forumNew topic

They are demanding a "cyber incident response team" from us — does a 15-person company really need one?

RRecep K***MemberCommunity member
Joined
Apr 2022
Message
6
#1

We are a 15-person software and data analytics agency based in Dubai. We are on the verge of signing a 450,000 AED annual service contract with a large enterprise client based in Abu Dhabi. However, their procurement and compliance departments just handed us a 40-page vendor security agreement. One clause explicitly mandates maintaining a 24/7 active cyber incident response team with a guaranteed response time of under 2 hours in the event of an incident.

Our entire annual IT and infrastructure budget is only around 30,000 AED. Even hiring a single full-time security specialist is completely out of reach at our scale, let alone building an in-house shift team, which would wipe out all the profit from this deal. Meanwhile, their account rep claims this clause is standard corporate procedure and cannot be waived.

How do small vendors like us actually fulfill these kinds of enterprise requirements? Is there a legitimate, accepted way to pass this audit without building a dedicated internal team?

GGamzeMember
Job title
HR Specialist
Organization type
120-person company
Joined
Jul 2024
Message
104
Most Helpful#2

Short answer: A company of this size is not expected to build an in-house, full-time incident response team, nor does it make commercial sense. What enterprise auditors are actually looking for is assurance that a data breach won't be left unattended, that there is a defined response plan in place, and that you have a retainer contract for external technical support.

You can meet this requirement by taking the following steps: 1) Secure an incident response retainer from an external cybersecurity firm. Under this model, you pay a reasonable monthly or annual retainer; you avoid hefty fees as long as no incident occurs, but your contract guarantees a 2-hour response window. You can then submit this partner's credentials and commitments on the client's compliance questionnaire. 2) Establish a formal internal Incident Response Plan document. Designate two internal staff members, such as your tech lead and operations manager, as primary points of contact. Their job is not to perform technical analysis, but to detect the incident, notify the external team, coordinate communication, and keep the client informed. 3) Provide an official briefing note to the client's security team outlining your company's scale, your internal escalation hierarchy, and your external incident response SLA. Corporate clients typically approve this clause once a defined third-party provider and a documented response workflow are presented.

OOsman T***Member
Job title
Technical service technician
Sector
Furniture manufacturing
Organization type
a company within a holding
Joined
Jan 2022
Message
3
#3

Big enterprises just copy-paste their internal standards onto vendor agreements. Speak directly with their security team. They know full well that a 15-person shop cannot support an in-house CSIRT. If you provide an external support contract alongside an internal escalation matrix, they will sign off on it.

GGamze D***Veteran
Job title
Courier coordinator
Sector
Food wholesale
Organization type
300-person organization
Joined
Jan 2024
Message
209
#4

Our 20-person team in Dubai ran into the exact same clause. We signed an on-call retainer with a security firm for 12,000 AED per year. They committed to a 4-hour response SLA. The client's audit team accepted the documentation, and we closed the deal.

edit: fixed a few typos.

CCaner G***MemberCommunity member
Joined
Aug 2023
Message
218
#5

Don't reject the clause outright, but don't sign it blindly either. Propose an addendum stating that the Incident Response Team function is fulfilled via an accredited external security provider backed by an SLA.

ŞŞerife Y***Member
Job title
Courier coordinator
Sector
Food wholesale
Organization type
120-person company
Joined
Apr 2023
Message
41
#6

Don't mind the account manager saying it's non-negotiable; they're just middlemen. Security clauses are negotiated directly with the client's CISO or risk team. If the data level your company accesses isn't critical, you can even get this clause completely waived.

MMustafa C***MemberCommunity member
Joined
Jan 2026
Message
96
#7

I recommend consulting your legal counsel before signing the contract. If you make this commitment without an agreement with an external provider and a potential breach occurs, severe liability for damages could arise due to breach of contract.

NNuri U***VeteranCommunity member
Joined
Feb 2024
Message
325
#8

when this happened to us we put two in-house devs on call rotation but the auditor didnt buy it and i mean getting an annual retainer externally is the cleanest way saves you the headache.

ZZeynep K***MemberCommunity member
Joined
Feb 2024
Message
41
#9

What customer data will you be accessing? Will your systems directly integrate with their servers, or will you just run analytics in an isolated environment? Your access level will be your biggest bargaining chip for relaxing the requirements.

KKader B***Expert
Job title
IT manager
Sector
Agriculture
Organization type
boutique agency
Joined
Mar 2023
Message
233
#10

don't panic at all; these kinds of clauses always look scary during enterprise RFPs. btw the goal isn't to sink you it's just to make sure there's an accountable person on the other end of the line if a crisis hits.

FFiliz E***Member
Job title
Graphic Designer
Sector
Catering
Organization type
two-branch business
Joined
Aug 2022
Message
200
#11

i went through the same thinng two years ago. solutions that work at a small scale collapse when you grow; I learned this late.

if you post the result here, it will help others too.

VVildan V***VeteranCommunity member
Joined
Jun 2025
Message
329
#12

I'll try it.

FFurkan K***MemberCommunity member
Joined
Nov 2023
Message
141
#13

I have an objection here. Forgotten test environments are more often the entry point than live systems.

When making a decision, first look at what data you have on hand. Of course, it varies if your situation is different.

TTuğçe C***Expert
Job title
Human Resources Specialist
Sector
Law
Organization type
40-person manufacturing company
Joined
Feb 2023
Message
185
#14

I didn't know that.

AAhmet B***ExpertCommunity member
Joined
Dec 2025
Message
264
#15

thanks a lot, I'll try it today.. then the harder it is to reverse a decision the slower you should make it.

when making a decision, first look at what data you have on hand. im also cuious if anyone does it differently.

AAslı Ç***Member
Job title
Production planning
Sector
Consulting
Organization type
300-person organization
Joined
Dec 2025
Message
124

Doki · KVKK compliance consulting · 2026

#16

there are three things to check when doing this and if 2FA is on, a stloen password alone is useless.

this is my opinion, I'm not claiming it's absolute truth.

NNecati D***MemberCommunity member
Joined
Oct 2023
Message
251
#17

Three different views emerged, they all complement each other. Any unwritten clause becomes a point of disagreement later, as both sides remember it differently.

If I were you, I'd go this route.

AAhmet O***MemberCommunity member
Joined
Feb 2025
Message
142
#18

Could you elaborate on that? An automated scan report is not the same as a penetration test.

Just because everyone does it doesn't mean it's right. That's all, sorry if I went on too long.

İİlker A***MemberCommunity member
Joined
Feb 2023
Message
292
#19

I've been dealing with this for a long time. The harder it is to reverse a decision the slower you should make it.

If I were you I'd go this route.

HHüsniye A***Member
Job title
Intern
Sector
IT services
Organization type
medium-sized business
Joined
Mar 2023
Message
250

Doki · Mobile app · 2025

#20

Absolutely. If I were to add anything: Don't rely on a single measure; go layer by layer.

Correct me if I'm wrong.

Reply