On-call · Recurring

Incident Response Retainer

When production breaks at 2am (credentials in a public repo, a customer reporting an exploit, your AWS account locked out) you need someone who answers the phone and knows what to do. $1K–$3K/month gets you that someone, with a guaranteed response SLA.

Book a scoping call

What you get for the monthly fee

Three tiers, one shape: a real human on call, a contracted SLA, and the relationship in place before you need it.

Starter$1,000 / mo
2hr ack · 8hr hands-on · 4 retainer hrs
Standard$2,000 / mo
1hr ack · 4hr hands-on · 8 retainer hrs
Priority$3,000 / mo
30min ack · 2hr hands-on · 12 retainer hrs

All tiers: 24/7 coverage, contracted SLA, escalation paths into your tooling (PagerDuty, Slack, phone, email). Unused retainer hours roll forward one month.

When the pager goes off

Active incidents, not advisory hours. We are in the call within the SLA, in your tooling, working the problem with your engineers.

01

Live incident command

We run the war room: triage severity, lead the bridge call, write status updates, coordinate engineering and customer comms. Your team focuses on the technical fix; we own the process.

02

Containment & eradication

Compromised credentials, malicious commits, exfiltration in progress, DDoS. We have done all of these. Years of running production systems at 99.9%+ uptime and operating an anti-DDoS platform that was acquired within a year of launch.

03

Postmortem & disclosure

Blameless postmortem with timeline, root cause, and remediation owners. If customer data was touched, we draft the breach disclosure and coordinate with your legal team. SOC 2 evidence captured along the way.

04

Quarterly tabletops

The retainer is not just for when things burn. Every quarter we run a tabletop on a realistic scenario for your stack (credential leak, ransomware, vendor compromise) so the playbook is tested before it is used.

Why startups buy this

A breach mid-fundraise will cost you more than the retainer's lifetime fees. The math is simple.

·

You do not have time to vet a responder mid-incident

The worst time to find an IR firm is while you are bleeding. The relationship, the contracts, the access, all of that needs to exist beforehand. The retainer puts the paperwork on the shelf so you only call.

·

SOC 2 and enterprise customers expect it

Your enterprise security questionnaire will ask if you have a retained incident response provider. Saying "yes, with documented SLA" closes the row. Saying "no, we will figure it out" loses deals.

·

Cheap when quiet, valuable when loud

Most months you will use a few retainer hours for tabletops and security reviews. The month you actually have an incident, the retainer pays back its lifetime cost in a single weekend.

Getting set up

Two weeks from contract to ready-state. We need the runbook in place before the first call.

01

Contract & access

MSA, retainer SOW, NDA. Read-only access into your cloud, identity provider, and observability stack so we can move fast on day one of an incident. We sign your security questionnaire, not the other way around.

02

Runbook & escalation tree

We document your stack, key contacts, decision authority, and escalation paths. PagerDuty integration, Slack channel, phone numbers. Your team knows exactly how to call us; we know exactly who to call back.

03

First tabletop

Within 30 days of signing, we run a tabletop on the most likely incident type for your business. Surfaces gaps in the runbook before they cost you a real one.

Works well with

Sign the paperwork before you need it

15-minute scoping call. Tier picked, contract drafted, retainer in place within a week.

Book a Call

Frequently asked questions

What does an incident response retainer include?

A retainer gives you a defined response path before something goes wrong: an agreed escalation process, prepared runbooks, and reserved access to responders when you need them. It covers triage, containment guidance, and coordination during an incident, plus periodic readiness work like tabletop exercises.

How fast do you respond?

Response targets are set in the retainer agreement so expectations are clear up front. Having a retainer in place is what makes a fast response possible, because access, contacts, and runbooks are already established before an incident rather than scrambled together during one.

Why a retainer instead of calling someone when we get hit?

During an active incident, hours matter and onboarding a stranger to your environment is slow and risky. A retainer means we already know your stack, your contacts, and your runbooks. You also get the preventative work (tabletops, escalation trees) that reduces the chance of an incident in the first place.

Do you handle the technical containment yourselves?

We lead triage, containment strategy, and coordination, and work hands-on within the scope agreed in your retainer. For deep forensic or specialist offensive work we bring in our partner Lorikeet Security. The retainer defines exactly what is covered so there are no surprises mid-incident.

Does this help with SOC 2 or cyber insurance?

Yes. A documented incident response plan and an IR retainer are commonly expected for SOC 2 and frequently requested by cyber insurers. The runbooks and tabletop records we produce serve as evidence for both.