Incident response retainer pricing is one of the few security line items where the cheapest quote and the most expensive quote can describe genuinely different products. One promises an acknowledgement email within four business hours. Another puts a named forensics lead on a bridge call inside sixty minutes, on any day of the year, having already mapped your network and collected your logging baseline. Both are sold under the same two words, and on a procurement spreadsheet they look interchangeable.

They are not. A retainer is a contract you buy before anything has happened, to guarantee access to people who are otherwise fully booked the moment a large ransomware event hits the market. The alternative is negotiating a rate card at 06:00 on the morning you find encrypted file servers, from a position of no leverage, against a provider whose consultants are already committed to somebody else’s incident response engagement. That is the whole commercial logic, and it is why an incident response retainer is priced as insurance rather than as consultancy.

This guide covers what you are actually buying: the standard inclusions, the exclusions that catch people out, the three pricing models in common use, realistic UK cost bands for 2026, what response-time service levels genuinely promise, and how prepaid hours are consumed, rolled over or lost. It is written for organisations of ordinary size — the ones without a dedicated cybersecurity team, where the same handful of people run the response and the day job simultaneously.

What an incident response retainer actually is

incident response retainer cost and inclusions b stopwatch blank dial

Incident response as a purchase splits into two very different things, and procurement teams routinely conflate them. The first is capability: the tooling, playbooks and rehearsal that let your own people handle a small event. The second is capacity: the guaranteed right to pull in specialists who do this every week, at a pre-agreed rate, when the event is bigger than you are. An incident response retainer buys the second.

Two purchases hiding inside one contract

Almost every incident response retainer bundles two components that are worth separating in your head. The reactive component is the guarantee — a service level for mobilisation, a named team, a pre-signed contract so legal does not have to negotiate scope while an attacker is still live in the estate. The proactive component is a bank of hours you can spend on readiness work before anything breaks.

Providers structure it this way because the reactive guarantee alone is hard to sell. Nobody enjoys paying for something they hope never to use. Bundling the hours makes the incident response retainer feel like a service rather than a premium, and it also makes you a better client — a provider who has already seen your architecture responds faster than one meeting it for the first time under pressure.

Why providers sell capacity, not outcomes

No credible provider will sell you an outcome. They will not guarantee that data is recovered, that the attacker is evicted by a given date, or that the business is trading again by Monday. What an incident response retainer guarantees is that qualified people start work within a defined window, and that the commercial terms for that work were agreed while everybody was calm.

This distinction matters when you read the contract. The service levels attach to responsiveness, not resolution. A provider who promises resolution timelines is either inexperienced or writing something they will disclaim at the first opportunity.

FactorWith a retainerCalling round on the day
Time to first responderContractual, typically 1-8 hoursUnpredictable; days during a mass event
Hourly ratePre-agreed, often 15-30% below listEmergency premium, list or above
Contracting timeAlready signedHours to days of legal review
Environment knowledgeOnboarded in advanceLearned live, billed to you
Insurer acceptanceUsually pre-approved panelMay be refused reimbursement
Annual costFixed and budgetableZero until it is very large

The insurer dimension nobody mentions

If you hold cyber insurance, your policy almost certainly names an approved panel of responders, and using someone outside that panel without written consent can reduce or void a claim. Buying an incident response retainer from a panel firm — or getting your preferred firm added to the panel in advance — removes a genuinely expensive failure mode. Check this before you shortlist, not after.

What is included in an incident response retainer

incident response retainer cost and inclusions c stack of blank sheets

The inclusions vary more than the marketing suggests. Two providers quoting similar annual figures can differ substantially on what the fee actually entitles you to, and the difference is usually buried in the schedule rather than the summary page.

The standard reactive inclusions

Nearly every incident response retainer includes a 24/7 contact route (a dedicated number or portal, not a general helpdesk), a defined mobilisation service level, triage and scoping of the event, containment guidance, and an initial technical investigation. Most include a written incident report suitable for showing to a board or a regulator.

What varies is depth. Some include full forensic acquisition and analysis within the base fee; many treat forensics as drawdown against your hours or as an entirely separate charge. Since forensic work is the expensive part of any serious event, this single line changes the economics of the whole agreement.

Proactive services bundled into the hours

The proactive half is where the incident response retainer earns its keep in the years when nothing goes wrong. Typical bundled services include an onboarding and environment discovery exercise, a review or authoring of your incident response plan, log source assessment, a tabletop exercise, and sometimes compromise assessment or threat hunting.

The onboarding exercise deserves particular attention. A provider who has documented your domain structure, backup topology, logging coverage and escalation contacts before an incident will move dramatically faster during one. Treat it as the primary deliverable of year one.

