When a company gets breached, the first call is to an incident response firm. The firm shows up, runs the playbook, contains the breach, writes a report, hands it to legal, leaves. The next breach finds the same gaps, the same mistakes, the same recommendations ignored. The IR market is structured to respond to breaches, not to prevent them, and the misalignment is structural.
The incident response industry is, by any reasonable measure, very good at what it does. The major firms have top tier responders. They have runbooks for the common cases. They have threat intelligence feeds that surface new attacker techniques within hours. They have relationships with the FBI, with the relevant sector regulators, with the major cloud providers, with the legal firms that handle the post breach work. When the call comes in, they are, in most cases, the right people to answer it.
The problem is what happens after they leave.
The IR firm business model
The IR firm makes money when companies get breached. The firm makes more money when the breach is serious enough to warrant a full engagement. The firm makes the most money when the breach is serious enough to warrant a multi month remediation. The IR retainer exists, but the retainer is a small fraction of the revenue. The real revenue sits as the breach response.
This is, on its face, a perverse incentive. The firm is incentivised to see more breaches, more serious breaches, longer remediations. The firm is not incentivised to prevent breaches, because the prevention of breaches would reduce the demand for the firm’s services. The incentive is structural. The firm is not, individually, hoping for more breaches. The firm’s revenue model, taken as a whole, depends on them.
The misalignment is not unique to the IR industry. The pharmaceutical industry is incentivised to sell more drugs. The defence industry is incentivised to sell more weapons. The misalignment is, in fact, a feature of every industry that sells a response to a problem. The response industry grows with the problem. The problem rarely shrinks. The customers of the response industry, in the long run, pay for the response and the prevention in equal measure, while the response industry captures most of the spend.
What the playbook actually does

The playbook is solid. Identify the scope. Contain the spread. Eradicate the access. Recover the systems. Document the timeline. Hand off to legal. The playbook has been refined over thousands of engagements. The playbook works, in the sense that it stops the immediate bleeding and produces a report that satisfies the regulator.
The playbook does not include the long term work. The playbook does not include implementing the recommendations. The playbook does not include the architectural changes that would have prevented the breach. The playbook does not include the training that would have made the help desk resistant to social engineering. The playbook does not include the budget process that would have funded the security team properly before the breach. The playbook, by design, ends when the immediate crisis is over.
Why the recommendations never get implemented
The IR report contains a list of recommendations. The recommendations are typically solid. The recommendations are typically specific. The recommendations are typically ranked by priority. The recommendations are, in most cases, never implemented.
The reason is not that the recommendations are bad. The reason is that the recommendations are work. The recommendations require budget, headcount, executive sponsorship, and a project to deliver them. The IR firm writes the recommendations, hands them to the CISO, and leaves. The CISO is now responsible for the implementation. The CISO has the same budget, the same headcount, and the same project queue they had before the breach. The recommendations go into the project queue. The project queue is full. The recommendations are deprioritised in favour of work that has a closer deadline. The recommendations sit in the queue for 6 to 18 months. The next breach hits. The same recommendations come out of the new IR report. The cycle continues.
This is not the CISO’s fault. The CISO is doing their job with the resources they have. The fault is in the structure, which produces recommendations without the resources to implement them.
The retainer that doesn’t retain
The IR retainer is sold as a way to get faster response and to get to know the client’s environment. The retainer is, in practice, mostly a way to bill a monthly fee for being on call. The retainer does not, in most cases, include proactive work. The retainer does not include threat hunting. The retainer does not include detection engineering. The retainer does not include the kind of work that would actually prevent the breach that justifies the retainer.
The retainer could be a force multiplier. The retainer firm could be embedded in the client’s security team, working on the long term gaps, using the breach response experience to inform the proactive work. The retainer could be the prevention arm of the response business. The retainer is, in most cases, none of these. The retainer is a fee for being available.
The handoff to the auditor
The IR report is, in most cases, eventually handed to the auditor. The auditor reads the report, asks a few questions, and adds the breach to the company’s risk register. The auditor’s job is to check that the company has a process for handling breaches. The company has a process. The process is to call the IR firm. The auditor is satisfied. The audit opinion is issued. The breach, in the audit’s view, is now a documented event, not an open risk.
The handoff is structurally absurd. The IR report is a forensic document, not a compliance document. The auditor reading the IR report is like a financial auditor reading the police report for a fraud case. The information is there, but the framing is wrong, and the questions the auditor is asking are not the questions the IR report was designed to answer.
What good IR would actually look like
Good IR would look more like a long term engagement than a firefighting service. The IR firm would be embedded in the security team, with a dedicated lead who knew the environment, knew the people, knew the gaps. The firm would do proactive work between incidents, with the incident response experience informing the proactive priorities. The firm would own the implementation of the recommendations from previous incidents, with the implementation tracked, budgeted, and reported to the board.
Good IR would also include the cost of the implementation in the original engagement. The IR firm would not just write the recommendations. The firm would scope, price, and staff the implementation. The recommendations would be implemented because the firm that wrote them becomes the firm doing the work. The misalignment between writing and doing would be removed.
This is, in some cases, what the larger firms offer. The larger firms have managed security service practices, with continuous monitoring, threat hunting, and remediation work, that go beyond the firefighting engagement. The smaller firms are mostly still in the firefighting model.
The realistic ask of an IR firm
If you are a CISO about to engage an IR firm, the negotiation is not about price. The negotiation is about scope. Ask for the implementation of the recommendations from previous incidents to be in scope. Ask for a dedicated lead who will be with you for the next 3 years. Ask for a proactive budget, billed against the retainer, that the firm uses to do the work between incidents. Ask for the recommendations from this incident to be priced, scoped, and scheduled before the firm leaves.
If the firm will not agree to those terms, the firm is in the response business, not the prevention business. The firm will do the response well. The firm will not do the prevention. The next breach will look familiar. The recommendations will be the same. The cycle will continue.
Why the industry resists this change
The IR industry resists the embedded model because the embedded model is less profitable. The firefighting model bills at high rates during incidents and lower rates during quiet periods. The embedded model bills at a steady, lower rate, with the firm responsible for the outcomes. The firefighting model lets the firm scale up during a breach and scale down after. The embedded model commits the firm’s best people to a single client for years. The economics favour the firefighting model. The security outcomes favour the embedded model. The misalignment amounts to the same one that has produced the recommendations no one implements.
The change will come from the buyers, not the firms. The CISO who negotiates for the implementation in scope, who tracks the recommendations across incidents, who treats the IR firm as a long term partner rather than a 911 service, will get better outcomes. The CISO who takes the cheapest retainer and treats the firm as a vendor will keep getting the same post incident report.
The bottom line
The incident response industry is good at responding to breaches. The industry is not structured to prevent them. The recommendations no one implements are not a failure of the recommendations. They are a failure of the structure. The fix is on the buyer side, not the supplier side. Embed the firm. Price the implementation. Track the recommendations across years. Treat the breach as the start of a long engagement, not the end of a short one.
The companies that have done this work have not had repeat breaches. The companies that have not done this work are on their third, fourth, fifth IR firm in five years, each producing the same recommendations, none of which were implemented. The pattern becomes the same. The fix amounts to the same. The work is yours.
Sources & Further Reading
All claims in this article are sourced from primary documentation, vendor advisories, and reputable security researchers.
Spotted an error? Email the editor. Corrections are issued with a visible correction note.
Editorial standards. Every article on humanrequired.org is reviewed by a human editor before publication. AI may assist with drafting or research; final editorial control is human. Read the full standards.



