For the engagement owner. A monitoring arrangement and an incident-response retainer answer different questions. Connect their activation, evidence and authority before relying on either.
State the capability you need
An organisation may want help receiving and investigating security signals, assistance preparing for incidents or access to specialists when an incident occurs. These are related requirements with different operating and commercial boundaries. Describe your current arrangements and the gap you need to close. Avoid starting with an acronym and assuming all suppliers include the same activities. The RFP should ask what the proposed service does, who delivers it, when it is available and what conditions must be met before work begins.
Read diagram text
- Monitoring
- Who reviews the agreed evidence?
- Readiness
- Are contacts, access and decisions prepared?
- Retainer
- How is response assistance activated?
Define monitoring as a sequence of responsibilities
Specify the sources covered, how collection health is checked, who investigates a signal and who receives the resulting assessment. Include tuning, exceptions and the management of changes to the environment. Ask for the hours during which each activity is performed rather than a single ambiguous statement of availability. A person answering a phone does not establish that all alerts are continuously investigated. Atlant Security can help frame these requirements; the actual monitoring delivery model, staffing and operating commitments must be confirmed during procurement.

Define a retainer through its activation terms
A retainer discussion should resolve how authorised assistance is requested, what capacity is included and which prerequisites affect mobilisation. Distinguish acknowledgement, consultation and the start of investigative work. Ask about unused hours, overages, specialist support, regions and renewal or exit arrangements. Readiness exercises and retained response capacity may be separate components. Do not assume a catalogue download or initial enquiry reserves either. Keep the contracted activation details available to authorised incident contacts through a channel that remains usable if the primary workplace systems are disrupted.
Read diagram text
- Request
- An authorised contact invokes the agreement
- Confirm
- Check scope, access and commercial authority
- Begin
- Start the agreed response activity
Connect the monitoring handoff to response authority
If a monitoring team escalates a serious concern, identify who decides whether to activate the response agreement. Specify how relevant evidence and case context reach the response team through approved channels. Confirm who can approve containment and expenditure. The monitoring provider, responder and business owner should understand the same handoff. The AWS incident-response guidance emphasises preparation and practice; use that principle to resolve access and communication dependencies before an emergency instead of discovering them during activation.
Read diagram text
- Assess
- Provide the investigation context
- Decide
- Reach an owner with activation authority
- Transfer
- Use the agreed evidence channel
Practice without treating the form as an emergency channel
Use a scheduled benign tabletop to check contacts, decision authority, evidence availability and commercial activation. Capture failures and assign corrective actions. Repeat the affected handoff after significant supplier or organisational changes. If there is a suspected active incident, follow your established response process and contact your response provider directly. This website does not dispatch responders. For planned procurement, request an explicit statement of what is included, what remains with your organisation and which targets are subject to negotiation. That makes monitoring and retainer proposals easier to compare and use.
For the next procurement discussion, read our related guides on retainer procurement questions and authorised testing scope. These cover complementary decisions; technical testing still needs its own scope and authorisation.
Prepare your requirements
Use the managed security services RFP builder to select your platforms, describe existing support and review suggested workstreams. You can edit your requirements before sending them through the contact form with an NDA or RFP. Approximate counts and business context are enough initially. Do not include credentials, personal records or live incident evidence. Service hours, delivery capacity and commercial commitments must be agreed in the proposal; submitting a form does not activate a service.
Read diagram text
- Exercise
- Walk through a benign activation
- Record
- Capture unavailable access or decision makers
- Improve
- Resolve and recheck the failed handoffs
Primary sources
- Atlant Security service catalogue
- Atlant Security cloud security consulting
- Atlant Security incident response
General information, not a compliance opinion. Confirm legal applicability and security service requirements for your entity and jurisdiction.
This guide and the related sector publications linked above are published by Atlant Security. Technical examples are planning examples, not claims about completed client tests.
Published by Atlant Security. Sources, editorial policy and corrections.

