- Job title
- Information Security Specialist
- Sector
- Agriculture
- Organization type
- two-branch business
- Joined
- Jul 2023
- Message
- 114
We're a 35-person B2B SaaS company incorporated in Delaware. We host our clients' critical databases and financial transaction pipelines in the cloud. Last week, an external security auditing firm we work with pitched us an incident response retainer.
Here's the gist of the offer: We pay $12,000 upfront annually. They guarantee an initial response time within 2 hours in the event of any cyberattack, data breach, or ransomware incident. In a crisis, they also discount their hourly rate from $550 to $350. If nothing happens all year, we can roll $4,000 of that $12k toward a penetration test at year-end while the rest expires.
We already run endpoint security tools and carry a cyber insurance policy with $5 million in coverage. For a company our size, is keeping a literal fire department on standby a rational expense or does it make more sense to just rely on the emergency team dispatched by our insurer if something happens?