Best incident response companies in 2026: who's worth the retainer

DCDaniel C. · Head of Security Operations
Competitive Content·10 min read

I'm renewing our IR retainer this quarter, and the shortlist my broker sent was a 2024 document with a 2026 date on it. Half the brands on it had been acquired out from under their own names. Here is how I actually sort the field.

I'm renewing our incident response retainer this quarter, and the shortlist my broker sent over was a 2024 document with a 2026 date on it. Secureworks was on the list; Secureworks has been part of Sophos since February 2025, and the name now sits under Sophos.

Stroz Friedberg was listed under Aon; it's been a LevelBlue company since 2025. Cybereason appeared as an independent; LevelBlue acquired Cybereason, a deal that closed in December 2025. The list was sorted by brand recognition, and the brands had changed.

Global digital forensics and incident response (DFIR) firms wired into breach counsel, MDR providers that fold incident response into the subscription, boutiques with a real niche, and negotiation firms nobody wants to need solve different buyer problems.

In Brief:

  • LevelBlue rolled up Stroz Friedberg, Trustwave, and the Cybereason business across 2025, then added Fortra's Alert Logic MDR practice in early 2026. Any roster or panel document naming those brands independently is stale.
  • Prepaid hours reserve capacity. Zero-dollar retainers run on best-effort allocation, so they tend to get deprioritized during mass exploitation events, exactly when the queue matters most.
  • MDR-embedded IR usually ends at the platform's agent footprint. Forensic imaging and litigation-grade reporting live in a separate DFIR retainer, and legal privilege requires that separate retainer too.
  • In the contracts I've reviewed, a stated 4-hour service-level agreement (SLA) can hide an 8-to-12-hour delay before a working analyst touches the case. Hotline staffing decides which number applies.

What you're actually buying with an incident response retainer

An incident response retainer usually bundles discounted prepaid hours or credits with a response-time SLA. More importantly, it buys a reserved place in the provider's queue, and the queue is the whole product during a mass exploitation event. Operationally, zero-dollar retainers pre-position paperwork, while prepaid blocks reserve capacity. During SolarWinds or Log4j, best-effort clients are the ones most likely to lose their place in line.

The hour mechanics matter as much as the SLA number. The Mandiant retainer, Unit 42 retainer, CrowdStrike Services, and Kroll retainer all let prepaid hours convert to compromise assessments and tabletops. Testing can use the same prepaid hours too, so an incident-free year isn't a write-off. Rollover varies: LevelBlue publishes 100% rollover at every tier, while in the contracts I reviewed rollover often required hours to be spent within the contract term.

And when hours run out mid-incident, surge billing can materially exceed the retainer rate, which is why I negotiate first-right-of-refusal to buy additional hours at the standard rate before signing.

How I'd shortlist an incident response company

Measure speed from first call to first analyst action. Then score forensic depth beyond what the endpoint detection and response (EDR) console and your own detection engineering already surface, and cloud and identity coverage matched to where breaches now start, since most cloud-native security programs still leave the identity layer thin.

After that comes counsel and carrier panel standing, because in a panel-driven claim breach counsel usually picks the DFIR firm, and prepaid versus hourly structure. The vendor deck showed a 2-hour SLA and never once defined what starts the clock. That distinction decides whether the retainer buys response capacity or just a faster acknowledgment.

Speed dominates the list because attacker timelines compressed again. Global median dwell time hit 14 days in 2025, up from 11, but the tail that hurts is the fast one: Unit 42's 2026 incident response report clocked the fastest quartile of intrusions reaching exfiltration in 72 minutes, down from 285 minutes the year before. A retainer with a 24-hour SLA prices a threat model that no longer exists.

The provider tiers, and who each one is right for

Group providers by the buyer each fits. The right answer depends on who directs the engagement, what surface you defend, and what happens when the hours run out.

Global DFIR firms aligned with breach counsel

These are the firms carriers and breach counsel reach for by default, with the panel standing and litigation-grade output a regulated breach demands. They are built for evidence preservation, and they are built for insurer choreography.

