We are a 35-person healthcare integration software company based in California. Per the data security addenda we signed with our enterprise clients, maintaining an active professional cyber incident response retainer (IR retainer) has become mandatory in the event of a breach or ransomware attack.
We received a proposal from a cybersecurity vendor for an annual prepaid IR retainer of 18,000 USD, which includes 40 hours of emergency response per year. However, reviewing the draft contract, we noticed that both the legal and operational terms are left far too vague.
This is our first time signing an agreement like this. What clauses must we absolutely stand our ground on to ensure the team actually shows up on-site or connects to our environment when disaster strikes? How can we avoid massive surprise bills down the road and make sure the team is genuinely ready to respond?