Incident Response and Breach Retainer
An incident response retainer puts a response team, a contact path and an agreed authority to act in place before an incident, so that when one happens the first hours go to containment and recovery rather than to finding help, and the notifications that follow are handled on the deadlines that apply.
- Part of
- Finding out what an attacker could do before one tries, and being ready to act when one does.
- Engaged as
- A defined piece of work, or as part of an ongoing vCISO engagement.
- Sits under
- Executive ownership of the cybersecurity program.
The service
What this engagement is
Who it is for
- Organizations whose response plan names a role no one has actually filled.
- Companies whose cyber-insurance policy expects a response arrangement to be in place.
- Businesses that have had a near miss and do not want to improvise the next one.
- Leadership teams that want a single number to call and a known person on the other end.
A standing arrangement: a named team that knows your environment, a contact path that works at any hour, authority to contain agreed in advance with leadership, and a response process that runs through investigation, eradication and recovery to the after-action review.
The retainer is engaged before anything has happened. Onboarding covers the environment, the contacts, the insurance and legal relationships, and the notification obligations, so that on the day nobody has to be briefed.
Scope
What Heights does
-
Onboarding and readiness
Environment, contacts, authority and obligations captured up front, reviewed on a fixed cadence.
-
Triage and containment
Rapid assessment of what is happening and what to isolate, under the authority agreed in advance.
-
Investigation and eradication
Establishing how access was gained, what was reached, and removing it, with evidence preserved for counsel and insurers.
-
Recovery
Restoring systems in an order that reflects what the business needs first, and verifying they are clean before they return.
-
Notification and communication
Regulatory, contractual, insurer and customer notifications handled on the deadlines that apply, with counsel where required.
-
After-action review
What happened, what worked, what did not, and the changes to plan, controls and contracts that follow.
The problem
Why this comes up
The first hours of an incident are spent, in most organizations, finding someone to call, agreeing what they may touch, and explaining the environment to them. Every one of those hours is time an attacker keeps.
The second cost arrives later. Regulators, insurers, customers and counsel each have notification expectations and deadlines, and an organization discovering them during the incident discovers them late.
Timing
When organizations engage this
- A phishing compromise, ransomware note or unexplained outage has already happened once.
- The response plan assigns duties to an outside party that has never been engaged.
- An insurer, customer or regulator asks who would respond to an incident and how quickly.
- The organization holds data with notification deadlines measured in hours or days.
- Leadership is not confident who has the authority to shut something down.
What you receive
- A retainer agreement with contact path, response commitments and authority to act
- An onboarding record of the environment, contacts and notification obligations
- Incident documentation preserved for counsel, insurers and regulators
- An after-action report with remediation actions tracked to closure
- NIST CSF
- A widely used structure for organizing a security program around outcomes rather than products. Its current version adds an explicit governance function, which is why it maps well onto executive-level work.
- HIPAA
- The HIPAA Security Rule requires administrative, physical and technical safeguards for electronic protected health information, including a documented risk analysis and risk management process. The Breach Notification Rule sets defined duties and timelines once a breach is discovered. HITECH extended enforcement and applies obligations directly to business associates.
- PCI DSS
- Prescriptive control requirements imposed through payment brand agreements wherever cardholder data is stored, processed or transmitted. Scope reduction is usually the highest-leverage decision available.
- SOC 2
- An examination performed by a licensed CPA firm against the AICPA trust services criteria. Security is always in scope; availability, confidentiality, processing integrity and privacy are added when relevant.
- CMMC
- NIST SP 800-171 sets the security requirements for protecting controlled unclassified information in non-federal systems. CMMC is the program under which contractors demonstrate that implementation, by self-assessment or third-party assessment depending on level.
The flagship
How this fits under vCISO leadership
Response is what happens when prevention has not held. The vCISO owns the plan the response runs on, the decisions leadership must make during it, and the changes to the program afterward. With both under one leadership, an incident becomes evidence rather than only damage.
Sectors
Where this comes up most
- Healthcare Statutory obligations for protected health information, clinical availability requirements that constrain how controls can be applied, and growing security scrutiny from payers and partners.
- Financial Services Several supervisory regimes at once, and several of them expecting a named individual to be accountable for the information security program.
- Legal and Professional Services Confidentiality duties owed to every client, ethics rules that now speak directly to technology, and corporate clients who audit their law and accounting firms the way they audit any other vendor.
- Manufacturing and Industrial Production environments where downtime is measured in dollars per minute, plant systems that outlive their software support, and customers pushing security requirements down the supply chain.
- Insurance Organizations Licensed entities holding concentrated nonpublic personal data, state insurance data security laws with annual certification duties, and carriers auditing the agencies and administrators they appoint.
First steps
How an engagement begins
The same three steps whichever service you start with.
-
A confidential conversation
What prompted the enquiry, what you are obliged to do, and what leadership is being asked to answer for. No cost, no obligation.
-
Scope agreed in writing
What Heights will do, what stays with you, the working rhythm, and how progress will be reported.
-
Work begins
Delivered by your team, your providers or Heights, with expectations and acceptance criteria stated up front.
FAQ
Questions we are asked about this
Broader questions about executive security leadership are answered on the vCISO page.
What is the difference between the retainer and incident readiness planning?
Readiness planning writes and exercises the plan: roles, criteria, escalation, tabletops. The retainer is the team that acts on it when an incident is real.
They are separate engagements because some organizations already have a plan and need responders, and others have responders under contract and need a plan those responders can follow.
Does the retainer work with our cyber-insurance panel?
It is set up to. Onboarding records the carrier, the policy notification requirements and any panel obligations, and the response process is written to preserve coverage rather than jeopardize it.
Where a policy requires the carrier's own responders or counsel to be engaged, the retainer coordinates with them rather than competing with them.
Who decides to shut a system down during an incident?
The person leadership named during onboarding, within the limits leadership set. Containment authority is agreed before the retainer goes live, including what may be isolated immediately and what needs a call first.
That decision made in advance is the difference between containing an incident in minutes and debating it for an afternoon.
Portfolio
Related services
- Penetration Testing and Vulnerability Assessment Authorized testing of your networks, applications and cloud environments, reported as findings ranked by what an attacker could actually do with them.
- Incident Readiness and Response Planning A response plan that names decision makers, defines escalation and notification paths, and has been tested with the executives who would have to use it.
- Security Program Assessment A documented picture of what your security program actually covers, measured against a recognized framework, with the gaps ranked by business consequence.