Incident Response Retainer, Priority Access Before You Need It.
When an incident hits, procurement delay and unfamiliarity with your environment cost you the most in those first hours. A retainer removes both, guaranteeing your organisation priority access to the DFIR team, 24/7/365, at a flat rate, with everything already in place before you need us.
Incident Response Retainer, Priority Access Before You Need It.
When an incident hits, procurement delay and unfamiliarity with your environment cost you the most in those first hours. A retainer removes both, guaranteeing your organisation priority access to the DFIR team, 24/7/365, at a flat rate, with everything already in place before you need us.
50 Hours of CREST-Certified DFIR Expertise
Engaging a DFIR (digital forensic incident response) partner with CREST Cyber Security Incident Response (CSIR) accreditation ensures your investigation meets internationally recognised standards. We apply proven methodologies, disciplined evidence handling and deep technical expertise to manage complex incidents across diverse environments.
01
Detect & Escalate
Endpoint - Identity - Cloud - Email - Network
02
24/7 Incident Response Activation
03
Analyse - Contain - Investigate - Respond
04
Containment & Recovery
Remediation - System restoration
05
Post-Incident Improvement
Root cause - Lessons learned - Preparedness
Why it Matters?
When an incident hits, the organisations that recover fastest are the ones who already had a partner in place. A retainer removes the delays that cost the most in those first hours.
-
No time lost sourcing and vetting a DFIR partner mid-incident
-
No unfamiliarity with your environment when every hour counts
-
Priority access ahead of non-retainer clients
-
A pre-agreed cost, not a crisis-time negotiation
-
Hours that flex across readiness, exercising and investigation work, not just response
-
A direct line to a team who already know your environment
Our Approach
Every retainer runs on the same simple cycle, so nothing needs figuring out when an incident actually hits.
Activation & Onboarding
Nominated contacts, pre-provisioned access and tooling are all set up before you ever need us. We deploy your response runbook and complete environment familiarisation, so nothing needs arranging in the middle of an incident.
Beyond Response
Once response needs are met, the same pool extends across any other service in this catalogue, from readiness assessments to threat intelligence. Nothing sits unused if there's no live incident to respond to.
Incident Response
Hours draw down first against live incident response, covering investigation and containment as the incident actually unfolds. This keeps priority access available exactly when it matters most.
Annual Maintenance
A scheduled yearly check confirms that response readiness still holds, with access re-validated and agents and collectors confirmed healthy. Contacts and the runbook are refreshed at the same time, before the cycle repeats.
What Else Can I Use My Retainer Hours For?
▪ This can include:
Frequently Asked Questions
How many hours do I get, and by when do I need to use them?
The standard retainer includes 50 hours over a 12-month term. For organisations needing a larger allocation or a tailored structure, Custom and MSP/Group White-Label packages are available on request.
Can retainer hours be used for anything other than a live incident?
Yes. Hours draw down against incident response first, then against any other service in the DFIR catalogue, including readiness assessments, exercising and threat intelligence, so there's no shortage of ways to put them to work throughout the year.
Ready to Lock In Priority Access?
Every hour spent sourcing a DFIR partner during an incident is an hour attackers keep moving. Get in touch with our team to scope the right retainer structure for your organisation, before you need it.