- Job title
- Human Resources Specialist
- Sector
- Furniture manufacturing
- Organization type
- sole proprietorship
- Joined
- Oct 2024
- Message
- 105
We are a 35-person financial advisory firm based in London. Due to our enterprise client contracts and cyber insurance policy requirements, we need to have a cyber incident response team on retainer to step in immediately in case of ransomware or a data breach.
We've started gathering quotes for incident response services from different cybersecurity vendors. But the differences in models and pricing have us really confused. One firm is asking for a flat £18,000 annual retainer fee which includes 40 hours of response time. Another firm offers just an SLA (guaranteed response time) for £4,000 a year, but charges £350 per hour if an incident actually occurs.
Does it make sense to tie up thousands of pounds every year for a scenario we've never faced? How do these retainer agreements actually work in practice, and do they really show up within the SLA during a real emergency?