Independent technical practice
Incident Response & Retainer Programs
Reviewed and approved by Joseph Caruso. .
When an incident starts, the contract should already be signed and the responders should already know your environment. That is what a retainer buys.
What the retainer says about response timing
The existing 24/7 response contact is an activation path. The retainer states acknowledgment, remote support or on-site commitments, locations, travel and staffing assumptions, exclusions, insurer approval and authorized change process.
Confirm those terms and the actual responder availability before relying on an arrival or restoration deadline. Maintain a decision/action log and scope validation with the operator; a completed check does not establish universal eradication.
Primary references: NIST incident-response guidance, April 2025 (opens in a new tab).
Who we serve
- Utilities
- Financial Institutions
- Law Firms
- Insurers
- Healthcare
- Manufacturers
Retainer tiers
Compare the tiers
Three levels of commitment, one hotline. Tiers are sized at onboarding against your environment and response expectations.
| What’s included | Silver | Gold | Platinum |
|---|---|---|---|
| 24/7 incident hotline | ✓ included | ✓ included | ✓ included |
| Named response lead on activation | ✓ included | ✓ included | ✓ included |
| Priority response commitment | No | ✓ included | ✓ included |
| Quarterly security review | No | ✓ included | ✓ included |
| Annual tabletop exercise | No | ✓ included | ✓ included |
| Threat intelligence briefing | No | ✓ included | ✓ included |
| Forensic analysis hours included | No | ✓ included | ✓ included |
| Executive briefing | No | No | ✓ included |
| On-site deployment under agreed activation terms | No | No | ✓ included |
| Board-level reporting | No | No | ✓ included |
| Deepfake & AI evidence analysis | No | No | ✓ included |
| Annual retainer | Engagement pricing on consultation | ||
Scope
How a retainer prepares activation
-
Procurement agreed before an incident
A signed agreement defines the activation process before an incident. Actual response timing follows its terms, required authority and responder availability.
-
We already know your environment
Onboarding captures the architecture, contacts and escalation path before anything goes wrong.
-
Evidence handling planned before activation
Documented acquisition, transfers and response actions support later analysis. Containment can change sources; the response record explains known changes and collection limits.
-
An agreed lead and escalation path
The activation agreement identifies lead assignment, escalation contacts and coverage during responder handoffs.
-
Hours for readiness work
Unused forensic hours can generally be applied to tabletop exercises, reviews and readiness work.
-
Reporting your board can use
Platinum engagements include board-level reporting written for directors, not for the SOC.
The 24/7 hotline is the contact path. Confirm the activation requirements and available responder before relying on a particular response time.
Methodology
How activation works

-
Onboard
Architecture, contacts, escalation path and authority to act, captured before an incident.
-
Call
Call the 24/7 contact number to request activation. Confirm the affected systems, immediate risks, authority and available response lead under the agreement.
-
Contain
Remote containment support begins when the agreed activation requirements and responder availability permit. On-site deployment requires confirmed scope, staffing, access and operational approval.
-
Analyze
Document source handling, acquisition and containment changes during the agreed examination. Identify evidence gaps and preserve the records available for later review.
-
Report & review
Findings and remediation, plus a board-level report and post-incident review when the tier includes them.
What counsel receives
A file another examiner could pick up.
The response file begins with authority to act and preserves a dated record of alerts, decisions, containment steps and evidence handling.
The timeline distinguishes confirmed activity from working hypotheses so later reporting does not turn an early assumption into a fact.
- Scope letter and stated assumptionsWhat was asked, what was examined, what was out of scope, and the assumptions the analysis rests on.
- Evidence handling recordAcquisition details, hash values, storage and transfer, and a chain-of-custody log for each item.
- Methodology statementTools, versions and procedures described so a second qualified examiner can repeat the work.
- Findings, separated from interpretationObserved facts first; expert opinion identified as opinion, with the basis for each conclusion.
- Limitations and unresolved questionsWhat the evidence cannot show, what was unavailable, and what further work would be required.
- Exhibits and supporting materialExtracted artifacts, timelines and schedules in a form that can be attached to a filing or a board pack.
- Response timeline and decision logA dated record of what was detected, decided and done, useful for regulators, insurers and later litigation.
Illustrative scope
Illustrative incident activation
Illustrative activation: an onboarded organization reports a suspected incident. A response plan would use the documented environment and contacts to agree containment, preservation and reporting priorities. Actual deployment and collection timing follow the contracted commitments, access and availability.
Credentials & standards
- 24/7 hotline answered by an examiner
- Priority response commitment on Gold and Platinum
- Chain of custody preserved from the first hour
- Works alongside carrier panel requirements
Response discipline
What the response record should contain
The sequence, documentation and technical scope that turn urgent activity into a usable record.
The response sequence
Triage establishes the level of compromise, sets realistic expectations and flags reporting and regulatory questions early. Containment limits further damage, eradication removes what was placed on the estate and restores affected systems, and recovery returns them to production deliberately so a second incident is not created by the fix. A postmortem closes the engagement with a play-by-play of who, what, where, when, why and how.
Documentation is part of the deliverable
Record the eradication actions and validation actually completed, tested systems, inaccessible areas and remaining visibility. That record supports technical reporting and follow-up; it does not prove every malicious component was removed or prevent recurrence.
Insider incidents
The response can examine misuse of legitimate access as well as external intrusion. Available evidence determines which explanations to test and which systems or accounts to examine.
Frequently asked
Common questions
What happens when we call the hotline?
Use the 24/7 hotline to request activation and provide the affected systems, immediate risks and authorized contact. Lead assignment and containment support follow the signed activation terms, required approvals and actual responder availability. Calling does not guarantee immediate remote work or on-site arrival.
Do unused hours roll over?
Structure varies by tier and is set during onboarding. Unused forensic hours can generally be applied to proactive work such as tabletop exercises and readiness reviews.
Can a retainer sit alongside our insurer's panel?
Carrier requirements vary. Confirm whether GDF is approved for the particular engagement, what panel or additional-provider authorization is required, and who can approve the work before relying on coverage. Agree evidence handling and reporting with the authorized carrier contact and retained counsel.
Talk with an examiner
Discuss your matter and next step
Tell us the systems, evidence and deadline. We can review relevant experience, potential conflicts and the scope before engagement.
Since 1992 · 24/7 dispatch · Court-tested experts
Talk with an examiner
Discuss the matter and the next step.
Tell us what happened and what you need to find out. Speak with a GDF expert about how we can help.
24/7 hotline: 1-800-868-8189