  • Mandiant (Google Cloud): Launched a retainer with a 2-hour response SLA in April 2025, and prepaid hours repurpose to other consulting within the term. It ran the Snowflake data-theft and Salesloft Drift investigations, and its own engagement data from late 2025 shows identity issues drove initial access in 83% of major cloud and SaaS incidents. In a 700-person shop, I'd expect the machinery to feel heavy below nation-state severity.
  • Unit 42 (Palo Alto Networks): Four prepaid tiers, from 250 credits at a 24-hour SLA up to 2,500+ credits at 2 hours, plus a no-cost 250-hour retainer with a 2-hour SLA for qualified top-tier Palo Alto customers. It responded to more than 750 major incidents across 50+ countries in 2025. If you're a large Palo Alto shop and haven't asked about the free retainer, make that call this week.
  • CrowdStrike Services: Multiple retainer tiers, with faster SLAs at higher hour commitments, plus a Flex option that adds proactive hours with no upfront payment. Carrier-panel fit is broad, with CrowdStrike appearing on AIG's and Coalition's published DFIR panels. Strongest when Falcon is already your EDR.
  • Kroll: Claims compatibility with 85+ cyber insurance carriers; the Silver tier promises incident support contact within 2 hours, Gold within 4 with onsite in transit inside 24. That SLA measures contact rather than analyst work. Pressure-test its cloud depth before leaning on it there.
  • Ownership check before signing: A Secureworks retainer is a Sophos contract now, and Stroz Friedberg is now part of LevelBlue, so current references should use that ownership rather than "Aon Stroz Friedberg." Re-confirm panel pre-approvals with the carrier under the current names.

MDR providers that fold IR into the subscription

Because the provider already holds your telemetry and runs your alert triage, response starts from live visibility. Write the scope down before anyone treats the subscription as the breach retainer.

  • Sophos MDR Complete: Unlimited incident response at no extra cost, including root cause analysis and full adversary ejection, with a $1 million breach protection warranty. The Essentials and Advanced tiers don't include full-scale IR, so read the tier language.
  • CrowdStrike Falcon Complete Next-Gen MDR: Full-cycle remediation, with a $2 million warranty covering incident response, legal fees, notification, and forensic investigation.
  • Rapid7 MDR Elite: Unlimited IR until remediation is complete; Active Remediation requires customer opt-in and additional terms. Embedded forensics remain limited, so use a dedicated forensic team when the response requires work beyond the MDR remediation workflow.
  • Arctic Wolf: Sells IR separately as the JumpStart Retainer (1-hour SLA, no prepay) or the flat-rate Incident360 Retainer, which covers one incident end to end with up to 30 hours of restoration work.
  • eSentire: MDR includes unlimited incident handling. The separate DFIR retainer carries the 4-hour remote threat suppression SLA.

Most of these stop at the agent footprint. MDR-embedded IR generally doesn't cover forensic disk imaging, systems outside the platform, attorney-client privilege from first engagement, or reporting built for regulators and litigation; MDR and DFIR retainers are separate buying motions. If a breach will end up in front of a carrier or a court, keep a dedicated DFIR retainer. That boundary is why I still separate MDR renewal from DFIR retainer renewal.

Boutique and specialist firms

Boutiques win when the niche matches the breach. Their surge capacity and geographic scale are thinner, so I treat them as the named specialist behind a broader retainer. Do not assume elite depth in one domain means general-purpose capacity during a regional surge.

  • Sygnia: Every engagement uses in-house Sygnia experts, with no third parties or hand-offs, through remediation and recovery. Its Latin America and Australia expansion is recent, so capacity outside core markets is unproven.
  • Dragos: The OT and ICS pick. Rapid Response Retainer terms include 1-hour first contact and analysis within 4 hours. Its 2026 year-in-review counted 119 ransomware groups targeting industrial organizations in 2025, up from 80.
  • Volexity: Memory forensics lineage (its people pioneered Volatility), a record of zero-day discovery, and a niche in nation-state intrusions. Use it for elite-depth cases, and keep volume response elsewhere.
  • Mitiga: Cloud and SaaS IR for organizations whose breach surface is M365, AWS, Snowflake, or Salesforce.
  • Charles River Associates: Litigation-grade forensics with hundreds of expert testimonies, on published carrier panels including Hartford, CNA, AXA XL, Chubb, and AIG. The pick when the incident is headed to court.

Ransomware negotiation and recovery specialists

During active extortion, the negotiation firm communicates with the threat actor and manages any approved payment through OFAC screening; the DFIR firm handles forensics and eradication; breach counsel directs both under privilege. Veeam acquired Coveware, which covers negotiation and cryptocurrency settlement, including decryption, with its Recon and Unidecrypt tooling.

Full-scope DFIR sits outside Coveware's lane, so pair it with technical IR. Its Q1 2026 data puts the ransom payment rate at 23%, down from 77% in 2019. Use negotiation firms for extortion communications and DFIR firms for containment.

Due diligence changed in July 2026, when former DigitalMint negotiator Angelo Martino was sentenced to 70 months in federal prison for giving BlackCat/ALPHV operators victims' negotiating positions and insurance policy limits; five victims paid a combined $75.3 million. That case exposed the information flows among counsel, carriers, brokers, and negotiators that run through every incident.

Write audit rights and personnel disclosure into the negotiation retainer before an incident, add conflict screening, and share policy limits only when the negotiation plan requires it.

