Incident Response Retainer
When the SOC escalates, we take the wheel.
An L4 incident-response capability that activates the moment your SOC declares a major incident. Response hours are agreed and purchased upfront, then drawn down when you need them — coordinated, communications-led, and run in a dedicated Microsoft Teams war room. Available only as an add-on for HexaShield managed SOC (IT & OT) customers.
An add-on for managed SOC customers only
This retainer extends HexaSOC for IT and OT estates. It is not sold separately — your environment must already be monitored by our managed SOC, so responders arrive with full context and telemetry, never a cold start.
Powered by HexaSOC™. Every action and update is one truth in HexaView™.
From SOC L3 to L4 incident response
Your SOC runs continuously across three tiers. When an event becomes a major incident that exceeds day-to-day operations, it crosses a line into L4 — the incident-response retainer. Beyond IR sits digital forensics, a specialist discipline we deliberately leave to a dedicated DFIR provider.
Incident Response
Named responders activate and take the wheel — drawing on your banked hours.
Digital Forensics
Specialist · not HexaShield
You retain a dedicated DFIR firm; we coordinate a clean handoff.Response time, banked in advance
You buy a block of incident-response time upfront — a set number of hours or days. When an incident is declared, responders draw from that block. It is topped up on renewal, and time you do not spend on incidents is never wasted.
- Predictable, agreed costNo emergency day-rates negotiated mid-crisis — the commercials are settled before anything happens.
- No cold startBecause we already run your SOC, the clock starts on response, not on onboarding and access.
- Unused hours build readinessQuiet quarter? Spend the block on tabletop exercises, playbook development and IR readiness reviews.
A calm, coordinated response — communication at every step
A walk-through of how we run an incident. The phases move fast, but the constant throughout is communication: everyone who needs to know, knows, at every stage.
- 01
Declare & mobilise
The SOC escalates the major incident; an Incident Commander is assigned and a Teams war room is opened within minutes.
- 02
Triage & scope
Confirm, classify severity and scope the blast radius across IT and OT, using full context from your managed SOC.
- 03
Contain
Isolate affected systems with guard-railed, OT-safe actions to stop the spread without breaking operations.
- 04
Eradicate
Remove attacker access and close the entry vector, verifying nothing is left behind.
- 05
Recover
Restore services safely, validate integrity and watch closely for any sign of reinfection.
- 06
Review & harden
A clear post-incident report, lessons learned, and new detections fed straight back into your SOC.
A steady cadence of updates to executives, legal, insurers and regulators, plus your technical team — owned by a dedicated Communications Lead so responders can stay on the response.
Your incident war room, in Microsoft Teams
The moment an incident is declared, we open a dedicated Microsoft Teams war room — the single source of truth for the whole response. Everyone who needs to be in the room is in the room.
- A dedicated channel per incident — opened automatically on declaration.
- Clear roles and a single line of authority, agreed in advance.
- A live decision and action log — who decided what, and when.
- Exec, legal and regulator updates from one place, on cadence.
- Actions and evidence linked back to HexaView™ for the record.
- Secure and access-controlled — only the room, in the room.
The response team
An incident is run by people, not tickets. These are the roles we bring — and the ones we agree on your side — so authority and communication are never in doubt.
Incident Commander
Owns the incident end to end: decisions, priorities, cadence and the single line of authority.
Lead Responder
Runs the technical response — triage, containment, eradication and recovery on the ground.
SOC L3 Analysts
The same analysts already watching your estate, now surging on the incident with full context.
OT Response Specialist
Brought in for OT incidents to keep containment safe for systems that cannot simply be switched off.
Communications Lead
Keeps executives, legal and regulators informed with the right message at the right moment.
Your Named Liaison
Your side of the bridge — the people we agree in advance who can authorise and unblock.
What the retainer gives you
- Priority access with agreed response SLAs
- A named Incident Commander for every incident
- Response hours banked upfront, drawn down on demand
- OT-safe containment across IT and OT estates
- A Microsoft Teams war room, opened on declaration
- Communications managed across execs, legal and regulators
- Full context from minute one — no cold start
- Post-incident report with lessons fed back to your SOC
- Unused hours convert to proactive IR readiness
Where our IR ends and DFIR begins
We are deliberately clear about scope. We run incident response; we do not provide digital forensics. Knowing the line in advance is what keeps a real incident clean.
- Escalation from your managed SOC (L3 to L4)
- Triage, severity classification and scoping
- OT-safe containment and eradication
- Safe recovery and reinfection watch
- Incident coordination and the Teams war room
- Executive, legal and regulator communications
- Post-incident report and hardening actions
- Court-admissible forensic acquisition & imaging
- Formal chain of custody for litigation or law enforcement
- Expert-witness testimony and legal reporting
- Deep malware reverse-engineering as legal evidence
- Long-term evidence preservation and disclosure
We don’t provide digital forensics. If an incident needs it, you engage a specialist DFIR retainer and we coordinate a clean handoff — preserving what we can along the way.
Add a retainer to your managed SOC
Already a HexaSOC customer? Let’s size the right block of response hours and put the war room, roles and playbooks in place — before the bad day.