Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.
Should you have an incident response retainer before a breach?
Updated
Buy a retainer when surge, panel, or a notification clock will outrun a new procurement. Use on-demand when the estate is small, in-house capture is sound, and YOUR policy does not require a panel. This is a decision tree, not a ranking. Not legal advice.
Operational guidance, last verified 7 September 2026 against NIST SP 800-61 Revision 3 (Incident Response Recommendations and Considerations for Cybersecurity Risk Management: A CSF 2.0 Community Profile) — current final as of April 2025; it superseded SP 800-61r2; it is guidance, not a statute, and it does not require you to buy a commercial retainer — CISA's Federal Government Cybersecurity Incident and Vulnerability Response Playbooks (CISA notes other organizations may use them to standardize practice), ENISA's Good Practice Guide for Incident Management (guidance for incident handling, not a statute), and generic insurer panel-vendor norms in NAIC cyber-claims materials. Published breach-cost benchmark reports (for example IBM's Cost of a Data Breach) are industry data, not law; this page does not reprint their figures and does not invent ROI. This page does not sell retainers, does not interpret YOUR policy, does not rank DFIR firms, does not name any, and is not a substitute for counsel, your insurer, or a retained DFIR firm. The incident-response-retainer page on this site is the explainer (what a retainer is, typical terms). The when-you-need-dfir page on this site is the retain-or-not tree. The how-to-select-a-dfir-provider page on this site is the selection decision tree. The contact-cyber-insurance page on this site is the notice-and-panel checklist. A dedicated incident-reporting-deadlines guide is not on this site yet. The breach-investigation-cost page on this site is the cost-driver explainer. Not legal advice. Not coverage advice. Not procurement advice. Not financial advice.
This is a buy-or-wait tree, not a ranking and not YOUR policy
Audience: a founder, eng leader, CISO, CTO, counsel, or incident commander deciding whether to commit budget to an IR / DFIR retainer now versus engage on-demand later. The incident-response-retainer page on this site is the commercial-structure explainer: what a retainer is, how it differs from on-demand, and typical terms (hours, panel, notice) as generic market design — not YOUR SOW. The when-you-need-dfir page on this site is the in-house-versus-firm decision. The how-to-select-a-dfir-provider page on this site is how to select, using criteria you can defend. This page is the buy-or-wait step: when a pre-breach retainer is worth the reservation versus when on-demand (plus, if you have a form, the panel) is enough. The contact-cyber-insurance page on this site is the notice-and-panel checklist. The what-is-dfir page on this site is the DFIR explainer. The best-digital-forensics-firms page on this site is the inclusion-criteria checklist. It does not rank DFIR firms, does not name any, and is not a directory. The questions-to-ask-an-incident-response-provider page on this site is the question bank. The breach-investigation-cost page on this site is the cost-driver explainer. A dedicated best-incident-response-firms guide is not on this site yet. A dedicated incident-reporting-deadlines guide is not on this site yet.
NIST SP 800-61r3 is the current final incident-response guidance this page cites — a CSF 2.0 community profile, guidance, not a statute. It superseded SP 800-61r2 in April 2025. It treats incident response as part of cybersecurity risk management and tells organizations to integrate detection, response, and recovery into operations before they need them. That is a preparedness argument, not a statute that you must buy a commercial retainer. CISA's incident-response playbooks are operational procedures for US federal civilian executive branch systems; CISA notes other organizations may use them to standardize practice; they include identifying resources before an incident. ENISA's Good Practice Guide for Incident Management describes incident-handling good practice for CSIRT-class work; it is guidance, not a requirement to retain a named commercial firm. NAIC cyber-claims materials describe panel-vendor and prior-agreement conditions as they appear in policies; they do not interpret YOUR policy. None of those sources is a ranking of firms, a model retainer, coverage advice, or an ROI. Last verified 7 September 2026. Not legal advice. Not coverage advice. Not procurement advice. Not financial advice.
