How does incident response work under a cybersecurity retainer?

Incident response process under my retainer agreements (used by factories, law firms and critical infrastructure operators in Poland)

PhaseWhat happens (retainer client)Typical SLA
1. Immediate notificationYou call/e-mail/SMS the dedicated emergency numberAcknowledgement < 15 min
2. Triage & classificationQuick remote assessment – ransomware, data leak, insider, etc.First call < 1 h (Pro), < 4 h (Standard)
3. ContainmentIsolation of affected systems, password resets, firewall rulesUsually same day
4. Forensic preservationCreation of forensic images before any recovery (evidence-safe)24–48 h
5. Deep forensic analysisFull timeline, attacker TTPs, data exfiltration proof3–10 days
6. Recovery supportSafe system restoration, patch verificationParallel with analysis
7. Final reportExecutive summary + technical annex + remediation roadmap + indicators of compromiseWithin 5 working days after containment

Why retainer clients survive incidents dramatically better

In 2024–2025 my retainer clients had on average 87 % shorter downtime and zero regulatory fines after incidents – simply because we reacted within the first “golden hour”.