Skip to main content
Cyber Crisis Management

Incident response retainer.
Help that is already contracted when the incident hits.

An Incident Response Retainer means you arrange cooperation, procedures and guarantees in advance. When an incident hits, you act immediately instead of signing contracts under pressure.

What is an Incident Response Retainer?

An Incident Response Retainer is your insurance against cyber crises. It includes guaranteed response times, pre-agreed procedures, knowledge of your environment and direct access to the CSIRT team. When an incident occurs, there is no startup time: the team knows your architecture, contacts and escalation procedures. Retainer hours can also be used proactively for threat hunting and exercises.

The Service

Ready before the incident happens

The retainer includes guaranteed response times, pre-agreed procedures, familiarity with your environment and direct access to the CSIRT team. When an incident occurs, there is no startup time: the team already knows your architecture, your contacts and your escalation procedures.

Retainer hours can also be used proactively: for threat hunting, compromise assessments, incident response exercises or security advice. This maximises value even when no incident occurs.

More and more insurers and regulators require an IR retainer or demonstrable IR capacity. A retainer with DEFION meets that requirement and gives management confidence that professional help is immediately available.

Why it matters

Without a retainer, you lose critical time

  • Onboarding takes time you do not have during a crisis

    Without a retainer, an IR team spends the first hours getting familiar with your environment. With a retainer, that knowledge is already in place. In ransomware incidents, the first hours are decisive.

  • Insurers and regulators require demonstrable IR capacity

    Cyber insurers increasingly require a qualified IR retainer. NIS2 requires organisations to have demonstrable incident handling capacity. A retainer with DEFION meets both requirements.

  • Ad hoc engagement is more expensive and slower

    Engaging an IR team without a pre-existing relationship means higher rates, slower startup and no guaranteed availability. During a major incident, qualified IR teams are in high demand.

Retainer vs ad-hoc

Retainer or ad-hoc incident response: the difference in the first hours

With a retainer

  • Guaranteed response time, 24/7, in writing
  • The CSIRT already knows your architecture, contacts and escalation path
  • Rates agreed in advance, no crisis surcharge, no procurement under pressure
  • Priority during large incident waves
  • Unused hours go to threat hunting, compromise assessments and exercises
  • Evidence for insurers and regulators that IR capacity is arranged

Ad-hoc, without a retainer

  • Start as soon as a team is available; during waves that can take days
  • The first hours go to onboarding instead of containment
  • Contracting, NDAs and rates negotiated while systems are down
  • Crisis rates apply
  • No preventive value in quiet periods
  • Often not accepted by insurers as "demonstrable IR capacity"

DEFION helps organisations without a retainer too, through the 24/7 incident response service. The retainer removes the waiting, the onboarding and the negotiation from the moment you can least afford them.

The agreement

What should be included in an incident response retainer agreement

Whether you sign with DEFION or someone else, check that the contract answers these points. If one is missing, you will discover it during the incident.

Response time per severity level (first contact, remote team active, on site), measured 24/7
Scope: containment, forensics, malware analysis, recovery support, crisis management, regulator and insurer reporting
Number of included hours, what happens to unused hours and the rate for additional hours
No crisis surcharge and no renegotiation during an incident
Onboarding deliverables: environment documentation, contact list, escalation path, playbooks
A named team and a single 24/7 contact path, not a generic mailbox
Evidence handling and chain of custody for insurers and legal proceedings
An annual exercise or readiness check and an update of your environment information
Confidentiality, data handling and where your data is analysed
Term, renewal and what you keep if you do not renew
Scope

What the DEFION retainer includes

Guaranteed response times (SLA)
Pre-inventoried environment and procedures
24/7 access to CSIRT team
Flexible use of retainer hours (IR, hunting, assessment)
Periodic readiness checks
Annual incident response exercise
Priority access during major incident waves
Named DFIR contacts who know your environment
Methodology

How the retainer works

01

Onboarding

Inventory of your environment, contacts, escalation procedures and communication channels. The team learns your architecture before any incident occurs.

02

Readiness assessment

Assessment of your current IR readiness and recommendations for improvement. Gaps are identified and addressed during the retainer period.

03

SLA and procedures

Documenting response times, communication agreements and escalation paths. All agreed before any incident occurs.

04

Periodic maintenance

Annual update of environment information and exercise. The retainer stays current as your environment evolves.

05

Activation on incident

Immediate mobilisation in accordance with the agreed SLA. No startup time, no contracting under pressure, no unfamiliar team.

What You Receive

Deliverables

  • Retainer agreement with SLA
  • Environment documentation and contact list
  • Readiness assessment report
  • Annual IR exercise
  • Flexible deployment of retainer hours
  • 24/7 hotline access
  • Named CSIRT contacts who know your environment
For Whom

Designed for organisations that cannot afford downtime

Organisations that want guaranteed IR capacity

You need certainty that professional help is immediately available when an incident occurs. A retainer provides that guarantee.

Companies with cyber insurance requiring an IR retainer

Many insurers require a qualified IR retainer as a condition of coverage. DEFION meets the qualifications insurers expect.

Organisations with NIS2 reporting obligations

NIS2 requires demonstrable incident handling capacity. A retainer with DEFION provides the documented evidence regulators require.

Boards that want certainty about crisis response

Under NIS2, boards are personally liable for incident management. A retainer gives them the assurance that professional support is in place.

Tech stack

Vendor-agnostic by design

DEFION works with the tooling you already have, or brings ours. No vendor lock-in.

Microsoft Defender
CrowdStrike Falcon
No More Ransom
Frequently Asked Questions

FAQ

What does a retainer cost if there is no incident?
Retainer hours are flexibly deployable for preventive activities: threat hunting, compromise assessments, exercises and security advice. You are not paying for nothing but investing in preparedness.
How fast is the guaranteed response time?
Depending on the chosen service level: standard 4 hours, premium 2 hours. For critical incidents, the team is mobilised immediately.
Can we use the retainer for proactive security?
Yes. The hours are flexibly deployable for threat hunting, compromise assessments, tabletop exercises and security advice.
How often is the environment information updated?
At minimum annually and upon significant changes to your environment. The team proactively reaches out for updates.
Is a retainer accepted by cyber insurers?
Yes. An IR retainer with a qualified IR partner is a frequently required condition by cyber insurers. The DEFION CSIRT team meets the qualifications insurers expect, and the retainer agreement names the response times and scope insurers ask to see.
What does an incident response retainer cost?
You pay a fixed annual or monthly fee for a guaranteed response time and a block of CSIRT hours, plus pre-agreed rates for hours beyond that block. There is no crisis surcharge. Unused hours go to proactive work such as threat hunting, compromise assessments and exercises. The fee depends on the response time you choose, the size and complexity of your environment and the number of hours. You receive a fixed quote after a short intake.
Do I need an incident response retainer?
You need one if downtime or data loss hits your revenue or your customers within hours, if your cyber insurer or a regulator (NIS2, DORA) asks for demonstrable incident response capacity, or if you do not have in-house forensic and crisis management skills. If you can afford to wait days for help and have those skills internally, ad-hoc incident response may be enough.
What is the difference between a DFIR retainer and an incident response retainer?
In practice the same service. A DFIR (digital forensics and incident response) retainer makes explicit that forensic investigation, evidence preservation and malware analysis are included alongside containment and recovery. The DEFION retainer always covers both.

Ready before the next incident?

Arrange your IR retainer now. Know that professional help is guaranteed when you need it most.