Incident Response (IR) Retainer Selling to the CISO and General Counsel — 60-Min Training
PULSEKNOWLEDGE LIBRARY
An incident response retainer sells to three buyers at once: the General Counsel funds it to preserve privilege over the investigation, the CISO operationalizes the runbook, and the cyber-insurance broker controls panel eligibility. Win by qualifying all three, anchoring on response-time SLA and forensic defensibility, then structuring a flat-fee retainer with discounted burst hours.
What an IR retainer actually buys, and why the legal frame beats the security frame
Sellers who come out of endpoint or SIEM sales default to a security pitch: faster detection, better telemetry, sharper threat intel. That pitch loses IR retainer deals, because the person who releases the money is usually not the person who consumes the service. The General Counsel signs because an incident that turns into litigation, a regulator inquiry, or an insurance dispute puts the company's legal exposure on the line, and a forensic report written outside privilege becomes discoverable evidence against the company. The retainer is, in the GC's mental model, a pre-negotiated engagement vehicle that lets outside cyber counsel direct a forensic firm the moment something breaks — no procurement cycle, no scope negotiation while the clock runs.
That distinction drives everything downstream in the sales motion. Two things follow.
First, the IR firm typically works *under* outside cyber counsel, not under the security org. The engagement letter runs counsel → IR firm, with the client as beneficiary, specifically so the work product sits inside attorney-client privilege and work-product doctrine. If your proposal assumes a direct client relationship, the GC will redline it before the CISO ever sees the technical scope. Ask early: "Who is your outside cyber counsel, and do they have preferred forensic firms?" That single question repositions you from vendor to panel candidate.
Second, the cyber-insurance carrier has a vote. Most cyber policies maintain a pre-approved panel of IR firms, and using an off-panel firm can reduce or complicate coverage of the response costs. A customer who loves your technical depth will still route the first call to a panel firm if going off-panel risks a claim dispute. So the seller's real qualification question is not "do you have a retainer?" but "which firms are on your carrier's panel, and does your policy allow a consent-to-use exception for a preferred non-panel firm?" Many carriers will grant that exception in advance if it's requested at binding or renewal — which means the broker, not the CISO, is often your fastest path to eligibility.

The adjacent motion worth borrowing from: this is structurally the same sale as a litigation-support or e-discovery retainer, and the same as an outside-counsel panel placement. In all three, the buyer is pre-purchasing *availability and defensibility*, not hours. Sellers coming from managed detection and response (MDR) or endpoint deals underestimate how much of the evaluation is contractual rather than technical. Sellers coming from professional-services or agency retainers usually get the frame right immediately.
The two metrics that decide the deal are narrow. Response-time SLA: how fast a qualified senior consultant is engaged after the customer declares an incident, typically expressed in hours, with tiers by retainer size. Forensic defensibility: whether the resulting report holds up under litigation, regulator review, or carrier scrutiny — chain of custody, evidence handling, consultant credentials, and the firm's track record of testifying or defending findings. A faster report that collapses under cross-examination is worth less than nothing, because it becomes the opposing party's exhibit. Anchor your differentiation on those two, and the rest of the technical conversation becomes supporting detail rather than the main event.
The step-by-step process from first call to bound retainer
Run this as a sequence with explicit gates. The most common failure is skipping straight from a technical discovery call to a proposal, which produces a document only the CISO can evaluate and nobody can fund.

Step one — pre-brief and buyer assembly. Send a one-page brief 24 to 48 hours ahead listing exactly what you'll cover and who needs to be present. Name the roles: security owner, legal owner, and either the broker or the risk manager who owns the cyber policy. If legal cannot attend, reschedule rather than run a half-room call — a security-only discovery produces a security-only proposal, and you will re-run the whole cycle when the GC finally reads it.