- A retainer is a pre-signed contract so a DFIR firm can start without a new procurement when an incident hits. It is not a trophy vendor and not a ranking. This page does not rank retainers and does not name firms.
- On-demand engagement is scoped after the incident is already running. Both models still sit under counsel, and under YOUR policy's notice and panel clauses if you have a cyber form. On-demand is not a failure and not 'the cheap option' this page will price.
- If you have a cyber policy, the panel or prior-consent clause is a contract constraint. It is not a quality ranking. Notice the carrier before you retain off-panel. The contact-cyber-insurance page on this site is that checklist. Verify YOUR policy.
- Company size, data class, regulatory clocks, and insurance posture are factors on the tree below. None of them is, by itself, a law that you must buy a retainer. Empty answers are unknowns, not a pass.
- This page does not sell retainers, does not interpret YOUR policy, does not invent dollar figures, does not invent ROI, does not rank DFIR firms, does not start a notification clock, is not legal advice, is not coverage advice, is not procurement advice, and is not financial advice.
Decision tree — retainer versus on-demand
Walk top to bottom with the commander, counsel, and, if you have a policy, the broker. A 'yes' on an earlier row does not skip the later questions: a panel clause still applies after you decided you want surge reserved; a notification clock, if it applies, does not replace insurer notice. Last verified 7 September 2026. Not legal advice. Not coverage advice. Not procurement advice. Not financial advice.
| Question | If the facts point yes | If the facts point no |
|---|---|---|
| Are we already mid-incident? | Do not shop a retainer now. Preserve first. Page the panel or on-demand firm after counsel and, if you have a policy, the carrier. The we've-been-breached page on this site is the first-moves hub. The preserve-evidence page on this site is the order-of-volatility checklist. A retainer you have not signed yet does not delay capture. | Continue this tree in peacetime. NIST SP 800-61r3: integrate incident response into risk management before you need it. That is guidance, not a SKU. |
| Have we decided we need a DFIR firm at all — forensic capture we cannot do in-house, regulated data, theft unknown, litigation in view, or an insurer panel? | Continue. The when-you-need-dfir page on this site is the retain-or-not tree. A retainer is one way to pre-establish that firm. It is not a reason to retain a firm as theatre. | Stop. You do not buy a retainer to decorate a vendor list. In-house method plus a documented on-demand path can be enough. Re-walk the tree when the estate, data class, or policy changes. |
| Does YOUR cyber policy have a panel or prior-consent clause for DFIR, or does the application ask whether you already have a retainer? | Read the form. A panel or prior-consent clause is a contract constraint, not a quality ranking. An application question about an existing retainer is underwriting, not a statute. Use the panel, or get written consent, before you sign off-panel. NAIC cyber-claims materials: some policies require a preapproved incident-response vendor list; others require prior mutual agreement to a particular provider. Verify YOUR policy. The contact-cyber-insurance page on this site is that checklist. Not coverage advice. | Do not invent a panel. The tree still applies: size, data, clocks, and surge. You are not using a carrier list as a substitute for class, jurisdiction, or scope. The how-to-select-a-dfir-provider page on this site is that tree. |
| Will a notification clock — if it applies — outrun a new procurement? (GDPR Article 33 72-hour band; CRA Article 14 24-hour / 72-hour / 14-day ladder; other clocks counsel maps.) | A pre-signed SOW is one way to stop procurement from eating the clock. A retainer does not start the clock, does not decide whether a duty applies, and is not a filing. This page does not start a clock. A dedicated incident-reporting-deadlines guide is not on this site yet. Counsel maps which clocks apply. | Clocks are not the only reason to reserve surge. You can still want a retainer for staffing. You can still use on-demand if capture is sound and counsel agrees. Do not treat a possible clock as a purchase order. |
