Incident Response Retainer: What Belongs in the Contract

Join our MSP Partner Program
become an MSP Pentesting partner
Incident Response Retainer title card with a stopwatch icon in the MSP Pentesting brand style.

An incident response retainer is a contract that guarantees you a responder when something goes wrong, at a price and a response time agreed before the incident, not during it. That last part is the whole point. Negotiating a scope of work at 2am on a Saturday while a client's file server is encrypting is how firms end up paying four times the rate for half the responder.

Most MSPs already do first-response work. They isolate the host, pull the backups, get the client back online. What they usually do not have is contracted access to a forensics team, a defined clock, and a paper trail an auditor or an underwriter will accept.

MSP Pentesting is channel-only. We white-label penetration testing for MSPs, MSSPs, vCISOs and GRC firms, so we see a lot of client environments right before and right after an incident. This is what actually distinguishes a retainer worth buying from a line item that does nothing.

What an incident response retainer actually buys

Four things, and only one of them is the response itself.

  • A guaranteed clock. A contractual time to first responder contact. Usually somewhere between one and eight hours depending on tier.
  • Pre-cleared legal and commercial terms. Rates, liability, data handling and the master services agreement are signed while nobody is panicking.
  • Preparation work. The good retainers include readiness activity: tabletop exercises, a reviewed IR plan, log source validation, and an agreed evidence-collection procedure.
  • Insurer and auditor acceptance. Named on the policy, or at least on the carrier's approved panel.

That third bullet is the one clients undervalue and the one that decides whether the response goes well. A responder who has never seen the environment spends their first shift discovering that the EDR was in audit mode and the firewall logs roll every 48 hours.

The three retainer models

Vendors use different names, but commercially there are only three shapes.

ModelHow you payBest forThe catch
Prepaid hoursBuy a block up front, draw down against itClients who will actually use the hours for readiness workUnused hours often expire at the anniversary
Zero-dollar standbyNo fee, discounted rate and priority queue if you callCost-sensitive clients who just need the paperwork pre-signedNo preparation is included, and "priority" is relative to paying clients
Blended subscriptionAnnual fee covering readiness, with response billed separatelyRegulated clients who need evidence of an ongoing programTwo invoices during an incident, which surprises people

For most SMB clients the blended model is the honest recommendation. Zero-dollar retainers look free because they are. You are buying a phone number.

What the contract has to specify

Read past the marketing page and check for these. If a clause is missing, it is missing on purpose.

Response time, and what starts the clock

"Four hour response" means nothing until you know what counts as response and what counts as the trigger. Is it an acknowledgement email or a responder on a bridge? Does the clock start when you submit the form or when a human triages it? Get both in writing.

Scope and asset coverage

Endpoint counts, cloud tenants, OT or industrial assets, and geographies. A retainer written for 200 endpoints will be repriced mid-incident if the client has 900.

Who can invoke it

Name the people. If only the client CFO can authorise the call and it happens on a Sunday, the retainer is decorative. As the MSP you usually want invocation authority delegated to you.

Evidence handling and chain of custody

This is the clause that matters if the incident becomes a legal or regulatory matter. ISO/IEC 27001:2022 Annex A control 5.28 covers evidence collection specifically, and any responder worth retaining will already work to a defensible process.

Data residency and privilege

Where do forensic images live, for how long, and is the engagement run under attorney-client privilege. For regulated clients this is not optional.

Which requirements are actually forcing this

Clients rarely buy a retainer because it seemed prudent. An auditor, an insurer or a regulator made them.

SOC 2. The Trust Services Criteria expect an entity to evaluate security events and to respond to identified incidents through a defined program. CC7.3 and CC7.4 are the criteria auditors point at. A retainer is not required by name, but it is one of the cleanest ways to evidence that response capability exists.

PCI DSS v4.0. Requirement 12.10 requires an incident response plan that is ready to be activated immediately, tested at least annually, with specific personnel assigned to 24/7 availability.

HIPAA Security Rule. The security incident procedures standard at 45 CFR 164.308(a)(6) requires covered entities and business associates to identify, respond to, and document security incidents and their outcomes.

NIST SP 800-61. The federal reference for incident handling. Revision 3 realigned the guidance around the CSF 2.0 functions rather than the older four-phase lifecycle, but the practical demand is unchanged: preparation is the phase that determines how the rest goes.

