A two-hour callback is worth very little if the responder has never seen your kind of system before.
Unit 42 and Mandiant publish the clearest response commitments in the industry, and we do not yet match them on paper. What they do not publish is a track record inside vessels, rail signalling and industrial control systems.
Our responders are the same people who have legally broken into ships, rail systems and payment networks, with the disclosures to show for it. The work is live containment, eradication and recovery on systems in service, followed by hardening that feeds straight back into the defences.
Side by side
| Attribute | Represented by UnstratIncident response & red teaming | Unit 42 (Palo Alto Networks)Unit 42 Retainer1United States | Mandiant (Google Cloud)Incident Response Retainer2United States |
|---|---|---|---|
| Published response commitment12Both competitors publish a number and we do not. For a buyer scoring responses, this is the single largest documentation gap on this page. | Not published | Remote response SLAs by tier: 24 hours, 8 hours, 4 hours and 2 hours, with an optional accelerated SLA upgrade | Guaranteed initial contact by email or phone within two hours, with a 24/7 incident response hotline |
| Commercial structure12 | Retainer and rapid-deployment options; terms not published | Four tiers of prepaid credits: 250, 550, 1,250 and 2,500+, with scope rising from small and medium businesses to large investigations | Prepaid blocks of hours at a discounted rate, with unused hours repurposable across other consulting services within the contract term |
| What the retainer can be spent on12 | Not published | Incident response, cloud IR and digital forensics, plus compromise assessment, ransomware readiness, penetration testing, purple team, tabletop exercises, IR plan development, security programme design, virtual CISO and zero-trust advisory | A range of technical and strategic Mandiant Consulting services, including the Incident Response Preparedness Service |
| Preparedness work before an incident12 | After-action hardening feeding findings straight into defensive platforms | Readiness assessments, breach readiness reviews and tabletop exercises drawn from retainer credits | IR Preparedness Service: review of monitoring, logging and detection, containment capability check, network and host architecture review, first-response evaluation and collaborative scenario planning |
| Scale of practice claimed12 | Not published as an engagement count | More than 1,000 incident response investigations each year | On the frontlines of complex breaches since 2004 |
| Domain experience published12 | Responsibly disclosed vulnerabilities across maritime, rail and industrial control systems | Not published as sector detail in this datasheet | Not published as sector detail in this datasheet |
| Adversary simulation from the same team12 | Yes. Red-team operations rehearsing realistic adversaries are part of the same offer | Yes, via retainer credits spent on penetration testing and purple-team exercises | Available, but as a separate Red Team Assessment engagement rather than inside the IR retainer |
| Insurance panel recognition12 | Not published | On the approved vendor panel of more than 70 major cyber-insurance carriers, honouring applicable panel rates | Not published in this datasheet |
| Contact routes published12 | Not published | Regional emergency numbers for North America, EMEA, the UK, APAC and Japan | 24/7 incident response hotline |
| Origin and political exposure12 | Independent, non-aligned origin, with no political exposure to any major-power ecosystem | United States (Palo Alto Networks) | United States (Google Cloud) |
Competitor values are quoted from the vendor documents listed under Sources, as published on the date shown. Configurations vary, so treat every row as a starting point for the evaluation rather than a like-for-like test result.
What the table means
The clock is not the only thing being measured
Unit 42 will call back within two hours on its top tier and Mandiant guarantees initial contact in two hours on any retainer. Those are real commitments and we do not currently publish an equivalent, which we will not dress up. Consider what happens after the callback. If the incident is on a vessel at sea, in a rail signalling estate or on a payment switch mid-settlement, the responder needs to know what can be isolated without stopping the ship, the train or the settlement window. That knowledge is not bought in two hours.
A retainer is procurement insurance as much as capability
The strongest practical argument for these retainers is not response speed, it is that the contract, the NDA and the data-handling terms are already signed when the incident starts. Unit 42 adds recognition on 70+ insurance panels, which shortens the argument with your insurer. Mandiant lets unused prepaid hours be redirected to other consulting so the budget is not wasted in a quiet year. Both are sensible commercial design and worth copying.
The responder ends up knowing everything
By the end of an engagement the response team holds forensic images, credential material, network maps and an accurate account of how a national system was defeated. Both competitors are US corporate groups, and neither datasheet addresses onward disclosure, because product literature rarely does. Ask the question and get the answer into the contract. Our answer is that there is no third government with standing to ask us for a copy.
Questions buyers ask
What response time should an incident response retainer guarantee?
The market benchmark is now two hours to first human contact: Mandiant guarantees it on any retainer, and Unit 42 offers it on its top tier, with 4, 8 and 24 hours below that. We do not publish an SLA, which is a genuine gap. What we would add is that time to first contact and time to containment are different numbers, and only the second one changes the outcome. Ask for both, from everyone.
Who can respond to a cyber incident on a ship or rail network?
Very few teams. Most IR practices are built for enterprise IT and will not know what can safely be isolated on a vessel under way or a signalling estate carrying traffic. Our responders come from the research that produced responsible disclosures across maritime, rail and industrial control systems, so the first hour is spent containing rather than learning the environment. Neither the Unit 42 nor the Mandiant retainer datasheet publishes sector experience of this kind.
Is an incident response retainer worth the money if we are never breached?
The design of the good ones answers this. Mandiant allows unused prepaid hours to be repurposed across other consulting within the term, and Unit 42 credits can be spent on readiness assessments, tabletop exercises, penetration testing and IR plan development. So the spend converts into preparedness rather than evaporating. If a supplier cannot tell you what happens to unused capacity, that is a reason to negotiate harder.
Should the same firm do our red teaming and our incident response?
There is a reasonable argument both ways. Separation gives you independence in the report. Combination gives you responders who already know where the estate is weak, because they broke it themselves last quarter. We offer both from one team deliberately, and Unit 42 does something similar by letting retainer credits fund penetration testing and purple-team exercises. Mandiant keeps its Red Team Assessment as a separate engagement.
Sources
- 1. Unit 42 (Palo Alto Networks), Unit 42 Retainer (datasheet, unit42_ds_unit-42-retainer_100424) (copy held on this site)Retrieved: 2026-07-31 · Four retainer tiers with prepaid credits and remote response SLAs, the service catalogue credits can be spent on, and the insurance-panel statement.
- 2. Mandiant (Google Cloud), Incident Response Retainer (datasheet, M-EXT-DS-US-EN-000038-11) (copy held on this site)Retrieved: 2026-07-31 · Two-hour initial contact commitment, 24/7 hotline, prepaid hours and the Incident Response Preparedness Service.
