Skip to main content

What is our Incident Response Retainer for? 

An Incident Response Retainer (IRR) Service from us provides you with immediate access to our full suite of Digital Forensics and Incident Response (DFIR) services, delivered by our highly experienced and motivated team.  

We understand that in the face of a security incident, time is of the essence. That’s why our IRR service is designed to eliminate the typical roadblocks that can delay critical assistance, such as lengthy contracts, NDAs, service provider due diligence, and the need to raise purchase orders.  

Our expertise  

We’re proud to be NCSC Assured for Cyber Incident Response (CIR) one of only a handful of providers to earn this recognition. 

It means our people, processes, and technical capability have been independently assessed by the UK’s National Cyber Security Centre, giving you confidence that we’re equipped to handle even the most sensitive incidents. 

With us, you can be confident that when an incident occurs, you can quickly engage our experts to minimise disruption, mitigate potential damage, and restore your operations swiftly and effectively

Incident Response Retainer packages

We offer a range of DFIR retainer packages to suit organisations of all sizes and risk profiles. Each tier is designed to provide increasing levels of support, speed, and value, ensuring that when incidents occur, your organisation is equipped with expert guidance and rapid response capabilities. 

All packages include free onboarding to align our teams and tooling with your environment, and as you move up the tiers, you’ll gain access to faster triage times, reduced day rates, and additional proactive services. Whether you’re looking for peace of mind or comprehensive threat visibility, there’s a retainer level to match your needs. 

What are the options?  

Essential retainer – Entry level assurance 

Perfect for teams seeking guaranteed availability and a faster response time during critical incidents. 

Enhanced retainer – Priority response 

A robust option for organisations that want more coverage and significantly improved rates. Enhanced clients receive faster response times and deeper engagement across incidents. 

Elite retainer – Comprehensive proactive defence  

The Elite package is our most advanced tier, providing premium access, rapid response, and proactive threat intelligence capabilities for clients operating in high-risk or high-profile environments. 

Clients on the Elite retainer also benefit from our Open Source Intelligence (OSINT) and Dark Web Monitoring service, providing early visibility into risks and threats emerging in open and covert digital spaces. 

Incident Response retainer packages breakdown 

We recognise that every organisation has different needs and budgets. We design our IRR service to be flexible, providing a variety of service tiers to meet your unique needs. 

Why choose us? 

Deep expertise 

Our team comprises highly skilled and experienced DFIR professionals with a proven track record of successfully handling complex security incidents across diverse industries. 

NCSC Assured for Cyber Incident Response (CIR)  

Our people, processes, and technical capability have been independently assessed by the UK’s National Cyber Security Centre, giving you confidence that we’re equipped to handle even the most sensitive incidents. 

Rapid response capabilities 

We leverage advanced remote incident response tooling to swiftly and effectively address incidents. We can swiftly deploy our agents into your environment, allowing us to quickly reach the attack’s core.  

From our dedicated DFIR lab, we can conduct in-depth threat hunting, gather vital data for further analysis, and search for identified indicators of compromise to uncover additional impacted systems. In some cases, we can assist in containing an active breach by neutralising malicious services and rogue processes. 

Detect & Respond

Free Pen Test Partners Socks!!!

Pen Test Partners socks are THE hot security accessory this season, if you're a security professional get yours now!

Get Socks
Framework 13. Press here to pwn 
  • Vulnerability Disclosure
Framework 13. Press here to pwn 

5 Min Read

Jul 15, 2025

Sil3ncer Deployed – RCE, Porn Diversion, and Ransomware on an SFTP-only Server
  • DFIR
Sil3ncer Deployed – RCE, Porn Diversion, and Ransomware on an SFTP-only Server

7 Min Read

Jul 11, 2025

How to conduct a Password Audit in Active Directory (AD)
  • How Tos
How to conduct a Password Audit in Active Directory (AD)

11 Min Read

Jul 08, 2025