Retainers
Incident response retainer and cyber recovery retainer
A retainer puts Triden’s forensic responders and recovery engineers under contract before anything goes wrong. We learn your environment in advance, so when an incident happens we can deploy quickly, find the cause and get you running again.

24/7 for retainer clients
Response around the clock once your retainer is in place
DFIR
Root cause and extent of compromise, found quickly
Recovery engineers
Networking, cloud and systems engineers to restore operations

Why a retainer
Sign the contract before the incident, not during it
Without a retainer, the first hours of an incident go to finding a firm, agreeing on terms, arranging access and explaining your network. A retainer settles all of that in advance. Contacts, escalation paths, access methods and legal terms are ready, and our team has already reviewed your environment.
Retainers also help with governance. Boards, auditors, regulators and cyber insurers increasingly ask who you would call during an incident. A retainer gives you a clear answer, backed by a plan you have tested.
Retainer options
Two retainers, one team
Choose the DFIR retainer, the cyber recovery retainer or both. Most organizations that depend on continuous operations take both.
24/7 DFIR retainer
Rapid deployment of digital forensics and incident response to find the root cause and extent of a compromise. Responders contain the threat, preserve evidence and give leadership, counsel and insurers the facts they need for decisions and notifications.
24/7 cyber recovery retainer
Rapid deployment of engineers in networking, cloud and systems to contain an incident and restore operations. Recovery engineers rebuild and restore systems, validate that they are clean and bring the business back online in a planned order.
Both retainers together
Investigation and recovery under one agreement. Forensic responders and recovery engineers work from the same plan, so root cause findings shape how and when systems are restored.
What’s included
What an IR retainer covers
Onboarding and environment review
We document your systems, critical applications, backups and contacts so responders start with context.
Agreed runbooks and access
Escalation paths, decision owners and the access responders need, agreed and tested before an incident.
24/7 activation
Clients under retainer can reach our team around the clock through the contacts in their agreement.
Post-incident reporting
Findings, root cause, actions taken and the fixes that prevent a repeat, written for IT and leadership.
How it works
Setting up your retainer
Scope
We review your environment, critical systems, insurance requirements and existing plans, and recommend the retainer that fits.
Onboard
We collect contacts, document your environment, agree on runbooks and set up the access responders will need.
Prepare
We review your incident response plan and can run a tabletop exercise so your team knows how response will work.
Stay ready
We keep your information current as your environment changes, and deploy under the retainer when an incident happens.
Cyber insurance
How a retainer works with your cyber insurance
Many cyber insurance policies include requirements for incident response, such as notifying the carrier first or using firms the carrier approves. Read your policy before you choose a retainer, and share it with us during scoping.
We structure the retainer to fit around those rules. That can mean working alongside a carrier-appointed firm, focusing on recovery engineering or supporting your internal team. Either way, you know in advance who does what.

FAQ
Incident response retainer questions
Related services
Related services
Talk to an expert
Put your incident response retainer in place
Tell us about your environment and insurance requirements. We’ll recommend a retainer and walk you through onboarding.
Prefer email? Write to [email protected] or call (858) 712-0040.