Cyber insurance. This is the sharpest driver right now. Most carriers maintain an approved panel of IR firms, and using an off-panel responder without prior consent can reduce or void the claim. Check your client's policy before you promise them a vendor. Our note on cyber insurance for MSPs covers the panel problem in more detail.

Note the pattern. None of these frameworks say "buy a retainer." They demand a documented, tested, resourced capability, and a retainer is the fastest way for an SMB to have one.

Where the retainer and the pentest connect

These get sold separately and they should not be.

A penetration test tells you which paths an attacker would take through the environment. That is the same map a responder needs on day one of an incident. If your client has a current test, the responder starts with a known attack surface, a documented list of internet-facing services, and an understanding of where the privilege escalation paths are.

The reverse is also true. Every incident produces detection gaps, and those gaps should feed the next test's scope. A client who got hit through an unmonitored VPN appliance should have that appliance in scope next time, explicitly.

Practically, sell them as a cycle. Assess, test, remediate, retain, respond, feed the findings back. A ransomware readiness assessment is a good entry point because it produces the gap list that justifies both the retainer and the test in the same conversation.

How to package and price it as an MSP

You have three options and they carry very different risk.

Refer it. Introduce the client to an IR firm, take a referral fee or nothing at all. Zero risk, zero margin, and you lose control of the incident narrative.

Resell it. Buy retainer capacity wholesale, wrap it in your own SLA, invoice the client. This is where most MSPs should land. You keep the relationship and a real margin, and the specialist carries the delivery risk.

Deliver it. Build the forensics capability in house. Only viable if you have the headcount, the tooling and the appetite for 2am calls. Most MSPs who try this discover the on-call burden the hard way.

On pricing, do not sell the retainer as insurance. Insurance is a grudge purchase and it gets cut in the first budget review. Sell the readiness work, because that is the part the client experiences during the year. The tabletop, the plan review, the log validation. The response guarantee is what makes the readiness work credible, not the other way around.

If you want the testing side handled under your brand while you own the client relationship, that is exactly what our MSP partner program is built for, with white-label reporting on every deliverable.

Frequently asked questions

What is an incident response retainer?

It is a prearranged agreement with a security firm that guarantees responder availability, a defined response time and agreed rates when an incident occurs. Contracts are typically annual and often bundle preparation work such as tabletop exercises and IR plan reviews.

What is a ransomware incident response retainer?

The same structure, scoped for ransomware specifically. It usually adds negotiation support, cryptocurrency handling, decryptor validation, and coordination with law enforcement and the insurer. Check whether ransom negotiation is included or billed separately, because it is frequently a separate specialist.

How much does an incident response retainer cost?

It varies widely by responder, environment size and tier, so treat any single figure with suspicion. The useful comparison is not the annual fee but the blended hourly rate you are locked into and how many prepaid hours convert to readiness work. A cheap retainer with a high incident rate is usually the expensive option.

Do you still need a retainer if you have cyber insurance?

Usually yes, and the two need to agree with each other. Insurers maintain approved panels, and a retainer with a firm your carrier will not authorise creates a conflict at the worst possible moment. Align the retainer to the policy panel before you sign either one.

Can an MSP be the incident response provider?

For first response and containment, often yes. For forensic analysis, breach determination and regulatory notification support, most MSPs should partner rather than pretend. There is also an independence problem: if the incident involves your own management stack, the client needs an investigator who does not report to you.

What to do this week

Pull your top ten clients by contract value. For each one, answer two questions. Who do they call at 2am, and can that person legally begin work without a new contract being signed first.

Wherever the answer is unclear, you have found a gap that is easy to close and easy to sell, because the client already assumed you had it handled.

Then check whether those same clients have a current penetration test. The retainer and the test answer the same question from opposite ends, and the responder you eventually call will ask for the test report in the first hour. If it is time to refresh one, get a pentest quote and we will scope it under your brand.

Zack ElMetennani - MSP Pentesting Team
Author

Zack ElMetennani

Security Lead

Zack is the technical lead behind our penetration testing operations. As our Security Lead, he oversees the offensive methodologies we use to ensure every report meets our quality standard. He has worked in help desk and IT consulting roles, both alongside MSPs and as an internal IT resource for enterprise organizations.

Join our MSP Partner Program

Want reseller pricing, sample reports, and partner resources?
Book a call with our team to get access.