Appearance
Incident Response Retainer Evaluation
Purpose
HIPAA 164.308(a)(6) and SOC2 CC7.4 both expect a pre-arranged path to specialist incident-response resources. Cirius already has Arctic Wolf MDR delivering 24×7 monitoring and a baseline level of managed incident response. This document evaluates whether we need a dedicated IR retainer on top of Arctic Wolf and, if so, which vendor.
Related story: IRRET-003. Related project: IRRET (Incident Response Retainer). Related docs: compliance/ir-tabletop-coordination.md, runbooks/incident-response.md.
Where We Are Today
- Arctic Wolf MDR — agent on all managed devices, full read/triage/respond rights in Azure (both tenants) and AWS, full read on M365. They can act first without approval for defined playbooks (account lock, host isolation, block malicious IOCs). They include a concierge security team with an on-call path and written runbooks for ransomware and BEC scenarios.
- Internal IR capability — Rory as the only security-staffed person; Kevin and Greg as escalation for T1 domain admin operations during recovery.
- Tooling — Cortex XDR (endpoint), Velociraptor (forensic triage), Palo Alto + Panorama (network), Veeam + Azure Recovery Services Vault + AWS Backup + offline kit (recovery).
What Arctic Wolf covers: Detection, initial response, containment, guided remediation, tactical threat hunting, and support during active incidents. They are the "first 4 hours" team.
What Arctic Wolf does not cover (typical scope gaps for MDRs):
- Deep forensics with legally-admissible chain of custody (breach investigations, ransomware negotiation support, criminal referral)
- HIPAA breach notification drafting and counsel coordination
- Prolonged (multi-week) forensic engagement on complex incidents
- Ransomware payment / cryptocurrency negotiation (an MDR will not touch this)
- Litigation support and expert testimony
A dedicated IR retainer exists to fill those gaps. The question is whether we buy one now or wait until we have a concrete trigger.
Candidates (≈$10–25k/year range for a 20-person HIPAA org)
1. CrowdStrike Services (Falcon OverWatch + Services Retainer)
- Response SLA: 1 hour from declared incident to first Falcon analyst on a bridge, 24×7. Flat-rate prepaid hours with a rollover window.
- Ransomware expertise: Excellent. CrowdStrike handles a very large share of named ransomware incidents publicly; their intel on TTPs is first-tier.
- HIPAA breach notification support: They will work with our counsel on the forensic narrative. They do not draft the notification itself — counsel does — but their forensic report is directly usable as the factual basis.
- Tooling fit: Requires deploying their Falcon agent for the engagement (or paying higher rates if they have to work with our existing EDR). Mixing Falcon with our existing Cortex XDR during an active incident is friction we want to avoid.
- Cost: Retainer entry point ~$20–30k/year for a small prepaid hour block (~40 hours). Additional hours at standard rates. Higher than the target band.
- Fit for 20-person HIPAA org: Over-scoped and expensive unless we switch endpoint platforms to Falcon. Not recommended while Cortex XDR is our EDR.
2. Secureworks Incident Response Retainer
- Response SLA: 1 hour to first analyst, 24×7. Prepaid hours model similar to CrowdStrike.
- Ransomware expertise: Strong. Secureworks has long-standing ransomware negotiation and recovery expertise. Their Counter Threat Unit intel is respected.
- HIPAA breach notification support: They provide forensic narrative and will work with our counsel. They also have established healthcare-sector engagements.
- Tooling fit: Agnostic — they will work with Cortex XDR and Velociraptor rather than forcing a tool change for the engagement.
- Cost: Retainer entry point ~$15–25k/year for 40 prepaid hours.
- Fit for 20-person HIPAA org: Workable. The tooling-agnostic approach is attractive. Upper bound of the target band.
3. Coveware (ransomware-specialist retainer)
- Response SLA: Same-business-day engagement for ransomware. Not positioned as a general IR retainer — they are narrow and deep on ransomware negotiation, recovery, and decryption.
- Ransomware expertise: Category leader in ransomware negotiation, decryption-key sourcing, and quarterly ransomware intelligence reporting.
- HIPAA breach notification support: Indirect — they handle the ransomware event and provide data-access forensics; counsel handles the notification.
