Choosing the right retainer package depends mainly on three factors:
| Factor | What it means in practice |
|---|---|
| Company size & industry | Law firm ≠ production plant ≠ critical infrastructure operator |
| Number of systems & users | 50-employee office vs multi-site manufacturing with OT/ICS |
| Risk level & regulatory requirements | NIS2, KSC, ISO 27001, DORA, GDPR high-risk processing, etc. |
Retainer tiers – how clients in Poland typically choose
| Level | Typical client profile | Monthly hours | Best for |
|---|---|---|---|
| Basic | Small and medium companies, law firms, offices up to ~150 users | 10–25 h | Ongoing consultations, policy reviews, quick incident triage, vendor assessment |
| Standard | Mid-size companies, manufacturers, regulated entities | 30–60 h | Audits, penetration tests, incident response playbook, compliance support (NIS2, ISO) |
| Pro | Large organisations, OT/ICS environments, critical infrastructure | 80–150+ h | Full external SOC support, on-demand forensics, 24/7 priority response, dedicated expert |
Most clients start with Standard – it gives predictable costs and real control over risk without having to build an internal team.
Want help selecting the right level for your organisation? Call or write – I’ll prepare a free 15-minute audit and exact recommendation within 24 hours.