Listing Thumbnail

    Group-IB Service Retainer

     Info
    Sold by: Group-IB 
    The Group-IB Services Retainer provides organizations with SLA-backed incident response and flexible access to the full Group-IB cybersecurity services portfolio, from emergency incident response to long-term resilience building, under a single, prepaid agreement with set pricing.

    Overview

    Cyber resilience requires continuous effort. As threats evolve (now quicker than ever as a result of AI) and attack surfaces expand across cloud and hybrid environments, organizations need immediate response capability combined with structured long-term improvement.

    The Group-IB Services Retainer gives your organization instant access to the full range of Group-IB cybersecurity services within one flexible agreement. It preserves SLA-backed Incident Response while expanding the scope to include proactive assessments, investigations, consulting, and training.

    Incident Response Methodology Our Incident Response (IR) service is structured around several key phases: Preparation: Prior to any breach, the IR team establishes robust operational foundations, bespoke incident response playbooks, and forensic readiness to ensure a highly structured execution during crisis management.

    Detection and Analysis: The team analyses complex telemetry and log data to verify false positives and reconstruct the attack vector. This establishes the true scope of the compromise.

    Containment, Eradication, and Recovery: Operating as a specialist unit, the incident response team executes this iterative phase holistically to limit damage and restore operations securely.

    Containment and Forensics: The objective is to halt the proliferation of the threat without destroying volatile evidence. The team advises on or executes network isolation, quarantines affected endpoints, and implements Identity and Access Management restrictions, such as revoking compromised cloud credentials. Crucially, during this containment process, the team secures a strict chain of custody for digital evidence by capturing volatile memory dumps and forensic images prior to any remediation activities.

    Eradication: Utilising the secured forensic data, the incident response team performs reverse engineering of malware and conducts rigorous root-cause analyses to locate the initial point of ingress, ensuring the complete removal of the attacker's presence.

    Recovery: The IR validates the integrity of the client's backups to ensure they are devoid of sleeper malware before authorising a staged, secure restoration. The IR also implements heightened monitoring during the re-entry phase to detect potential reinfections.

    Post-Incident Activity: Following the resolution of the threat, the IR moderates post-mortem reviews. This phase is critical for feeding empirical data back into the preparation phase, refining playbooks, addressing procedural weaknesses, and updating security controls to prevent recurrence. Furthermore, the IR supports proactive 'peace-time' activities, such as tabletop exercises, to validate readiness and improve communication pathways.

    AWS Integration. The Group-IB Services Retainer is built to work across on-premises, hybrid, and cloud environments - and integrates seamlessly with AWS for organizations running workloads there. Our incident response practice leverages AWS CloudTrail for forensic analysis of API activity, enabling our team to reconstruct attack timelines and trace adversary actions. Group-IB experts take a flexible approach, combining the client's existing security controls with AWS-native capabilities where applicable.

    Services available as part of the retainer

    • Reactive services
    • Incident Response
    • Digital Forensics
    • High-Tech Crime Investigations
    • Compromise Assessment

    Proactive and assessment services

    • SOC Assessment
    • Cyber Fraud Assessment
    • Threat Landscape Development
    • Hunting Missions
    • Security Controls Gaps Assessment
    • Penetration Testing
    • Vulnerability Assessment
    • Tabletop Exercises
    • Incident Response Readiness Assessment
    • AI Red Teaming
    • Purple Teaming
    • Red Teaming

    Development and enablement services

    • SOC Development
    • Threat Intelligence Program Development
    • Building the Ultimate SOC Course
    • Management Masterclasses
    • Training for Technical Specialists
    • Awareness Masterclasses

    Why organizations choose the Group-IB Services Retainer SLA-backed Incident Response ensures immediate activation with no additional procurement steps Prepaid hours can be reallocated between urgent response and strategic initiatives throughout the year Fixed annual pricing increases budget predictability One agreement replaces fragmented vendor relationships and inconsistent service terms Every engagement is supported by Group-IB’s Threat Intelligence, Managed XDR, and Business Email Protection capabilities

    Highlights

    • More than 30 cybersecurity services under one agreement SLA-backed 24/7 incident response Senior specialists at your disposal across all cybersecurity domains
    • Flexible allocation of prepaid hours across reactive, ongoing, and proactive services Predictable annual budgeting with preferential rates for additional hours
    • Custom cybersecurity roadmap aligned with your goals, industry, and threat profile

    Details

    Sold by

    Delivery method

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Pricing

    Custom pricing options

    Pricing is based on your specific requirements and eligibility. To get a custom quote for your needs, request a private offer.

    How can we make this page better?

    Tell us how we can improve this page, or report an issue with this product.
    Tell us how we can improve this page, or report an issue with this product.

    Legal

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Support

    Vendor support

    Group-IB provides 24/7 global incident response support backed by SLA commitments. Customers receive direct access to senior cybersecurity specialists across all regions. Support is available via phone and email around the clock.

    Support contacts: APAC: +65 3159 4398 Europe:+31 20 226 90-90 MEA: +971 4 568 1785 Central Asia: +65 3159-3798 Latin America: +65 3159-3798
Email: response@cert-gib.com 

    Support includes: initial contact SLA, remote response SLA, and onsite response by request. Retainer customers receive priority queuing, a dedicated account team, and access to Group-IB's own SOC teams across all regions, with discounted rates for additional hours beyond the prepaid package.