What does an incident response retainer cost?
Search for the cost of an incident response retainer and you will find ranges. None of them comes from a provider. This guide explains why the figure is not published, what is actually knowable about the price, and how to compare two quotes without pretending the headline fee is the comparison.
Start with the verified negative
On 13 September 2026 we checked the public service pages of four providers that sell incident response retainers: Mandiant through Google Cloud, Unit 42 at Palo Alto Networks, CrowdStrike and Arctic Wolf. Between them those pages publish response times, service descriptions and, in two cases, what prepaid funds may be spent on. None of them publishes a price, an hourly rate or an hour count. Every page routes a buyer to a contact form.
That is not evasion, it is the shape of the product. A retainer is priced against a specific estate, a specific service tier and a specific set of obligations, and the same provider will quote two organisations of identical headcount very differently. Any figure you find online is therefore either one customer’s contract, repeated out of context, or an estimate somebody assembled from the same absence of data you are looking at.
You are buying three things, and only one of them is labour
It helps to separate the fee from the work. A retainer fee buys three distinct things, and understanding which of them you actually need is what decides the model.
- Removal of procurement latency. The contract, the data processing agreement, the liability position and the rate card already exist when the incident starts. This is the component every retainer includes and the one that is impossible to buy after the fact.
- A queue position. Retained customers are served first. ENISA describes the same arrangement from the responder’s side in its incident management guidance: contracted customers get priority one service, and the rest of the constituency gets a good-effort service.
- A discount against the emergency rate. Arctic Wolf frames the value of its retainer in exactly these terms, advertising a saving of up to 70 per cent against a standalone emergency incident response engagement. Whatever the number is for your shortlist, that gap is the financial product.
Labour is the fourth thing, and in two of the three models you have not bought any of it yet.
The three models, and what each one costs you when nothing happens
| Model | What the fee covers | A year with no incident | The term to negotiate hardest |
|---|---|---|---|
| Prepaid block | Hours or funds bought up front, drawn down at an agreed rate | The balance is either spent on readiness, rolled over, or lost | Whether unused balance can be spent on proactive work, and whether it rolls over |
| Standby | The contract and the response target; response billed when used | A small fee, and no provider familiarity gained | The rate that applies when it is used, including the out-of-hours rate |
| Subscription | A defined scope, often bundled with monitoring | The monitoring was consumed; the response scope was not | Exactly where the covered scope ends and billable work begins |
Prepaid block
You buy a quantity of hours or a fund and draw against it. Mandiant publishes this structure openly: pre-negotiated terms and pre-paid funds for proactive services, training and incident response. Note the order of that list. The prepaid pot is described first as a way to buy readiness, and only third as a way to buy response.
The buyer risk is straightforward: buy too little and the block is exhausted in the first week of a real incident, at which point the post-block rate governs everything; buy too much and you have prepaid for work you will not do. Sizing advice that does not know your estate is worthless, but one principle holds: size the block against your worst realistic week, not your average month, and then make sure the balance is spendable on readiness so that a quiet year still returns something.
Standby
A small or nominal annual fee, sometimes folded into another product, buys the contract and the response target. The response itself is billed at pre-agreed rates. The cash stays in the business until something happens, and the procurement latency is still gone.
The catch is that a standby agreement funds no onboarding. A provider that has never seen your network, does not know which identity provider you use and has no tested access method will spend the first hours of your incident doing discovery you could have paid for in advance at a calmer rate. If you choose this model, budget one onboarding session and one exercise as separate line items.
Subscription
A fixed recurring fee for a stated scope. Frequently the response sits alongside managed detection, on the sensible logic that the team that sees the alert should be the team that acts on it.
Subscriptions are the easiest to budget and the hardest to compare, because the scope boundary is doing all the work. Ask for the definition of a covered incident, the hour cap if there is one, and what specifically becomes billable extra. Then ask the same of the second vendor and compare those two definitions rather than the two monthly figures.
What legitimately moves the number
A provider pricing a retainer is estimating two things: how much work it would take to become useful to you, and how much risk it is accepting by promising to be available. Every variable below feeds one of those two.
| Variable | Why it moves the price |
|---|---|
| Estate size and complexity | Endpoint, server and identity counts, number of cloud tenants, and whether operational technology is in scope |
| Number of jurisdictions | Each country adds a supervisory authority, a language, a timezone and possibly a data-residency constraint |
| Service tier | The response target is explicitly a function of the tier, not a fixed property of the provider |
| Coverage window | Whether the same numeric target survives nights, weekends and public holidays |
| On-site attendance | Whether responders travel, within what time, and at whose cost |
| Evidentiary standard | Whether findings must survive litigation or a criminal referral, which changes chain of custody, tooling and reporting |
| Third parties in the loop | Whether the provider must interface with a regulator, an insurer, a parent group or a managed service provider |
| Readiness bundled in | Whether plan review, exercises and compromise assessment sit inside the fee or are billed on top |
Two things that do not legitimately move it: your industry’s reputation for being attacked, and the provider’s assessment of how frightened you are. If a quote moves substantially after you mention a recent incident at a competitor, you are being priced on urgency rather than scope.
