Black Shard

Insights6 October 2026

What an incident response retainer should include in Australia

An incident response retainer is a contract signed before an incident that fixes who responds, how fast, with what access and under whose authority. In Australia it also has to fit the Notifiable Data Breaches scheme's 30-day assessment window, the 72-hour ransomware payment report under the Cyber Security Act 2024, the organisation's cyber insurance policy and any panel it names, and the legal privilege question. A retainer that settles those points in advance lets responders start work in the first hour, with terms, access and authority already agreed.

What is an incident response retainer?

An incident response retainer is an agreement with a response firm, signed before anything goes wrong, that sets out how the firm responds when an incident is declared. It fixes the contact path, the response time, the scope of work, the access the responders will need, the rates, and who on the client side can authorise containment. Without one, the first hours of an incident go on finding a firm, agreeing terms, getting a purchase order approved and granting access.

Retainers come in two broad shapes. A zero-dollar or standby retainer sets terms and rates in advance and is paid only when used. A prepaid retainer buys a block of hours, with any unused hours often convertible into readiness work such as a tabletop exercise or a plan review. Either can work. What matters is that the terms are agreed and the access is ready before the call.

What happens during an incident response engagement?

The work follows the same sequence whatever the incident. Triage establishes what happened and how far it reached. Containment stops the spread: accounts disabled, sessions revoked, hosts isolated, firewall rules changed. Evidence is preserved before anything is wiped. Investigation traces the intrusion to its entry point and maps what the attacker touched. Eradication and recovery remove the foothold and bring systems back, rebuilt or restored from clean backups. Close-out confirms the entry point is closed and records what changed.

Running alongside the technical work are decisions only the client can make: whether to take a system offline, whether personal information is involved, when to notify, what to tell staff and customers. A retainer cannot make those decisions. It can name who makes them, so the responders are not waiting for an answer while the attacker keeps working.

Which Australian obligations does the retainer have to fit?

Three reporting regimes set the clock for most Australian organisations. The responders' first findings feed each of them, so the retainer has to produce facts fast enough for the client and its lawyers to meet them.

ObligationWho it applies toThe clock
Notifiable Data Breaches scheme, Privacy Act 1988APP entities, including most businesses with annual turnover above $3 million and all health service providersAssess a suspected eligible data breach within 30 days, then notify the OAIC and affected individuals as soon as practicable if serious harm is likely
Ransomware payment reporting, Cyber Security Act 2024Businesses with annual turnover above $3 million, and critical infrastructure responsible entitiesReport a ransomware or cyber extortion payment to ASD within 72 hours of making it, or of becoming aware it was made
SOCI Act cyber incident reportingResponsible entities for critical infrastructure assets12 hours for a critical incident with a significant impact, 72 hours for an incident with a relevant impact

Reporting obligations an Australian incident response has to support

How fast should responders start?

Response time clauses vary in what they measure. An acknowledgement within an hour is different from a responder working on the problem within four, and a commitment to be on site within a day is different again. The retainer should state the time to first contact with a named responder, the time to active remote triage, and whether on-site attendance is offered and in which cities.

Remote response covers most of the work in a cloud-heavy environment, provided access has been arranged in advance. That means a break-glass path for the responders into Entra ID and the endpoint platform, agreed roles, and a record of who approved it. Access left to be arranged on the day adds hours before responders can start.

What does the insurer need from the retainer?

Most cyber policies sold in Australia include incident response costs, and many require the insured to use a firm on the insurer's panel or to get the insurer's consent before appointing one. A retainer with a firm outside the panel can still be the right choice, provided the policy allows it and the insurer has agreed in writing before an incident. Finding the conflict during an incident costs time and can cost cover.

The retainer should state which party notifies the insurer and when. Most policies require prompt notice of a suspected incident, and the insurer's breach coach, usually a law firm, will want to direct the response from early on.

Should the response be engaged through lawyers?

Organisations often engage incident responders through their lawyers so the forensic report attracts legal professional privilege. The Federal Court decision in the Optus data breach litigation in 2023 found that a forensic report commissioned after the breach was not privileged, because it had been commissioned for several purposes and its dominant purpose was not legal advice.

The lesson for a retainer is structural: if privilege matters, the engagement letter, the instructions and the reporting lines have to show the work is done for the purpose of legal advice, and operational remediation reporting is kept separate.

The retainer should allow for that structure from the start. That means a tripartite engagement option with the client's lawyers, a clear split between privileged investigation findings and the operational remediation record, and a communications channel that does not run through the compromised mail system.

What should a retainer include?

A workable retainer answers the questions the first hour will ask, and leaves nothing that needs a signature on the day.

  • A 24-hour contact path that does not depend on the client's own email or phone system working.
  • Response times stated as time to first contact, time to active triage, and on-site attendance where offered.
  • Named client decision-makers with authority to approve containment, including taking systems offline.
  • Pre-arranged access: responder accounts or a documented break-glass path into Entra ID, endpoint tooling and logging.
  • Rates, any prepaid hours, and what unused hours convert into.
  • Insurer panel position and written consent where the firm sits outside the panel.
  • An engagement structure that supports legal professional privilege when the client's lawyers need it.
  • Evidence handling: what is collected, how it is stored, how long it is kept, and who can access it.
  • A readiness component: a plan review or tabletop exercise each year so the retainer is tested before it is used.

What drives the cost of a retainer?

Retainer pricing follows a few variables. The size and complexity of the environment sets how much work a typical incident involves. The response commitment sets how much capacity the firm has to hold for the client: a four-hour remote start costs less to guarantee than a same-day on-site presence in a regional city. Prepaid hours lower the hourly rate and carry a commitment. Readiness work bundled into the retainer, such as an annual tabletop or plan review, adds to the fixed component and reduces the time an incident takes.

The comparison that matters is with the cost of the first day without one. Finding a firm, negotiating terms, waiting for internal approval and arranging access can take a business day, and in that day the attacker keeps working. Insurers know this, and some policies reward a pre-arranged response capability at renewal.

How do you test a retainer before you need it?

Run the call. A tabletop exercise that starts with a real phone call or message to the retainer's contact path, at an awkward hour, tests the response time, the decision-makers' availability and the access arrangements together. It usually finds an expired mobile number, a responder account that was disabled in a clean-up, or a decision-maker who did not know they were named.

Check the access paths quarterly. Responder accounts and break-glass credentials should be tested on the same schedule as the organisation's own emergency access accounts, and the test recorded. A retainer whose access path has not been exercised for a year will fail on the day it is needed.

Where does readiness work fit?

A retainer works best for an organisation that has already done the groundwork. An incident response plan with named roles, logs retained long enough to investigate, backups that have been restored in a test, and an asset list the responders can trust all shorten the incident. A tabletop exercise each year tests the plan and the retainer together, and usually finds the contact list is out of date.

Black Shard runs incident response for Australian organisations: containment and triage, root-cause analysis, remediation of the flaw behind the incident, a re-test before close-out, and a factual incident record to support the Notifiable Data Breaches assessment. Incident readiness, covering the plan, the tabletop and a verified restore, runs on its own or inside a vCISO engagement. Terms and access are set up on a free 30-minute scoping call.

Tell us what you have found.

Brisbane head office.

Open a briefinfo@blackshard.com.au