For the engagement owner. An effective retainer discussion resolves how help becomes available and authorised. A catalogue request does not reserve response capacity.
Distinguish readiness from retained response
Incident readiness work can improve plans, contacts, evidence access and decision-making before an event. A retainer is a commercial arrangement whose actual availability and included work depend on its terms. Ask the supplier to explain both components and identify any separate charges or prerequisites. Do not assume that buying an assessment activates emergency support. Your internal incident procedure should state how the contracted service is invoked, which agreement applies and who can approve the initial expenditure. Maintain a usable copy of those arrangements outside the systems most likely to be disrupted.
Read diagram text
- Readiness
- Contacts, plans, access and exercises
- Retainer
- Agreed commercial access to assistance
- Response
- Authorised work for the actual incident
Define mobilisation in observable steps
Ask what happens when an authorised caller requests assistance. Distinguish acknowledgement, an initial consultation, access to an investigator and the start of agreed response work. Define the required hours, regions and communication methods, then ask the provider to confirm what it can contractually support. A time target is ambiguous if the event that starts the clock is unspecified. Include what happens when prerequisite access is unavailable, the caller lacks authority or the incident requires a specialist outside the proposed team. Record these dependencies during procurement, when there is time to resolve them.

Prepare evidence and decision authority
Identify the business services that matter most and the people who own operational decisions. At a high level, list where identity, endpoint, cloud and application evidence may be available. Ask how the response team obtains approved access and how evidence handling will be coordinated with your internal advisers. Define who can authorise disruptive containment and who can accept operational risk. The initial RFP should not contain credentials, personal records or live incident evidence. Establish an appropriate secure channel before exchanging sensitive material, and agree the applicable confidentiality and processing arrangements.
Read diagram text
- Request
- Who can invoke the agreement?
- Acknowledge
- What event and hours define the target?
- Start work
- Which prerequisites must be available?
Read the commercial boundaries carefully
Compare included hours, whether capacity is reserved, the work covered, overage approval, unused capacity treatment and renewal or termination arrangements. Ask whether readiness exercises, on-site attendance, specialist analysis or post-incident reporting are included or separate. Your finance and operational owners should understand the same service description. Avoid comparing retainers solely by a headline monthly fee if the activation rules and included effort differ. A written assumptions table makes the proposals easier to assess and gives the later incident manager a clearer starting point.
Read diagram text
- Evidence
- Know its owners and access process
- Containment
- Name the decision makers and limits
- Coordination
- Agree communication and adviser roles
Exercise the handoff before relying on it
A benign tabletop can reveal that an emergency contact is outdated, a supplier owns essential evidence or an approval chain depends on an unavailable executive. Record the resulting actions and repeat the relevant handoffs after changes. The AWS incident-response guidance also highlights preparation and practice for cloud response. Technical assurance can complement readiness but should remain a separately authorised activity.
Technical validation can complement a service programme when it has a separate purpose and authorisation. Our related guides explain cloud and CI security boundaries and assessment procurement and permissions. Use that work to answer a defined assurance question, then assign the resulting actions to the service owners. These publications are part of the same Atlant Security portfolio.
Prepare the discussion before an emergency
Use the services RFP builder to record your platforms, current support, desired coverage and constraints. It produces a proposed shortlist with reasons, followed by an optional AI-assisted draft for your review. Unknown facts remain questions for the proposal. You can amend the draft and submit it to our team with your NDA or existing RFP. Do not include passwords, detailed production identifiers or confidential incident evidence. The tool does not activate a service or agree contractual terms.
If you suspect an active incident, follow your established response process and contact your response provider directly. This website and its RFP tool do not dispatch responders or confirm emergency availability.
Read diagram text
- Included
- Hours, activities and availability
- Additional
- Approval for specialist or extra work
- Exit
- Records, renewal and termination terms
Primary sources
General information, not a compliance opinion. Confirm legal applicability and security service requirements for your entity and jurisdiction.
This guide and the related sector publications linked above are published by Atlant Security. Technical examples are planning examples, not claims about completed client tests.
Published by Atlant Security. Sources, editorial policy and corrections.