- Tooling fit: Agnostic; they focus on the ransomware event scope.
- Cost: Coveware sells primarily hourly engagement, typically $10–15k for a standard ransomware engagement. Retainer pricing is lower (~$5–10k/year) but hours are modest.
- Fit for 20-person HIPAA org: Useful as a narrow supplement but does not replace a general IR retainer. Best paired with a general retainer, not standalone.
4. Arctic Wolf IR Jumpstart (our existing MDR's IR arm)
- Response SLA: Arctic Wolf's existing concierge SLA applies (time-to-eyes 15 minutes, time-to-response SLA per contract); IR Jumpstart engagement is their hand-off to a dedicated IR team.
- Ransomware expertise: Good. Built on top of Tetra Defense (acquired by Arctic Wolf) which has material ransomware-response history.
- HIPAA breach notification support: Yes, with healthcare-sector familiarity.
- Tooling fit: Native — they are already in our environment with authorization, agent, and visibility. No onboarding during an incident.
- Cost: Retainer add-on ~$10–15k/year on top of MDR. Lowest friction.
- Fit for 20-person HIPAA org: Best bang-for-buck if we decide we need a dedicated retainer now, because the Arctic Wolf team already knows our environment.
Comparison
| Criterion | CrowdStrike | Secureworks | Coveware | Arctic Wolf IR |
|---|---|---|---|---|
| Response SLA | 1 hr | 1 hr | Same day (ransom) | Native MDR SLA |
| Ransomware expertise | Excellent | Strong | Category leader | Good |
| HIPAA breach support | Strong | Strong | Indirect | Strong |
| Tooling fit (we run Cortex XDR) | Requires Falcon | Agnostic | Agnostic | Native |
| Time-to-value in our env | Onboarding delay | Onboarding delay | Narrow scope | Zero |
| Cost / yr | $20–30k | $15–25k | $5–10k | $10–15k |
| Fit for 20-person HIPAA SMB | Over-scoped | Good fit | Supplement only | Best fit |
Recommendation
Do not buy a separate dedicated IR retainer yet. Instead:
- Formalize the Arctic Wolf escalation path as our first-line IR retainer. Meet with our Arctic Wolf concierge TAM to confirm: who we call at 2am on a Sunday, what the expected initial response time is, what triggers Arctic Wolf's own IR handoff, and what documentation they produce that our counsel can use.
- Exercise the path in the Q2 2026 tabletop (see
compliance/ir-tabletop-coordination.md). Invite the Arctic Wolf concierge as observer — the tabletop is the time to find the gaps in our escalation path before a real incident finds them. - Identify Coveware as the pre-cleared ransomware specialist. Have their engagement letter reviewed by counsel now, so that in a ransomware scenario the legal paperwork is ready to sign and does not block engagement in the first 48 hours.
- Revisit the dedicated retainer decision after the tabletop. If the tabletop exposes material gaps in what Arctic Wolf can cover for us, re-scope this evaluation with the concrete gap list and make a second pass — most likely Arctic Wolf IR Jumpstart (native fit, lowest friction) would be the winner in that scenario, with Secureworks as the tool-agnostic alternative.
Why this recommendation:
- A 20-person org with Arctic Wolf MDR already has more baseline IR coverage than most SMBs
- Buying a second retainer before we know what gaps exist wastes $15–25k/year of budget that could fund KnowBe4 + a FIDO2 hardware rollout + Coveware pre-clearance together
- Tooling friction during an incident is a real risk — bringing in a CrowdStrike or Secureworks team that is not already in our environment adds hours of onboarding at exactly the wrong moment
- The Q2 tabletop is the right forcing function to decide; do not decide in isolation
Budget we are holding back: If we decided to buy, the planning number is ~$12k/year for Arctic Wolf IR add-on, or ~$20k/year for Secureworks. Keep this in the FY27 budget placeholder as a conditional line item.
SOC2 / HIPAA Mapping
- HIPAA 164.308(a)(6) — security incident procedures (pre-arranged specialist path)
- HIPAA 164.308(b)(1) — business associate contracts (IR retainer is a BAA vendor when engaged)
- SOC2 CC7.3 — identification and analysis of security events
- SOC2 CC7.4 — incident response plan and support