{
  "slug": "incident-response-retainer-value",
  "title": "Incident Response Retainer Value Calculator",
  "heading": "Incident Response Retainer Value Calculator",
  "category": "financial",
  "url": "https://www.revenuelab.fyi/toolbox/incident-response-retainer-value",
  "summary": "Compare a pre-paid IR retainer against emergency hourly rates during a real breach.",
  "description": "Incident response firms charge dramatically more for emergency, no-retainer engagements than for pre-negotiated retainer clients, often 1.5-2.5x the retainer hourly rate, and emergency engagements also carry longer response-time SLAs since retainer clients get priority staffing. This calculator compares the annual cost of a retainer (which usually includes a block of prepaid hours plus a committed response SLA) against the expected cost of needing emergency IR services without one, based on your estimated probability of needing IR support in a given year and the typical hours a real incident consumes. It also captures the value of faster response time itself: a retainer client typically gets a responder on a call within 1-4 hours versus 24-72 hours for a new emergency client sourcing a firm cold, and that gap directly extends dwell time and downtime cost during exactly the incident you're trying to contain quickly.",
  "formula": "Expected annual cost without retainer = P(needing IR) × hours needed × emergency hourly rate. Retainer total cost = annual retainer fee + (hours beyond prepaid block × retainer hourly rate × P(needing IR)).",
  "dateModified": "2026-09-30",
  "run_url": "https://www.revenuelab.fyi/api/public/calc?tool=incident-response-retainer-value",
  "inputs": [
    {
      "id": "probabilityNeedIr",
      "label": "Probability of needing IR support this year (%)",
      "kind": "number",
      "hint": null,
      "default": 25,
      "unit": null,
      "min": 0,
      "max": 100
    },
    {
      "id": "hoursPerIncident",
      "label": "Estimated IR hours for a typical incident",
      "kind": "number",
      "hint": null,
      "default": 120,
      "unit": null,
      "min": 1,
      "max": null
    },
    {
      "id": "emergencyRate",
      "label": "Emergency (no retainer) hourly rate",
      "kind": "number",
      "hint": null,
      "default": 500,
      "unit": null,
      "min": 0,
      "max": null
    },
    {
      "id": "retainerAnnualFee",
      "label": "Annual retainer fee",
      "kind": "number",
      "hint": null,
      "default": 35000,
      "unit": null,
      "min": 0,
      "max": null
    },
    {
      "id": "retainerPrepaidHours",
      "label": "Prepaid hours included in retainer",
      "kind": "number",
      "hint": null,
      "default": 40,
      "unit": null,
      "min": 0,
      "max": null
    },
    {
      "id": "retainerRate",
      "label": "Retainer hourly rate (beyond prepaid)",
      "kind": "number",
      "hint": null,
      "default": 350,
      "unit": null,
      "min": 0,
      "max": null
    }
  ],
  "outputs": [
    {
      "id": "costWithRetainer",
      "label": "Expected annual cost with retainer",
      "format": "currency",
      "hint": null,
      "primary": true
    },
    {
      "id": "costWithoutRetainer",
      "label": "Expected annual cost without retainer",
      "format": "currency",
      "hint": null,
      "primary": false
    },
    {
      "id": "savings",
      "label": "Expected savings from retainer",
      "format": "currency",
      "hint": null,
      "primary": false
    },
    {
      "id": "savingsPct",
      "label": "Savings as % of no-retainer cost",
      "format": "percent",
      "hint": null,
      "primary": false
    },
    {
      "id": "extraHours",
      "label": "Hours beyond prepaid block (typical incident)",
      "format": "number",
      "hint": null,
      "primary": false
    }
  ],
  "worked_example": {
    "inputs": [
      "Probability of needing IR support this year (%): 25",
      "Estimated IR hours for a typical incident: 120",
      "Emergency (no retainer) hourly rate: 500",
      "Annual retainer fee: 35000",
      "Prepaid hours included in retainer: 40",
      "Retainer hourly rate (beyond prepaid): 350"
    ],
    "outputs": [
      "Expected annual cost with retainer: $42,000",
      "Expected annual cost without retainer: $15,000",
      "Expected savings from retainer: -$27,000",
      "Savings as % of no-retainer cost: -180%",
      "Hours beyond prepaid block (typical incident): 80"
    ]
  },
  "how_to": {
    "title": "How to use this",
    "steps": [
      "Enter probability of needing ir support this year (%).",
      "Enter estimated ir hours for a typical incident.",
      "Enter emergency (no retainer) hourly rate.",
      "Enter annual retainer fee.",
      "Enter prepaid hours included in retainer.",
      "Enter retainer hourly rate (beyond prepaid).",
      "Read your expected annual cost with retainer on the right — it updates as you type.",
      "Hit Share to keep the scenario or send it to someone."
