Incident Response·~16 min read·3,425 words

The IR retainer decision: picking a firm, scoping the contract, knowing what happens at 2amPremium

Practitioner reference for CISOs, CFOs, GCs, and the executive about to sign an incident response retainer they have not really read · 2026-05-25 · Written from twelve years of either being the retainer's customer, advising on the retainer's selection, or watching the retainer's actual performance during a serious incident and concluding that the customer had bought the wrong product entirely


Why this decision matters more than it looks

The incident response retainer is a strange contract. You pay for a service you hope never to use, with terms that only matter on the worst day of your year, against a vendor whose performance you cannot observe until the moment you most need to be confident in them. Most CISOs sign the retainer because the cyber insurance policy or the customer questionnaire requires it; most CISOs do not actually know whether their retainer will perform. The first time you find out is usually the wrong time.

I have watched perhaps forty IR retainer activations closely over the last twelve years. Maybe twenty-five performed well; maybe ten performed adequately; maybe five performed badly enough that the client should have terminated the engagement mid-incident. The performance distribution does not correlate neatly with the brand on the retainer’s letterhead. Two of the worst performances I have observed came from firms whose names you would recognise; two of the best came from smaller specialists who happened to have the right person on the on-call rota that night.

This guide is what I tell clients when they ask me to help them pick or renegotiate an IR retainer. The principles transfer across the major retainer markets — Mandiant / Google Cloud, CrowdStrike, Kroll, Stroz Friedberg, Coalition’s IR-from-insurance offering, the Big Four IR practices, the boutique specialists. The decision logic is portable; the actual pick depends on your specific risk profile and your existing supplier relationships.


What the retainer actually is

An IR retainer is, structurally, a pre-negotiated contract for incident response services that obligates the firm to respond within a specified time at a pre-negotiated rate. The retainer fee buys you priority access to the firm’s capacity, not the response itself. The response is billed on top of the retainer, typically at the firm’s rack rate, often with hour bands that consume the prepaid retainer hours first and then bill the overage.

Three structural variants worth distinguishing:

Pre-paid retainer with consumption. You pay an annual fee that includes a specified number of hours of response. Hours unused at year-end either roll over (rare), convert to other services like proactive assessments (common), or expire (also common). Hours over the included allocation bill at the contracted rate. The retainer fee gets you the contracted response time and the contracted rate.

Zero-dollar retainer with priority access. Some firms offer a zero-fee retainer that obligates them to respond within a specified time but does not include any prepaid hours. All response work bills at the contracted rate. The retainer is purely a priority-access mechanism. This model is increasingly common among cyber insurance carriers offering bundled IR.

Hours-only retainer. A pure consumption model where you commit to a minimum annual spend, but the firm responds priority to your needs as long as you are an active retainer client. The annual minimum is consumed by whatever IR work occurs; if there is no incident, the spend converts to proactive engagements like tabletop facilitation, IR readiness assessments, or threat hunting.

The variant matters because the cost structures look different. A US$50,000 pre-paid retainer with 100 included hours has different math from a zero-dollar retainer where the first incident might bill $80,000 at the contracted rate. Read the contract carefully; the headline retainer fee is not the cost.


Why you need one (and when you don’t)

The standard answer is “you need one because the cyber insurance requires it.” That is true but uninteresting; it begs the question of why the cyber insurance requires it. The deeper answer is that an IR retainer reduces the time-to-engaged-experts during an incident, which materially affects the incident’s outcome.

The mechanics: in a serious incident, every hour between detection and expert engagement is an hour during which the attacker is operating in your environment. Containment delayed is dwell time extended. Without a retainer, the cycle from “we have an incident” to “Mandiant is on the bridge” is typically 12-48 hours: identifying which firm to engage, negotiating an emergency engagement letter at non-negotiated rates, completing onboarding (NDAs, data-sharing terms, access provisioning), and getting the first responders on the line. With a retainer, the cycle is 2-6 hours depending on the contracted response time and the firm’s actual delivery.

For organisations with a meaningful incident probability, the retainer is worth the cost. Meaningful incident probability is, in my estimation, any company with one or more of:

  • Internet-facing applications processing personal data or financial transactions
  • Regulated-sector operations (banks, NBFCs, insurers, capital markets entities, healthcare)
  • More than 100 employees
  • A customer security questionnaire population that asks for IR readiness evidence
  • A cyber insurance policy that names IR retainer requirements as a coverage condition

Organisations below this threshold can defensibly operate without a retainer, relying on their cyber insurance carrier’s bundled IR (most major policies include some form of IR access during a covered incident) and their general counsel’s relationships with IR firms. The defensibility erodes as the organisation grows; my rule of thumb is that any organisation with annual revenue above ₹50 crore (US$6M) should have a retainer.