The digital forensics question

Ask explicitly whether forensic image acquisition, malware reverse engineering and cloud log analysis are included, drawn down, or extra. Ask whether the provider can handle your specific platforms — Microsoft 365 and Entra ID, Google Workspace, AWS, Azure, and any operational technology you run. A generalist team that has to learn your cloud during the event is billing you for their education.

ServiceUsually in the base feeUsually drawdown or extra
24/7 hotline and triageYes
Mobilisation service levelYes
Onboarding and discoveryUsuallySometimes drawdown
Incident response plan reviewSometimesCommonly drawdown
Tabletop exerciseRarelyDrawdown
Forensic acquisition and analysisRarelyDrawdown or extra
Threat huntingRarelyDrawdown
Ransom negotiationNoSpecialist third party
Legal and breach notificationNoYour counsel
Rebuild and remediationNoSeparate engagement

What an incident response retainer costs in 2026

incident response retainer cost and inclusions d four rising blank columns

Published pricing is rare, so the figures below reflect the bands UK organisations typically encounter when they go to market. Treat them as a sanity check on quotes rather than as a tariff, because scope differences swamp headline price differences.

Typical UK price bands

For a small organisation of under 100 staff with a straightforward Microsoft 365 estate, an entry-level incident response retainer generally lands between £4,000 and £9,000 per year, buying a modest hours bank and a business-hours-plus mobilisation commitment. Mid-market organisations of 100 to 500 staff typically pay £12,000 to £30,000 for 24/7 cover and a meaningful hours allocation.

Larger or regulated organisations, or those with operational technology and multi-cloud estates, routinely see £40,000 to £120,000 and above. At that level the incident response retainer is usually bespoke, with named personnel, tighter service levels and pre-deployed telemetry.

Typical annual UK retainer cost by tier (indicative, 2026)
Entry, under 100 staff £4k-£9k
Standard, 100-250 staff £12k-£20k
Enhanced, 250-500 staff £20k-£30k
Regulated or multi-cloud £40k-£70k
Enterprise, named team £70k-£120k+

What drives the price up

Five variables account for most of the spread in incident response retainer quotes. Estate complexity comes first: multi-cloud, operational technology and legacy on-premises systems all raise the skill mix required. Service level is second — a one-hour, 365-day commitment costs materially more than next-business-day.

Hours volume is third, and it is the one buyers over-buy. Geography is fourth, since on-site attendance in a remote location carries a premium. Regulatory exposure is fifth: firms under financial services or critical national infrastructure rules need responders comfortable with their reporting obligations, and that expertise is priced accordingly.

TierIndicative annual feePrepaid hoursMobilisation SLA
Entry£4,000-£9,00020-408 business hours
Standard£12,000-£20,00040-804 hours, 24/7
Enhanced£20,000-£30,00080-1502 hours, 24/7
Regulated£40,000-£70,000150-3001 hour, 24/7
Enterprise£70,000+300+ or uncapped1 hour, named team

The rate card matters more than the fee

A low annual fee attached to a £400 hourly rate can cost far more during a real event than a higher fee attached to £220. Ask for the full rate card by role — incident lead, forensic analyst, malware reverse engineer, cloud specialist — plus out-of-hours multipliers and any on-site day rate. That schedule, not the headline number, is what you will actually pay.

Incident response retainer pricing models compared

incident response retainer cost and inclusions e hub with radiating nodes

Three commercial structures dominate the UK market, and they suit genuinely different buyers. Choosing the wrong one is the most common way organisations waste money on an incident response retainer without ever noticing.

Prepaid hours with drawdown

You pay an annual fee that buys a block of hours. Incident work and proactive work both draw against the block. It is predictable, it is easy to budget, and it makes the provider’s commitment tangible. The risk is the same as any prepaid arrangement: unused hours can expire, and buyers frequently purchase more than their actual consumption.

Zero-fee and credit-back retainers

Some providers charge nothing, or a nominal amount, to hold the contract and the service level, then bill at a pre-agreed rate if you invoke it. Others charge a fee but credit it back against incident work. This suits organisations that want the guarantee and the pre-signed paperwork without funding hours they may never use.

Read the fine print. A zero-fee incident response retainer sometimes carries a weaker service level, or a “commercially reasonable efforts” clause instead of a contractual commitment, which is close to worthless during a market-wide event.

Subscription with a blended rate

Newer providers bundle response into a broader subscription alongside monitoring or managed IT services, charging a single blended rate. The integration is genuinely useful — the team responding already holds your telemetry. The trade-off is that you lose the independence of a separate responder, which matters if the incident involves the provider’s own tooling or people.

