The Business of Cyber Security

Incident Response and DFIR

Incident response (IR) is the emergency-response function of cybersecurity: containment, forensics, and recovery after a breach. According to Unit 42's 2026 Global Incident Response Report, attacks are now ~4× faster than in prior years, with data exfiltration in under an hour in some cases (Palo Alto/Unit 42). As the window from intrusion to exfiltration falls below the time it takes to dispatch a human IR team, retained, telemetry-connected, increasingly automated response becomes the model that works — a central reason the most valuable IR capability has been absorbed into product platforms rather than left in standalone firms.

What IR/DFIR is, and how the money works

Incident response is the emergency room of cybersecurity: when an organization is breached, the IR firm contains the attacker, performs digital forensics (DFIR — reconstructing what happened, what was taken, and how), eradicates the foothold, restores operations, and produces the report that satisfies regulators, insurers, and litigators. It is distinct from the always-on monitoring of MDR: IR is episodic and adversarial, triggered by a breach, often under legal privilege and on a clock measured in hours.

The economics run on three revenue forms, each capturing value differently:

For M&A, the standalone IR firm is structurally a feature, not a platform. Its forensic depth is a magnet for relationships, but the recurring revenue and the telemetry both live elsewhere — in the EDR/SIEM product the responders use and in the MDR contract the breach converts into. That is why IR has been captured by platforms more than any other services segment.

The named-player map (four archetypes)

Archetype Players What they bring Value capture
Platform-owned IR Mandiant (Google), Unit 42 (Palo Alto), CrowdStrike Services, Microsoft DART, Cisco Talos IR, Secureworks (Sophos) Forensic brand + their own EDR/telemetry; IR feeds product pull-through Highest — IR converts to product + MDR ARR
Independent specialists Sygnia, Coveware (ransomware/negotiation; Veeam-owned), Arete, Tidal Cyber, Surefire, GroupSense Vendor-neutral depth, speed, ransomware negotiation Reputation + insurance-panel flow; prime tuck-in targets
Advisory/IB-owned Kroll, Stroz Friedberg (Aon→LevelBlue), FTI, Booz Allen Litigation/regulatory/financial credibility; breach-coach ties Project + retainer; bolts onto risk-advisory
Big Four / SI Deloitte, PwC, EY, KPMG, Accenture, IBM X-Force Scale, global reach, board access Pull-through to remediation programs (04d)

The differentiation that matters: Mandiant is the brand for nation-state and the most complex breaches; CrowdStrike and Unit 42 win on tech-integration and speed because they respond inside their own telemetry; Sygnia competes on raw speed; Coveware owns ransomware negotiation as a niche so deep it scores like a full-scope firm. When Google bought Mandiant (2022) and Palo Alto built Unit 42, the logic was identical: own the forensic relationship at the moment of maximum customer trust, and convert it into platform commitment. A breach is the single best cross-sell event in security, and the platforms have bought their way to the front of it.

Why speed compresses the human model

The closing window: attacker speed vs. human response 6h 12h 24h 48h+ ~1h ~24h+ exfil time (prior yrs) <1h exfil time (2026) ~hrs human IR dispatch min automated containment Directional. As exfil time collapses below human dispatch time, value shifts to retained + automated response.
Illustrative, anchored on Unit 42's finding that attacks are ~4× faster with sub-hour exfiltration in some cases. When the attacker window falls below human dispatch time, the premium shifts from ad-hoc forensics to retained, telemetry-connected, automated response — favoring platform-owned IR and the agentic SOC. Source: Unit 42 2026 Global IR Report.

As the exfiltration window collapses toward an hour, after-the-fact forensics loses value relative to real-time, automated containment. That re-rating flows directly into the agentic SOC: the same AI agents that triage alerts are being pointed at the first minutes of an incident — auto-isolating hosts, pulling forensic timelines, and drafting the breach narrative — compressing the junior-responder work that filled IR engagement hours. Human responders move up the stack to incident command, attribution, negotiation, and the regulatory/litigation interface, where judgment is irreplaceable and rates stay high. The standalone IR firm whose margin depended on billable forensic analysts faces the same labor-cost squeeze as the MSSP (04a).

The bear case

The bull case: breaches are more frequent, faster, and more regulated, IR retainers are a sticky annuity, and a specialist firm with insurance-panel flow is an attractive tuck-in for a platform or advisory roll-up. Three counterweights. First, IR is structurally a feature — the durable value (telemetry, recurring revenue, the breach-to-MDR cross-sell) accrues to whoever owns the product, so an independent IR firm is perpetually one platform acquisition away from losing its distribution edge. Second, automation eats the billable base — if agents do first-hour containment and draft the forensic timeline, the junior-analyst hours that funded IR margin shrink, and a roll-up of analyst-heavy shops inherits a declining-margin business. Third, insurance-panel economics compress rates — as carriers consolidate panels and push fixed-fee breach response, independent firms become rate-takers. Falsifiable test: watch whether independent IR specialists grow retainer revenue and hold rates as automation matures (thesis holds — IR is a durable specialty annuity), or whether the platforms' embedded IR + agentic containment captures the breach moment and independents become panel-priced commodity labor (thesis weakens to "IR is a relationship feature that belongs inside a platform").

Cross-references: Service Providers, MDR, The Agentic SOC, Consulting & the Big Four, Offensive Security & PTaaS, Threat Economy, Cyber Insurance.


Updated 2026-08-16 18:13 UTC · © El Dorado Capital · el-doradocapital.com · Market intelligence for informational purposes only; not investment advice.