The picking criteria

Five criteria worth applying when evaluating IR firms. Most procurement processes focus on the first two; the last three are where the real differentiation lives.

One: response time guarantee. The contracted time from your activation call to a first responder on the bridge. Common contracted times: 2 hours (premium retainers), 4 hours (standard), 8 hours (basic). The contracted time is what you can hold the firm to; the actual time experienced may be different. Ask for evidence of recent activation response times from existing clients in your time zone — most firms will share this in aggregate form even when they cannot share specific clients.

Two: technical depth in your specific environment. Does the firm have demonstrated experience with your cloud provider, your operating systems, your applications, your industry. A firm with deep AWS expertise but limited Azure depth is a poor match for an Azure-heavy environment. A firm with deep enterprise on-premises expertise but limited cloud-native experience is a poor match for a SaaS company. Ask for the named senior responders’ resumes and look at their actual deployment experience.

Three: the firm’s senior responder availability. The proposal will name senior partners and senior responders. The actual responders on your incident may be different — the named seniors may be on other engagements or may be in different time zones. Ask specifically: “If I activate at 2am Mumbai time on a Tuesday, who is the most senior person I get?” The honest answer might be a regional manager handing off to a US-based team that comes online later, or a regional lead taking the activation directly. The honest answer determines actual response quality.

Four: the firm’s external relationships. During a serious incident, you need the IR firm to coordinate with external counsel, with the cyber insurance carrier’s panel counsel, with notification advisors, sometimes with law enforcement, sometimes with the regulator’s specific contacts, sometimes with the IT vendor whose system is compromised. The firm’s existing relationships with these actors matter; the firm that has worked with your specific external counsel or your specific insurance carrier brings shorter coordination cycles than the firm starting fresh.

Five: the firm’s experience with your regulator(s). If you are RBI-regulated, has the firm done IR work with banks and NBFCs that have engaged with RBI cybersecurity supervision? If you are SEBI-regulated, has the firm dealt with CSCRF inspections post-incident? If you are GDPR-relevant, has the firm written reports that satisfied EU supervisory authorities? Regulatory experience is often the deciding factor between two technically-equivalent firms.

A short list of red flags during the evaluation:

  • The firm cannot or will not name the actual senior responders who would handle your activation
  • The firm’s recent client references all come from a specific industry or geography that does not match yours
  • The contracted response time is significantly worse than competitor offers, justified by “we are more thorough”
  • The firm declines to share even aggregate response-time evidence
  • The firm’s rack rate is dramatically higher than competitor offers without a corresponding capability differentiation
  • The contract has indemnification clauses that disadvantage you significantly (excluding consequential damages, capping liability at the retainer fee, requiring arbitration in their home jurisdiction)

The contract details that matter

Most IR retainer contracts are negotiated by procurement on the basis of the headline fee and the headline response time. The clauses that matter during a real incident are usually buried deeper and rarely negotiated. The ones I look for:

Scope of work definition. What activities are covered by the retainer hours and what is billed separately. Forensic analysis is usually covered; report writing may or may not be; expert testimony in subsequent litigation is usually separate; remediation execution is usually separate. The fine print of what counts toward your prepaid hours determines whether the included hours actually cover the incident or stop short.

The “in-scope incident” definition. Some retainers cover only specific incident types (ransomware, data breach, system compromise) and exclude others (insider threats, intellectual property theft, supply chain compromises). Read this carefully — the exclusion list is sometimes broader than the inclusion.

Engagement activation mechanics. Who can activate, how, with what authorisation. Some retainers require the named CISO to activate; others accept any authorised contact. The mechanics matter at 2am when the CISO may be unreachable and the deputy needs to act.

Confidentiality and data handling. The firm will handle highly sensitive information during an investigation. What is their data retention policy after the engagement closes? Where does the data live? Who in the firm has access to it? Can you require return or destruction of all artefacts after report delivery? The post-engagement data position is sometimes overlooked and matters significantly for subsequent litigation and regulatory inquiry.

Privilege protection. In many jurisdictions, the IR work product is more defensible against discovery if it is engaged through legal counsel under attorney-client privilege. The retainer contract should permit and ideally facilitate this structure — engagement letters that allow the work to be commissioned through external counsel rather than through the company directly. This is one of the most-missed contract details and one of the most impactful when litigation follows the incident.

