forumNew topic

They're requiring a "cyber incident response team" — does a 20-person firm really need this?

LLale B***MemberCommunity member
Joined
Oct 2025
Message
282
#1

We're a 20-person software and integration company based in Dubai. We're on the verge of winning a warehouse logistics systems tender for an international retail chain in the region. We've reached the contracting phase but their information security department added a clause to the vendor specifications requiring a dedicated 24/7 "cyber incident response team."

We only have two full-time systems engineers on our staff. Setting up a fully-fledged security operations center or an on-call incident response team in-house is financially impossible for us. The security audit form they sent asks for the team's org chart, escalation processes, and designated contact details. We're at risk of losing the contract over this one clause.

What is the bare minimum compliance level for a firm of our size to satisfy this requirement? Would outsourcing this (via an MSSP or an incident response retainer) be acceptable, and what documentation do we need to hand over to the auditors?

HHavva K***MemberCommunity member
Joined
Jul 2024
Message
111
Most Helpful#2

Short answer: A 20-person firm does not need to build an in-house, dedicated 24/7 incident response team, nor do enterprise auditors actually expect that. The industry-standard way to satisfy this is appointing an internal technical lead as the team head and contracting out the operational response capacity to a third-party cybersecurity service provider.

To get full marks on the audit, you need three main components ready: 1) External IR Agreement: Secure an annual incident response retainer with guaranteed hourly SLAs from a local cybersecurity provider. 2) Incident Response Plan: Prepare a 4-5 page formal escalation document detailing what happens within the first hour of a breach or attack, when the client gets notified, and who the authorized contacts are. 3) Role Assignment: Appoint the senior of your two systems engineers as the "Incident Response Manager" and reflect this on the org chart.

Big enterprise clients don't expect vendors to build their own internal security divisions; they just want written assurance about who to contact during an incident and proof that technical response will be handled by qualified pros. Once you list your outsourced provider's name, contract number, and 24/7 emergency hotline on the audit form, you'll fully meet their criteria.

UUfuk B***Member
Job title
Field sales representative
Sector
Paper
Organization type
chain store
Joined
Nov 2024
Message
2
#3

Don't push back on the clause right away. Just respond to their security team with this: We handle our incident response capacity via a hybrid model using an external security service provider. Internal coordination is managed by our systems administrator, while tier-2 technical response is handled by our external partner. That usually gets approved without issues.

SSultanExpert
Job title
Textile exporter
Organization type
two-branch business
Joined
Sep 2023
Message
148
#4

We ran into the exact same issue last year during a bank integration audit in Dubai. We signed an on-call incident response retainer with a local security provider for 18.000 AED a year. We attached their contract and the escalation matrix we put together to the audit questionnaire, and it passed with zero follow-up questions.

İİbrahim Y***Member
Job title
Marketing manager
Sector
Electrical-electronics
Organization type
20-person company
Joined
Nov 2023
Message
95
#5

What they'll actually look at during the audit isn't your SIEM stack, it's how communications flow once something is detected. Define a maximum 2-hour response SLA for critical incidents, secure log retention in an isolated environment, and a written notification protocol to the data controller in the event of a breach. If that procedure is documented in the form, the technical audit clears.

edit: fixed a few typos.

ÖÖmer Ş***Member
Job title
Project manager
Sector
Software
Organization type
chain store
Joined
Feb 2025
Message
179

Doki · Brand identity · 2025

#6

Does the draft contract mandate ISO 27001 or a similar international certification, or is it just asking you to declare on the form that such a team exists? Will you have direct access to the client's database, or will the system communicate solely through an isolated API?

HHasan S***MemberCommunity member
Joined
Jan 2024
Message
114
#7

corporate procurement departments just copy-paste boilerplate templates then list your two-person team as internal coordinators, tack on a cheap outsourced on-call support agreement and youre good nobody expects you to run an actual soc room.

KKadir G***VeteranCommunity member
Joined
Feb 2023
Message
14
#8

Two years ago, back when we only had 15 employees a quasi-governmental client pushed this exact same requirement on us. At first we panicked and crunched the numbers on hiring two dedicated security people, but the annual cost would've wrecked our budget. Then we talked to an auditor we knew, submitted an outsourced MSP contract and it got approved on the first try. Lost sleep over nothing.

SSerkan G***MemberCommunity member
Joined
Aug 2023
Message
37
#9

Just watch out when setting up that outsourced contract; some vendors just email an automated scan report once a month and call it incident response. If the client's auditor digs deeper and asks "who's responding if ransomware hits at 3 AM," that paper-only contract will blow up in your face. Make sure you pick a provider that actually picks up the phone.

LLeyla Y***MemberCommunity member
Joined
Mar 2024
Message
44
#10

demanding a 24/7 security operations unit from a 20-person shop is like requiring a corner store to use an armored cash-in-transit truck but anyway enterprise procurement folks sometimes assume small vendors have the same security budgets as their own enterprise. just show them an outsourced contract and move on.

MMustafa Ç***Member
Job title
Clinic manager
Sector
Glass
Organization type
two-branch business
Joined
Oct 2022
Message
49
#11

Yes, that's exactly how it is with cyber incident response team. If you don't write this down from the start, it leads to arguments later.

When making a decision, first look at what data you have on hand.

KKoray C***MemberCommunity member
Joined
Oct 2022
Message
180
#12

Three different views emerged, they all complement each other. If it's your first time, start small; scaling comes later.

That's all, sorry if I went on too long.

AAli G***Member
Job title
Logistics planning
Sector
Electrical-electronics
Organization type
family business
Joined
Jul 2023
Message
1
#13

I've been down this road, let me tell you. Solutions that work at a small scale collapse when you grow; I learned this late.

Just leaving this note it might be useful.

RRecep S***Member
Job title
Production planning
Sector
Retail
Organization type
sole proprietorship
Joined
Sep 2023
Message
103
#14

lets separae the concepts theyre getting mixed up. like when you try to change everything at once nothing settles.

proven by experience.

YYavuz E***Member
Job title
Courier coordinator
Sector
Freight
Organization type
two-branch business
Joined
Feb 2024
Message
169
#15

Could you elaborate on that? If you scold false alarms nobody will report again.

Correct me if I'm wrong.

PPınarExpert
Job title
Analytics Specialist
Joined
Jan 2024
Message
198

Doki · Mobile app · 2025

#16

The cheap-looking path usually ends up costing more later. Processes without records never improve because you don't know what to fix.

FFatih E***Member
Job title
Operations manager
Sector
Consulting
Organization type
medium-sized business
Joined
May 2023
Message
26
#17

I have a question, don't want to go off-topic though. The harder it is to reverse a decision the slower you should make it.

Good luck with that.

MMelis Ç***New member
Job title
Production planning
Sector
E-commerce
Organization type
sole proprietorship
Joined
May 2026
Message
179
#18

We experienced almost the exact same thing last year. Trying to do this alone is the most expensive way.

Good luck with that.

FFurkan Y***MemberCommunity member
Joined
Feb 2023
Message
53
#19

I'll try it.

RRıdvanMember
Job title
Dealer network manager
Organization type
regional distributor
Joined
Mar 2024
Message
92
#20

There's a part I don't understand. If permission and scope aren't in writing, don't start that test.

I'm also curious if anyone does it differently.

Reply