Get 24/7 incident response assistance from our global team
- APAC: +65 3159 4398
- EU & NA: +31 20 890 55 59
- MEA: +971 4 540 6400
- LATAM: +56 2 275 473 79
Get 24/7 incident response assistance from our global team
Please review the following rules before submitting your application:
1. Our main objective is to foster a community of like-minded individuals dedicated to combatting cybercrime and who have never engaged in Blackhat activities.
2. All applications must include research or a research draft. You can find content criteria in the blog. Please provide a link to your research or research draft using the form below.
Call on Group-IB experts to address complex cybersecurity incidents and accelerate recovery so you can get back to business sooner.
An Incident Response Retainer gives you on-demand access to DFIR specialists when you need expert assistance. Guided by extensive threat intelligence and forensic evidence, we work alongside your team to respond to active threats and minimize the impact of an attack.




Group-IB offers Incident Response Retainer agreements tailored to various budgets and cybersecurity needs. Your agreement outlines SLA windows, activation procedures, and the allocation of prepaid hours for both proactive and reactive services to complement your organization’s existing capabilities.
Distributed team across the world is created to provide our clients with a tailored and prompt Incident Response
Contact Group-IB IR team to discuss a tailored retainer subscription that best fits your business needs.
One single agreement which gives you flexible access to a comprehensive suite of proactive and emergency services, including incident response, digital forensics, threat assessments, training, and strategic consulting.
It is possible to decrypt files after a ransomware attack in rare cases only. Usually, if there are no backups it is impossible to recover the data.
We need a signed 3-way NDA (non-disclosure agreement between you, us and the partner) and issued PO (purchase order) or service engagement letter.
Pricing is based on included hours and the specialists required for the engagement, with defined terms for additional time. Retainer structures may also allow unused hours to be applied to approved proactive cybersecurity services.
We expect our clients to perform following actions:
Our Incident Response team leverages an in-house solution – Group-IB Managed XDR, which enables advanced protection, rapid collection of forensic data and containment of compromised hosts, as well as 24/7 monitoring and notification supported by CERT-GIB.
We install EDR agents and for two weeks after responding to the incident, the CERT-GIB team will monitor the infrastructure so your IT team has time to implement our recommendations.
While the incident is going, you will be supported by our account manager. Depending on the type of incident, we will allocate not only incident responder, but digital forensics specialist, malware analyst and a cyber threat intelligence specialist.
On average, there are 2 DFIR specialists allocated for each incident. Depends on a complexity of the incident could be up to 5 specialists.
You can activate a response instantly through your pre-approved escalation channel. We move the legal and procurement steps to the beginning of our partnership so that during a real attack, our only focus is on minimizing your downtime.
Response time targets are defined in the retainer terms and depend on factors such as region, time zone, and whether on-site support is required. The onboarding phase confirms the activation process, so your team is not improvising under pressure.
If you aren’t dealing with an active threat, you can use those hours to improve your readiness with cybersecurity services like simulated attack drills, security assessments, and staff training.