Independent technical practice

Incident Response & Retainer Programs

When an incident starts, the contract should already be signed and the responders should already know your environment. That is what a retainer buys.

Incident response plan beside a hotline handset.

Who we serve

  • Utilities
  • Financial Institutions
  • Law Firms
  • Insurers
  • Healthcare
  • Manufacturers

Retainer tiers

Compare the tiers

Three levels of commitment, one hotline. Tiers are sized at onboarding against your environment and response expectations.

Feature availability by retainer tier.
What’s includedSilverGoldPlatinum
24/7 incident hotline included included included
Named response lead on activation included included included
Priority response commitmentNo included included
Quarterly security reviewNo included included
Annual tabletop exerciseNo included included
Threat intelligence briefingNo included included
Forensic analysis hours includedNo included included
Executive briefingNoNo included
24/7 on-site responseNoNo included
Board-level reportingNoNo included
Deepfake & AI evidence analysisNoNo included
Annual retainerEngagement pricing on consultation

Scope

Why a retainer changes the outcome

  • No procurement delay

    Terms are signed in advance, so response starts with the first call rather than the first contract review.

  • We already know your environment

    Onboarding captures the architecture, contacts and escalation path before anything goes wrong.

  • Evidence handled correctly from hour one

    Chain of custody is preserved from the start, which protects both the technical analysis and any later litigation.

  • A named lead, not a ticket

    Every activation is assigned to a named responder who stays with the matter through closure.

  • Proactive hours, not just reactive ones

    Unused forensic hours can generally be applied to tabletop exercises, reviews and readiness work.

  • Reporting your board can use

    Platinum engagements include board-level reporting written for directors, not for the SOC.

Retainer clients reach a responder on the 24/7 hotline, not a queue.

Methodology

How activation works

  1. Onboard

    Architecture, contacts, escalation path and authority to act, captured before an incident.

  2. Call

    One number, 24/7. You reach a responder and a named lead is assigned on the first call.

  3. Contain

    Initial containment guidance immediately; on-site response where the tier and the incident require it.

  4. Analyze

    Forensic examination with chain of custody preserved for any later claim or proceeding.

  5. Report & review

    Findings and remediation, plus a board-level report and post-incident review when the tier includes them.

What counsel receives

A file another examiner could pick up.

The response file begins with authority to act and preserves a dated record of alerts, decisions, containment steps and evidence handling.

The timeline distinguishes confirmed activity from working hypotheses so later reporting does not turn an early assumption into a fact.

  • Scope letter and stated assumptionsWhat was asked, what was examined, what was out of scope, and the assumptions the analysis rests on.
  • Evidence handling recordAcquisition details, hash values, storage and transfer, and a chain-of-custody log for each item.
  • Methodology statementTools, versions and procedures described so a second qualified examiner can repeat the work.
  • Findings, separated from interpretationObserved facts first; expert opinion identified as opinion, with the basis for each conclusion.
  • Limitations and unresolved questionsWhat the evidence cannot show, what was unavailable, and what further work would be required.
  • Exhibits and supporting materialExtracted artifacts, timelines and schedules in a form that can be attached to a filing or a board pack.
  • Response timeline and decision logA dated record of what was detected, decided and done, useful for regulators, insurers and later litigation.

Proof

Ransomware activation, multi-site manufacturer

A retainer client called the hotline within forty minutes of detection. Because onboarding had already documented the environment, containment guidance began on the first call and forensic imaging started that evening. Evidence was preserved in a form the insurer and outside counsel could both use.

Credentials & standards

  • 24/7 hotline answered by an examiner
  • Priority response commitment on Gold and Platinum
  • Chain of custody preserved from the first hour
  • Works alongside carrier panel requirements

Response discipline

What the response record should contain

The sequence, documentation and technical scope that turn urgent activity into a usable record.

The response sequence

Triage establishes the level of compromise, sets realistic expectations and flags reporting and regulatory questions early. Containment limits further damage, eradication removes what was placed on the estate and restores affected systems, and recovery returns them to production deliberately so a second incident is not created by the fix. A postmortem closes the engagement with a play-by-play of who, what, where, when, why and how.

Documentation is part of the deliverable

Every action is documented while it is taken, not reconstructed afterwards. That record supports cost and impact analysis, evidences that malicious content was fully removed, and carries a significant part of the regulatory and contractual reporting burden, along with the questions clients, vendors and investors ask once the incident is public.

Insider incidents

Internal compromise is as common as external intrusion and is frequently harder to detect, because the access being abused is legitimate. Response scope is set to cover both rather than assuming an outside actor.

Related

Related services

Frequently asked

Common questions

What happens when we call the hotline?

You reach a responder, not a queue. A named lead is assigned and initial containment guidance begins on the first call, before any paperwork is revisited.

Do unused hours roll over?

Structure varies by tier and is set during onboarding. Unused forensic hours can generally be applied to proactive work such as tabletop exercises and readiness reviews.

Can a retainer sit alongside our insurer's panel?

Yes. We regularly work as an approved or additional provider alongside carrier panel requirements, and we structure evidence handling so the carrier and outside counsel can both rely on it.

Talk with an examiner

Discuss the matter and the next step.

Call to discuss timing, scope and the safest way to share information. Do not send evidence or credentials by email.

24/7 hotline: 1-800-868-8189

Privacy center

Choose your site settings

Optional technology stays off until you choose otherwise. You can change these browser settings at any time. Access to the core site does not depend on optional technologies.

Technology preferences
Sale or cross-context sharing: not used GDF does not sell or share website personal information for cross-context behavioral advertising.