Security

Real offensive depth

Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
Security

How Much Does Incident Response Cost in Canada? (2026)

If you searched for this, you're probably in one of two positions: you just had an incident and are staring at an invoice that feels arbitrary, or you're trying to budget for incident response before you need it. Both are reasonable places to start, and both deserve a straight answer instead of a "it depends" that goes nowhere.

It does depend, but not on mysterious factors. Incident response pricing in Canada is driven by a small number of variables you can actually reason about: whether you're buying a retainer or paying emergency rates, the size and complexity of your environment, the type of provider you hire, and how tightly the engagement is scoped. This article breaks each of those down with real ranges.

The short answer: what IR actually costs

For Canadian small and mid-sized businesses, here's roughly what you should expect to pay:

  • Emergency, no-retainer incident response (you call a firm mid-breach with no prior relationship): $300 to $600 CAD per hour, often with a minimum engagement of 40 to 80 hours. A moderate breach investigation and containment can land anywhere from $15,000 to $80,000, and a serious one (ransomware with data exfiltration, multiple compromised systems) can run well past $100,000.
  • An IR retainer (named responders on contract before anything happens): typically $1,500 to $6,000 CAD per month for small and mid-sized organizations, depending on headcount, environment complexity, and SLA. That monthly fee usually includes a set number of prepaid response hours plus preferential rates on anything beyond that.
  • Solo consultants and independents: often the cheapest hourly rate ($150 to $300/hour) but rarely offer a true SLA, backup coverage, or 24/7 availability, which matters more than the rate once you're actually mid-incident.
  • Large platform vendors and MSSP-attached IR: retainers can start at $5,000 to $15,000+ CAD per month, often bundled with SOC monitoring or EDR licensing you may not need if you already run those tools.

Those are wide ranges on purpose. The variables below explain why a given company lands at the low end or the high end.

What actually drives the price

Retainer vs. emergency-rate response

This is the single biggest cost lever, and it's the one most buyers get backwards. Paying for a retainer before an incident happens is consistently cheaper per hour, faster to activate (no new-client onboarding while your systems are on fire), and it avoids the "crisis premium" that firms charge when you call them cold. An incident response retainer gets you named responders and a contracted SLA, which is materially cheaper than standing up an internal SOC and still far cheaper than a panicked emergency engagement.

If your organization has any regulated data, customer contracts with security requirements, or a board that asks about breach readiness, the retainer math works out in your favour within the first year even if you never use it, because the emergency rate you'd otherwise pay is 2 to 4x higher.

Environment size and complexity

A 20-person SaaS company with cloud-only infrastructure and a single identity provider is a fundamentally different scope than a 200-person company running hybrid cloud, legacy on-prem servers, and a patchwork of acquired systems. Responders bill for the time it takes to understand your environment before they can even start containment. If you don't know your own asset inventory, expect to pay for the discovery work that should have already been done.

Boutique firm vs. platform vendor vs. solo consultant

Three buyer profiles show up in this market, and each has a real tradeoff:

  • Solo consultants are cheap and personal but have no bench. If your one responder is unreachable or overloaded during a multi-day incident, you have no fallback, and there's rarely a written SLA to hold anyone to.
  • Large platform vendors have deep benches and 24/7 coverage but often require you to buy their monitoring stack, and pricing is built for enterprise budgets, not a 50-person company.
  • Boutique firms sit in between: named responders you actually know, contracted response times, and pricing scaled to your headcount rather than a one-size-enterprise rate card. This is generally the best fit for Canadian SMBs and mid-market companies that need real accountability without enterprise overhead.

Scope of the retainer itself

Retainer pricing moves with a few concrete terms, so ask about these specifically when comparing quotes:

  • Response SLA: a 1-hour acknowledgment SLA costs more than a 4-hour one. Match it to how critical your systems actually are, not to what sounds impressive.
  • Prepaid hours: most retainers bundle a set number of hours monthly or annually. Unused hours sometimes roll over, sometimes don't, so ask.
  • Scope of coverage: does the retainer cover ransomware, business email compromise, insider threats, and third-party vendor breaches, or just malware on endpoints? Get this in writing.
  • Forensics and legal support: some retainers include digital forensics and coordination with breach counsel; others bill that separately. This is a common source of surprise invoices.
Before you need it. Incident response on retainer means the contracts, the access and the runbooks already exist when the pager goes off. See how a retainer works

How to scope an engagement without overpaying

The most reliable way to avoid overpaying is to right-size the engagement before you sign, not after. A few practical steps:

  • Get an accurate asset and identity inventory first. If you don't know what systems, cloud accounts, and identity providers you run, any quote you get is a guess dressed up as a number.
  • Match SLA tier to actual business risk. A marketing website doesn't need the same response time as a production payment system. Tiering your systems lets you negotiate a lower blended rate.
  • Ask what's included versus billed separately. Forensics, legal liaison, ransomware negotiation support, and post-incident reporting are sometimes bundled and sometimes not. Get an itemized breakdown before comparing two quotes side by side.
  • Check whether the retainer overlaps with compliance work you already need. If you're pursuing SOC 2 or another framework, incident response planning is already part of that scope, and a firm that does both can avoid duplicated discovery costs. See our compliance services if that applies to you.
  • Don't buy more platform than you need. If a vendor's IR retainer requires you to also license their EDR or SIEM, price that bundle against buying IR and tooling separately. It's not always cheaper together.

