Incident response process under my retainer agreements (used by factories, law firms and critical infrastructure operators in Poland)
| Phase | What happens (retainer client) | Typical SLA |
|---|---|---|
| 1. Immediate notification | You call/e-mail/SMS the dedicated emergency number | Acknowledgement < 15 min |
| 2. Triage & classification | Quick remote assessment – ransomware, data leak, insider, etc. | First call < 1 h (Pro), < 4 h (Standard) |
| 3. Containment | Isolation of affected systems, password resets, firewall rules | Usually same day |
| 4. Forensic preservation | Creation of forensic images before any recovery (evidence-safe) | 24–48 h |
| 5. Deep forensic analysis | Full timeline, attacker TTPs, data exfiltration proof | 3–10 days |
| 6. Recovery support | Safe system restoration, patch verification | Parallel with analysis |
| 7. Final report | Executive summary + technical annex + remediation roadmap + indicators of compromise | Within 5 working days after containment |
Why retainer clients survive incidents dramatically better
- No “first-contact delay” – I already know your infrastructure, people and risks
- Guaranteed availability (no queue like with one-off services)
- All forensic work is performed with court-admissibility in mind from minute one
- Fixed monthly cost = zero surprise invoices even during a major breach
In 2024–2025 my retainer clients had on average 87 % shorter downtime and zero regulatory fines after incidents – simply because we reacted within the first “golden hour”.