How to choose the right cybersecurity retainer level for your company?

Choosing the right retainer package depends mainly on three factors:

FactorWhat it means in practice
Company size & industryLaw firm ≠ production plant ≠ critical infrastructure operator
Number of systems & users50-employee office vs multi-site manufacturing with OT/ICS
Risk level & regulatory requirementsNIS2, KSC, ISO 27001, DORA, GDPR high-risk processing, etc.

Retainer tiers – how clients in Poland typically choose

LevelTypical client profileMonthly hoursBest for
BasicSmall and medium companies, law firms, offices up to ~150 users10–25 hOngoing consultations, policy reviews, quick incident triage, vendor assessment
StandardMid-size companies, manufacturers, regulated entities30–60 hAudits, penetration tests, incident response playbook, compliance support (NIS2, ISO)
ProLarge organisations, OT/ICS environments, critical infrastructure80–150+ hFull external SOC support, on-demand forensics, 24/7 priority response, dedicated expert

Most clients start with Standard – it gives predictable costs and real control over risk without having to build an internal team.

Want help selecting the right level for your organisation? Call or write – I’ll prepare a free 15-minute audit and exact recommendation within 24 hours.