By David Chernitzky, CEO, Armour Cybersecurity · Serving Toronto and organizations across North America · Last updated August 21, 2026
Quick Answer
The cold-start problem is what happens when an organization detects a cyber incident and has no pre-established incident response relationship in place. The security team identifies the breach. They escalate to leadership. Leadership asks who handles incident response. There is no answer. The search begins for a firm that can engage immediately, on whatever day and time the incident was detected, with capacity available. Each firm asked requires the same information: describe your environment, identify your systems, tell us who the stakeholders are. This orientation work takes hours. During those hours, the attacker may still be active, data may continue to be exfiltrated, ransomware may continue to encrypt, and systems that were not yet affected become affected. The cost of those hours is not abstract: it shows up in the total scope of the breach, the recovery time, and the final incident bill. A pre-established incident response retainer with proactive onboarding eliminates the cold start. The relationship is already in place, the context is already documented, and the response team starts work rather than starts orientation when the activation call comes in.
Key Takeaways
- Dwell time is the period between when an attacker first gains access and when they are detected and contained. Every hour of uncontested dwell time during an active incident response is time the attacker uses to deepen their access, exfiltrate additional data, or extend their presence to systems that had not yet been compromised. Cold-start engagements extend effective dwell time during the response phase: even after the incident is detected, the time spent orienting a response team that has no prior knowledge of the environment is time during which the attacker may remain active.
- The first few hours of incident response are the most critical for containing scope. Containment actions taken quickly, isolating affected systems, blocking attacker communication channels, resetting compromised credentials, limit the attacker’s ability to expand the breach. Containment actions taken after hours of orientation, when the response team is only just completing its understanding of the environment, arrive late. The breach scope that was containable in the first two hours may require three days of remediation if those two hours were spent on cold-start orientation instead.
- Finding available incident response capacity during an active breach is not guaranteed. Established IR firms maintain rosters of active clients and respond to new engagements on a capacity-available basis. A Friday-night ransomware detection that prompts calls to five IR firms may produce one firm with availability, two firms that can engage Monday morning, and two firms that are fully committed for the next two weeks. The organization’s choices are constrained by the market at the moment of need. A retainer guarantees availability for the firm and team already in relationship with the organization.
- The context that a pre-established retainer provides has direct monetary value. The two-hour onboarding workshop that maps the organization’s environment, systems, and stakeholders eliminates the orientation work that a cold-start engagement must conduct during billable hours. If that orientation takes four hours at a blended rate of five hundred dollars per hour, the cold-start engagement costs two thousand dollars more than a retainer-backed engagement for the orientation work alone, before any containment action is taken.
- Cold-start engagements often produce lower-quality response outcomes because the team is making decisions with incomplete information about the environment. A response team that does not know which systems are business-critical may prioritize containment actions that protect the wrong systems. A team that does not know the normal state of the network cannot distinguish anomalous traffic from legitimate traffic quickly. A team that does not know the organization’s regulatory obligations may make communication decisions that create compliance exposure. Pre-established context from onboarding eliminates each of these risks.
How the Cold Start Plays Out in Practice
The Friday night scenario
Ransomware does not respect business hours. The scenario that IR practitioners describe most consistently is the late-evening or weekend breach detection: an employee notices that files are encrypting, or a monitoring alert fires, or a ransom note appears on a shared screen. The internal IT team confirms that something is wrong and escalates. Leadership is reached by phone. The CISO or IT director asks for authorization to engage external incident response. Authorization is given. The search for an available firm begins at 9 PM on a Friday.
The firms called have emergency contact lines. Some answer immediately; others route to on-call personnel who call back within 30 to 60 minutes. Each firm that engages asks the same questions: what type of incident, what systems are affected, how large is the environment, who are the stakeholders, do you have an incident response plan? This information gathering takes 30 to 60 minutes per firm. If the organization calls three firms before finding one that is both willing and able to engage immediately, two to three hours have passed since the first call was made. The response team has not yet begun technical work. The attacker has had those hours to continue their activity.
