The call comes at 11pm on a Friday. An employee noticed something wrong with their files. IT pulled a server and confirmed it: ransomware. Half the file shares are encrypted, the backup server is also affected, and nobody knows how far it spread.
At this moment, most mid-market companies face a second crisis on top of the first: they don't know who to call.
Finding a qualified incident response firm under time pressure, negotiating terms mid-incident, and getting a team onboarded and productive while the clock is running — this is a problem you can solve in advance, cheaply, before you ever need it. An IR retainer is how you do that.
What an IR Retainer Actually Is
An IR retainer is a pre-negotiated contract with a cybersecurity incident response firm that gives you guaranteed access to their team and pre-agreed rates when you need them.
The structure varies by firm and engagement level, but the core value is consistent: you pay a relatively small annual fee to establish the relationship, negotiate the terms, and secure capacity. When an incident occurs, you invoke the retainer, the response team is on a call within hours, and the billing and scope are already settled.
Retainer fees for mid-market companies typically run $15,000–$50,000 per year depending on the firm and what's included. For context: a mid-sized ransomware incident with no IR firm in place commonly costs $500,000 or more in combined response costs, downtime, ransom, and recovery — before factoring in regulatory exposure or reputational impact.
What You're Actually Buying
Speed of response. When a qualified IR firm is already engaged, has reviewed your environment, and has pre-signed NDAs and contracts on file, they can be on a call in two hours, not two days. In ransomware scenarios, the first 24 hours determine whether the incident is contained or becomes a full-scale data breach.
Pre-agreed rates. Mid-incident negotiation is not where you want to be when your IR firm has all the leverage and your business is down. Retainer terms lock in hourly rates, scope definitions, and payment structures before you're under duress. IR hourly rates for qualified firms run $350–$700+ per hour; retainer rates are typically discounted 10–25%.
Pre-incident engagement. The best retainer relationships include work before any incident: IR firms will often review your logging configuration, assess your containment and recovery capabilities, update your IR plan, and participate in a tabletop exercise. This makes the actual response faster and more effective — they already know your environment, key personnel, and where your critical systems are.
Regulatory and legal coordination. Most qualified IR firms have established relationships with breach notification counsel and can help coordinate legal obligations from day one. For HIPAA-covered entities, financial services firms under GLBA, or companies with customers in GDPR jurisdictions, breach notification timelines are short and the penalties for missing them are significant.
What to Look for in an IR Firm
Not all firms are equal, and the retainer relationship only delivers value if the firm is actually capable.
Look for real response experience. Ask for case examples — not generic descriptions of methodology, but actual incident types they've responded to. Ransomware, business email compromise, cloud environment compromises, and insider threat are the scenarios most mid-market companies face. Have they responded to each?
Verify their forensic capability. Containment is half the job; understanding what happened is the other half. Post-incident forensics determines whether you understand the root cause, what data was accessed, and whether the attacker is still in your environment. Firms without strong forensic capability may contain and remediate without ever telling you what actually happened.
Confirm their notification capacity. Most quality IR firms have pre-established relationships with breach notification counsel. If your incident involves personal data, medical records, or financial information, the legal obligations begin the moment you confirm a breach. You want IR and legal coordinated from the start, not introduced to each other three days in.
Check cyber insurance alignment. If you carry cyber insurance — and you should — confirm your policy's requirements around incident response. Many cyber policies require pre-approval before engaging an IR firm or mandate use of a panel firm. Choosing a retainer partner that's on your insurer's panel, or at minimum pre-approving your preferred firm with your insurer, prevents coverage disputes during a crisis.
The Retainer Conversation to Have Before Signing
Before finalizing a retainer, have explicit answers to:
- What is the guaranteed response time for a Priority 1 incident?
- What is included in the annual retainer fee versus billed hourly during response?
- What pre-incident engagement is included (environment review, tabletop, plan review)?
- Who is my named point of contact, and what is the escalation path if they're unavailable?
- How does the firm handle multi-jurisdictional breach notification requirements?
These aren't hostile questions — they're what any quality IR firm expects a prepared client to ask.
Where This Fits in Your Security Program
An IR retainer is not a substitute for prevention. Companies that invest in retainers but neglect identity security, endpoint protection, and network visibility still get hit and still suffer. The retainer is your response capability insurance, not your risk reduction program.
What it does do is eliminate one of the most damaging aspects of a security incident for mid-market companies: the chaotic, expensive scramble to find qualified help after the fact. You've already made that decision, under calm conditions, with time to choose well.
If you don't currently have an IR retainer and you're operating in an industry that handles sensitive data — healthcare, financial services, professional services, SaaS — getting one is among the highest-ROI security investments you can make this year.
Ready to assess your incident response readiness and select the right IR firm for your environment? Schedule a free consultation with ProTechtive — we help mid-market companies build response capability that works when it matters.