Subcontracting and assignment. Can the firm subcontract any of the work? To whom? With what oversight? Some firms subcontract specific technical disciplines (mobile forensics, cloud-specific analysis) to specialists. The contract should require disclosure of subcontractors and your right to refuse specific subcontractors.

Pricing escalation. What is the firm’s right to increase rates? Annual contractual escalators are normal (typically 3-5% per year); mid-engagement rate increases on the rack rates billed against your retainer hours are not. The contract should fix the rates for the engagement duration once activated.

Exit and renewal terms. Can you terminate the retainer for convenience? With what notice? What happens to unused prepaid hours? Auto-renewal clauses often include onerous notice periods for non-renewal (90-180 days); negotiate these to 30-60 days at signing.

Cyber insurance integration. If your cyber insurance carrier has a preferred-vendor panel, can the retainer’s IR firm work as a panel vendor for claim purposes? Carriers sometimes require panel vendors for indemnification of IR costs; a retainer firm that is not on the panel may produce out-of-pocket costs during a claim even though you have coverage.


What happens at 2am

The realistic sequence of an activation at an unfortunate hour, narrated from the customer’s side, with the questions you will want to have answered before the night happens.

T-0: detection. Your SOC alerts on suspicious activity. Triage suggests something serious — lateral movement, data exfiltration in progress, ransomware staging. The on-call SOC lead escalates.

T+0:15 to T+0:30: internal escalation. The CISO is paged. The IR escalation chain activates. The CISO decides whether to activate the retainer. This decision is non-trivial — activating prematurely costs money and signals; activating late lets the attacker progress. The decision should not require the CISO to think it through from scratch at 2am; it should be a documented criterion in the IR runbook with clear thresholds.

T+0:30 to T+1:00: activation. The CISO calls the retainer hotline. The activation is logged. The firm’s on-call lead acknowledges. Initial intake is captured. The contracted response clock starts.

T+1:00 to T+5:00: first response window. The firm’s senior responders dial in. NDAs are confirmed (the retainer pre-execution should have these in place; otherwise, the lawyers spend the first hour on paperwork). Initial briefing happens. The firm requests initial access and artefacts. Your team starts producing.

The first 4 hours are where retainers earn or lose their value. If the firm shows up with the contracted seniors, asks the right questions, identifies the immediate containment actions, and starts producing useful guidance within the first hour, the retainer was worth it. If the first responders are junior, ask basic questions, and need significant onboarding before producing value, the retainer was the wrong product.

T+5:00 to T+24:00: investigation depth. The firm goes deep on forensics. Endpoint telemetry analysis, network capture review, cloud log analysis, malware reverse engineering if applicable. Initial findings emerge. Containment recommendations sharpen. The customer’s team executes containment under the firm’s guidance.

T+24:00 onwards: extended engagement. Investigation continues. Reports are drafted. Regulator notifications are prepared. Communications strategy is developed. Recovery planning begins. The engagement typically runs 2-8 weeks for a serious incident, with active intensity dropping after the first week.

T+8 weeks onwards: report delivery and post-incident. Final reports delivered. Regulator interactions concluded. Litigation preparation if applicable. The IR firm transitions out; your team takes over the long-tail remediation and process improvements.

Three questions worth answering before the activation, not during:

  • What containment actions can be executed without legal sign-off? Containment that takes systems offline can have business impact that requires CEO or CFO approval. The decision authority for emergency containment should be in the IR runbook.
  • What is the threshold for regulator notification, and who decides? The 6-hour CIMS clock, the 72-hour GDPR clock, the DPDPA tiered notification clock all start before the IR firm finishes their investigation. The decision to notify cannot wait for the report.
  • What is the threshold for customer communication, and who decides? If the incident involves customer data, when do customers get told, what do they get told, who signs off on the language. The communications strategy needs the GC and the head of communications, not just the CISO.

The cost math

The economics of IR retainers vary widely by firm tier and contract structure. A short reality check:

Pre-paid retainer with hours, premium tier (Mandiant, CrowdStrike, Kroll): typically US$50,000-150,000 annually with 50-150 included hours. Rack rates US$450-650/hour for senior responders, US$700+ for principal-level.

Pre-paid retainer with hours, mid-tier (Stroz Friedberg, Big Four IR practices, regional specialists): typically US$25,000-60,000 annually with 40-100 included hours. Rack rates US$350-500/hour.

Zero-dollar retainer with priority (Coalition’s bundled IR, some carrier panels, smaller firms): zero retainer fee, response work billed at carrier-negotiated rates (often around US$300-450/hour) that may flow through cyber insurance coverage.