ModelBest forMain advantageMain risk
Prepaid hoursFirms wanting readiness work doneBudget certainty; hours get usedExpiry of unused hours
Zero-fee or credit-backFirms with in-house capabilityLow or no standing costWeaker service level wording
Blended subscriptionFirms already outsourcing securityResponder holds your telemetryNo independent second opinion

Response time service levels and what they actually promise

incident response retainer cost and inclusions f magnifying glass upright

The mobilisation figure is the headline of every incident response retainer, and it is also the most misread number in the contract. Three different clocks hide behind the same phrase, and providers are not always eager to distinguish them.

Acknowledgement is not mobilisation

Acknowledgement means somebody has confirmed receipt of your call. Mobilisation means a qualified responder is assigned and working. Some contracts quote acknowledgement times and let the reader assume mobilisation. A four-hour acknowledgement with no mobilisation commitment is a promise to answer the phone.

Insist on a defined mobilisation window, in writing, with the measurement point stated — from your call, from your written declaration, or from the provider’s own triage decision. The difference is easily several hours.

Remote triage versus on-site attendance

Most modern response is remote, and that is usually correct: an analyst with your logs and endpoint telemetry is more useful than a body in the building. But some events genuinely need physical presence — isolated operational technology, air-gapped systems, or evidence handling with a chain of custody. Confirm whether on-site attendance is available at all, within what window, and at what rate.

What each service tier typically commits to (hours to responder assigned)
Enterprise, named team 1 hour
Regulated tier 1 hour
Enhanced tier 2 hours
Standard tier 4 hours
Entry tier 8 business hours

The service credit question

Ask what happens if the provider misses the window. Many incident response retainer agreements carry no remedy at all. Others offer a service credit, typically a percentage of the annual fee. A credit will never compensate for the delay, but its presence tells you the provider is willing to stand behind the number, which is useful signal during selection.

Prepaid hours, drawdown and unused time

Hours are the currency of a prepaid incident response retainer, and how they are counted, rolled over or lost is where the commercial detail lives. Two contracts with identical hour counts can deliver very different value.

How hours are consumed

Confirm the billing increment. Hours billed in one-hour blocks consume faster than hours billed in fifteen-minute increments, and over a long engagement the difference is significant. Confirm whether travel time, report writing and internal handovers are billable, and whether out-of-hours work draws down at a multiplier — a 1.5x or 2x night rate can empty a modest bank in one weekend.

Roll-over, expiry and credit-back

The default in most contracts is use-it-or-lose-it at the anniversary. Better agreements allow a percentage to roll forward, or let unused incident hours be converted into proactive work near the term end. Negotiate this at signature; it is a routine concession and almost nobody asks.

What hours are actually spent on

In practice, most organisations spend the majority of their hours on readiness rather than response, simply because most years contain no qualifying incident. That is a feature, not waste — provided you actively schedule the work. Hours that expire unspent are the single largest source of poor value in an incident response retainer.

Where retainer hours typically go in a year with no major incident
Onboarding and environment discovery 30%
Plan and playbook development 22%
Tabletop exercises and training 18%
Minor event triage 16%
Unspent and expired 14%

What is not included: the exclusions that cost you

The gap between what an incident response retainer covers and what a serious incident actually costs is wide, and it is where budgets get destroyed. None of the items below is unreasonable to exclude — they simply need funding from somewhere else.

Legal, notification and communications

Breach notification decisions are legal decisions. Whether an event is reportable to the Information Commissioner’s Office within 72 hours, what must be told to affected individuals, and how to phrase it are matters for counsel, not for a forensic analyst. Public relations support during a significant event is a separate specialism again, and both are routinely outside the incident response retainer scope.

Remediation, rebuild and recovery

Responders contain the incident, establish what happened and advise on eviction. Rebuilding domain controllers, restoring from immutable backups, re-imaging endpoints and re-establishing trust across the estate is delivery work, usually performed by your own team or your managed provider. Budget for it separately; on a serious ransomware event it frequently exceeds the response cost several times over.

Tooling, data and third-party charges

Endpoint detection agents deployed for the investigation, cloud log export and egress charges, additional licensing, and secure evidence storage can all be passed through. Ransom negotiation and cryptocurrency settlement, where an organisation goes that route, is a distinct specialism with its own fee structure and its own legal constraints.

Adjacent controls the retainer assumes you have

An incident response retainer is not a substitute for detection. If nothing in your estate generates usable telemetry, responders arrive to find no evidence of what happened. Comparing managed detection and response with EDR and antivirus is a separate exercise, but the two purchases are complementary rather than alternative: detection tells you there is a problem, the retainer brings people who can deal with it.

