Back

IR Retainer Guide: What You're Paying for Before an Incident

Eldad Rudich
Eldad Rudich
October 2, 2026
Insights
IR Retainer Guide: What You're Paying for Before an IncidentBright curved horizon of a planet glowing against the dark backdrop of space.Bright curved horizon of a planet glowing against the dark backdrop of space.

An IR retainer is a contract with an incident response firm, signed before an incident, that fixes rates, scope, and response commitments so the firm can start work without a procurement cycle. Most security leaders who signed a retainer two renewals ago can name the firm and the annual fee. Fewer can say whether the service-level agreement (SLA) applies on a Sunday or whether the hours expire in March. Fewer still know whether the carrier will reimburse the firm, or whether the firm's report could end up as evidence in a lawsuit.

The word "retainer" covers four contract structures with different capacity commitments. Activation terms, your cyber policy's panel rules, and how outside counsel structures the engagement decide what the contract is worth before anyone dials the hotline.

TL;DR:

  • Prepaid hours or credits are the clearest evidence of committed responder capacity. A zero-dollar retainer locks a rate and terms, and reserves capacity only when the contract says so.
  • Coverage window, capacity ceiling, unused-hour rules, and pre-incident onboarding determine what the headline response time is worth when you call.
  • Whether the insurer pays for the firm and whether its report stays privileged are largely shaped at policy binding and counsel engagement, long before an incident tests them.
  • Containment can sit inside the monitoring contract when the MDR contract assigns response execution to the provider. Forensics, negotiation, and legal-grade investigation stay retainer work.

How the Four IR Retainer Structures Differ Before an Incident

Gartner's guidance on retainers for digital forensics and incident response describes them as adding capacity and capability when organizations respond to incidents. The four structures differ in how much of that capacity is actually reserved for you, which matters most when a mass-exploitation event floods the firm with calls.

Prepaid Hour Blocks

The buyer prepays for a block of hours, usually for an annual term, and draws them down against live incidents. Pre-incident, you hold an allocated hour bank, and block size may also set your SLA tier. Size it for your worst plausible week.

Zero-Dollar Retainers

Billing starts at activation, with no upfront payment. The buyer establishes rates, scope, and future incident response terms without pre-purchasing hours. Without an express capacity commitment, allocation may be best efforts when an incident occurs.

Subscription and Service-Unit Retainers

A recurring fee buys access to a pool of credits redeemable across reactive and proactive work. These arrangements can let the buyer redirect value as priorities change without renegotiating the core contract. Some contracts reserve proactive services for buyers who keep a minimum credit balance, and some use subscription pricing with no prepaid incident-hour block at all.

Hybrid and Tiered Retainers

Higher prepaid tiers may buy faster SLAs, broader service scope, or both. The contract should state the credit level, remote response window, included services, and any accelerated-SLA option for each tier.

The table below sets out what each structure commits before the first call.

How the Four Retainer Structures Differ Before an Incident
What is committed before an incident Capacity reserved?
Prepaid hour block Fixed annual hour bank, SLA tied to block size; unused hours may convert to proactive work Yes
Zero-dollar Locked rate, scope, and SLA; billing begins at activation No defined hour bank; allocation may be best efforts
Subscription / service units Team access, discounted rates, defined SLA; credits may span reactive and proactive services Varies by provider
Hybrid / tiered SLA and scope scale with the prepaid tier Yes, at tier level

‍

Across all four, the hour or credit count is the number sales leads with, and whether that count holds depends on terms buried in the service description.

The Terms That Decide Whether the SLA Holds

An SLA holds only during its coverage window and within its capacity ceiling, and only if the responders already know your environment. Check whether promises of fast acknowledgement or containment apply around the clock or only during business hours. Put the numeric response time, the on-site commitment, and the remedy for a missed SLA in the agreement itself, since service pages often leave them out.

The incident definition decides when the clock starts. Some agreements count any request for help, others only a confirmed security incident, and a narrow definition can leave a suspected compromise waiting while the parties argue about whether it qualifies.

Responder familiarity takes work beyond signing. Separate readiness work has to validate the contact tree and test whether activation works at the speed you need. Favor a provider whose onboarding builds a detailed picture of your environment ahead of any incident.

Unused-hour terms are where prepaid value leaks. Under many agreements, unused hours may carry over only for a limited period or go toward other services such as readiness exercises. The same agreements often bill hours beyond the prepaid block at a different rate; ask for the overage rate card up front.

Check geography as well. Confirm which regions the firm covers with its own staff, whether on-site response outside them relies on partners, and whether travel time and expenses draw down the hour bank.

Panel Alignment and Privilege Are Decided Before the Incident

Many insurers require policyholders to use specific legal, forensic, and recovery firms, according to carrier notification guidance from March 2025. The same guidance recommends signing agreements with pre-approved vendors before an incident. A USENIX Security 2023 paper on cyber insurance and incident response found that IR firms joining an insurer's panel typically commit to prices ahead of time, "often below market rates. A discount of 30% is typical in our sample."

Three Court Rulings That Shape How Retainers Should Be Structured

In the 2020 Capital One case, Mandiant was already working under a statement of work signed before the breach. After the breach, Capital One, Mandiant, and outside counsel signed a letter agreement covering the same work, and the final report went to four regulators and the company's accountant. The court found the report would have been written in much the same form with or without litigation, and ordered Capital One to hand it over.

In the 2021 Wengui v. Clark Hill case, the law firm Clark Hill said it ran two investigations, one for the business and one for its lawyers. There was no evidence the business-side vendor produced findings of its own. The court decided the lawyer-hired firm had simply replaced the business investigation, so its report was neither work product nor privileged.