| Is the data class high-stakes for THIS estate — cardholder data (PFI class), special-category personal data, trade secrets, OT — such that a rushed on-demand pick is the failure mode? | A pre-established relationship (retainer or panel-cleared on-demand) is the preparedness move. Select on class, jurisdiction, and scope, not a brand. The how-to-select-a-dfir-provider page on this site is that tree. The best-digital-forensics-firms page on this site is the roster checklist. | Data class alone is not a statute. A small estate with no regulated data and sound in-house capture can wait. Re-walk when the data class changes. |
| Is the estate large or complex enough that surge staffing — who pages after hours, for THIS class of work — is the constraint, not the hour bank? | A retainer that names the surge clock is one way to reserve that staffing. A marketing SLA is not a ranking and not a statute. Read what they actually staff. The incident-response-retainer page on this site is the terms explainer. This page does not invent hour numbers. | Size is a factor, not a law. A 10-person company with card data or a panel clause is not 'too small for a retainer.' A large estate with a cleared panel and a documented on-demand path is not required to prepay hours. Empty answers are unknowns. |
| Is the cost of delay — procurement, panel consent, and scoping on the incident clock while logs rotate — worse than unused prepaid hours sitting through a quiet year? | That is a judgment for the commander, counsel, and finance. It is not an ROI this page will invent. See the fictional delay example below. The breach-investigation-cost page on this site is the cost-driver explainer. Not financial advice. | On-demand plus a written panel path can be the honest call. Document who you would page, how you would notice the carrier, and who signs the SOW. Unused hours are not a quality score. This page does not invent dollar figures. |
Factors — size, data, regulation, insurance (not a statute)
The rows below are factors, not a scoring model and not a purchase rule. Combine them on the tree; do not treat any one cell as a law. Last verified 7 September 2026. Not legal advice. Not coverage advice. Not procurement advice. Not financial advice.
| Factor | Tilts toward a retainer | Tilts toward on-demand | Limit |
|---|---|---|---|
| Company size / estate complexity | Many systems, after-hours operations, or no trained capture bench — surge is the constraint. | Small estate, few systems, in-house capture is sound, and a named on-demand path exists. | Headcount is not a statute. A small company with card data or a panel clause is not exempt. A large company with a cleared panel is not required to prepay hours. |
| Data sensitivity | Cardholder data, special-category personal data, trade secrets, or OT in play — a rushed pick is the failure mode. | No regulated personal data, no card data, no OT, and counsel agrees in-house method is enough. | Data class is a factor. It is not, by itself, a duty to buy a retainer. PFI is a cardholder-data investigation class, not a general 'you must retain' mark. |
| Regulatory exposure | A clock that may apply (GDPR Article 33, CRA Article 14, NIS2, DORA) will outrun a new SOW. Counsel has mapped a plausible duty. | No plausible notification duty on the facts counsel has now, and capture will not collide with a clock. | This page does not start a clock and does not decide whether a duty applies. A retainer is not a filing. A dedicated incident-reporting-deadlines guide is not on this site yet. |
| Insurance posture | The form has a panel or prior-consent clause, or the application asks whether a retainer is already in place. Pre-clearing the firm removes a coverage argument later. | No cyber form, or the form has no panel / prior-consent clause and does not ask about a retainer. | Panel is a contract role, not a quality ranking. An application question is underwriting, not a law. Verify YOUR policy. This page does not interpret it. Not coverage advice. |
Cost of delay — a fictional example, not an ROI
This is a delay story, labeled fictional, so a founder and finance can see the clock without a fabricated price. It is not YOUR incident, not a benchmark, and not a reason to buy. This page does not invent dollar figures, hour counts, or ROI. Published breach-cost benchmark reports (for example IBM's Cost of a Data Breach) are industry data, not law; they mix investigation, interruption, notification, and lost business, and they do not tell YOU to buy a retainer. The breach-investigation-cost page on this site is the cost-driver explainer. Last verified 7 September 2026. Not financial advice. Not legal advice. Not coverage advice.