How to compare incident response retainer providers

Once you have three quotes, the hard part is comparing things that are not alike. A structured scorecard beats an impression, and it also gives procurement something defensible.

Accreditation and demonstrable evidence

For UK buyers, CREST accreditation for incident response is the most widely recognised marker, and NCSC’s Cyber Incident Response scheme covers the most serious nationally significant cases. Ask for redacted example reports, the CVs of the people who would actually be assigned, and references from organisations of your size in your sector.

Questions worth asking before signing

Ask how many incidents the team handled last year, and how many concurrently at peak. Ask what happens if three clients invoke on the same morning — during a widely exploited vulnerability, that is not hypothetical. Ask who holds priority, and whether your tier guarantees it.

Ask about handover: how a live incident is transferred between shifts and time zones, and whether you get a consistent incident lead. Ask about data handling, since forensic images of your systems will sit in the provider’s environment and that has compliance implications of its own.

Evaluation areaWeak answerStrong answer
Mobilisation clock“We respond quickly”Defined window, measured from your call
ConcurrencyNot discussedStated surge capacity and priority rules
Rate cardSingle blended rate, no detailFull card by role, multipliers stated
Platform coverage“All environments”Named platform experience and tooling
Hours treatmentSilent on expiryRoll-over or conversion terms in writing
Insurer alignmentUnknownOn your insurer’s approved panel
OnboardingKick-off call onlyDocumented environment profile and contacts

Sizing the decision: who actually needs one

Not every organisation needs a full incident response retainer, and the honest answer for some small firms is that the money is better spent on backups, multi-factor authentication and patching first. The decision turns on exposure and on what you could absorb.

Smaller organisations under 50 staff

If your estate is a single cloud tenancy, your data is not especially sensitive, and a week of disruption would be survivable, an entry-level or zero-fee incident response retainer is usually sufficient. What matters most at this size is that somebody has your details on file and that the contract is signed, so the first hour is not spent on procurement.

Regulated firms and supply-chain-exposed businesses

Financial services, healthcare, legal, and any business with contractual notification obligations to enterprise customers sit in a different category. Here an incident response retainer is close to mandatory, and the IT security requirements flowing down through customer contracts increasingly name it explicitly. Regulatory reporting clocks start early and run regardless of whether you have anyone available to investigate.

The businesses that regret not having one

The pattern is consistent: organisations that discover during an incident that their cybersecurity provider does not do forensics, that their insurer will not reimburse an unapproved responder, and that every reputable firm in the market is quoting a two-week lead time because a widely exploited vulnerability has just been published.

Getting value from the retainer before an incident

An unused incident response retainer that sat in a drawer for three years and then worked perfectly is a good outcome. An unused one that sat in a drawer and then failed because nothing was ever set up is the common one.

Onboarding is the real deliverable

Insist that year one includes a documented environment profile: domain and tenancy structure, critical systems, backup topology and restore points, logging sources and retention, network egress points, and a current escalation contact list with out-of-hours numbers. Confirm that the provider stores it somewhere reachable when your own systems are down — a profile living only on the estate it describes is no profile at all.

Rehearse the call-out

Run at least one cyber tabletop exercise with the provider in the room, and separately test the out-of-hours number. Organisations regularly discover that the hotline routes to a general helpdesk at 03:00, or that the only person who knows the contract reference is on annual leave.

Review it annually

Estates change, staff leave and the hours you bought two years ago may no longer match consumption. Review the incident response retainer at each renewal against actual usage, estate changes and any new obligations arriving through customer contracts or regulation.

Frequently asked questions

Is an incident response retainer the same as cyber insurance?

No. Insurance transfers financial loss after the event; an incident response retainer provides the people who do the work during it. They are complementary, and most insurers expect or require a named responder. Check that your chosen provider is on your insurer’s approved panel before signing.

How quickly can we get one in place?

Typically two to six weeks, dominated by legal review and onboarding rather than commercial negotiation. During a period of mass exploitation, lead times stretch considerably, which is precisely when everyone tries to buy one.

What happens to the money if we never have an incident?

Under a prepaid model, unused hours are usually redirected into readiness work — plan development, exercises, log reviews — or lost at the anniversary if you do not schedule them. Under a zero-fee model there is little or no standing cost to lose.

Can our existing IT provider do this?

Sometimes, and there is real benefit in a responder who already knows the estate. The counterargument is independence: if the incident touches the provider’s own tooling, access or configuration, an external investigator is more credible to your board, your insurer and your regulator.

Do we still need one if we have a security operations centre?

Usually yes. Monitoring identifies events; deep forensics, malware analysis and major-incident command are a different skill set that most monitoring services do not include. Confirm exactly where your provider’s obligation stops.

References