If you searched for this, you're probably in one of two positions: you just had an incident and are staring at an invoice that feels arbitrary, or you're trying to budget for incident response before you need it. Both are reasonable places to start, and both deserve a straight answer instead of a "it depends" that goes nowhere.
It does depend, but not on mysterious factors. Incident response pricing in Canada is driven by a small number of variables you can actually reason about: whether you're buying a retainer or paying emergency rates, the size and complexity of your environment, the type of provider you hire, and how tightly the engagement is scoped. This article breaks each of those down with real ranges.
The short answer: what IR actually costs
For Canadian small and mid-sized businesses, here's roughly what you should expect to pay:
- Emergency, no-retainer incident response (you call a firm mid-breach with no prior relationship): $300 to $600 CAD per hour, often with a minimum engagement of 40 to 80 hours. A moderate breach investigation and containment can land anywhere from $15,000 to $80,000, and a serious one (ransomware with data exfiltration, multiple compromised systems) can run well past $100,000.
- An IR retainer (named responders on contract before anything happens): typically $1,500 to $6,000 CAD per month for small and mid-sized organizations, depending on headcount, environment complexity, and SLA. That monthly fee usually includes a set number of prepaid response hours plus preferential rates on anything beyond that.
- Solo consultants and independents: often the cheapest hourly rate ($150 to $300/hour) but rarely offer a true SLA, backup coverage, or 24/7 availability, which matters more than the rate once you're actually mid-incident.
- Large platform vendors and MSSP-attached IR: retainers can start at $5,000 to $15,000+ CAD per month, often bundled with SOC monitoring or EDR licensing you may not need if you already run those tools.
Those are wide ranges on purpose. The variables below explain why a given company lands at the low end or the high end.
What actually drives the price
Retainer vs. emergency-rate response
This is the single biggest cost lever, and it's the one most buyers get backwards. Paying for a retainer before an incident happens is consistently cheaper per hour, faster to activate (no new-client onboarding while your systems are on fire), and it avoids the "crisis premium" that firms charge when you call them cold. An incident response retainer gets you named responders and a contracted SLA, which is materially cheaper than standing up an internal SOC and still far cheaper than a panicked emergency engagement.
If your organization has any regulated data, customer contracts with security requirements, or a board that asks about breach readiness, the retainer math works out in your favour within the first year even if you never use it, because the emergency rate you'd otherwise pay is 2 to 4x higher.
Environment size and complexity
A 20-person SaaS company with cloud-only infrastructure and a single identity provider is a fundamentally different scope than a 200-person company running hybrid cloud, legacy on-prem servers, and a patchwork of acquired systems. Responders bill for the time it takes to understand your environment before they can even start containment. If you don't know your own asset inventory, expect to pay for the discovery work that should have already been done.
Boutique firm vs. platform vendor vs. solo consultant
Three buyer profiles show up in this market, and each has a real tradeoff:
- Solo consultants are cheap and personal but have no bench. If your one responder is unreachable or overloaded during a multi-day incident, you have no fallback, and there's rarely a written SLA to hold anyone to.
- Large platform vendors have deep benches and 24/7 coverage but often require you to buy their monitoring stack, and pricing is built for enterprise budgets, not a 50-person company.
- Boutique firms sit in between: named responders you actually know, contracted response times, and pricing scaled to your headcount rather than a one-size-enterprise rate card. This is generally the best fit for Canadian SMBs and mid-market companies that need real accountability without enterprise overhead.
Scope of the retainer itself
Retainer pricing moves with a few concrete terms, so ask about these specifically when comparing quotes:
- Response SLA: a 1-hour acknowledgment SLA costs more than a 4-hour one. Match it to how critical your systems actually are, not to what sounds impressive.
- Prepaid hours: most retainers bundle a set number of hours monthly or annually. Unused hours sometimes roll over, sometimes don't, so ask.
- Scope of coverage: does the retainer cover ransomware, business email compromise, insider threats, and third-party vendor breaches, or just malware on endpoints? Get this in writing.
- Forensics and legal support: some retainers include digital forensics and coordination with breach counsel; others bill that separately. This is a common source of surprise invoices.
How to scope an engagement without overpaying
The most reliable way to avoid overpaying is to right-size the engagement before you sign, not after. A few practical steps:
- Get an accurate asset and identity inventory first. If you don't know what systems, cloud accounts, and identity providers you run, any quote you get is a guess dressed up as a number.
- Match SLA tier to actual business risk. A marketing website doesn't need the same response time as a production payment system. Tiering your systems lets you negotiate a lower blended rate.
- Ask what's included versus billed separately. Forensics, legal liaison, ransomware negotiation support, and post-incident reporting are sometimes bundled and sometimes not. Get an itemized breakdown before comparing two quotes side by side.
- Check whether the retainer overlaps with compliance work you already need. If you're pursuing SOC 2 or another framework, incident response planning is already part of that scope, and a firm that does both can avoid duplicated discovery costs. See our compliance services if that applies to you.
- Don't buy more platform than you need. If a vendor's IR retainer requires you to also license their EDR or SIEM, price that bundle against buying IR and tooling separately. It's not always cheaper together.
Why waiting costs more than a retainer does
The math here is not subtle. A mid-sized Canadian company paying $2,500 to $4,000 a month for a retainer spends roughly $30,000 to $48,000 a year, whether or not an incident happens. The same company calling a firm cold during a live ransomware event should expect to pay that much, or more, for a single incident, on top of downtime, customer notification costs, and potential regulatory exposure. The retainer isn't insurance you hope you never use. It's the mechanism that keeps a bad week from becoming a bad year.
If you're weighing whether to build this in-house, the honest comparison is a single security analyst salary versus a full retainer with named responders, contracted SLAs, and forensics support on standby. For most organizations under a few hundred employees, the retainer wins on cost and on actual coverage.
Get a real number, not a ballpark
Ranges are useful for budgeting, but the number that matters is the one scoped to your actual environment, headcount, and risk profile. If you want a straight quote for an incident response retainer, or you're trying to figure out whether you need one at all, contact traztech and we'll walk through your environment and give you a real range, not a marketing one.