Incident response retainer pricing is one of the few security line items where the cheapest quote and the most expensive quote can describe genuinely different products. One promises an acknowledgement email within four business hours. Another puts a named forensics lead on a bridge call inside sixty minutes, on any day of the year, having already mapped your network and collected your logging baseline. Both are sold under the same two words, and on a procurement spreadsheet they look interchangeable.
They are not. A retainer is a contract you buy before anything has happened, to guarantee access to people who are otherwise fully booked the moment a large ransomware event hits the market. The alternative is negotiating a rate card at 06:00 on the morning you find encrypted file servers, from a position of no leverage, against a provider whose consultants are already committed to somebody else’s incident response engagement. That is the whole commercial logic, and it is why an incident response retainer is priced as insurance rather than as consultancy.
This guide covers what you are actually buying: the standard inclusions, the exclusions that catch people out, the three pricing models in common use, realistic UK cost bands for 2026, what response-time service levels genuinely promise, and how prepaid hours are consumed, rolled over or lost. It is written for organisations of ordinary size — the ones without a dedicated cybersecurity team, where the same handful of people run the response and the day job simultaneously.
Table of contents
- What an incident response retainer actually is
- What is included in an incident response retainer
- What an incident response retainer costs in 2026
- Incident response retainer pricing models compared
- Response time service levels and what they actually promise
- Prepaid hours, drawdown and unused time
- What is not included: the exclusions that cost you
- How to compare incident response retainer providers
- Sizing the decision: who actually needs one
- Getting value from the retainer before an incident
- Frequently asked questions
- References
What an incident response retainer actually is
Incident response as a purchase splits into two very different things, and procurement teams routinely conflate them. The first is capability: the tooling, playbooks and rehearsal that let your own people handle a small event. The second is capacity: the guaranteed right to pull in specialists who do this every week, at a pre-agreed rate, when the event is bigger than you are. An incident response retainer buys the second.
Two purchases hiding inside one contract
Almost every incident response retainer bundles two components that are worth separating in your head. The reactive component is the guarantee — a service level for mobilisation, a named team, a pre-signed contract so legal does not have to negotiate scope while an attacker is still live in the estate. The proactive component is a bank of hours you can spend on readiness work before anything breaks.
Providers structure it this way because the reactive guarantee alone is hard to sell. Nobody enjoys paying for something they hope never to use. Bundling the hours makes the incident response retainer feel like a service rather than a premium, and it also makes you a better client — a provider who has already seen your architecture responds faster than one meeting it for the first time under pressure.
Why providers sell capacity, not outcomes
No credible provider will sell you an outcome. They will not guarantee that data is recovered, that the attacker is evicted by a given date, or that the business is trading again by Monday. What an incident response retainer guarantees is that qualified people start work within a defined window, and that the commercial terms for that work were agreed while everybody was calm.
This distinction matters when you read the contract. The service levels attach to responsiveness, not resolution. A provider who promises resolution timelines is either inexperienced or writing something they will disclaim at the first opportunity.
| Factor | With a retainer | Calling round on the day |
|---|---|---|
| Time to first responder | Contractual, typically 1-8 hours | Unpredictable; days during a mass event |
| Hourly rate | Pre-agreed, often 15-30% below list | Emergency premium, list or above |
| Contracting time | Already signed | Hours to days of legal review |
| Environment knowledge | Onboarded in advance | Learned live, billed to you |
| Insurer acceptance | Usually pre-approved panel | May be refused reimbursement |
| Annual cost | Fixed and budgetable | Zero until it is very large |
The insurer dimension nobody mentions
If you hold cyber insurance, your policy almost certainly names an approved panel of responders, and using someone outside that panel without written consent can reduce or void a claim. Buying an incident response retainer from a panel firm — or getting your preferred firm added to the panel in advance — removes a genuinely expensive failure mode. Check this before you shortlist, not after.
What is included in an incident response retainer
The inclusions vary more than the marketing suggests. Two providers quoting similar annual figures can differ substantially on what the fee actually entitles you to, and the difference is usually buried in the schedule rather than the summary page.
The standard reactive inclusions
Nearly every incident response retainer includes a 24/7 contact route (a dedicated number or portal, not a general helpdesk), a defined mobilisation service level, triage and scoping of the event, containment guidance, and an initial technical investigation. Most include a written incident report suitable for showing to a board or a regulator.
What varies is depth. Some include full forensic acquisition and analysis within the base fee; many treat forensics as drawdown against your hours or as an entirely separate charge. Since forensic work is the expensive part of any serious event, this single line changes the economics of the whole agreement.
Proactive services bundled into the hours
The proactive half is where the incident response retainer earns its keep in the years when nothing goes wrong. Typical bundled services include an onboarding and environment discovery exercise, a review or authoring of your incident response plan, log source assessment, a tabletop exercise, and sometimes compromise assessment or threat hunting.
