When Should You Call an Outside Incident Response Firm?
Call an outside incident response firm the moment any one of five things is true: an attacker holds domain admin (or equivalent cloud-tenant) privileges, you've found data staged for exfiltration, your backups have been deleted or encrypted, regulated data is plausibly in scope, or someone is demanding money. Any single trigger is enough. You don't need certainty, and waiting for certainty is how a contained intrusion turns into a reportable breach.
There's a second answer hiding inside the first, and it's the one most vendors leave off the pricing page: you shouldn't make the call yourself. Your outside counsel should engage the forensics firm, so the investigation sits under attorney-client privilege. Get that order wrong and there is no undo button.
Key takeaways
- Any one of five triggers is enough: an attacker with domain admin or equivalent cloud-tenant privileges, data staged for exfiltration, backups deleted or encrypted, regulated data plausibly in scope, or extortion in any form.
- You do not need certainty. Waiting for certainty is how a contained intrusion turns into a reportable breach.
- Outside counsel should engage the forensics firm, under a new incident-specific engagement letter, so the investigation has a credible claim to attorney work-product protection. That sequencing cannot be undone later.
- Your carrier has probably already narrowed the choice through a panel or a consent requirement. Read the policy for the notice deadline, the breach hotline and the panel language now.
- The first hour still belongs to your in-house team: isolate at the network layer without powering off, snapshot cloud volumes, export logs before retention rolls them, and move communications out of band.
The five triggers, one at a time
1. Domain admin compromise
Once an attacker holds Domain Admin in Active Directory, Global Administrator in Entra ID, or organization-level rights in your cloud accounts, you can no longer trust your own telemetry. They can read the tickets you file about them and sit in your Slack war room. Investigating an adversary who controls the environment you're investigating from is a losing game. You need responders working from clean infrastructure with their own tooling, and you need out-of-band communications immediately.
2. Data staged for exfiltration
Multi-part RAR archives sitting in ProgramData, gigabytes of database exports parked on one server, a burst of outbound traffic to a file-sharing service nobody's heard of. Staging means the attacker was preparing to take data out and may already have. At that point the central question stops being technical and becomes legal: what exactly left, when, and does it trigger notification obligations? Answering that defensibly requires evidence handling that stands up to a regulator or a plaintiff's expert, not a best-effort log review.
3. Backups touched
An attacker who deletes your snapshots, kills backup jobs, or encrypts the backup repository is not browsing. That's the standard precursor to ransomware detonation, which means you may be hours away from encryption across the whole estate. Of the five triggers, this is the one where speed matters most.
4. Regulated data in scope
If PHI, cardholder data, CUI, or the personal data of EU or California residents might sit in the compromised environment, the investigation's output becomes a legal record. HIPAA breach risk assessments, state attorney general notifications, contractual disclosure clauses to enterprise customers: each one gets scrutinized later by someone motivated to find gaps. You want that record built by people who have written hundreds of them.
5. Extortion, in any form
Ransom notes, "pay or we publish" emails, a stranger on a Tox chat with samples of your data. Negotiation is a genuine specialty, and so is checking whether the threat actor is subject to OFAC sanctions, because paying a designated entity is its own federal problem. Don't learn either skill live.
What is not on the list
Notice what's not on the list: a phishing click your mail filter caught, commodity malware that EDR quarantined on one laptop, a lost phone with verified encryption and remote wipe. Those are Tuesday. Handle them in-house, document them, and move on.
Counsel engages the firm. Not you, not IT.
This is the sequencing point that decides whether your forensic report ends up as protected work product or as Exhibit A, and it's the part of incident response that IR vendors consistently underplay because it's not their contract to fix.
The logic is simple. When outside counsel retains the forensics firm, directs its work, and receives its findings for the purpose of giving you legal advice, the investigation has a credible claim to attorney work-product protection. When your IT director signs the engagement letter, or the work runs under a pre-existing services agreement, that claim gets much weaker. In the Capital One breach litigation (In re Capital One Customer Data Security Breach Litigation, No. 1:19-md-02915, E.D. Va.), the court granted in part the plaintiffs' motion to compel production of the Mandiant forensic report in May 2020 and overruled Capital One's objections that June.
Here's the sequence we walk clients through, and it fits on an index card:
1. On any qualifying trigger, notify your cyber insurance carrier (watch the notice deadline in your policy) and call outside breach counsel. Both calls happen before any vendor is hired.
2. Counsel retains the forensics firm under a new, incident-specific engagement letter that states the work is directed by counsel to inform legal advice. Not your existing pentest MSA. A fresh contract.
3. Findings flow to counsel first. Distribution stays controlled. If operations needs a working remediation document, counsel can authorize a separate factual track for that purpose.
Two caveats, because honesty beats marketing. Privilege is never automatic; courts look at substance, and a report that gets emailed to the whole company or attached to a board deck can lose protection regardless of who signed the engagement. And the protection question cuts the other way too: if we're already your penetration testing vendor under a standing agreement, that existing relationship is precisely the thing that sank Capital One's privilege claim. A good firm will tell you that and paper the incident separately. A firm that offers to "just add forensics to the current SOW" is doing you quiet, permanent damage.