Why waiting costs more than a retainer does

The math here is not subtle. A mid-sized Canadian company paying $2,500 to $4,000 a month for a retainer spends roughly $30,000 to $48,000 a year, whether or not an incident happens. The same company calling a firm cold during a live ransomware event should expect to pay that much, or more, for a single incident, on top of downtime, customer notification costs, and potential regulatory exposure. The retainer isn't insurance you hope you never use. It's the mechanism that keeps a bad week from becoming a bad year.

If you're weighing whether to build this in-house, the honest comparison is a single security analyst salary versus a full retainer with named responders, contracted SLAs, and forensics support on standby. For most organizations under a few hundred employees, the retainer wins on cost and on actual coverage.

Get a real number, not a ballpark

Ranges are useful for budgeting, but the number that matters is the one scoped to your actual environment, headcount, and risk profile. If you want a straight quote for an incident response retainer, or you're trying to figure out whether you need one at all, contact traztech and we'll walk through your environment and give you a real range, not a marketing one.

The costs that never appear on the responder's invoice

Buyers budget for the technical responders and get surprised by everything else. In a real Canadian breach of any size, the responder's fee is often a minority of total spend. Breach counsel is usually engaged first, partly for advice and partly because privilege over the investigation report is worth having, and Canadian privacy and cyber counsel bill in the range of $450 to $900 an hour. Notification has a per-person cost once you are writing to affected individuals, covering mail or email delivery, a call centre if the volume justifies it, and credit monitoring if you offer it, and that last item alone runs into six figures at consumer scale.

Then there is the internal cost that never gets counted. Your engineering team stops shipping for one to three weeks. Your support team absorbs a spike in tickets. Your account managers spend a month on customer reassurance calls, and some of those customers will ask for contractual credits or an out. Downtime is the line that dwarfs everything for a company whose product is the revenue, and it is entirely determined by how quickly you can rebuild from known-good backups rather than by how fast your responders work.

Check your cyber insurance policy before you sign any retainer

This catches people out constantly and it is worth ten minutes today. Most Canadian cyber policies name an approved panel of incident response firms and breach counsel, and using a firm outside that panel without pre-approval can reduce or void reimbursement for those costs. Companies discover this at the worst possible moment, having already engaged a responder they trust, and then face a choice between switching mid-incident or eating the bill.

The fix is to read the policy schedule now and find the panel list, then ask your broker two questions. Can our preferred firm be added to the panel, which is often possible on request with a rate card and proof of qualifications. And what is the notification requirement, because many policies require notice within 72 hours of discovery and some require insurer consent before you spend a dollar on response. Getting a firm pre-approved costs nothing and removes a decision you should not be making at 2am.

Insurance also changes the retainer maths in your favour. A retainer with a panel firm plus a documented, tested response plan is the kind of thing underwriters price on, and it is worth asking your broker what evidence would move your premium at renewal.

What Canadian breach law adds to the bill

Regulatory obligations create work whether or not the technical incident was serious. Under PIPEDA, a breach of security safeguards has to be reported to the Office of the Privacy Commissioner and to affected individuals where it creates a real risk of significant harm, and you must keep a record of every breach, including the ones you decided not to report, for 24 months. That record-keeping requirement means even a small incident generates documentation work, and the assessment of whether the harm threshold is met is a legal judgement you will be paying counsel to make.

Quebec's Law 25 adds a confidentiality incident register and notification to the Commission d'accès à l'information where the risk of serious injury exists, on a different assessment standard and with its own timing expectations. If you hold health information you are into provincial health privacy statutes with their own reporting duties. A company operating across Canada with US customers can therefore be running three or four parallel notification analyses off a single incident, and each one has an hourly cost attached.

The practical implication for budgeting is that the legal and regulatory workstream scales with the number of jurisdictions your affected records touch, not with the technical severity of the intrusion. A tidy, quickly contained intrusion into a database holding records from five provinces and eleven US states is more expensive to close out than a messy intrusion into a system holding nothing personal.

