Qantid
Class DRetainerRenews

Incident Response Retainer

A four-hour response commitment with a pre-agreed team, contract and access model, so the paperwork is done before the incident.

Fee & intake

Sign in to see the engagement fee (plus 7.5% VAT), complete the intake form, save a draft if you need to, then pay to submit.

Renews
Every 12 months

Regulatory and standards basis

This engagement is performed against the following instruments. Each is cited in the deliverable at the point it is relied on.

  • NIST SP 800-61 Rev. 2
  • CBN Risk-Based Cybersecurity Framework incident reporting requirements
  • Nigeria Data Protection Act 2023 breach notification requirements

Who this is for

  • Firms holding customer data or funds

What you receive

  1. 01Four-hour response commitment with named responders
  2. 02Annual incident response plan review and tabletop exercise
  3. 03Incident handling, containment and forensic support
  4. 04Regulatory notification support

How the engagement runs

  1. Phase 1

    Onboarding

    Appointment, regulator notification where required, and a handover of existing programme material.

  2. Phase 2

    Steady state

    The named role-holder discharges the function: reviews, decisions, filings and escalations.

  3. Phase 3

    Reporting

    Monthly management information and quarterly board reporting.

  4. Phase 4

    Review

    Annual programme review, with the engagement rolling on a 12-month term.

Questions

Who approves the deliverable?

A named member of the engagement team reviews it and a partner approves it. Their name, title and credentials are printed on the report, and the approval is recorded against the engagement in the portal.

What is the minimum term?

Twelve months, invoiced monthly in advance, or annually in advance where agreed at intake.

What happens next year?

The portal reminds you 90, 60 and 30 days before it is due, and you start a new version of this engagement pre-filled from the answers you gave last time. You update only what has changed, and you see a side-by-side of what changed before you submit.

Where do our documents live?

In private storage, accessible only through short-lived signed links, with every view and download logged. Nothing is attached to email. Our sub-processors and data residency are published on the trust page.

How do we pay?

By card through Stripe after you complete intake in the portal. You can save a draft without paying; submission happens only after payment succeeds.

Related engagements in Cybersecurity and Assurance

Business Continuity and Disaster Recovery Plan

Continuity and recovery planning built from a business impact analysis, with recovery objectives that reflect what your infrastructure can actually deliver.

CBN Risk-Based Cybersecurity Framework Assessment

An assessment against the CBN Risk-Based Cybersecurity Framework, producing the evidence base for your annual return.

Incident Response Plan and Playbooks

An incident response plan with scenario playbooks, written so an on-call engineer at 3am can follow it.