We're a 20-person software and integration company based in Dubai. We're on the verge of winning a warehouse logistics systems tender for an international retail chain in the region. We've reached the contracting phase but their information security department added a clause to the vendor specifications requiring a dedicated 24/7 "cyber incident response team."
We only have two full-time systems engineers on our staff. Setting up a fully-fledged security operations center or an on-call incident response team in-house is financially impossible for us. The security audit form they sent asks for the team's org chart, escalation processes, and designated contact details. We're at risk of losing the contract over this one clause.
What is the bare minimum compliance level for a firm of our size to satisfy this requirement? Would outsourcing this (via an MSSP or an incident response retainer) be acceptable, and what documentation do we need to hand over to the auditors?