Who's worth the retainer for a mid-market SOC

For the 500-to-5,000-employee SOC I write checks for, surge capacity drives the pick, since a mass exploitation event pulls the same handful of DFIR teams in at once and prepaid buyers hold their place. My mid-market shortlist runs to four:

  • LevelBlue: published tiers from $25,000 (4-hour SLA, 100% rollover) up to a 1-hour SLA at $150,000+.
  • Pondurance: built for mid-market PHI and PII shops, with a hotline staffed by analysts.
  • Arete: carrier-panel presence across At-Bay's preferred partners, Coalition's DFIR panel, AXA XL, CNA, Chubb, and Hartford.
  • Unit 42 (Tier 3): 1,250 credits and a 4-hour SLA cover most engagements without enterprise pricing.

That mix gives me one consolidated platform, one mid-market operator, one ransomware-heavy panel fit, and one enterprise option if the environment already runs Palo Alto.

The stakes math holds. Ransomware appeared in 48% of breaches in the 2026 DBIR, and organizations that caught the breach themselves rather than hearing it from an attacker saved $900,000 on average. For a team already stretched thin by alert fatigue, a retainer is the cheapest Tier 3 forensic capability available at this size, and building the equivalent bench in-house isn't close.

The question that decides it on day zero

When the call goes out at 2 am, the deciding test is whether a working analyst answers or intake opens a ticket. Pondurance states outright that its hotline is answered around the clock by a security analyst or engineer; in contracts and tabletop tests I reviewed, intake and internal case assignment can take 8 to 12 hours to reach active analyst work behind a stated 4-hour SLA. The published SLA only matters after you know which of those operating models is true.

Ask what starts the SLA clock, whether "engage" means acknowledgment or analyst action, and whether collection agents deploy at onboarding, the way eSentire pre-deploys its Atlas extended detection and response (XDR) Investigator agents, or only once the engagement starts, the way CrowdStrike deploys Falcon tooling during response.

Before I sign or renew, I run a timed tabletop: call the hotline, walk the responder through our incident response plan, and clock the elapsed time from first contact to the first analyst doing real work. I've watched a large provider lose that exercise to a smaller firm by six hours. Whoever picks up at 2 am, and what they do in the first hour, is the product I'm paying for.

Frequently asked questions about incident response companies

How much does an incident response retainer cost in 2026?

Among provider pages I reviewed, published pricing is sparse, and most directional ranges move once scope, SLA, carrier panel status, and prepaid-hour structure enter the negotiation. LevelBlue is one of the few firms publishing retainer tiers, from $25,000 for a 4-hour SLA to $150,000+ for 1 hour. Without a retainer, emergency IR is usually billed hourly and can be materially more expensive than retained capacity.

Is a zero-dollar incident response retainer worth signing?

A zero-dollar retainer is useful for paperwork pre-positioning, since NDAs and rates get settled before a crisis. It does not reserve capacity, because zero-dollar models allocate best-effort at incident time and those clients fall behind prepaid ones during mass exploitation events.

Do MDR providers include incident response in the subscription?

It varies by provider and tier. Sophos MDR Complete includes unlimited IR and CrowdStrike Falcon Complete includes full-cycle remediation, while Arctic Wolf and eSentire sell IR retainers as separate products. No subscription model covers forensic imaging and privilege-backed, litigation-grade reporting the way a dedicated DFIR retainer does.

Can I use my own IR firm with cyber insurance?

Only with carrier approval, and usually only if that approval happens before the incident. Chubb's non-panel program requires the provider to be listed on the policy before any claim, and self-selected vendors can erode policy limits where panel vendors don't. Get a preferred firm added during policy negotiation.

What response SLA should an IR retainer have?

One to two hours remote is the available baseline: Mandiant publishes 2 hours, and LevelBlue's Premium tier publishes 1 hour. Ask what the SLA measures, since first callback and first analyst action can sit many hours apart. Given that the fastest intrusions now exfiltrate in roughly an hour, a 24-hour SLA is a legacy artifact.


About the author

DCDaniel C. is a security operations leader with over a decade of experience building and scaling SOC capabilities for cloud-native companies. He has led security teams through multiple stages of growth — from early-stage environments with minimal tooling to mature organizations operating 24/7 security operations with distributed teams. His experience includes designing SOC architectures, evaluating and managing MDR providers, and building internal detection and response capabilities. Daniel has been responsible for vendor selection across SIEM, EDR, and XDR platforms, as well as defining SLAs, response models, and escalation frameworks. He has also worked closely with executive leadership on budgeting, board reporting, and aligning security operations with broader business risk. He writes about the practical decisions security leaders face — including build vs buy tradeoffs, how to evaluate security vendors, and what it actually takes to run an effective security operations function at scale

Stay sharp on security operations

Practitioner takes on SOC modernization, detection engineering, threat hunting, and more. No fluff. No product pitches.

Best incident response companies in 2026: who's worth the retainer | Future of SecOps