How to compare two quotes honestly
Headline fees are not comparable, because they are attached to different scopes and different targets. Four numbers and one document make them comparable.
- The retained rate and the walk-in rate. Ask both providers for both. The gap is what the fee is really buying, and it varies far more between providers than the fee does.
- The out-of-hours multiplier. Most incidents that matter start outside business hours. A retainer whose rate doubles at 18:00 is a different proposition from one that does not.
- The post-block rate. If a prepaid block is involved, the rate that applies after it is exhausted governs the expensive part of a real incident.
- The onboarding cost. Included, discounted or extra. If it is extra, add it to the fee before comparing, because a retainer without onboarding is a different product.
- The scope table. Take the six services from the FIRST CSIRT Services Framework: report acceptance, incident analysis, artifact and forensic evidence analysis, mitigation and recovery, incident coordination, crisis management support. Mark each in or out for both quotes. That single table usually explains most of the price difference.
Budgeting it inside a regulated organisation
If you are a DORA financial entity, one clause changes the economics of the negotiation. Article 30(2)(f) requires the contractual arrangement to include an obligation on the ICT third-party service provider “to provide assistance to the financial entity at no additional cost, or at a cost that is determined ex-ante, when an ICT incident that is related to the ICT service provided to the financial entity occurs”. Note what that covers and what it does not: it bites where the incident relates to the service the provider itself supplies. It is nonetheless a useful reference point when a provider resists fixing rates in advance.
Article 30(3)(a) then requires, for services supporting critical or important functions, full service level descriptions “with precise quantitative and qualitative performance targets”. A provider unwilling to write a number into the contract is a provider you cannot use for those functions, regardless of price.
Under NIS2 the constraint is different but real. Article 21(2)(d) makes supply chain security one of the minimum measures, and Article 21(3) requires entities to take into account the vulnerabilities specific to each direct supplier and service provider. Assessing a responder that will hold privileged access to your whole estate is work, and it belongs in the budget line next to the fee.
A note on what a cheap retainer usually is
The cheapest quote in a shortlist is almost always a standby agreement with a long target, no onboarding and analysis-only scope. That is a legitimate product, and for an organisation with a real 24/7 team it may be exactly right. It is not the same product as the most expensive quote, and the difference is not the provider’s margin.
The honest way to close the comparison is to write down what you expect to happen in the first four hours of a serious incident, then check which quotes can actually deliver it. The scoping tool produces that expectation as SLA wording, and the SLA guide explains why the wording matters more than the number attached to it.
Sources
- Mandiant Incident Response Services Publishes a two-hour response time and pre-negotiated terms with pre-paid funds for proactive services, training and incident response. No price published. Checked 13 September 2026.
- Unit 42 Incident Response Publishes that response SLAs range from 24 hours to two hours by retainer and service level. No price published. Checked 13 September 2026.
- Incident Response Publishes a one-hour response time, bundled IR planning and tabletop exercise, and a saving of up to 70 per cent against a standalone emergency engagement. No price published. Checked 13 September 2026.
- Incident Response services Publishes 24/7/365 availability and global deployment within hours, with no numeric target and no price. Checked 13 September 2026.
- Regulation (EU) 2022/2554 (DORA), Article 30 Key contractual provisions, including 30(2)(f) on assistance at no additional cost or a cost determined ex ante, and 30(3)(a) on precise quantitative and qualitative performance targets.
- Directive (EU) 2022/2555 (NIS2), Article 21 Point (2)(d) on supply chain security and Article 21(3) on assessing each direct supplier and service provider.
- Good Practice Guide for Incident Management Worked prioritisation example in which contracted SLA customers receive priority one service and the remaining constituency receives best effort.
- CSIRT Services Framework, version 2.1 The six services inside incident management, usable as a scope comparison table.
Follow-up
Questions this raises
Why will nobody give me a ballpark?
Is a retainer cheaper than paying an emergency rate once?
Should the retainer fee count against the first invoice?
Can we reduce the price by lowering the response target?
Keep reading
More from the file
-
What is an incident response retainer?
The definition, the six components that recur across real agreements, the three commercial models, and the honest list of things a retainer does not do for you.
Read the guide -
The response-time SLA: what the number actually promises
One hour, two hours, next business day. None of those figures says what the responder must have done by then, what starts the clock, or what happens when the target is missed.
Read the guide -
NIS2, DORA and the incident response retainer
Neither instrument requires a retainer. Both require a capability, both run clocks a retainer has to feed, and one of them regulates the retainer contract itself, clause by clause.
Read the guide