Indian-market specialists: typically ₹8-25 lakh annually for a retainer with 40-80 included hours, rack rates ₹15,000-30,000/hour for senior responders. Some are CERT-In empanelled, which is operationally important for RBI/SEBI-regulated entities.

For a moderately exposed mid-market company, the typical annual retainer spend is US$30,000-80,000 (₹25 lakh to ₹66 lakh). The unused-hours-converted-to-proactive model means that even years without incidents produce some value (tabletops, readiness assessments, threat hunting).

The cost relative to the cost of a serious incident: a contained ransomware incident in a mid-market company typically costs US$500,000-2M in direct response costs (IR firm, external counsel, communications, customer notification, regulatory) plus indirect costs (business disruption, customer churn, reputational). A retainer that reduces dwell time by 24 hours easily pays for itself across a few years of operations.

The honest counter: organisations that never have an incident pay the retainer with no realised value beyond the optionality. The cost is what it is; the value is conditional on incidents that may not happen. The retainer is insurance, not investment.


The relationship management

The retainer is not a fire-and-forget contract. The retainer that performs during an incident is the one where the customer and the firm have an active operating relationship before the incident. The discipline that produces this:

Quarterly check-ins. A 30-minute call with the firm’s account team every quarter. Updates on your environment changes, retainer hours utilisation, threat landscape relevant to your sector, upcoming changes on either side. Costs nothing; produces a relationship that activates faster during an incident.

Annual joint exercise. Use some of the prepaid hours for a tabletop exercise where the IR firm participates as themselves. This both tests the retainer’s response and produces operational improvements on both sides. The firm’s facilitation of a realistic scenario is often more valuable than internally-run tabletops.

Active utilisation of converted hours. Prepaid hours not consumed by incidents should be converted to proactive work — threat hunting, IR readiness assessments, IR runbook reviews, tabletop facilitation, post-incident retrospective audits. Letting hours expire at year-end signals to the firm that you are a low-engagement client; converting them produces ongoing value and a stronger relationship.

Annual contract review. Renew with eyes open. Compare to competitor offers every 2-3 years. Renegotiate response times if the firm is not delivering against the contracted commitment. Switch firms if the relationship is not producing the value you need.


When the retainer is failing

Signals during a real activation that the retainer is not performing:

  • The contracted seniors do not appear within the first 2 hours despite the contracted response time
  • The first responders are junior and require basic onboarding rather than engaging substantively
  • The firm asks for artefacts and information that should have been pre-staged in the retainer setup
  • The firm’s guidance is generic and not specific to your environment
  • The firm’s communication cadence is poor — no status updates, no clear next steps, no consistent point of contact
  • The firm’s report drafts are templated and lack specifics from your investigation

If you observe these signals during an active incident, you have a choice: continue with the firm and manage around the performance gap, or activate a second IR firm to operate alongside or replace the first. The second-firm activation is expensive (a non-retainer firm responds at higher rates and longer ramp time) but is sometimes the right call when the original firm is meaningfully underperforming.

The post-incident review should include an honest assessment of the IR firm’s performance against the retainer’s promises. If the firm underperformed, the renewal is at risk. The firm should be invited to address the gaps; their response indicates whether the renewal is salvageable.


What this guide does not cover

Three areas worth their own treatment:

  1. The cyber insurance interaction with IR retainers. Cyber insurance carriers often have specific IR firm requirements, claim notification protocols, and reimbursement mechanics that interact with your retainer choice. The carrier’s claims process, the panel vendor question, the legal-privilege structure under the policy — these warrant a dedicated guide.

  2. Specific retainer firm comparisons. I have not ranked specific firms by performance. The rankings shift; the firms acquire and are acquired by others; the senior personnel move between firms. Evaluate firms on your own basis at the time of purchase, using the criteria in this guide.

  3. The legal counsel decision for incident response. IR retainers handle the technical investigation; the legal coordination requires separate external counsel selection. The criteria for picking incident counsel are related but distinct. Worth its own treatment.


This guide is a practitioner reference, not procurement or legal advice. It reflects how IR retainer engagements typically work as of May 2026 in India and internationally, and is not affiliated with any specific IR firm. Compliance teams should adapt the framework to their specific risk profile, regulatory environment, and existing supplier relationships.

ControlForge maps IR readiness controls against ISO 27001, SOC 2, NIST CSF, RBI CSF, SEBI CSCRF, IRDAI, DPDPA, GDPR, and other frameworks, and the synthesis surface helps trace which IR capabilities carry compliance weight across multiple regimes.