Step two — the 60-minute joint discovery. Structure it in blocks. Open with incident history: the last 18 to 24 months, which incidents required outside help, which were handled internally, and what the trigger threshold was. Move to SLA baseline: what the current engagement commitment is, whether it's measured from notification or from executed scope, and whether senior consultants or intake staff answer first. Then forensic posture: has any prior investigation been tested by litigation, a regulator, or a coverage dispute, and how did the report hold. Then retainer structure: flat fee, pre-paid hours, or zero-dollar standby, and whether unused hours roll into proactive services. Then carrier posture: panel composition and consent-to-use flexibility. Then counsel relationship. Close on renewal timing and any notice or auto-renew friction in the incumbent contract.
Step three — the scoping workshop. This is where deals are actually won. Schedule 90 minutes with security and legal together within ten business days of discovery. Walk through the notification path (who calls whom at 2 a.m.), the evidence-preservation protocol, the environments and data types in scope, the named senior consultants who would respond, and the escalation matrix. Publish an agenda in advance; the major firms all publish comparable scoping agendas, and matching that rigor signals you belong in the same tier.
Step four — proposal and legal review. The proposal should contain the SLA with its measurement definition, the hourly rate card with retainer-holder discount, the burst provision, the named-consultant roster, and the privileged-engagement language. Expect legal to redline indemnity, limitation of liability, and data-handling terms. Budget two to four weeks for this if the customer's legal team is busy; it is the single most underestimated part of the timeline.
Step five — kickoff and tabletop. Do not treat signature as the finish line. A tabletop exercise inside the first 60 days is the cheapest renewal insurance available, because it converts an abstract contract into a shared experience the GC can describe to the board.

Costs, timelines, and how retainers are typically structured
Pricing in this category varies widely by firm tier, geography, and the customer's environment, so treat any number you cite as a structure rather than a quote. What is consistent is the *shape* of the commercial models, and sellers who can explain the shapes clearly close faster than those who send a rate card and wait.
Zero-dollar or credit-back standby. The customer pays nothing (or a nominal fee) for guaranteed availability and a discounted rate card. Attractive to budget-constrained buyers, weak on prioritization — when a widespread event hits multiple clients at once, paying retainer holders get consultants first. Sell against this by asking what the firm's queue policy is during a mass-exploitation event.
Pre-paid hours. The customer buys a block of hours at a discount, drawn down during incidents. The critical terms are expiration and convertibility: do unused hours expire at the anniversary, and can they be spent on proactive work like tabletops, readiness assessments, or runbook development? Convertible hours make the renewal conversation dramatically easier, because the customer got value in a quiet year rather than watching budget evaporate.
Flat-fee retainer with discounted burst. An annual fee covers a defined bundle — SLA tier, a set of proactive deliverables, a named team — with incident hours billed at a discounted rate above the included allotment. This is the structure most enterprise buyers now expect, because it gives finance a predictable line item and gives the GC a guaranteed engagement path with a ceiling on surprise.
On timelines: a mid-market cycle from first qualified conversation to executed retainer commonly runs one to three months when legal is engaged early; enterprise cycles with a formal panel process, security review, and multi-party redlining routinely run four to nine months. The two accelerants are an expiring incumbent contract and a policy renewal date — both create a natural forcing function. The two decelerants are procurement-first routing and an absent GC.

Multi-year structures follow the same logic as any professional-services retainer: a modest discount for a two- or three-year term, a larger one for longer commitments, generally in exchange for something beyond signature — case-study rights, a reference call, or a joint tabletop the firm can anonymize. Push for the trade rather than giving margin away for tenure alone.
One adjacent economic argument worth having: many cyber policies now reimburse or credit portions of proactive readiness spend, and some carriers offer premium considerations for demonstrable IR preparedness. That reframes the retainer from pure cost to a line item with a potential offset. Ask the broker directly what their carriers recognize — the answer varies by carrier and is exactly the kind of specific, verifiable value the CISO cannot produce alone.