With a retainer in place, the scenario plays out differently. The IT director escalates to leadership. Leadership authorizes the activation call to the retainer firm. The response team that conducted the onboarding four months ago picks up the phone with the asset and stakeholder inventory already in front of them. The activation call is a briefing on the current state of the incident, not a general orientation to the organization. Technical response planning begins during the call. By the time the Friday-night break-glass engagement is still searching for available capacity, the retainer-backed response is already executing containment actions.
The cost of delayed containment
Ransomware incidents provide the clearest illustration of delayed containment cost because the damage is directly observable: every system that encrypts after containment could have started is a system that requires remediation, recovery, or replacement. An organization with 500 endpoints and a ransomware payload that encrypts at a rate of 50 systems per hour will lose 200 more systems in the four hours that a cold-start engagement spends on orientation than it would in the first hour of a retainer-backed response. The recovery cost differential, in labor, replacement hardware, lost productivity, and data recovery, can easily exceed the cost of the retainer that would have prevented those four additional hours of uncontested encryption. Fast, well-informed breach response is what compresses that window.
Data exfiltration incidents present a different but equally measurable version of the same problem. Modern ransomware actors commonly exfiltrate data before deploying encryption, using the exfiltrated data as leverage for extortion. Business email compromise incidents involve fraudulent transactions that are reversible only within a narrow window, sometimes measured in hours, before funds are transferred beyond recovery. In each of these scenarios, the hours spent on cold-start orientation are hours during which the window for effective mitigation narrows. The cost is not the orientation time itself; it is the lost opportunity to contain the incident when containment was still most effective.
The scale of the underlying problem is well documented. The IBM Cost of a Data Breach 2025 report puts the global average breach at USD 4.44 million, with a mean time to identify and contain of 241 days, and it consistently finds that breaches contained faster cost materially less than those that run long. The cold-start delay operates at the sharp end of that curve: it lengthens exactly the window that drives cost. Across the 260+ organizations Armour Cybersecurity protects in 52+ industries, the incidents that stay small are almost always the ones where containment began in the first hour, and the single most reliable predictor of a fast first hour is whether the response relationship existed before the incident did.
What a Pre-Established Retainer Eliminates
The availability problem
A signed retainer with a documented 24-hour remote response activation guarantee eliminates the availability problem entirely. The organization does not search for available capacity during an active incident; the capacity is already committed in the retainer agreement. The only call needed is the activation call, and that call triggers a guaranteed response sequence rather than a negotiation for availability. For incidents that occur outside business hours, on weekends, or during holiday periods, the guarantee matters most: this is exactly when ad-hoc availability is most constrained and when the availability problem is most likely to produce the worst-case cold-start outcome.
The context problem
The proactive onboarding workshop resolves the context problem before any incident occurs. The two-hour session that maps assets, identifies stakeholders, documents contact details, and establishes out-of-band communication channels produces the inventory that eliminates orientation time during the response. The response team arrives at the activation call knowing the organization’s environment at a level of detail that a cold-start team takes hours to reach. The hours saved in orientation are hours available for containment, investigation, and eradication during the most critical phase of the response.
The context value of the onboarding compounds over the retainer term. An organization whose environment changes significantly, adding cloud services, onboarding new business applications, expanding the endpoint fleet, can update the asset inventory as part of the retainer relationship without waiting for an incident. The response team’s knowledge of the environment stays current rather than becoming stale over the twelve-month term. A cold-start team has no prior context to update; their knowledge of the environment is always zero until the engagement begins.
The decision-quality problem
Incident response decisions made under pressure with incomplete information produce worse outcomes than decisions made with thorough context. Which systems to prioritize for containment, which stakeholders to notify first, which regulatory reporting obligations apply, which communication channels to use when primary channels may be compromised: all of these decisions benefit from context that a retainer provides and a cold-start engagement must develop during the response itself. Armour Cybersecurity’s zero dollar IR retainer is structured to provide this context through the proactive onboarding workshop and to make it available to the response team the moment an incident is declared. The financial model, no upfront block-hour fee, removes the budget barrier that causes organizations to defer this relationship until the incident proves its value.
