Retainers

Incident response retainer and cyber recovery retainer

A retainer puts Triden’s forensic responders and recovery engineers under contract before anything goes wrong. We learn your environment in advance, so when an incident happens we can deploy quickly, find the cause and get you running again.

  • 24/7 response for clients under retainer
  • Forensics and recovery from one team
  • Onboarding and readiness work included
Hand stopping a line of falling dominoes

24/7 for retainer clients

Response around the clock once your retainer is in place

DFIR

Root cause and extent of compromise, found quickly

Recovery engineers

Networking, cloud and systems engineers to restore operations

Consultants reviewing plans with a client on site

Why a retainer

Sign the contract before the incident, not during it

Without a retainer, the first hours of an incident go to finding a firm, agreeing on terms, arranging access and explaining your network. A retainer settles all of that in advance. Contacts, escalation paths, access methods and legal terms are ready, and our team has already reviewed your environment.

Retainers also help with governance. Boards, auditors, regulators and cyber insurers increasingly ask who you would call during an incident. A retainer gives you a clear answer, backed by a plan you have tested.

Retainer options

Two retainers, one team

Choose the DFIR retainer, the cyber recovery retainer or both. Most organizations that depend on continuous operations take both.

What’s included

What an IR retainer covers

How it works

Setting up your retainer

1

Scope

We review your environment, critical systems, insurance requirements and existing plans, and recommend the retainer that fits.

2

Onboard

We collect contacts, document your environment, agree on runbooks and set up the access responders will need.

3

Prepare

We review your incident response plan and can run a tabletop exercise so your team knows how response will work.

4

Stay ready

We keep your information current as your environment changes, and deploy under the retainer when an incident happens.

Cyber insurance

How a retainer works with your cyber insurance

Many cyber insurance policies include requirements for incident response, such as notifying the carrier first or using firms the carrier approves. Read your policy before you choose a retainer, and share it with us during scoping.

We structure the retainer to fit around those rules. That can mean working alongside a carrier-appointed firm, focusing on recovery engineering or supporting your internal team. Either way, you know in advance who does what.

  • Review of your policy’s incident response requirements
  • Roles agreed with you before an incident
  • Documentation that supports insurance applications and renewals
Advisor meeting with a client at a table

FAQ

Incident response retainer questions

An incident response retainer is an agreement, signed in advance, that gives you access to a response team when an incident happens. Terms, contacts and access are settled beforehand, and the team learns your environment so it can deploy quickly.

The DFIR retainer focuses on investigation and containment, finding the root cause and extent of compromise. The cyber recovery retainer focuses on restoring operations, with engineers in networking, cloud and systems who rebuild and bring systems back safely. Many clients take both.

Retainer cost depends on the size and complexity of your environment, which retainers you choose and how much readiness work, such as plan reviews and tabletop exercises, is included. Response effort during an incident depends on the incident itself. We scope the retainer with you and explain what is included before you sign.

Retainers are designed to be set up before an incident, so we can respond without delays. If you are dealing with an incident now and are not a client, contact your cyber insurance carrier first. Then talk to us about a retainer for the future.

MDR catches and contains most threats early. A larger incident, such as ransomware or a significant breach, can need forensic investigation and recovery engineering beyond day-to-day response. Triden MDR clients can add a retainer so the same team handles both.

Key contacts and decision owners, an overview of critical systems and applications, your backup approach, your incident response plan if you have one and your cyber insurance requirements. We help fill any gaps.

Talk to an expert

Put your incident response retainer in place

Tell us about your environment and insurance requirements. We’ll recommend a retainer and walk you through onboarding.

  • DFIR, cyber recovery or both
  • Onboarding and readiness planned with you

Prefer email? Write to [email protected] or call (858) 712-0040.

Send us a message