How to read an incident response invoice

Ask for the itemisation before you compare quotes, because the same total can hide very different work. A typical invoice separates hours by role, with a lead investigator or principal at the top of the rate card, analysts below, and a project or engagement manager whose hours are pure coordination. Forensic imaging and processing sometimes carries a per-endpoint or per-terabyte charge on top of hours. Cloud egress and storage for evidence preservation is a real line item when you are pulling images out of a cloud provider. After-hours and weekend multipliers, commonly 1.25x to 1.5x, apply to exactly the periods when incidents get worked.

Minimum engagement blocks are the item most likely to make a small incident feel overpriced. A 40-hour minimum on a matter that genuinely needed twelve hours of work is not a firm gouging you, it is the cost of holding a bench available, and it is one of the clearest arguments for a retainer where prepaid hours are already committed.

Two companies, the same intrusion, very different bills

Consider identical initial access through a phished credential on a cloud console. The first company retains 90 days of centralised logs, runs endpoint detection with retained telemetry, has a single identity provider, and holds an asset inventory that is current. Responders can answer the three questions that drive cost, which are how they got in, what they touched, and whether they are still there, in about two days. Scope is bounded, notification analysis is narrow because the data accessed is known, and the engagement closes inside a week.

The second company has 7-day log retention on some systems and none on others, no endpoint telemetry, three identity systems including a legacy directory, and an asset list from two years ago. Responders cannot prove what was accessed, and the absence of proof is not treated as proof of absence by regulators, counsel, or customers. The investigation expands to cover everything the compromised credential could theoretically have reached, notification goes wide because scope could not be narrowed, and the engagement runs three weeks with a far larger legal tail attached.

The difference between those two invoices is bought in advance for a fraction of the gap, and the purchase is log retention, identity consolidation, and an inventory you maintain. That is unglamorous security engineering work, and it is the highest-return incident response spending available to a company that has not yet had an incident.

The first hour, and what it does to the cost

A handful of decisions in the first hour move the final number more than any negotiation over rates. Preserve before you remediate. Wiping and rebuilding a compromised server feels productive and destroys the evidence needed to determine scope, which pushes the investigation towards worst-case assumptions and wider notification. Snapshot volumes rather than powering machines down blindly, because memory contents are lost on shutdown and are sometimes the only place the answer lives. Extend log retention immediately across identity, cloud, and endpoint tooling, since default retention windows keep rolling while you deliberate and every hour of deliberation deletes evidence.

Move incident communications off the systems you suspect are compromised. Engage counsel before the technical investigation produces written findings, so the investigation runs under privilege rather than generating a document you later wish did not exist. And write a timeline as you go, with times in a single timezone, because reconstructing it three weeks later from memory and chat scrollback is billable work you are paying someone to do badly.

When a retainer is the wrong purchase

We will say this plainly because it costs us business. If you are a ten-person company running on managed cloud services, with no customer personal data beyond email addresses, no regulated obligations, and no contracts committing you to response times, a monthly incident response retainer is probably not your best next dollar. Buy the fundamentals first. Enforce multi-factor authentication everywhere, turn on and retain the logs your platforms already offer for free, verify that a backup restore actually works by doing one, and write a two-page plan naming who calls whom. That work costs very little and removes more expected loss than a retainer does at your size.

Equally, if your cyber policy already includes a panel firm with a pre-agreed rate and an acceptable response time, you may effectively hold a retainer already. Read it before buying a second one. And if the real gap is that nobody senior owns security decisions between incidents, a retainer for emergencies does not fix that. Fractional CISO engagements start from $3,000 a month and address the ownership problem rather than the response problem, which for a lot of companies is the more honest diagnosis.

The case for a retainer becomes strong when you hold regulated or sensitive data, when customer contracts commit you to notification windows you cannot currently meet, when downtime has a number attached that your CFO can state, or when you have already had one incident and know what the cold-call experience is like. If you are in that position, our retainer and continuous response options set out what is contracted and what is billed separately, and published starting prices for the fixed-scope work sit on the pricing page.

Before you need it. Incident response on retainer means the contracts, the access and the runbooks already exist when the pager goes off.

See how a retainer worksOr talk about a retainer

What we charge for this. The figures above are market ranges. Our own fixed-scope prices are on the pricing page, alongside every cost breakdown we have written.

Before you go

Want the rest of this by email?

If this was useful, I send a few short notes on incident response. Unsubscribe in one click, and replies reach me directly.

From Jacob Masse, principal of traztech. No spam, unsubscribe in one click.

Want a second opinion on where you stand?

We run SOC 2, ISO 27001 and the rest of the compliance stack for startups and SMEs, and the security testing that sits behind it. The first call is free, and we will tell you if you are not ready to start yet.

Book a free call

Track record

Who is actually doing the work

5
Published CVEs, including a CVSS 9.1
76
Controls taken from nothing to a passed SOC 2 Type II
Zero
Exceptions on that Type II report
20+
Penetration testing engagements delivered

Published vulnerability research

Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

A SOC 2 Type II built from nothing

At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15.