    ]
  },
  "scenarios": [
    {
      "name": "Conservative",
      "description": "Lower-end numbers — what if things land soft?",
      "values": {
        "probabilityNeedIr": 15,
        "hoursPerIncident": 70,
        "emergencyRate": 300,
        "retainerAnnualFee": 21000,
        "retainerPrepaidHours": 25,
        "retainerRate": 210
      }
    },
    {
      "name": "Typical",
      "description": "Defaults — the most common real-world setup.",
      "values": {
        "probabilityNeedIr": 25,
        "hoursPerIncident": 120,
        "emergencyRate": 500,
        "retainerAnnualFee": 35000,
        "retainerPrepaidHours": 40,
        "retainerRate": 350
      }
    },
    {
      "name": "Ambitious",
      "description": "Higher-end numbers — what if things really pop?",
      "values": {
        "probabilityNeedIr": 40,
        "hoursPerIncident": 190,
        "emergencyRate": 800,
        "retainerAnnualFee": 56000,
        "retainerPrepaidHours": 65,
        "retainerRate": 560
      }
    }
  ],
  "limitations": [
    "Results are estimates before tax, fees, and inflation unless an input explicitly covers them.",
    "Rates are treated as fixed for the whole period — variable-rate products will drift from this projection.",
    "This is educational maths, not financial advice. Check anything contractual with the lender or your accountant."
  ],
  "faq": [
    {
      "q": "Is a retainer worth it if I might never need IR support?",
      "a": "Even at a modest 15-25% annual probability of needing support, the expected cost calculation usually favors a retainer once you include the faster response-time value, but if your probability is genuinely under 10% (small, low-profile organization with mature controls) a retainer may not pencil out purely on the math, though the guaranteed response SLA still has value during any incident, including ones that turn out to be false alarms."
    },
    {
      "q": "What does 'faster response time' actually save?",
      "a": "Every hour between detection and a skilled responder starting containment is an hour attackers can spread laterally or continue exfiltrating data, so the 1-4 hour retainer response window versus 24-72 hours for a cold emergency engagement can meaningfully shorten total dwell time, which correlates directly with total breach cost in every major cost-of-breach study."
    },
    {
      "q": "Do unused retainer hours roll over or expire?",
      "a": "This varies by contract, some IR firms let you use retainer hours for proactive work like tabletop exercises or readiness assessments if no incident occurs, while others treat it as a pure standby fee that expires unused. Read the contract terms carefully since this materially changes the retainer's value if you go a year without an incident."
    },
    {
      "q": "How many hours does a typical incident really take?",
      "a": "A contained, well-scoped incident (single system, clear ransomware note, tested backups) might run 40-80 hours of IR firm time; a complex multi-system breach with forensic investigation, regulatory reporting support, and negotiation can run 200+ hours, so budget your hours-per-incident input based on your actual environment complexity, not a best-case scenario."
    }
  ],
  "related": [
    "https://www.revenuelab.fyi/toolbox/cyber-insurance-premium-vs-retention",
    "https://www.revenuelab.fyi/toolbox/mttd-mttr-cost-impact",
    "https://www.revenuelab.fyi/toolbox/ransomware-downtime-cost"
  ],
  "license": "CC-BY-4.0",
  "citation": "RevenueLab — Incident Response Retainer Value Calculator (https://www.revenuelab.fyi/toolbox/incident-response-retainer-value)"
}