Managed cyber security

Incident Response Retainer

A known number, agreed process and priority support when something goes wrong.

What is Incident Response Retainer?

An incident-response retainer gives the business a known escalation route, pre-agreed contacts, response priorities and practical preparation before an attack occurs. 39Security helps contain technical risk, coordinate recovery and record actions, while specialist legal, insurance, forensic or communications advisers can be involved where the incident requires them.

Who is this service for?

Businesses that cannot justify an internal incident-response team but need a dependable route for ransomware, account compromise, data exposure, payment fraud or major system disruption.

What problem does it solve?

During an incident, teams lose time deciding who has authority, whether systems should be disconnected, how evidence should be preserved and who must be notified. Unplanned changes can destroy useful evidence or increase business interruption.

What is included?

  • Incident-response planning workshop
  • Named escalation contacts and priority route
  • Initial triage and severity assessment
  • Remote containment guidance and coordination
  • Identity, endpoint, email, firewall and backup actions within managed scope
  • Evidence-preservation guidance
  • Incident log and post-incident review
  • Tabletop exercise according to the retainer

What is not included?

  • Unlimited response hours
  • Guaranteed recovery of encrypted or stolen data
  • Legal privilege, regulatory advice or crisis PR
  • Specialist forensic imaging unless commissioned
  • Ransom negotiation or payment services

How implementation works

We identify decision-makers, insurers, legal contacts, key suppliers, critical systems and communication routes. Response authority, out-of-hours contacts and evidence requirements are documented. A tabletop exercise tests the plan and produces improvement actions before a real event.

Supported platforms and products

The retainer can coordinate incidents involving Microsoft 365, Windows endpoints and servers, email, firewalls, networks, supported backups and managed security platforms. Third-party application and cloud-provider involvement depends on access and supplier cooperation.

How quickly are alerts investigated?

The retainer provides the escalation path stated in the agreement. Detection may come from MDR, EDR, email security, monitoring, staff or a third party. Exact response hours and priority targets are documented so the buyer knows what “priority” means.

Who responds?

A named technical lead triages the incident, agrees immediate containment, maintains an action log and coordinates relevant teams. Actions can include isolating devices, securing accounts, preserving logs, validating backups and planning controlled recovery.

What evidence and reporting will you receive?

The customer receives an incident record, timeline, decisions, actions and post-incident recommendations. This can support insurer, customer and management conversations, but legal or regulatory submissions should be reviewed by the appropriate adviser.

Cyber Essentials, insurance and Microsoft 365

Incident preparation supports cyber insurance, business continuity and ISO/IEC 27001 governance. Cyber Essentials reduces common attack paths but does not remove the need for an incident plan or response capability.

What does it cost?

Retainers are priced according to response hours, covered systems, availability and included preparation. Additional response, travel, specialist forensics or recovery projects are charged under the agreed schedule and exclude VAT unless stated.

How is the service governed?

Before activation, the proposal should identify the covered users, devices, locations and platforms, together with the service window, escalation contacts and change responsibilities. During operation, material exceptions are recorded rather than hidden, and recommendations are separated into urgent actions, planned improvements and optional projects. This gives managers a practical view of risk, cost and ownership.

Service reviews should test whether coverage still matches the business. New starters, leavers, acquisitions, cloud applications, office moves and supplier changes can all create gaps. 39Security therefore treats onboarding, reporting and periodic review as part of the control, not as administration around the edge of the product.

What should good delivery look like?

A buyer should be able to identify what is protected, who is watching it, what happens when something goes wrong and which evidence will be available afterwards. The provider should explain limitations honestly, avoid vague promises and document any dependency on Microsoft licensing, internet connectivity, third-party suppliers or customer action. Clear boundaries make response faster and reduce disputes during an incident.

Questions to ask before selecting a provider

  • Which systems, users and locations are included in the quoted scope?
  • Who reviews alerts, during which hours, and what happens when the named contact is unavailable?
  • What evidence will we receive for clients, insurers, auditors or board reporting?
  • Which actions are included in the monthly fee and which require separate project approval?
  • How are service quality, response times, exclusions and exit arrangements documented?

Frequently asked questions

What should we do first after a suspected cyber incident?

Use the agreed escalation route, preserve evidence and avoid uncontrolled changes. Protect affected accounts or systems where safe, record what has happened and contact the response team, insurer and legal adviser according to the incident plan.

Does a retainer include 24/7 unlimited response?

Not automatically. The agreement must state coverage hours, included response time, priority targets and additional charges. Buyers should avoid relying on vague claims that are not supported by a written service schedule.

Will you contact the ICO or customers for us?

39Security can provide technical facts and evidence, but legal notification decisions should be made with the organisation’s data-protection and legal advisers. The client remains responsible for regulatory and customer communications.

Can you recover from ransomware?

Recovery depends on containment, clean backups, system condition and the attacker’s access. The response team coordinates safe recovery and validation, but no responsible provider can guarantee that every system or item of data will be recoverable.