Named team and agreed response time
A named point of contact and a defined response time from the moment you invoke, in business hours or around the clock depending on the tier. You know who answers before you need them to.
The hour you need a number to call is the worst possible hour to start procuring one. A retainer puts a named team, an agreed response time and a pre-approved scope in place before anything happens, so the first call is about the incident rather than about paperwork.
A standing arrangement under which Orbix responds to your security incidents. Contracting, scope and access are settled in advance, so when something happens the engagement starts immediately instead of after a procurement cycle.
Orbix already builds incident response plans and runs the tabletop exercises that test them. The gap that engagement leaves is the actual incident: the plan says who to call, and for most organisations that is nobody. Meanwhile the amended PDPA runs a notification clock from the point of awareness, and the decisions that determine whether you meet it are made in the first few hours.
Retainers are sized by hours and response time rather than sold as one package, because a thirty-person company and a regulated financial institution need very different arrangements.
A named point of contact and a defined response time from the moment you invoke, in business hours or around the clock depending on the tier. You know who answers before you need them to.
Contract, rates, authorities and data handling terms agreed and signed while nobody is under pressure. The single biggest delay in a live incident is usually commercial, not technical.
Before any incident, we document your environment, your critical systems, your escalation contacts and your existing plan, so responders are not learning your architecture during a live event.
Triage, containment guidance, scoping the compromise, evidence preservation and coordination with your IT team or managed service provider. Structured decision support for the calls that have to be made quickly.
Assessing whether a personal data breach has occurred, what it affects, and what the amended PDPA requires you to notify and when. Drafting support for the notification and for affected individuals, working with your legal counsel.
Root cause, a lessons learned register, and a remediation plan that changes controls rather than documents. Fed back into the incident response plan so the next exercise tests what actually happened.
Every hour lost to contracting is an hour the attacker keeps. Pre-signed terms convert that into response time.
Breach assessment is a specific skill under time pressure. Having it available immediately is the difference between a defensible notification decision and a guess.
Onboarding means the team arrives with your architecture, contacts and critical systems documented, instead of asking basic questions while systems are down.
A retainer is concrete evidence of preparedness, which matters in cyber insurance underwriting and in board and regulator conversations about resilience.
Where a retainer goes unused, the hours convert to proactive work such as tabletop exercises, plan revision or a readiness review, so the spend produces something either way.
Orbix wrote or tested the plan for many clients already. A retainer means the same people who know the plan are the ones who arrive when it is invoked.
Understanding your environment, risk profile and regulatory position, then agreeing response time, hours and escalation tier.
Terms, rates, authorities, data handling and confidentiality agreed and signed in advance, including how evidence is handled.
Documenting architecture, critical systems, contacts, existing plan and escalation paths. A short readiness review identifies anything that would obstruct a response.
Contact details and documentation kept current, with periodic review. Unused hours applied to exercises or proactive work.
You invoke, we respond within the agreed time, and run triage, containment support, scoping, evidence preservation and decision support.
Post-incident review, root cause, remediation plan and plan revision, so the next incident meets a better prepared organisation.
Signed terms covering scope, response time, rates, authorities, data handling and confidentiality.
Documented architecture, critical systems, escalation contacts and dependencies, kept current.
Anything in your current position that would obstruct a response, identified before it matters.
During a live incident, a maintained timeline of events, decisions and actions, which is what regulators and insurers later ask for.
Documented assessment against the notification threshold, and drafting support for regulator and individual notification.
Root cause, impact, response evaluation, lessons learned and a remediation plan with owners and dates.
We do not resell products, so nothing here is shaped by a vendor margin. The recommendation is whatever your risk and your budget actually justify, including telling you that you do not need the engagement yet.
Findings come with a sequence, an owner and a realistic effort estimate, sized to the team you have rather than the team a framework assumes. A report that cannot be acted on is an expense, not a control.
Our people have carried the obligation internally, not only audited it. That shows up in what we consider proportionate, and in how much documentation we think you genuinely need.
Work is grounded in Malaysian law and regulator expectation, from the PDPA and the Cyber Security Act 2024 to Bursa, BNM and SC requirements, rather than translated from a European or American template.
Where an engagement includes training, the training component is structured to be HRD Corp SBL-Khas claimable, which changes what the programme costs you in practice.
Suspected or confirmed compromise: ransomware, business email compromise, unauthorised access, data exfiltration, insider incidents and suspected personal data breaches. The agreement defines this precisely so there is no argument at the point of invocation.
No. We work alongside your IT team or your managed service provider, providing direction, decision support and specialist analysis. Containment actions are executed by whoever holds the access, under agreed authority.
Tiers typically range from next business day through to a same-day or around-the-clock commitment. Faster response costs more, and the right tier depends on how much downtime actually costs you, which is part of the scoping conversation.
They convert to proactive work rather than lapsing. Most clients use them for tabletop exercises, plan revision, readiness reviews or targeted assessments.
Yes, and this is one of the main reasons organisations take a retainer. We assess whether a personal data breach occurred and what it affects, and support the notification decision and drafting. Where legal advice is required, we work alongside your counsel rather than replacing them.
We preserve evidence properly and maintain a defensible chain of custody. Where a matter is heading to litigation or prosecution, we will say so early and work with a specialist forensic firm or your counsel as required.
Often yes, and sometimes your policy requires it. Insurers frequently have panel responders, so we check your policy during scoping to make sure a retainer complements the cover rather than conflicting with it.
Tell us your headcount, your sector and what your current plan says to do at two in the morning. We will come back with a tier recommendation, a response time and a fixed quotation, and we will tell you if your existing arrangements already cover it.