The irreversibility is the point worth repeating. You can upgrade your tooling mid-incident. You can swap vendors mid-incident. You cannot go back and re-form the engagement that already happened.
Your insurer already narrowed your options
Most cyber policies don't let you hire whoever you want. Carriers maintain panels of approved breach counsel and forensics firms, and using an off-panel vendor without prior approval can reduce or void reimbursement. Some carriers publish an approved vendor list and will pre-approve a preferred firm before any incident occurs; others handle it as a consent requirement at the time of the claim. Your policy and your broker are the only reliable answer for your own carrier.
Either way, the moment to sort this out is now, not at 2 a.m. on the day. Read the policy and find three things: the notice deadline (some policies want notice within days, others "as soon as practicable"), the breach hotline number, and the panel or consent language. If you already have an IR firm you trust, ask your broker to get them listed or pre-approved this quarter.
One genuinely helpful side effect: the carrier's breach hotline usually routes you to panel breach counsel first, and counsel then engages forensics. The insurance workflow enforces the correct privilege sequencing almost by accident. Use it.
What your in-house team can and should own
Calling an outside firm doesn't mean your team stands down. The first hour belongs to you, and what you do with it determines what the responders have to work with.
In-house teams should own: isolating affected machines at the network level (don't power them off; memory is evidence), snapshotting cloud volumes, exporting logs before retention windows roll them over, disabling suspect accounts, starting a written timeline kept somewhere off the affected environment, and moving incident communications to out-of-band channels. Every one of those is documented in a decent incident response plan, which is why the plan gets written and rehearsed in peacetime.
Equally important is what not to do: don't reimage anything, don't mass-reset passwords before scoping (it tips off the attacker and can destroy your visibility into which accounts they hold), and don't discuss the incident over email on a tenant the attacker may be reading.
And a concession, since it's true: if you run a mature internal SOC with dedicated forensics staff and breach counsel already on retainer, you may only need an outside firm for surge capacity or an independent second opinion for the board. That's a fine reason to keep a light retainer and nothing more. Not everyone needs to buy the full engagement, and anyone who tells you otherwise is selling.
Assume a third party is in the blast radius
The 2026 Verizon DBIR found third-party involvement in 48% of breaches, up 60% from the prior year. In practice that means your incident often isn't entirely yours: the initial access came through an MSP's remote-management tool, a SaaS vendor's compromised integration, or a contractor's stolen credentials.
This has a direct bearing on who investigates. If your managed service provider's credentials are a plausible vector, the MSP cannot be the party scoping the intrusion; they'd be grading their own homework, with their contract renewal riding on the answer. An outside IR firm with no stake in any of your IT vendors is the only party in the room whose findings you can hand to a regulator without a conflict disclosure.
Do this on a calm Tuesday
Everything above compresses into four preparation steps:
- Pick outside breach counsel before you need them.
- Confirm your carrier's panel and notice requirements.
- Put an incident response firm under retainer with the engagement structure pre-blessed by counsel.
- Tabletop the whole sequence once a year so the first real call isn't the first call ever.
As of August 2026, with the global average breach at $4.99M and US breach costs averaging $11.5M per IBM's Cost of a Data Breach 2026 (vendor-published figures, but directionally right in our experience), the retainer is a rounding error against the downside. If nobody in your organization owns that checklist, that's a gap a vCISO closes in the first month.
Frequently asked questions
What does an outside IR engagement cost in the first 48 hours?
As of August 2026, in our experience, a non-retainer emergency engagement means senior responder rates somewhere in the $400 to $700 per hour range plus a minimum commitment. That is meaningfully below the $800 to $1,500 per hour that incidentcost.com publishes for cold emergency engagements, and the gap is worth naming rather than hiding: the survey aggregates the whole market, including the largest national firms and true middle-of-the-night cold calls, while our figure reflects the mid-market engagements we actually scope. Both are real; budget against the published ceiling and be pleasantly surprised. A mid-market intrusion typically runs $25,000 to $75,000 in the first week, more if ransomware negotiation is involved. Retainer clients usually draw against prepaid hours at better rates with a guaranteed response SLA. If your cyber policy applies and you followed the panel and notice requirements, the carrier reimburses most of it, which is exactly why the policy reading belongs on this week's calendar.
Will our MSP handle the incident for us?
Mostly no, and you shouldn't want them to. MSPs are operations shops: excellent at executing containment steps under direction, but they generally lack forensic tooling, evidence-handling discipline, and any privilege structure. There's also the conflict problem: with third parties involved in 48% of breaches per the 2026 DBIR, your MSP's own access is itself a candidate vector, and they can't objectively investigate themselves. Keep them in the room as hands, not as the investigator.
Related Services
Need help with your compliance program?
Our team of senior practitioners can help you navigate complex compliance requirements and build a security program that holds up under scrutiny.
Schedule a Free ConsultationGet insights like this in your inbox
Practical compliance and security guidance for teams preparing for their next audit. No spam, unsubscribe anytime.
Ask to be added to our mailing list for practical compliance and security guidance. We add you by hand, we confirm before sending anything, and we never share your address.