Your client's cyber insurance renewal is coming up. The application asks: "Do you have a retained incident response and forensics partner?" The answer used to be optional. It's not anymore.
32% of cyber insurance carriers now require a documented IR plan or retainer as a condition of coverage. That number was 18% in 2024. By 2027, industry analysts expect it to exceed 50%. For MSPs managing client security, this shift creates both a risk and a massive opportunity.
What Changed in the Insurance Market
Cyber insurers got burned. Between 2020 and 2023, ransomware payouts exploded, and carriers realized their underwriting models were broken. The response was a complete overhaul of what they require before issuing or renewing a policy.
The baseline "utility stack" that insurers now treat as mandatory:
- MFA everywhere — on all remote access, email, privileged accounts
- Modern EDR with continuous monitoring — not just antivirus
- Immutable backups — air-gapped or cloud with versioning
- DNS-layer protection — blocking known malicious domains
- Documented IR plan — with evidence of testing
- Retained DFIR capability — a partner who can investigate when needed
The critical shift: insurers no longer accept checkbox attestations. They want verified evidence — exports, screenshots, and tool reports proving controls are in place. An MSP saying "yes, we have MFA" isn't enough. They want to see the Duo dashboard.
32% — of carriers require IR plan or retainer (increasing each renewal cycle)
The DFIR Retainer Problem
Enterprise DFIR retainers cost between $37,000 and $200,000 per year. CrowdStrike Services, Mandiant (Google), and Kroll are the big names, and their pricing reflects an enterprise buyer.
| Provider | Annual Retainer | Target Market |
|---|---|---|
| CrowdStrike Services | $50,000-$200,000+ | Enterprise |
| Mandiant (Google) | $50,000-$200,000+ | Enterprise |
| Kroll | $40,000-$150,000+ | Enterprise |
| IBM X-Force | $37,000-$105,000 | Enterprise |
| Sophos IR Retainer | $600/yr (200-device min) | SMB/MSP |
For an MSP managing 25 SMB clients with 50 endpoints each, a CrowdStrike retainer is absurd. The entire annual revenue from those clients might be $100K-$200K. Spending $50K-$200K on DFIR would eliminate all profit.
Sophos offers a budget option at $3/device/year, but it's a retainer for access to human responders — not a platform. When you call, you're in a queue. The investigation starts when they're available, not when you need it.
What Insurers Actually Want to See
Having spoken with MSPs who've navigated recent renewals, here's what insurers are looking for:
- A current IR plan — documented, reviewed within the last 12 months
- Evidence of tabletop exercises — proof you've tested the plan, not just written it
- A retained forensics partner — name, contact information, SLA
- An on-call roster — who responds at 2 AM on a Saturday?
- Remediation tracking — evidence that issues found in exercises were addressed
- Continuous monitoring proof — EDR dashboards, SIEM alerts, backup verification logs
Notice what's NOT on this list: "have you had an incident recently?" Insurers don't care whether you've been breached. They care whether you can respond effectively when you are.
The MSP Opportunity
Here's where this gets interesting for MSPs. If your clients need DFIR capability to get insured, and you can provide it through your platform, you've just created:
- A new revenue stream — "IR-ready managed security" at a premium over basic managed IT
- A retention lock — clients can't switch MSPs without losing their DFIR capability and potentially their insurance
- A competitive differentiator — "We include DFIR retainer coverage" is something most MSPs cannot say
- A trust signal — "Your insurer requires DFIR, and we have it" closes deals
The MSP that can tell a prospect "we include incident response retainer coverage in our managed services" will win against the MSP that says "we can find someone if something happens."
How to Add DFIR to Your MSP Stack
You have three options:
Option 1: Hire a DFIR Analyst ($90K-$150K/year)
Pros: dedicated expertise, knows your clients. Cons: one person can't cover 24/7, expensive, hard to recruit (talent scarcity), no coverage during vacation/sick days.
Option 2: Partner with a DFIR Firm ($37K-$200K/year)
Pros: expert-level capability, established processes. Cons: expensive, you're in a queue during major incidents, no integration with your existing tools, response time depends on their availability.
Option 3: Use an AI-Powered DFIR Platform ($4K-$8K/month)
Pros: immediate investigation capability, automated compliance reporting, integrated with your existing EDR/RMM, 24/7 availability, human analyst review included, compliance reports auto-generated. Cons: AI findings require human validation for legal proceedings.
Option 3 is what the market is moving toward. AI handles 90% of the investigation work at machine speed. Human analysts validate and sign off on findings. Compliance reports are generated from the investigation data, not written from scratch. And it costs a fraction of enterprise retainers.
What to Tell Your Clients
When your clients' insurance renewals come up, proactively reach out with this message:
"Your cyber insurance policy is up for renewal in [X months]. Insurers are increasingly requiring a retained IR capability. As your managed security provider, we've added DFIR capability to our platform. This means you have 24/7 incident response coverage, automated forensic investigation, and compliance-ready reporting — all included in your managed services. We recommend updating your insurance application to reflect this new capability."
This positions you as proactive, knowledgeable, and valuable. The client sees you preventing a problem they didn't even know was coming. That builds trust and retention.
The ROI Math
For an MSP with 25 clients:
- DFIR platform cost: ~$4,000-$8,000/month
- Added charge to each client for "IR-ready managed security": $200-$400/month
- Revenue from 25 clients: $5,000-$10,000/month
- Net margin on DFIR capability: $1,000-$6,000/month
- Plus: zero emergency IR costs when incidents happen (previously $12K-$40K per incident)
One avoided emergency IR engagement pays for a full year of the platform. Everything after that is pure margin.