Where sales teams get this wrong
Selling speed as the whole story. Response-time SLA is table stakes for anyone in the conversation. Every serious firm publishes one. Differentiating solely on hours reduces you to a commodity and invites the incumbent to simply match the number. Speed matters most when paired with *who* arrives — a two-hour SLA that delivers an intake coordinator is worse than a four-hour SLA that delivers a named senior consultant with courtroom experience.
Ignoring the carrier. Sellers who never ask about the panel discover it during legal review, when the customer's risk manager quietly kills the deal. Map the panel in discovery. If you're off-panel, the honest play is a parallel retainer covering scenarios outside the claim path — internal investigations, insider matters, M&A diligence, third-party incidents that don't trigger the policy — while you build the case for a consent-to-use exception at renewal.
Running procurement-solo negotiations. Once the deal routes to procurement without the GC and the CISO on the call, the conversation becomes rate-per-hour and nothing else. The defensible position is simple and should be stated politely and early: pricing conversations include the legal and security owners because the terms being priced are legal terms. Sellers who set that expectation in discovery rarely have to enforce it later.

Quoting scope without a workshop. A proposal built from a discovery call alone will mis-scope environments, miss regulated data types, and omit the notification path. That produces either a padded price the customer rejects or a thin price that generates an ugly change order during a live incident — the worst possible moment to renegotiate.
Forgetting the operational reality of the CISO's week. The CISO is evaluating you while running vulnerability management, audit findings, board reporting, and a hiring plan. A twelve-page proposal will not be read closely. A one-page summary — SLA, named team, what's included, what's billed, what it costs — attached to the full document gets read in the elevator and forwarded to legal.
Treating the tabletop as an upsell. Bundling a readiness exercise into year one costs you delivery hours and buys you the single most valuable renewal artifact: a documented, shared experience where the customer's own executives saw the runbook work. Sellers who hold the tabletop back for a separate SOW consistently renew worse.
Silence between incidents. The structural hazard of any retainer is that a good year looks like a wasted year. If the only contact is the invoice, renewal becomes a line-item review. Quarterly readiness touchpoints — even 30 minutes — keep the relationship alive and surface the environment changes that should adjust scope.

Choosing a structure: a decision framework
The right retainer shape depends on three variables: incident frequency, regulatory exposure, and carrier constraints. Work them in that order.
Start with frequency and severity history. An organization that has run two or more outside-counsel-directed investigations in the past 24 months should be on a flat-fee retainer with a defined SLA tier — the volume justifies the predictability, and the finance conversation is easy because the spend is already occurring unpredictably. An organization with no incident history but meaningful exposure is often better served starting with pre-paid convertible hours, spending most of them on readiness work, and stepping up at renewal.
Then apply regulatory and litigation exposure. Healthcare, financial services, public companies, and any organization handling large volumes of consumer personal data face notification deadlines and regulator scrutiny that make forensic defensibility the dominant criterion. In those environments, prioritize the firm with the strongest litigation-support track record and named consultants who have testified, even at a premium. For lower-exposure organizations, operational speed and cost efficiency reasonably outweigh courtroom pedigree.
Then apply the carrier constraint as a filter, not a starting point. If the preferred firm is on-panel, proceed. If not, decide between pursuing consent-to-use through the broker at the next policy renewal or running a scoped parallel retainer for non-claim matters.
A fourth consideration cuts across all three: existing service relationships. If the customer already buys MDR or managed SOC services, ask whether that provider's IR arm is contractually implicated. Bundled arrangements can create either a real advantage — telemetry already in place, familiarity with the environment — or a genuine conflict, when the firm investigating an incident is the same firm whose monitoring may be questioned. The GC will usually see that conflict faster than the CISO does; raising it yourself is credibility-building rather than negative selling.
Related questions
Who signs an IR retainer — the CISO or the General Counsel?
