
Incident Response Retainer: What the Quote Should Say About Hours, Overage, and the Response Clock
An incident response retainer quote can hide the terms that decide its value. What prepaid hours, overage, and the response clock should state before you sign.
The short answer
An incident response retainer is only as good as four lines in the quote: how many hours are prepaid and what happens to the ones you do not use, what an hour costs after the pool runs out, when the response clock starts and what ends it, and what counts as an incident worth activating it for. Most retainers are sold on the response-time headline. The terms that decide whether the money was well spent are the commercial ones underneath it, and they are the ones to compare line by line before you sign.
Who this is for
This is for the Head of Security, CISO, or finance partner at a casino, crypto exchange, or fintech who has been asked to put an incident response retainer in place and is holding one or more quotes. It covers the commercial terms. For the readiness work that makes a retainer fast in practice (named contacts, pre-provisioned access, evidence preservation), see incident response retainers for online casinos; this article does not repeat it.
What a retainer is, and what it is not
A retainer reserves capacity. You pay in advance so that when something goes wrong, a team that already knows your environment answers first, instead of you running a procurement process during an intrusion. The value is in the first hours, when a cold engagement spends its time on contracts, access, and orientation.
It is not a promise about outcome. No retainer guarantees containment by a given time, because that depends on what the attacker did before anyone noticed. Treat any wording that implies otherwise as a reason to ask more questions.
The four terms that decide the value
1. The hour pool
Most retainers include a number of prepaid hours. The quote should state:
- The number of hours, and the period they cover (monthly, annual).
- What the pool can be spent on: live incident response only, or also forensics, reporting, and regulator communication.
- What happens to unused hours: expire, roll over, or convert to proactive work.
- Whether proactive work, such as a tabletop exercise or a plan review, draws from the same pool.
A pool that expires silently and cannot be converted turns the retainer into insurance with no way of getting any use from it in a quiet year. That can still be a reasonable purchase, but it should be a choice you made, not a clause you found later.
2. Overage
A serious incident can use more hours than any sensible pool includes. The overage terms are what you will actually live with:
- The hourly rate beyond the pool, and whether it equals the retainer rate or the provider's standard rate.
- Whether work continues automatically past the pool, or stops for a new approval.
- Who on your side can authorise additional spend at 3 a.m., named in the contract.
- Whether there is a cap, and what the provider does when it is reached.
Overage that needs a fresh purchase order mid-incident gives back the speed the retainer was meant to buy.
3. The response clock
Every retainer advertises a response time. Read the definition, not the number:
| Question | Why it matters |
|---|---|
| What starts the clock? | A call, a ticket, an email, and an alert from your SOC are not equivalent |
| Which channel counts? | A shared mailbox read at 9 a.m. is not a 24-hour channel |
| Does it apply out of hours and on holidays? | Many incidents start there |
| What ends the clock? | Usually "a responder on the call", which is not containment |
| What remedy applies if it is missed? | Credit, refund, or nothing |
The last row is the one most quotes omit. A response commitment with no stated remedy is a statement of intent.
4. The trigger
The retainer should say what you can activate it for. A written list beats judgment under stress: a confirmed intrusion, suspected ransomware, data exfiltration, suspicious privileged-account activity, or an attack beyond your DDoS provider's capacity. Check that the list matches your real exposure and that a confirmed high-severity alert from your Managed SOC is one of the entries.
Retainer versus calling someone when it happens
A cold engagement is not a bad option for a small team with a low-consequence environment. It is slower to start, you pay for the orientation hour, and the provider may be unavailable. A retainer pays off when the cost of the first hours is high: a live platform, regulated notification duties, or money that can move. If a missed hour is expensive, the retainer's terms are worth the negotiation. If it is not, a lighter arrangement may be enough.
Questions worth asking on the first call
- If we use none of the hours this year, what do we get?
- What does the second hour of a major incident cost compared with the first?
- Who at your end answers, and what is the out-of-hours route?
- What happens, in writing, if you miss the response time?
- Can we see the retainer's activation list and the onboarding checklist before we sign?
A provider that runs retainers regularly answers these with documents. A provider that does not answers with reassurance.
What this does not replace
A retainer does not prevent incidents. Penetration testing finds the path in beforehand, and a managed SOC detects activity as it happens. The retainer is the response capability that sits after both. It also does not replace your own incident plan: someone on your side still has to decide, authorise, and communicate.
Limitations
This is a buyer's framework for reading a quote. It does not set a response time or an hour count for your organisation, does not interpret any specific regulation's notification rules, and ranks no provider. It cites no statistics and no AnySec-original figures.
What to do next
Put each quote you hold next to the four terms above and mark what is missing. To see how an engagement is structured from activation to the post-incident report, read the Incident Response page; to have a draft retainer scope reviewed, get an IR retainer quote and attach the terms you want clarified.
Frequently asked questions
What is an incident response retainer? An agreement signed before an incident that reserves a provider's responders for you, usually combining a response-time commitment, prepaid hours, and onboarding done in advance.
What happens to unused retainer hours? It depends on the contract: they may expire, roll forward, or convert to proactive work. The quote has to say which.
What happens when an incident uses more hours than the retainer includes? The overage terms apply. Check the rate, whether work continues without a new signature, and who can authorise spend.
When does the response-time clock start on an IR retainer? The contract must define it, along with the channel that counts and what "responded" means. It commonly ends at a responder on the call, not at containment.
Is an incident response retainer worth it if we already have a managed SOC? They do different jobs. The SOC detects; the retainer supplies responders. Connect them by writing the SOC's confirmed high-severity alert into the retainer as a trigger.
Sources and review
This article describes retainer terms in general terms and cites no external statistics and no AnySec-original numbers, case results, or SLA figures. Author: AnySec Engineering. Published 2026-10-06; last reviewed 2026-10-06.
Related reading
- Incident response retainers for online casinos — the onboarding and evidence-preservation work that makes a retainer fast.
- Ransomware response for an online casino: the first hours — what the first hours look like once the retainer is activated.
- Crypto exchange breach response: the first hours — activation triggers for a hot-wallet compromise.
- Incident response for a digital bank: the payment-finality clock — why the clock matters more when money moves fast.
Keep reading
All insights →Rather not learn this in production.
Talk to the engineers behind these write-ups — no sales script, a straight read on where you stand.
Get a fixed quote
