Incident Response and DFIR
Incident response (IR) is the emergency-response function of cybersecurity: containment, forensics, and recovery after a breach. According to Unit 42's 2026 Global Incident Response Report, attacks are now ~4× faster than in prior years, with data exfiltration in under an hour in some cases (Palo Alto/Unit 42). As the window from intrusion to exfiltration falls below the time it takes to dispatch a human IR team, retained, telemetry-connected, increasingly automated response becomes the model that works — a central reason the most valuable IR capability has been absorbed into product platforms rather than left in standalone firms.
What IR/DFIR is, and how the money works
Incident response is the emergency room of cybersecurity: when an organization is breached, the IR firm contains the attacker, performs digital forensics (DFIR — reconstructing what happened, what was taken, and how), eradicates the foothold, restores operations, and produces the report that satisfies regulators, insurers, and litigators. It is distinct from the always-on monitoring of MDR: IR is episodic and adversarial, triggered by a breach, often under legal privilege and on a clock measured in hours.
The economics run on three revenue forms, each capturing value differently:
- Emergency / time-and-materials engagements — the breach call. High day-rates ($400–600+/hr for senior responders), unpredictable timing, lumpy revenue. Profitable per-hour but un-bankable as recurring revenue.
- IR retainers — the annuity. Organizations pre-pay for guaranteed response SLAs ("we will be on-site / online within N hours"). This is the part insurers and boards demand, and the part that carries a recurring-revenue multiple. The retainer is the strategic prize: it converts an emergency service into a subscription and creates a standing relationship that pulls through MDR, assessments, and product.
- Insurance-panel work — cyber insurers maintain panels of approved IR/forensics/legal vendors (see Cyber Insurance). Being on the panel is a distribution channel: it routes a steady flow of breach work to the firm, but compresses rates because the insurer negotiates them. The breach-coach attorney (the privileged quarterback of a breach) often selects the IR firm — so legal relationships are a core go-to-market.
For M&A, the standalone IR firm is structurally a feature, not a platform. Its forensic depth is a magnet for relationships, but the recurring revenue and the telemetry both live elsewhere — in the EDR/SIEM product the responders use and in the MDR contract the breach converts into. That is why IR has been captured by platforms more than any other services segment.
The named-player map (four archetypes)
| Archetype | Players | What they bring | Value capture |
|---|---|---|---|
| Platform-owned IR | Mandiant (Google), Unit 42 (Palo Alto), CrowdStrike Services, Microsoft DART, Cisco Talos IR, Secureworks (Sophos) | Forensic brand + their own EDR/telemetry; IR feeds product pull-through | Highest — IR converts to product + MDR ARR |
| Independent specialists | Sygnia, Coveware (ransomware/negotiation; Veeam-owned), Arete, Tidal Cyber, Surefire, GroupSense | Vendor-neutral depth, speed, ransomware negotiation | Reputation + insurance-panel flow; prime tuck-in targets |
| Advisory/IB-owned | Kroll, Stroz Friedberg (Aon→LevelBlue), FTI, Booz Allen | Litigation/regulatory/financial credibility; breach-coach ties | Project + retainer; bolts onto risk-advisory |
| Big Four / SI | Deloitte, PwC, EY, KPMG, Accenture, IBM X-Force | Scale, global reach, board access | Pull-through to remediation programs (04d) |
The differentiation that matters: Mandiant is the brand for nation-state and the most complex breaches; CrowdStrike and Unit 42 win on tech-integration and speed because they respond inside their own telemetry; Sygnia competes on raw speed; Coveware owns ransomware negotiation as a niche so deep it scores like a full-scope firm. When Google bought Mandiant (2022) and Palo Alto built Unit 42, the logic was identical: own the forensic relationship at the moment of maximum customer trust, and convert it into platform commitment. A breach is the single best cross-sell event in security, and the platforms have bought their way to the front of it.
Why speed compresses the human model
As the exfiltration window collapses toward an hour, after-the-fact forensics loses value relative to real-time, automated containment. That re-rating flows directly into the agentic SOC: the same AI agents that triage alerts are being pointed at the first minutes of an incident — auto-isolating hosts, pulling forensic timelines, and drafting the breach narrative — compressing the junior-responder work that filled IR engagement hours. Human responders move up the stack to incident command, attribution, negotiation, and the regulatory/litigation interface, where judgment is irreplaceable and rates stay high. The standalone IR firm whose margin depended on billable forensic analysts faces the same labor-cost squeeze as the MSSP (04a).
The bear case
The bull case: breaches are more frequent, faster, and more regulated, IR retainers are a sticky annuity, and a specialist firm with insurance-panel flow is an attractive tuck-in for a platform or advisory roll-up. Three counterweights. First, IR is structurally a feature — the durable value (telemetry, recurring revenue, the breach-to-MDR cross-sell) accrues to whoever owns the product, so an independent IR firm is perpetually one platform acquisition away from losing its distribution edge. Second, automation eats the billable base — if agents do first-hour containment and draft the forensic timeline, the junior-analyst hours that funded IR margin shrink, and a roll-up of analyst-heavy shops inherits a declining-margin business. Third, insurance-panel economics compress rates — as carriers consolidate panels and push fixed-fee breach response, independent firms become rate-takers. Falsifiable test: watch whether independent IR specialists grow retainer revenue and hold rates as automation matures (thesis holds — IR is a durable specialty annuity), or whether the platforms' embedded IR + agentic containment captures the breach moment and independents become panel-priced commodity labor (thesis weakens to "IR is a relationship feature that belongs inside a platform").
→ Cross-references: Service Providers, MDR, The Agentic SOC, Consulting & the Big Four, Offensive Security & PTaaS, Threat Economy, Cyber Insurance.
Updated 2026-08-16 18:13 UTC · © El Dorado Capital · el-doradocapital.com · Market intelligence for informational purposes only; not investment advice.