Retainer Agreement
Definition
A contract between an organisation and an external IR firm that guarantees a defined response time and service scope in exchange for a pre-paid monthly or annual fee. Retainers ensure the firm has pre-authorised access to the environment and is familiar with the organisation's architecture before an incident occurs.
- Field
- Incident response team building
- Structure
- Pre-paid monthly or annual fee
- Guarantees
- Defined response time and service scope
- Key benefit
- Pre-authorised access before an incident occurs
Common questions
Why does pre-authorised access speed up an incident response?+
Legal and procurement steps such as vendor onboarding, NDAs, and network access approvals are the slowest part of engaging an unfamiliar firm during an active incident. A retainer completes those steps in advance so the firm can start work within the guaranteed response window.
What happens if a retained firm's guaranteed response time is missed?+
Retainer agreements typically specify service-level penalties or credits for missed response windows, and organisations should verify these terms and any exclusions before relying on the retainer as their sole incident response capability.
Is a retainer agreement the same as a cyber insurance policy?+
No, a retainer secures a specific firm's hands-on response services, while cyber insurance covers financial losses from an incident. Many insurance policies require or recommend the insured have a retainer with an approved responder panel.
Related terms
- CSIRT
- Computer Security Incident Response Team. The organisational unit responsible for preparing for, detecting, coordinating, and resolving security incidents. Sometimes called CERT (Computer...
- FIRST
- Forum of Incident Response and Security Teams. A global membership organisation that sets standards for CSIRT capability and facilitates trusted information sharing...
- Legal Liaison
- The CSIRT role responsible for advising on legal obligations during an incident: evidence preservation requirements, breach notification deadlines, law enforcement engagement, and...
- National CERT
- A government-operated or government-designated team responsible for coordinating cyber incident information at the national level. Examples include CERT-In (India), CISA (US), NCSC...
- Team Lead
- The person who owns the incident response process during an active incident. The team lead coordinates analyst tasks, manages escalation to leadership,...