Usually the GC or legal owns the contract because the engagement runs through outside counsel for privilege, while the CISO owns the operational scope. Budget may sit in either org. Qualify both, and confirm which cost center funds it before proposing.
Does using an off-panel IR firm void insurance coverage?
Not automatically, but it can create coverage disputes over response costs. Most carriers require prior consent to use a non-panel firm. The clean path is requesting consent-to-use at binding or renewal, coordinated through the broker.
How is a retainer different from just calling a firm during an incident?
A retainer pre-negotiates rates, terms, data handling, and the engagement path, and typically grants priority access to consultants. Without one, you negotiate contracts during the incident — losing hours and leverage at the worst possible moment.
Should the tabletop exercise be included or sold separately?
Include it in year one. It converts an abstract contract into a shared experience executives remember, surfaces runbook gaps while it's cheap, and gives the GC a concrete story for the board — which is what defends the renewal.
FAQ
Why does privilege matter so much in an IR engagement?
If a forensic report is produced outside a counsel-directed engagement, it is far more likely to be discoverable in later litigation or regulatory action — meaning the company's own investigation becomes evidence against it. Structuring the work under outside counsel is the standard approach to preserving attorney-client privilege and work-product protection, though courts evaluate this case by case and structure alone is not a guarantee.
What should a response-time SLA actually specify?
Three things: the clock start (notification versus executed scope), the seniority of who responds, and the tiering by retainer level. An SLA that promises contact in two hours but doesn't define who makes contact is marketing, not a commitment. Ask competitors' customers what actually happened at 2 a.m.
How do we compete against a large incumbent firm with brand advantage?
Compete on named consultants, scoping flexibility, and carrier alignment rather than on rate. Ask who is specifically assigned to the account, whether the incumbent's team changes between the sales cycle and the incident, and whether the incumbent's panel coverage spans the carriers the customer might move to at renewal.
Can an IR retainer coexist with an existing MDR or managed SOC contract?
Yes, and often should. Monitoring and investigation are different disciplines with different evidentiary standards. The point to raise carefully with legal is independence — an investigator with no stake in whether prior monitoring performed well produces findings that are easier to defend.
What derails IR retainer deals most often in the final stage?
Legal redlines on limitation of liability, indemnity, and data handling. Get your standard positions in front of the customer's legal team early rather than at signature. Sellers who send the contract template alongside the proposal cut weeks off the cycle.
How should this training be run for a distributed sales team?
Sixty minutes works if the room does the talking. Ten minutes on the three-buyer frame, twenty on live discovery role-play with a rep playing GC, fifteen on scoping workshop mechanics, fifteen on objections. Record the role-plays and grade them against a rubric rather than lecturing.
Sources
- https://www.cisa.gov/resources-tools/resources/incident-response-plan-basics
- https://www.nist.gov/cyberframework
- https://csrc.nist.gov/pubs/sp/800/61/r2/final
- https://www.sec.gov/newsroom/press-releases/2023-139
- https://www.americanbar.org/groups/business_law/
- https://www.ftc.gov/business-guidance/resources/data-breach-response-guide-business
- https://www.iso.org/standard/78973.html
- https://www.sans.org/incident-response/
- https://www.hhs.gov/hipaa/for-professionals/breach-notification/index.html
- https://www.naic.org/cipr-topics/cyber-risk
Related on PULSE
- [Cybersecurity Incident Response Engagement Selling — 60-Min Training](/knowledge/st367)
- [Endpoint Detection and Response (EDR) Selling to the CISO — 60-Min Training](/knowledge/st394)
- [MDR (Managed Detection and Response) Services Selling to Mid-Market — 60-Min Training](/knowledge/st385)
- [AI Legal Tools Selling to the General Counsel — 60-Min Training](/knowledge/st430)
- [Recruiting and Executive Search Retainer Selling — 60-Min Training](/knowledge/st381)
- [PR and Communications Agency Retainer Selling — 60-Min Training](/knowledge/st372)









