Incident Response Retainer .
A pre-arranged number to call before you need it — so you're not negotiating a contract while ransomware is encrypting.
[ 00 / brief ]
The worst time to be procuring incident response is during an incident. Hours that should be going to containment go to legal review, vendor selection, and explaining your environment from scratch to a stranger.
An IR retainer fixes that ahead of time. You sign once. We learn enough about your environment to be useful in a hurry. Response time, scope, and pricing are written down. When the bad call comes in, there’s a number to dial and an answer on the other end.
This is a different service from Grid SOC, which includes incident response as part of ongoing monitoring. The IR Retainer is for organizations that aren’t Grid customers — or for Grid customers who want additional response depth on top of their SOC engagement.
[ 01 / what’s covered ]
The retainer has two halves. One is the work we do when something’s actually gone wrong. The other is the work we do the rest of the year — proactive engagements paid for out of the same hour pool, designed to make the first half less likely to ever happen.
// when an incident happens
-
24/7 response activation — A phone number that gets answered, a defined acknowledgement SLA, and a senior responder on the line. You don’t have to explain who you are or argue with a queue.
-
Active incident response — Containment, investigation, evidence preservation, and coordination with your IT or security team, your MSP, your insurance carrier, and your counsel. We work with the people you already work with, not around them.
-
Communications support — Internal drafts, executive briefings, and regulatory notification framing where required. Not legal advice — that’s your counsel’s job — but the technical clarity legal needs to do theirs.
-
Post-incident report and debrief — A written record of what happened, what was done, what’s still open, and what should change. Paired with a scheduled debrief a few weeks later: what we’d do differently, what to invest in, where the next gap is.
// the rest of the year
-
Annual environment review — A working understanding of your stack — identity, endpoints, network, cloud, the critical SaaS, the people we’d need on a bridge — kept current, so the first call isn’t an introduction.
-
Tabletop exercises and incident simulations — Scenario-driven walkthroughs with your team, designed to find the gaps in your IR plan before reality does.
-
Attack-surface and exposure reviews — An honest look at what’s exposed externally and how an attacker would map your environment. Findings come with prioritized work, not raw output.
-
Threat hunts and compromise assessments — An active search across your environment for indicators of pre-existing compromise. Useful as an annual check, after a phishing campaign that “didn’t seem to land,” or before a major change.
-
IR plan and playbook development — Plans written in language people can actually follow at three in the morning. Updated as your environment changes, and tested by the tabletop exercises above.
[ 02 / how the retainer works ]
Two ways to engage, depending on the shape of your risk.
Annual retainer. A fixed annual fee that buys you a guaranteed response SLA, the environment-review work above, and a pool of pre-paid hours. The hours are yours to use. If an incident happens, they go to response. If one doesn’t, they go to the proactive work that prevents the next one — tabletop exercises, attack-surface reviews, threat hunts, IR plan and playbook work, compromise assessments. The retainer pays for being ready; using the hours is how you stay that way.
Time-and-materials standby. No annual fee, lower priority during an incident, but a signed master agreement and pre-approved rates so engagement starts in hours instead of days. Suitable for organizations whose risk profile or budget doesn’t justify a full retainer but who still want to skip the procurement step when it matters.
Either way, the goal is the same — the procurement, scoping, and access-grant work is done in advance, so the moment we’re needed, we’re working.
[ 03 / who hires us ]
- Organizations without internal IR capability who recognize that “we’ll figure it out” is not an incident-response plan.
- Mid-market companies between insurance renewals whose cyber-insurance carrier wants a named IR partner on the policy.
- Public-sector and nonprofit organizations whose procurement processes would make day-of vendor selection genuinely impossible.
- Grid customers with elevated risk profiles who want IR depth beyond what’s bundled into the SOC engagement.
- MSPs and IT-services firms who want a referenceable IR partner to bring to their own clients without having to build the practice in-house.
Tell us about your environment.
Tell us roughly what you have in place, what an incident would touch, and who would need to be involved. We'll scope the retainer honestly — and tell you whether you actually need one or if your existing coverage is enough.
> info@censoredsystems.com