In the 2021 Rutter's case, counsel hired Kroll after alerts of a possible compromise, before anyone knew a breach had happened. A company witness testified that Kroll's report would have been prepared regardless of any litigation, and the court rejected both the work-product and attorney-client privilege claims.

Across these cases, courts counted facts like these against protection: a forensic relationship that started before the breach, a scope that stayed the same after counsel arrived, a report that was the only full analysis, and a report shared widely. To give privilege a better chance, have outside counsel hire the forensic firm for each incident under a new engagement letter that names the litigation risk. Run two real investigation tracks, each producing its own findings, and limit who sees the legal-track report. Even then, privilege is not guaranteed.

Where MDR Response Ends and the IR Retainer Begins

Gartner's 2026 MDR Market Guide frames MDR as delivering "cyberattack disruption and containment." How far that containment goes depends on the statement of work. Some MDR contracts stop at remediation advice. Others run a limited set of approved actions, sell active response as an add-on, or make the provider contractually responsible for carrying out the response. Providers may also bundle a retainer or partner with an IR firm, so check whose responders the contract actually commits.

Who carries out containment matters most in the first hours. An external team waiting on hotline activation, authorization, and environment access may arrive after a fast intrusion has already moved laterally or exfiltrated data. A provider with continuous access and preauthorized response actions can handle containment within the monitoring contract, and the contract should name who executes containment and which actions need approval.

Retainer scope starts where those obligations end. Depending on the contract, IR retainer work extends to establishing dwell time, determining which files were accessed or stolen, threat actor negotiation, ransom settlement, data recovery, and system restoration. It may also cover coordination with cyber insurance carriers, law firms, and law enforcement, plus expert witness and litigation support. The line between MDR response and a separately billable IR engagement is the clause to read twice. Ask every provider: "At what point does the engagement become a separate billable event?"

Decision Criteria: Which Retainer Structure Fits Your Situation

Match the structure to the constraint that would hurt most during an incident:

  • If you have no 24/7 internal SOC, the after-hours activation clause is likely the most important term you negotiate. Require explicit 24/7 coverage with tiered response windows, and reject any SLA qualified by business hours.
  • If you face short regulatory notification clocks, prioritize committed capacity, meaning a prepaid block or an upper tier. Examples include DORA, NIS2's 24-hour early warning, and the four-business-day SEC Item 1.05 window that starts once an incident is judged material. Negotiate a binding remote response SLA that leaves time to investigate before the deadline, and confirm the tier SLA in writing.
  • If incidents are rare for you but the severity risk is high, prioritize subscription or block structures that let you convert unused hours to proactive services. A block that expires annually with no conversion returns nothing in a quiet year.
  • If your cyber policy carries a panel requirement, confirm the firm's panel status before signing or obtain the carrier's written approval at binding. Under policies that require advance approval, a firm engaged without it may become an excluded cost.
  • If your MDR provider executes containment under contractual accountability, weight the retainer toward forensics, negotiation, notification, and legal liaison with a smaller reactive hour bank. If your provider only recommends actions, reactive depth and SLA speed come first.
  • If litigation or regulatory enforcement is a plausible outcome, require chain-of-custody procedures in writing and ask whether the firm's reports have been admitted in proceedings. Have counsel set up a separate engagement letter for each incident instead of extending the retainer's master agreement.

Whichever structure you choose, agree on a documented escalation protocol between the MDR and retainer providers ahead of the first incident, covering how evidence transfers and how billing splits.

Size the Retainer for the Work That Starts After Containment

The retainer you sign is a set of decisions about capacity, coverage hours, insurer approval, and legal structure, made while nothing is on fire. Settle each one at renewal, and when selecting an IR provider, get all of them written into the agreement.

Daylight's MDR service is built to own the cycle from alert to resolution with contractual accountability, so routine containment typically stays inside the managed service. The retainer, held with a separate forensics firm, can then be sized for the major-breach work that follows.

Frequently Asked Questions About IR Retainers

How Much Does an IR Retainer Cost?

There is no reliable public price range, because firms rarely publish hourly rates and quotes vary widely by structure. Cost is driven by block or tier size, the negotiated rate, the SLA tier, overage rates beyond the block, and whether the firm sits on your insurer's panel. A pre-negotiated rate can also limit exposure to emergency pricing.

Does an MDR Breach Warranty Replace an IR Retainer?

No. A breach warranty is a reimbursement instrument that may repay defined expenses after a covered event, subject to its own conditions. It does not commit responders, set an SLA, or assign responsibility for containment decisions and response execution. It sits alongside a retainer and your cyber policy.

When Should You Activate an IR Retainer?

Activate it as soon as an incident needs work your team and MDR provider don't cover, such as forensic scoping, legal-grade investigation, or negotiation, or looks likely to outrun their capacity. If litigation is plausible, have outside counsel engage the firm for that specific incident, knowing privilege still isn't guaranteed.

Does Cyber Insurance Pay for an IR Retainer?

It depends on the policy wording. Policies that cover incident response costs after a covered event often tie that coverage to panel status or prior consent. Whether the prepaid retainer fee itself is reimbursable is a separate question, so put both to your broker before you sign.

Table of contents
form submission image form submission image

Ready to escape the dark and elevate your security?

Get a demo
form submission image form submission image

Ready to escape the dark and elevate your security?

Get a demo

Ready to escape the dark and elevate your security?

Stop settling for escalation factories. Get AI-native detection and response with senior experts and full accountability.

Book a Demo
moutain illustration
form submission image form submission image

Ready to escape the dark and elevate your security?

Get a demo
moutain illustration