The onboarding exercise deserves particular attention. A provider who has documented your domain structure, backup topology, logging coverage and escalation contacts before an incident will move dramatically faster during one. Treat it as the primary deliverable of year one.
The digital forensics question
Ask explicitly whether forensic image acquisition, malware reverse engineering and cloud log analysis are included, drawn down, or extra. Ask whether the provider can handle your specific platforms — Microsoft 365 and Entra ID, Google Workspace, AWS, Azure, and any operational technology you run. A generalist team that has to learn your cloud during the event is billing you for their education.
| Service | Usually in the base fee | Usually drawdown or extra |
|---|---|---|
| 24/7 hotline and triage | Yes | – |
| Mobilisation service level | Yes | – |
| Onboarding and discovery | Usually | Sometimes drawdown |
| Incident response plan review | Sometimes | Commonly drawdown |
| Tabletop exercise | Rarely | Drawdown |
| Forensic acquisition and analysis | Rarely | Drawdown or extra |
| Threat hunting | Rarely | Drawdown |
| Ransom negotiation | No | Specialist third party |
| Legal and breach notification | No | Your counsel |
| Rebuild and remediation | No | Separate engagement |
What an incident response retainer costs in 2026
Published pricing is rare, so the figures below reflect the bands UK organisations typically encounter when they go to market. Treat them as a sanity check on quotes rather than as a tariff, because scope differences swamp headline price differences.
Typical UK price bands
For a small organisation of under 100 staff with a straightforward Microsoft 365 estate, an entry-level incident response retainer generally lands between £4,000 and £9,000 per year, buying a modest hours bank and a business-hours-plus mobilisation commitment. Mid-market organisations of 100 to 500 staff typically pay £12,000 to £30,000 for 24/7 cover and a meaningful hours allocation.
Larger or regulated organisations, or those with operational technology and multi-cloud estates, routinely see £40,000 to £120,000 and above. At that level the incident response retainer is usually bespoke, with named personnel, tighter service levels and pre-deployed telemetry.
What drives the price up
Five variables account for most of the spread in incident response retainer quotes. Estate complexity comes first: multi-cloud, operational technology and legacy on-premises systems all raise the skill mix required. Service level is second — a one-hour, 365-day commitment costs materially more than next-business-day.
Hours volume is third, and it is the one buyers over-buy. Geography is fourth, since on-site attendance in a remote location carries a premium. Regulatory exposure is fifth: firms under financial services or critical national infrastructure rules need responders comfortable with their reporting obligations, and that expertise is priced accordingly.
| Tier | Indicative annual fee | Prepaid hours | Mobilisation SLA |
|---|---|---|---|
| Entry | £4,000-£9,000 | 20-40 | 8 business hours |
| Standard | £12,000-£20,000 | 40-80 | 4 hours, 24/7 |
| Enhanced | £20,000-£30,000 | 80-150 | 2 hours, 24/7 |
| Regulated | £40,000-£70,000 | 150-300 | 1 hour, 24/7 |
| Enterprise | £70,000+ | 300+ or uncapped | 1 hour, named team |
The rate card matters more than the fee
A low annual fee attached to a £400 hourly rate can cost far more during a real event than a higher fee attached to £220. Ask for the full rate card by role — incident lead, forensic analyst, malware reverse engineer, cloud specialist — plus out-of-hours multipliers and any on-site day rate. That schedule, not the headline number, is what you will actually pay.
Incident response retainer pricing models compared
Three commercial structures dominate the UK market, and they suit genuinely different buyers. Choosing the wrong one is the most common way organisations waste money on an incident response retainer without ever noticing.
Prepaid hours with drawdown
You pay an annual fee that buys a block of hours. Incident work and proactive work both draw against the block. It is predictable, it is easy to budget, and it makes the provider’s commitment tangible. The risk is the same as any prepaid arrangement: unused hours can expire, and buyers frequently purchase more than their actual consumption.
Zero-fee and credit-back retainers
Some providers charge nothing, or a nominal amount, to hold the contract and the service level, then bill at a pre-agreed rate if you invoke it. Others charge a fee but credit it back against incident work. This suits organisations that want the guarantee and the pre-signed paperwork without funding hours they may never use.
Read the fine print. A zero-fee incident response retainer sometimes carries a weaker service level, or a “commercially reasonable efforts” clause instead of a contractual commitment, which is close to worthless during a market-wide event.
