← Consultancy
Incident response retainer

Responders on call before you need them

Pre-agreed terms, pre-approved hours and a team that already knows your environment, so when something happens, we start in minutes, not days.

Pre-agreed termsUnused hours convertForensics includedRecovery support
Incident · Suspected ransomwareIR-2026-007
02:14 Call receivedRetainer verified, lead assigned 00:04
02:31 Hosts isolatedPre-approved containment 00:21
06:00 Scope confirmed3 servers, 1 account Done
Day 2 RecoveryClean rebuild of affected hosts In progress
Why it's different

The worst time to sign a contract is during an incident

The usual way With Touchpoint
Hours lost agreeing terms and rates mid-incident Terms, rates and authority agreed in advance
Responders start blind Onboarding done up front: contacts, systems, backups
Investigation only; recovery is someone else’s job Investigation, containment and recovery from one team
Unused retainer hours are lost Unused hours convert to tabletop exercises or assessments
Insurers ask who your IR provider is A named provider that meets insurer panel requirements
What’s covered

From first call to back in business

Triage & containment Rapid scoping and isolation of affected systems and accounts.
Digital forensics Evidence collection, timeline and root cause, preserved for legal use.
Ransomware response Scope, containment, recovery options and threat-actor intelligence.
Business email compromise Mailbox investigation, fraud tracing and account recovery.
Recovery & rebuild Clean rebuild of servers, Active Directory and cloud tenants.
Regulatory & legal support Evidence and timelines for regulators, insurers and counsel.
How it works

How the retainer works

  1. 01 Onboard Contacts, critical systems, backups and approval rules documented.
  2. 02 Prepare IR plan review and a tabletop exercise in the first quarter.
  3. 03 Respond A 24/7 line with guaranteed response times.
  4. 04 Recover Containment, eradication and rebuild, led by the same team.
  5. 05 Learn Post-incident report, lessons learned and detection recommendations.
What you get

Ready before it happens

The retainer includes preparation work, so the first call isn’t the first conversation.

✓ IR plan reviewYour plan tested against real scenarios.
✓ PlaybooksRansomware, BEC and data-theft runbooks for your team.
✓ Guaranteed responseAgreed response times, 24/7.
✓ Forensic reportTimeline, root cause and evidence.
✓ Recovery planPrioritised steps to restore service safely.
✓ Lessons learnedWhat to change so it doesn’t happen again.
Engagement options

Choose your level

Essentials Zero-hour retainer Terms agreed in advance, pay only if you call.
  • ✓Pre-agreed rates
  • ✓Onboarding
  • ✓24/7 hotline
  • ✓Response SLA
Get a fixed quote →
Most chosen Pre-paid hours A bank of hours with faster response.
  • ✓Guaranteed response time
  • ✓IR plan review
  • ✓Annual tabletop
  • ✓Unused hours convert
Get a fixed quote →
Enterprise Full retainer For regulated or high-risk organisations.
  • ✓Fastest response SLA
  • ✓Quarterly readiness work
  • ✓Forensics and recovery included
  • ✓Named IR lead
Get a fixed quote →
Questions

Before you ask

Do we need other Touchpoint services?+

No. The retainer is standalone and works with whatever security tools and providers you have.

What if we don’t use the hours?+

Unused pre-paid hours convert to tabletop exercises, assessments or engineering work.

Do you help with recovery?+

Yes. Our engineers can rebuild servers, Active Directory and cloud tenants as part of the response.

Will this satisfy our cyber insurer?+

Most insurers ask for a named IR provider. We’ll provide the details they need.

Have a responder on speed dial

Set up terms now, so your first call is about the incident, not the contract.

Set up a retainer
Other consultancy services Penetration testing→ Cloud security→ Tabletop exercises→ vCISO→