| Clock | Without a pre-signed retainer | With a pre-signed on-panel retainer |
|---|---|---|
| Friday 22:00 — commander confirms an incident | Preserve first anyway. Then: who is on the panel, who can sign a new SOW, who notices the carrier. Those questions run on the incident clock. | Preserve first anyway. Notice the carrier. Page the named firm against the pre-signed SOW. Notice is not the same as paging the firm. Verify YOUR policy. |
| Saturday 02:00 — logs still rotating | If the SOW is not signed, capture is still on you. A firm you have not engaged cannot image a host you already rebuilt. The preserve-evidence page on this site is that checklist. | The firm can start if the SOW and panel already allow it. Unused prepaid hours are what you spent to skip this delay. They are not a quality score. |
| Monday 09:00 — a 72-hour band may be running | Procurement and panel consent have already used part of the band. A retainer would not have started the clock; it would have stopped procurement from eating it. This page does not decide whether a duty applies. | The firm is already working. The clock, if it applies, is still counsel's. A retainer is not a GDPR Article 33 notice and not a CRA Article 14 filing. |
| What this example is not | Not a claim that on-demand always misses evidence. Not a price. Not a fabricated statistic. Not YOUR ROI. | Not a claim that a retainer always pays for itself. Not a product this site sells. Not a ranking of firms. |
Four kinds of claim — do not mix them
A statute, a policy clause, a NIST or ENISA guide, and a product surface are not the same kind of claim. This page keeps them apart. Last verified 7 September 2026. Not legal advice. Not coverage advice. Not financial advice.
| Kind of claim | What it is | What this page does with it |
|---|---|---|
| Legal requirement | Rare. NIST SP 800-61r3, CISA IR playbooks, and ENISA incident-management guidance do not require you to buy a commercial retainer. Notification statutes (GDPR Article 33, CRA Article 14, NIS2, DORA, US-state clocks) are separate duties counsel maps. | Do not treat a retainer as a law. This page does not start a notification clock and does not decide whether a duty applies. A dedicated incident-reporting-deadlines guide is not on this site yet. |
| Insurer requirement | Some cyber forms require a preapproved panel or prior consent before DFIR costs are covered; some applications ask whether you already have a retainer. NAIC cyber-claims materials record panel-vendor and prior-agreement designs. | Describe generic panel-vendor norms. Verify YOUR policy. This page does not interpret it and is not coverage advice. The contact-cyber-insurance page on this site is the notice-and-panel checklist. |
| Best practice / guidance | NIST SP 800-61r3: integrate incident response into cybersecurity risk management before you need it. CISA IR playbooks: identify resources. ENISA Good Practice Guide for Incident Management: incident-handling good practice. Relationships are the point; a specific commercial product is not. Published breach-cost reports are industry data, not law. | Cite the guides as guides, not as a statute and not as a SKU. A retainer is one way to pre-establish the relationship. On-demand plus a panel can be another. This page does not reprint benchmark figures and does not invent ROI. |
| SRM recommendation | This product does not sell retainers, does not interpret YOUR policy, and does not rank or retain DFIR firms. Signed-in app → Compliance → CRA reporting tracks a CRA Article 14 ladder from recorded awareness for CRA-in-scope findings; that is not a retainer and not a forensic exam. ShipReady Passport is a shareable posture snapshot, not a DFIR onboarding pack. | Honesty. A retainer plus a reporting clock is a preparation pairing some teams use; the product is not that pairing, does not require a retainer, and does not sell one. |
Who decides
Buying a retainer is a cross-role call, not a product recommendation. Empty seats at this table are unknowns, not a pass. Last verified 7 September 2026. Not legal advice. Not coverage advice. Not procurement advice. Not financial advice.
