Cyber Risk Retainer

Kroll delivers more than a typical incident response retainer—secure a true cyber risk retainer with elite digital forensics and incident response capabilities and maximum flexibility for proactive and notification services.
Contact Us

When faced with a cyber incident, your organization must be prepared to respond quickly and effectively to protect your operations, reputation and bottom line. Timely response and notification for cyber incidents is also mandated by many privacy and consumer protection laws. Prepare now with Kroll’s cyber risk retainer.

Kroll’s cyber risk retainer offers maximum flexibility with transparent pricing so you get tangible value for your retainer dollars and gain peace of mind knowing you can depend on Kroll’s prioritized response and global resources in a crisis.

Our cyber risk retainer adapts to and maximizes your existing security stack, so there's no need to buy new tech. You also have options to leverage a wide array of our end-to-end cyber risk solutions to strengthen your overall resiliency.

Incident Response Retainers


Customizable Incident Response Retainer

Kroll knows that for clients, the prospect of preparing for and dealing with a cyber incident is fraught with unknowns. That’s why we created a robust but flexible retainer to adapt to your business, while providing you with the comfort that Kroll’s team of forensic experts will respond to contain and remediate an incident. From preparedness services to breach response, Kroll’s cyber risk retainer services are configurable to your needs and environment regardless of the technologies you use.

A Kroll cyber risk retainer guarantees expedited response as well as notification and proactive services to minimize the impact of an incident. Our retainer options address the pressure organizations feel to maximize the value of cyber security investments with upfront pricing and service structure.

How Flexible is the Cyber Risk Retainer?

Unlike most providers, you can customize retainer packages to include a wide range of services:

Digital Forensics
Incident Response
Breach Notification
Testing & Assessments
Tabletop Exercises
Litigation Support
Cyber Risk Retainer
Cyber Risk Retainer
Cyber Risk Retainer
Cyber Risk Retainer
Cyber Risk Retainer
Cyber Risk Retainer
Cyber Security Retainer
Cyber Security Retainer
Cyber Security Retainer
Cyber Security Retainer
Cyber Security Retainer
Cyber Security Retainer

Client Testimonials

Option Care Health

“As a Cyber Risk Retainer client, we have appreciated Kroll’s expedited response for potentially critical issues. Their subject matter expertise allowed us to contain a situation prior to it developing into a significant issue.” – Option Care Health

Netscout Systems

“Kroll's Cyber Risk Retainer program gave us the flexibility to utilize our retainer credits to help us accomplish some of our IT security goals during the year, while having the peace of mind that we had a Tier 1 partner to quickly respond if we had some type of cyber incident.” – Netscout Systems, Inc


Incident Response Retainer Service Features

  • Prompt access to an elite, global team of 500+ incident response and breach notification experts
  • Rapid response service levels to provide peace of mind in the event of an emergency
  • Robust preparedness services, including tabletops, simulations, risk assessments, penetration testing, policy reviews and strategic advisory
  • Flexibility to choose from a wide range of cyber services


  • Ability to roll over a percentage of unused credits
  • No minimum hourly usage requirements or lead times
  • Technology-agnostic services can be catered to your specific security stack
  • Rate discounts for hourly cyber security services offered by Kroll
  • Compatible with over 60 cyber insurance carriers under pre-negotiated rates

In addition, cyber insurance plays an integral role in mature cyber security programs. Kroll is an approved vendor for over 50 cyber insurance carriers worldwide, with a dedicated insurance team that can help handle claims efficiently.

Choose the Incident Response Retainer Option That Fits Your Organization’s Posture and Need

Response Time Service Levels
Incident support contact within two hours (24/7/365)
Incident support contact within four hours (24/7/365)
Service Credits Application
100% of retainer credits can be applied towards any cyber risk consulting service
Rollover Credits
Up to 20% of unused services credit may be applied to the following year upon renewal
Rate Discount
15% discount on any additional hourly-based proactive or incident response cyber risk service
10% discount on any additional hourly-based proactive or incident response cyber risk service

Customize Your Incident Response Retainer for Optimal Coverage

Unlike other firms, Kroll gives you the opportunity to customize cyber risk retainers with a wide variety of proactive, response and notification services best suited for your situation and goals. Below are just a few examples of the services available:

Security Validation & Assessments

Incident Response Services


Peace of Mind and Expert Support Just a Call Away

Kroll manages over 3,000 cyber investigations every year for clients of all sizes and complexities. We also have decades of experience helping clients notify customers affected by breaches. We can help you determine the right cyber risk retainer for you, beyond incident response. For peace of mind and support before and during an incident, speak with one of our cyber experts today.

Talk to a Cyber Expert

Kroll is ready to help, 24x7. Use the links on this page to explore our services further or speak to a Kroll expert today via our 24x7 cyber hotlines or our contact page.

Data Breach Outlook: Finance Surpasses Healthcare as Most Breached Industry in 2023

Data Breach Outlook 2024

In 2023 finance was the most breached industry, accounting for 27% of the breaches handled by Kroll, compared to 19% in 2022. Supply-chain risk was a constant menace, driven by the MOVEit Transfer vulnerability and a rise in social engineering.

Read our Data Breach Outlook report for more insights.

Download the Report

Frequently Asked Questions

An incident response retainer provides organizations with a structured form of expertise and support through a security partner, enabling them to respond quickly and effectively in the event of a cyber incident. Having an incident response retainer in place allows you to benefit from proactive support with protecting your operations, reputation and bottom line. Timely response and notification for cyber incidents is mandated by many privacy and consumer protection laws. Having a retainer in place also reduces the challenges of identifying expert support in the event of a major event which affects many organizations at the same time.

Data Collection and Preservation

Improve investigations and reduce your potential for litigation and fines with the strict chain-of-custody protocol our experts follow at every stage of the data collection process.

Computer Forensics

Kroll's computer forensics experts ensure that no digital evidence is overlooked and assist at any stage of an investigation or litigation, regardless of the number or location of data sources.

24x7 Incident Response

Kroll is the largest global IR provider with experienced responders who can handle the entire security incident lifecycle.

Office 365 Security, Forensics and Incident Response

Digital forensic experts investigate hundreds of Office 365 incidents per year and help strengthen your security.

Malware Analysis and Reverse Engineering

Kroll’s Malware Analysis and Reverse Engineering team draws from decades of private and public-sector experience, across all industries, to deliver actionable findings through in-depth technical analysis of benign and malicious code.

Malware and Advanced Persistent Threat Detection

Our expertise allows us to identify and analyze the scope and intent of advanced persistent threats to launch a targeted and effective response.

Business Email Compromise (BEC) Response and Investigation

In a business email compromise (BEC) attack, fast and decisive response can make a tremendous difference in limiting financial, reputational and litigation risk. With decades of experience investigating BEC scams across a variety of platforms and proprietary forensic tools, Kroll is your ultimate BEC response partner.

Digital Forensics Services

In the event of a security incident, Kroll’s digital forensics investigators can expertly help investigate and preserve data to help provide evidence and ensure business continuity.

Mobile Device Forensics

With a global mobile device forensics team and a proven track record in investigation and litigation support, Kroll enables key digital insights to be accessed quickly and securely.