
- 01Negotiating an incident response engagement during an active incident is operationally and commercially terrible. Pre-negotiated retainers, properly structured, save days of response time and meaningful negotiating leverage when it matters most.
- 02What to negotiate in the retainer: response SLA (hours-to-onsite or hours-to-engagement), hourly rates locked for the term with capacity guarantees, pre-approved scope and rate for the most likely engagement types, use of unused retainer hours for tabletops or readiness work, clarity on chain of custody and evidence handling, indemnification/conflict of interest/confidentiality terms.
- 03Multiple firms, in tiers: a primary firm with the deepest relationship and largest retainer, a secondary firm with a smaller retainer for surge capacity/conflicts/geographic specialization, cyber insurance carrier's preferred firm noted (even if not your primary). Diversification matters more than depth at any one firm.
- 04Use the relationship between incidents: run a tabletop with your IR firm annually, have them review your runbooks, have them brief your team on current threat trends. The relationship matters; cold-calling a firm with a vague retainer mid-incident is not the experience you want.
Negotiating an incident response engagement during an active incident is operationally and commercially terrible. Pre-negotiated retainers, properly structured, save days of response time and meaningful negotiating leverage when it matters most.
What to negotiate in the retainer
- 01Response SLA (hours-to-onsite or hours-to-engagement)
- 02Hourly rates locked for the term, with capacity guarantees
- 03Pre-approved scope and rate for the most likely engagement types
- 04Use of unused retainer hours for tabletops or readiness work
- 05Clarity on chain of custody and evidence handling
- 06Indemnification, conflict of interest, and confidentiality terms
Multiple firms, in tiers
A primary firm with the deepest relationship and largest retainer. A secondary firm with a smaller retainer for surge capacity, conflicts, or geographic specialization. Cyber insurance carrier's preferred firm noted, even if not your primary. The diversification matters more than the depth at any one firm.
Use the relationship between incidents
Run a tabletop with your IR firm annually. Have them review your runbooks. Have them brief your team on current threat trends. The relationship matters; cold-calling a firm with a vague retainer mid-incident is not the experience you want.