| Role | What they own on this tree | What they do not own |
|---|---|---|
| Founder / CISO / incident commander | Whether surge, data class, and estate complexity make a quiet-year reservation worth it. Whether in-house capture is actually sound. | Not a coverage determination. Not a notification determination. Not an ROI this page will invent. |
| Counsel | Privilege-and-engagement (counsel-directed SOW is common practice). Which clocks may apply. DPA / data-residency on evidence. Whether a duty exists. | Not a vendor ranking. Not YOUR policy interpretation unless they are also coverage counsel. The contact-breach-counsel page on this site is the privilege checklist. |
| Broker / carrier | Panel, prior consent, and whether a retainer is an underwriting question on THIS form. Notice timetable. | Not a quality ranking of firms. Not a statute. Verify YOUR policy. The contact-cyber-insurance page on this site is that checklist. Not coverage advice. |
| Finance | Whether unused prepaid hours are an acceptable reservation cost versus procurement delay on the incident clock. | Not an ROI this page will invent. The breach-investigation-cost page on this site is the cost-driver explainer. Not financial advice. |
| Board (if material) | Risk-acceptance: live with on-demand delay, or reserve surge. Document the choice. | Not a product this site sells. Not a ranking. Not a substitute for counsel. |
What you need to do now
Order is the failure mode. Signing a favourite-firm retainer, then asking counsel to wrap privilege around it, then telling the carrier, is the reverse of common practice. The sequence below is practice, not a statute. Last verified 7 September 2026. Not legal advice. Not coverage advice. Not procurement advice. Not financial advice.
- If you are mid-incident, preserve first. Do not reimage or rotate logs before capture. Do not shop a retainer on the incident clock. The we've-been-breached page on this site is the first-moves hub. The preserve-evidence page on this site is the order-of-volatility checklist.
- Walk the retain-or-not tree with the commander and counsel. The when-you-need-dfir page on this site is that tree. If you do not need a firm, stop.
- Walk this page's decision tree: panel, clocks, data class, estate complexity, cost of delay. Empty answers are unknowns, not a pass.
- If you have a cyber policy, notice the carrier before you pick a non-panel firm — including before you convert an unsigned retainer into an engagement. Panel is a contract role, not a ranking. The contact-cyber-insurance page on this site is that checklist. Verify YOUR policy.
- Counsel-directed engagement is common practice. The contact-breach-counsel page on this site is the privilege-and-engagement checklist.
- If the tree says buy, read the retainer SOW against the typical-terms table on the incident-response-retainer page on this site. Select on stated criteria, not a blog list. The how-to-select-a-dfir-provider page on this site is that tree. The best-digital-forensics-firms page on this site is the roster checklist. This page does not rank firms and does not name any.
- If the tree says wait, write down the on-demand path: who you would page, how you would notice the carrier, who signs the SOW, and when you will re-walk the tree.
- The questions-to-ask-an-incident-response-provider page on this site is the question bank: class, roster listing, jurisdiction, scope, method, custody fields, independence, surge as a contract term, and where evidence will live.
- The breach-investigation-cost page on this site is the cost-driver explainer. A dedicated incident-reporting-deadlines guide is not on this site yet. This page does not invent dollar figures, does not invent ROI, and does not start a clock.
Where this shows up in ShipReady Metrics
The signed-in app does not sell retainers, does not interpret YOUR policy, does not image hosts, keep a chain of custody, produce a forensic report, notice an insurer, or file with a regulator. It does not rank forensic vendors, does not retain a DFIR firm, and does not keep a copy of your policy. If you already have a session: signed-in app → Compliance → CRA reporting tracks the 24-hour / 72-hour / 14-day ladder from your recorded awareness for findings the org has classified as CRA-in-scope. That ladder is not a retainer, it is not a forensic exam, it does not start a clock for you, and it is not a determination that CRA applies. A named human still submits. ShipReady Passport is a shareable posture snapshot some teams hand a provider during scoping; it is not a DFIR onboarding pack and not a substitute for the intake the firm will still run. None of those surfaces is a substitute for the commander, counsel, the insurer, or DFIR.
Primary sources (last verified 7 September 2026)
Every operational claim on this page is taken from one of these. If a later revision of a source changes the advice, the date above is how you can see we have not re-checked yet.