Subscription with a blended rate
Newer providers bundle response into a broader subscription alongside monitoring or managed IT services, charging a single blended rate. The integration is genuinely useful — the team responding already holds your telemetry. The trade-off is that you lose the independence of a separate responder, which matters if the incident involves the provider’s own tooling or people.
| Model | Best for | Main advantage | Main risk |
|---|---|---|---|
| Prepaid hours | Firms wanting readiness work done | Budget certainty; hours get used | Expiry of unused hours |
| Zero-fee or credit-back | Firms with in-house capability | Low or no standing cost | Weaker service level wording |
| Blended subscription | Firms already outsourcing security | Responder holds your telemetry | No independent second opinion |
Response time service levels and what they actually promise
The mobilisation figure is the headline of every incident response retainer, and it is also the most misread number in the contract. Three different clocks hide behind the same phrase, and providers are not always eager to distinguish them.
Acknowledgement is not mobilisation
Acknowledgement means somebody has confirmed receipt of your call. Mobilisation means a qualified responder is assigned and working. Some contracts quote acknowledgement times and let the reader assume mobilisation. A four-hour acknowledgement with no mobilisation commitment is a promise to answer the phone.
Insist on a defined mobilisation window, in writing, with the measurement point stated — from your call, from your written declaration, or from the provider’s own triage decision. The difference is easily several hours.
Remote triage versus on-site attendance
Most modern response is remote, and that is usually correct: an analyst with your logs and endpoint telemetry is more useful than a body in the building. But some events genuinely need physical presence — isolated operational technology, air-gapped systems, or evidence handling with a chain of custody. Confirm whether on-site attendance is available at all, within what window, and at what rate.
The service credit question
Ask what happens if the provider misses the window. Many incident response retainer agreements carry no remedy at all. Others offer a service credit, typically a percentage of the annual fee. A credit will never compensate for the delay, but its presence tells you the provider is willing to stand behind the number, which is useful signal during selection.
Prepaid hours, drawdown and unused time
Hours are the currency of a prepaid incident response retainer, and how they are counted, rolled over or lost is where the commercial detail lives. Two contracts with identical hour counts can deliver very different value.
How hours are consumed
Confirm the billing increment. Hours billed in one-hour blocks consume faster than hours billed in fifteen-minute increments, and over a long engagement the difference is significant. Confirm whether travel time, report writing and internal handovers are billable, and whether out-of-hours work draws down at a multiplier — a 1.5x or 2x night rate can empty a modest bank in one weekend.
Roll-over, expiry and credit-back
The default in most contracts is use-it-or-lose-it at the anniversary. Better agreements allow a percentage to roll forward, or let unused incident hours be converted into proactive work near the term end. Negotiate this at signature; it is a routine concession and almost nobody asks.
What hours are actually spent on
In practice, most organisations spend the majority of their hours on readiness rather than response, simply because most years contain no qualifying incident. That is a feature, not waste — provided you actively schedule the work. Hours that expire unspent are the single largest source of poor value in an incident response retainer.
What is not included: the exclusions that cost you
The gap between what an incident response retainer covers and what a serious incident actually costs is wide, and it is where budgets get destroyed. None of the items below is unreasonable to exclude — they simply need funding from somewhere else.
Legal, notification and communications
Breach notification decisions are legal decisions. Whether an event is reportable to the Information Commissioner’s Office within 72 hours, what must be told to affected individuals, and how to phrase it are matters for counsel, not for a forensic analyst. Public relations support during a significant event is a separate specialism again, and both are routinely outside the incident response retainer scope.
Remediation, rebuild and recovery
Responders contain the incident, establish what happened and advise on eviction. Rebuilding domain controllers, restoring from immutable backups, re-imaging endpoints and re-establishing trust across the estate is delivery work, usually performed by your own team or your managed provider. Budget for it separately; on a serious ransomware event it frequently exceeds the response cost several times over.
Tooling, data and third-party charges
Endpoint detection agents deployed for the investigation, cloud log export and egress charges, additional licensing, and secure evidence storage can all be passed through. Ransom negotiation and cryptocurrency settlement, where an organisation goes that route, is a distinct specialism with its own fee structure and its own legal constraints.
Adjacent controls the retainer assumes you have
An incident response retainer is not a substitute for detection. If nothing in your estate generates usable telemetry, responders arrive to find no evidence of what happened. Comparing managed detection and response with EDR and antivirus is a separate exercise, but the two purchases are complementary rather than alternative: detection tells you there is a problem, the retainer brings people who can deal with it.
How to compare incident response retainer providers
Once you have three quotes, the hard part is comparing things that are not alike. A structured scorecard beats an impression, and it also gives procurement something defensible.
Accreditation and demonstrable evidence
For UK buyers, CREST accreditation for incident response is the most widely recognised marker, and NCSC’s Cyber Incident Response scheme covers the most serious nationally significant cases. Ask for redacted example reports, the CVs of the people who would actually be assigned, and references from organisations of your size in your sector.
