you, and how much risk it is accepting by promising to be available. Every variable below feeds one of those two.

Variables that move a retainer quote
VariableWhy it moves the price
Estate size and complexityEndpoint, server and identity counts, number of cloud tenants, and whether operational technology is in scope
Number of jurisdictionsEach country adds a supervisory authority, a language, a timezone and possibly a data-residency constraint
Service tierThe response target is explicitly a function of the tier, not a fixed property of the provider
Coverage windowWhether the same numeric target survives nights, weekends and public holidays
On-site attendanceWhether responders travel, within what time, and at whose cost
Evidentiary standardWhether findings must survive litigation or a criminal referral, which changes chain of custody, tooling and reporting
Third parties in the loopWhether the provider must interface with a regulator, an insurer, a parent group or a managed service provider
Readiness bundled inWhether plan review, exercises and compromise assessment sit inside the fee or are billed on top

Two things that do not legitimately move it: your industry’s reputation for being attacked, and the provider’s assessment of how frightened you are. If a quote moves substantially after you mention a recent incident at a competitor, you are being priced on urgency rather than scope.

How to compare two quotes honestly

Headline fees are not comparable, because they are attached to different scopes and different targets. Four numbers and one document make them comparable.

  • The retained rate and the walk-in rate. Ask both providers for both. The gap is what the fee is really buying, and it varies far more between providers than the fee does.
  • The out-of-hours multiplier. Most incidents that matter start outside business hours. A retainer whose rate doubles at 18:00 is a different proposition from one that does not.
  • The post-block rate. If a prepaid block is involved, the rate that applies after it is exhausted governs the expensive part of a real incident.
  • The onboarding cost. Included, discounted or extra. If it is extra, add it to the fee before comparing, because a retainer without onboarding is a different product.
  • The scope table. Take the six services from the FIRST CSIRT Services Framework: report acceptance, incident analysis, artifact and forensic evidence analysis, mitigation and recovery, incident coordination, crisis management support. Mark each in or out for both quotes. That single table usually explains most of the price difference.

Budgeting it inside a regulated organisation

If you are a DORA financial entity, one clause changes the economics of the negotiation. Article 30(2)(f) requires the contractual arrangement to include an obligation on the ICT third-party service provider “to provide assistance to the financial entity at no additional cost, or at a cost that is determined ex-ante, when an ICT incident that is related to the ICT service provided to the financial entity occurs”. Note what that covers and what it does not: it bites where the incident relates to the service the provider itself supplies. It is nonetheless a useful reference point when a provider resists fixing rates in advance.

Article 30(3)(a) then requires, for services supporting critical or important functions, full service level descriptions “with precise quantitative and qualitative performance targets”. A provider unwilling to write a number into the contract is a provider you cannot use for those functions, regardless of price.

Under NIS2 the constraint is different but real. Article 21(2)(d) makes supply chain security one of the minimum measures, and Article 21(3) requires entities to take into account the vulnerabilities specific to each direct supplier and service provider. Assessing a responder that will hold privileged access to your whole estate is work, and it belongs in the budget line next to the fee.

A note on what a cheap retainer usually is

The cheapest quote in a shortlist is almost always a standby agreement with a long target, no onboarding and analysis-only scope. That is a legitimate product, and for an organisation with a real 24/7 team it may be exactly right. It is not the same product as the most expensive quote, and the difference is not the provider’s margin.

The honest way to close the comparison is to write down what you expect to happen in the first four hours of a serious incident, then check which quotes can actually deliver it. The scoping tool produces that expectation as SLA wording, and the SLA guide explains why the wording matters more than the number attached to it.

Sources

  1. Mandiant Incident Response Services Google Cloud Publishes a two-hour response time and pre-negotiated terms with pre-paid funds for proactive services, training and incident response. No price published. Checked 13 September 2026.
  2. Unit 42 Incident Response Palo Alto Networks Publishes that response SLAs range from 24 hours to two hours by retainer and service level. No price published. Checked 13 September 2026.
  3. Incident Response Arctic Wolf Publishes a one-hour response time, bundled IR planning and tabletop exercise, and a saving of up to 70 per cent against a standalone emergency engagement. No price published. Checked 13 September 2026.
  4. Incident Response services CrowdStrike Publishes 24/7/365 availability and global deployment within hours, with no numeric target and no price. Checked 13 September 2026.
  5. Regulation (EU) 2022/2554 (DORA), Article 30 EUR-Lex · 2022 Key contractual provisions, including 30(2)(f) on assistance at no additional cost or a cost determined ex ante, and 30(3)(a) on precise quantitative and qualitative performance targets.
  6. Directive (EU) 2022/2555 (NIS2), Article 21 EUR-Lex · 2022 Point (2)(d) on supply chain security and Article 21(3) on assessing each direct supplier and service provider.
  7. Good Practice Guide for Incident Management ENISA · 2010 Worked prioritisation example in which contracted SLA customers receive priority one service and the remaining constituency receives best effort.
  8. CSIRT Services Framework, version 2.1 FIRST The six services inside incident management, usable as a scope comparison table.

Follow-up

Questions this raises

Why will nobody give me a ballpark?
Because the honest ballpark spans an order of magnitude. The same provider might sell a small organisation a standby agreement with a next-business-day target and sell a multinational bank a prepaid fund with a two-hour target, round-the-clock coverage, bundled exercises and audit rights. Those are different products wearing the same word. A provider that quotes a number before understanding your estate is quoting a product it has not scoped.
Is a retainer cheaper than paying an emergency rate once?
It depends entirely on whether you have an incident and how large it is. The comparison people actually make is not financial, it is about time: a retainer removes the procurement day and the discovery hours from the start of an incident. If you want to make it financial, ask for the retained and walk-in rates and model the crossover point at a realistic engagement size.
Should the retainer fee count against the first invoice?
In a prepaid model it inherently does, because the fee is the balance. In a standby model, ask. Some providers credit part of the standby fee against the first engagement, and it is a reasonable thing to request when you are also being asked to pay a premium rate.
Can we reduce the price by lowering the response target?
Yes, and that is the cleanest lever available, because the target is explicitly a function of the tier. It is also the lever most likely to make the retainer useless. Decide the target from your statutory clocks first: DORA gives four hours from classification, NIS2 gives 24 hours from awareness, the GDPR gives 72 hours. Then buy the cheapest tier that lets you meet them.