NIST SP 800-61 Revision 3 (April 2025), Incident Response Recommendations and Considerations for Cybersecurity Risk Management: A CSF 2.0 Community Profile, is the current final this page cites — guidance, not a statute; it superseded SP 800-61r2; it treats incident response as part of cybersecurity risk management and does not require a commercial retainer. CISA's Federal Government Cybersecurity Incident and Vulnerability Response Playbooks are operational procedures for US FCEB systems; CISA notes other organizations may use them to standardize practice; they include identifying resources. CISA's #StopRansomware Guide lists the cyber insurance company as a response stakeholder. ENISA's Good Practice Guide for Incident Management (December 2010) describes incident-handling good practice; it is guidance, not a statute and not a requirement to buy a named commercial retainer. NAIC cyber-claims materials describe panel-vendor and prior-agreement conditions as they appear in policies; they do not interpret YOUR policy. IBM's Cost of a Data Breach is a published industry benchmark, not law; this page does not reprint its figures. NIST SP 800-86 (August 2006), Guide to Integrating Forensic Techniques into Incident Response, remains the current final guide this cluster cites for forensic method — guidance, not a statute, last verified still final on 7 September 2026.
Frequently asked questions
Should you have an incident response retainer before a breach?
When surge, a panel or prior-consent clause, or a notification clock that may apply will outrun a new procurement — yes, a pre-signed retainer is one way to reserve that start. When the estate is small, in-house capture is sound, and YOUR policy does not require a panel, on-demand can be enough. Walk the tree; do not treat any one factor as a law. This page does not sell retainers. Not legal advice. Not coverage advice. Not financial advice.
When is on-demand engagement enough?
When you do not need a firm at all (the when-you-need-dfir page on this site is that tree), or when you do need a firm but a documented on-demand path — panel-cleared if the form has a panel, counsel-directed, class and jurisdiction matched — will start fast enough that unused prepaid hours are not worth the reservation. On-demand is not a failure. Not procurement advice. Not legal advice.
Does cyber insurance require a retainer?
Often it requires a panel or prior consent, which is not the same as requiring prepaid hours. Some applications ask whether you already have a retainer; that is underwriting, not a statute. NAIC cyber-claims materials: some policies require a preapproved incident-response vendor list; others require prior mutual agreement to a particular provider. Notice the carrier before you retain off-panel. Verify YOUR policy. Not coverage advice. Not legal advice.
Is a retainer a legal requirement?
Rarely, and not because of NIST SP 800-61r3, CISA IR playbooks, or ENISA incident-management guidance. Those are guides: integrate incident response into operations before you need it; identify resources. A commercial retainer is one way to do that, not a statute. Notification duties are separate questions for counsel. This page does not start a clock. Not legal advice.
Who decides whether to buy one?
The commander or CISO on surge and data class; counsel on privilege, clocks, and DPA; the broker or carrier on panel and notice; finance on unused hours versus delay; the board if the reservation is material. Empty seats are unknowns, not a pass. This page is not a RACI and not a product recommendation. Not legal advice. Not financial advice.
Is this a ranking?
No. It is a decision tree: when a retainer is worth the reservation versus when on-demand is enough, by size, data, regulation, and insurance. This page does not rank DFIR firms, does not rank retainers, does not name any, and does not sell retainers. The how-to-select-a-dfir-provider page on this site is the selection tree. Not legal advice.
Does ShipReady Metrics sell retainers or interpret policies?
No. The product does not sell retainers, does not interpret YOUR policy, does not rank or retain DFIR firms, and does not keep a copy of your form. Signed-in app → Compliance → CRA reporting tracks a CRA Article 14 ladder from recorded awareness for CRA-in-scope findings; that is not a retainer and not a forensic exam. Not legal advice. Not coverage advice.
Is this legal advice?
No. It is operational guidance distilled from NIST SP 800-61r3, CISA incident-response playbooks, ENISA incident-management guidance, and generic insurer panel-vendor norms in NAIC cyber-claims materials. Whether YOU should buy a retainer, whether a panel clause is satisfied, whether privilege attaches, and whether a notification duty applies are questions for counsel and YOUR policy. This page does not sell retainers, is not coverage advice, is not procurement advice, and is not financial advice.
Published by ShipReady Metrics, an evidence-based technology and compliance intelligence platform. This guide is educational and vendor-neutral.