Questions worth asking before signing
Ask how many incidents the team handled last year, and how many concurrently at peak. Ask what happens if three clients invoke on the same morning — during a widely exploited vulnerability, that is not hypothetical. Ask who holds priority, and whether your tier guarantees it.
Ask about handover: how a live incident is transferred between shifts and time zones, and whether you get a consistent incident lead. Ask about data handling, since forensic images of your systems will sit in the provider’s environment and that has compliance implications of its own.
| Evaluation area | Weak answer | Strong answer |
|---|---|---|
| Mobilisation clock | “We respond quickly” | Defined window, measured from your call |
| Concurrency | Not discussed | Stated surge capacity and priority rules |
| Rate card | Single blended rate, no detail | Full card by role, multipliers stated |
| Platform coverage | “All environments” | Named platform experience and tooling |
| Hours treatment | Silent on expiry | Roll-over or conversion terms in writing |
| Insurer alignment | Unknown | On your insurer’s approved panel |
| Onboarding | Kick-off call only | Documented environment profile and contacts |
Sizing the decision: who actually needs one
Not every organisation needs a full incident response retainer, and the honest answer for some small firms is that the money is better spent on backups, multi-factor authentication and patching first. The decision turns on exposure and on what you could absorb.
Smaller organisations under 50 staff
If your estate is a single cloud tenancy, your data is not especially sensitive, and a week of disruption would be survivable, an entry-level or zero-fee incident response retainer is usually sufficient. What matters most at this size is that somebody has your details on file and that the contract is signed, so the first hour is not spent on procurement.
Regulated firms and supply-chain-exposed businesses
Financial services, healthcare, legal, and any business with contractual notification obligations to enterprise customers sit in a different category. Here an incident response retainer is close to mandatory, and the IT security requirements flowing down through customer contracts increasingly name it explicitly. Regulatory reporting clocks start early and run regardless of whether you have anyone available to investigate.
The businesses that regret not having one
The pattern is consistent: organisations that discover during an incident that their cybersecurity provider does not do forensics, that their insurer will not reimburse an unapproved responder, and that every reputable firm in the market is quoting a two-week lead time because a widely exploited vulnerability has just been published.
Getting value from the retainer before an incident
An unused incident response retainer that sat in a drawer for three years and then worked perfectly is a good outcome. An unused one that sat in a drawer and then failed because nothing was ever set up is the common one.
Onboarding is the real deliverable
Insist that year one includes a documented environment profile: domain and tenancy structure, critical systems, backup topology and restore points, logging sources and retention, network egress points, and a current escalation contact list with out-of-hours numbers. Confirm that the provider stores it somewhere reachable when your own systems are down — a profile living only on the estate it describes is no profile at all.
Rehearse the call-out
Run at least one cyber tabletop exercise with the provider in the room, and separately test the out-of-hours number. Organisations regularly discover that the hotline routes to a general helpdesk at 03:00, or that the only person who knows the contract reference is on annual leave.
Review it annually
Estates change, staff leave and the hours you bought two years ago may no longer match consumption. Review the incident response retainer at each renewal against actual usage, estate changes and any new obligations arriving through customer contracts or regulation.
Frequently asked questions
Is an incident response retainer the same as cyber insurance?
No. Insurance transfers financial loss after the event; an incident response retainer provides the people who do the work during it. They are complementary, and most insurers expect or require a named responder. Check that your chosen provider is on your insurer’s approved panel before signing.
How quickly can we get one in place?
Typically two to six weeks, dominated by legal review and onboarding rather than commercial negotiation. During a period of mass exploitation, lead times stretch considerably, which is precisely when everyone tries to buy one.
What happens to the money if we never have an incident?
Under a prepaid model, unused hours are usually redirected into readiness work — plan development, exercises, log reviews — or lost at the anniversary if you do not schedule them. Under a zero-fee model there is little or no standing cost to lose.
Can our existing IT provider do this?
Sometimes, and there is real benefit in a responder who already knows the estate. The counterargument is independence: if the incident touches the provider’s own tooling, access or configuration, an external investigator is more credible to your board, your insurer and your regulator.
Do we still need one if we have a security operations centre?
Usually yes. Monitoring identifies events; deep forensics, malware analysis and major-incident command are a different skill set that most monitoring services do not include. Confirm exactly where your provider’s obligation stops.
References
NCSC Incident Management Collection
NCSC Cyber Incident Response Processes
NIST SP 800-61r3 Incident Response Recommendations and Considerations
NIST SP 800-84 Guide to Test, Training and Exercise Programs
NIST SP 800-34r1 Contingency Planning Guide for Federal Information Systems
ICO Personal Data Breach Reporting