Frequently Asked Questions
How much does incident response actually cost without a retainer?
Incident response costs without a retainer vary by incident type, severity, and duration, but the cost components are consistent: hourly professional fees for the response team, forensic tool and infrastructure costs, travel and on-site expenses if physical presence is required, legal counsel fees for breach notification and regulatory compliance, regulatory fines or penalties if notification obligations are not met, customer notification costs, and business interruption losses during the recovery period. Industry studies consistently place the average cost of a mid-market data breach in the hundreds of thousands of dollars before business interruption is included, and the IBM Cost of a Data Breach 2025 report puts the global average at USD 4.44 million with a 241-day mean time to identify and contain. The portion attributable to extended response time due to cold-start orientation is difficult to isolate, but the direct comparison is clear: every hour of orientation time that a retainer eliminates is an hour of billable professional time that is not spent on containment, and potentially an hour during which breach scope continues to expand.
Can the retainer onboarding information become a security risk itself?
The asset and stakeholder inventory produced during the onboarding workshop is sensitive documentation that requires appropriate information handling. Armour Cybersecurity maintains retainer documentation with the same security controls applied to client data in any engagement: restricted access limited to personnel directly serving the retainer, secure storage, and confidential handling consistent with the organization’s own requirements. The inventory is not shared beyond the response team and is not referenced in contexts outside the retainer engagement. The security risk of the documentation is manageable and significantly lower than the operational risk of having no documented context available when an incident occurs.
What if we already have some internal IR capability?
An internal security operations team or IR capability and an external retainer are complementary rather than competing. Internal teams handle the initial triage, escalation, and first-response actions that occur in the first minutes of an incident detection. External retainer teams augment the internal capability with specialized forensic skills, surge capacity for extended incidents, and the independence that regulatory bodies, insurance carriers, and legal counsel often require when an incident report must be produced by a party without a conflict of interest in the outcome. Many organizations with internal security teams maintain external IR retainers specifically for the surge capacity, specialized expertise, and independent attestation that internal teams cannot provide for themselves.
Is the cold-start risk really that significant for a smaller organization?
The cold-start risk is proportionally higher for smaller organizations than for larger ones, for two reasons. First, smaller organizations have less internal capacity to manage an incident while simultaneously searching for and orienting an external response team. A 50-person professional services firm whose entire IT function is one managed service provider and one internal IT generalist has far less capacity to absorb the cold-start overhead than an enterprise with a dedicated security operations team. Second, smaller organizations typically hold a higher proportion of their total operational capacity in the systems most likely to be targeted by ransomware. A cold-start delay that adds two days to the recovery timeline for an enterprise is a significant disruption; for a 40-person firm whose billing, document management, and client communication systems are all affected by the same ransomware deployment, two additional days of recovery may represent an existential operational impact.
The Bottom Line
The cold start is the most expensive part of an incident that no one budgets for. The hours spent finding a firm and explaining your environment while ransomware keeps encrypting do not show up as a line item, but they show up in the breach scope, the recovery timeline, and the final bill, and they hit smaller organizations hardest. The math is not complicated: the window when containment is most effective is the same window a cold start burns on orientation. A pre-established retainer moves that orientation to a two-hour workshop that happens before anything goes wrong, so the activation call starts containment instead of introductions. Armour Cybersecurity’s zero dollar IR retainer removes the upfront cost that makes organizations defer this until it is too late, so the relationship is already in place on the Friday night you need it.
About the author
David Chernitzky is the CEO and Co-Founder of Armour Cybersecurity, a Toronto-based firm that protects organizations across North America from advanced cyber threats. He brings more than 25 years of cybersecurity and military cyber intelligence experience, having served as an officer in an elite technology unit before co-founding Armour. Armour’s team of military-intelligence veterans and senior advisors serves 260+ clients across 52+ industries with a 97% client retention rate. Learn more about Armour Cybersecurity.



