Independent technical practice

Incident Response & Retainer Programs

Reviewed and approved by Joseph Caruso. .

When an incident starts, the contract should already be signed and the responders should already know your environment. That is what a retainer buys.

Incident response plan beside a hotline handset.

What the retainer says about response timing

The existing 24/7 response contact is an activation path. The retainer states acknowledgment, remote support or on-site commitments, locations, travel and staffing assumptions, exclusions, insurer approval and authorized change process.

Confirm those terms and the actual responder availability before relying on an arrival or restoration deadline. Maintain a decision/action log and scope validation with the operator; a completed check does not establish universal eradication.

Primary references: NIST incident-response guidance, April 2025 (opens in a new tab).

Who we serve

  • Utilities
  • Financial Institutions
  • Law Firms
  • Insurers
  • Healthcare
  • Manufacturers

Retainer tiers

Compare the tiers

Three levels of commitment, one hotline. Tiers are sized at onboarding against your environment and response expectations.

Feature availability by retainer tier.
What’s includedSilverGoldPlatinum
24/7 incident hotline✓ included✓ included✓ included
Named response lead on activation✓ included✓ included✓ included
Priority response commitmentNo✓ included✓ included
Quarterly security reviewNo✓ included✓ included
Annual tabletop exerciseNo✓ included✓ included
Threat intelligence briefingNo✓ included✓ included
Forensic analysis hours includedNo✓ included✓ included
Executive briefingNoNo✓ included
On-site deployment under agreed activation termsNoNo✓ included
Board-level reportingNoNo✓ included
Deepfake & AI evidence analysisNoNo✓ included
Annual retainerEngagement pricing on consultation

Scope

How a retainer prepares activation

  • Procurement agreed before an incident

    A signed agreement defines the activation process before an incident. Actual response timing follows its terms, required authority and responder availability.

  • We already know your environment

    Onboarding captures the architecture, contacts and escalation path before anything goes wrong.

  • Evidence handling planned before activation

    Documented acquisition, transfers and response actions support later analysis. Containment can change sources; the response record explains known changes and collection limits.

  • An agreed lead and escalation path

    The activation agreement identifies lead assignment, escalation contacts and coverage during responder handoffs.

  • Hours for readiness work

    Unused forensic hours can generally be applied to tabletop exercises, reviews and readiness work.

  • Reporting your board can use

    Platinum engagements include board-level reporting written for directors, not for the SOC.

The 24/7 hotline is the contact path. Confirm the activation requirements and available responder before relying on a particular response time.

Methodology

How activation works

Prepare: Contacts, systems and authority; Respond: Activate and coordinate containment; Examine: Preserve evidence and trace events; Improve: Findings and recovery priorities
  1. Onboard

    Architecture, contacts, escalation path and authority to act, captured before an incident.

  2. Call

    Call the 24/7 contact number to request activation. Confirm the affected systems, immediate risks, authority and available response lead under the agreement.

  3. Contain

    Remote containment support begins when the agreed activation requirements and responder availability permit. On-site deployment requires confirmed scope, staffing, access and operational approval.

  4. Analyze

    Document source handling, acquisition and containment changes during the agreed examination. Identify evidence gaps and preserve the records available for later review.

  5. Report & review

    Findings and remediation, plus a board-level report and post-incident review when the tier includes them.

What counsel receives

A file another examiner could pick up.

The response file begins with authority to act and preserves a dated record of alerts, decisions, containment steps and evidence handling.

The timeline distinguishes confirmed activity from working hypotheses so later reporting does not turn an early assumption into a fact.

  • Scope letter and stated assumptionsWhat was asked, what was examined, what was out of scope, and the assumptions the analysis rests on.
  • Evidence handling recordAcquisition details, hash values, storage and transfer, and a chain-of-custody log for each item.
  • Methodology statementTools, versions and procedures described so a second qualified examiner can repeat the work.
  • Findings, separated from interpretationObserved facts first; expert opinion identified as opinion, with the basis for each conclusion.
  • Limitations and unresolved questionsWhat the evidence cannot show, what was unavailable, and what further work would be required.
  • Exhibits and supporting materialExtracted artifacts, timelines and schedules in a form that can be attached to a filing or a board pack.
  • Response timeline and decision logA dated record of what was detected, decided and done, useful for regulators, insurers and later litigation.

Illustrative scope

Illustrative incident activation

Illustrative activation: an onboarded organization reports a suspected incident. A response plan would use the documented environment and contacts to agree containment, preservation and reporting priorities. Actual deployment and collection timing follow the contracted commitments, access and availability.

Credentials & standards

  • 24/7 hotline answered by an examiner
  • Priority response commitment on Gold and Platinum
  • Chain of custody preserved from the first hour
  • Works alongside carrier panel requirements

Response discipline

What the response record should contain

The sequence, documentation and technical scope that turn urgent activity into a usable record.

The response sequence

Triage establishes the level of compromise, sets realistic expectations and flags reporting and regulatory questions early. Containment limits further damage, eradication removes what was placed on the estate and restores affected systems, and recovery returns them to production deliberately so a second incident is not created by the fix. A postmortem closes the engagement with a play-by-play of who, what, where, when, why and how.

Documentation is part of the deliverable

Record the eradication actions and validation actually completed, tested systems, inaccessible areas and remaining visibility. That record supports technical reporting and follow-up; it does not prove every malicious component was removed or prevent recurrence.

Insider incidents

The response can examine misuse of legitimate access as well as external intrusion. Available evidence determines which explanations to test and which systems or accounts to examine.

Frequently asked

Common questions

What happens when we call the hotline?

Use the 24/7 hotline to request activation and provide the affected systems, immediate risks and authorized contact. Lead assignment and containment support follow the signed activation terms, required approvals and actual responder availability. Calling does not guarantee immediate remote work or on-site arrival.

Do unused hours roll over?

Structure varies by tier and is set during onboarding. Unused forensic hours can generally be applied to proactive work such as tabletop exercises and readiness reviews.

Can a retainer sit alongside our insurer's panel?

Carrier requirements vary. Confirm whether GDF is approved for the particular engagement, what panel or additional-provider authorization is required, and who can approve the work before relying on coverage. Agree evidence handling and reporting with the authorized carrier contact and retained counsel.

Talk with an examiner

Discuss your matter and next step

Tell us the systems, evidence and deadline. We can review relevant experience, potential conflicts and the scope before engagement.

Since 1992 · 24/7 dispatch · Court-tested experts

Or call 1-800-868-8189

Email or phone is required. A submission does not create an engagement. For an active incident, please call. Read what we send with the request.

Talk with an examiner

Discuss the matter and the next step.

Tell us what happened and what you need to find out. Speak with a GDF expert about how we can help.

24/7 hotline: 1-800-868-8189

Privacy center

Choose your site settings

Optional technology stays off until you choose otherwise. You can change these browser settings at any time. Access to the core site does not depend on optional technologies.

Technology preferences
Sale or cross-context sharing: not used GDF does not sell or share website personal information for cross-context behavioral advertising.