Skip to Content

A Retainer You Never Use Is Not a Retainer: 1 376 Response Days, 156 Used

Purchased response capacity decays quietly, and the decay is only visible on the day it matters.

Buying incident response capacity feels like buying insurance. You pay, the capability sits there, and if the bad day comes you call someone. The European Union ran exactly that model across its member states and then audited it, which makes this one of the few places where you can see what happens to capacity that is bought rather than operated.

The result is not close. Of the response capacity made available, roughly nine days in ten were never used.

The numbers

ENISA's Cybersecurity Support Action spent 11.3 million euros up to 2023. Of that, 84 % went to preparation and 16 % to response (Figure 4).

Sixteen member states took an incident response retainer. Four of them used it. Of 1 376 person-days available for response, 156 were consumed - 11 % (Figure 4).

For the 2024 to 2026 period, nine states asked for a retainer (para. 59).

That last number is the one worth sitting with. After a period in which the capacity was demonstrably available and demonstrably unused, the number buying it fell by almost half. Read one way, that is an organisation learning something real about its own demand. Read another way, it suggests the capacity was never dimensioned against anything measurable to begin with.

Why this outcome is predictable

None of this requires anyone to have behaved unreasonably, which is what makes it worth writing about. The mechanism is structural and it will reproduce itself inside a single company just as reliably as across 27 states.

Response capacity is bought as insurance and then treated as precious. Nobody wants to spend a day of it on an exercise, because the days are finite and the real incident might be next week. So the capacity is preserved, and preserving it means never testing it.

A tool you use daily tells you when it breaks. A retainer has no natural occasion to be exercised at all. In the gap between signature and incident, the things a retainer depends on quietly rot: the contact numbers, the escalation path, the shared understanding of what your environment even looks like, and the people on the provider side who knew your account and have since moved on.

An unused retainer is therefore not idle capacity. It is decaying capacity, and the decay is invisible until the moment it matters. The difference is between a spare tyre and a spare tyre whose pressure you have never checked.

Money that cannot move

There is a second lesson in the same audit, and it is about how shared budgets get dimensioned.

The EU Cybersecurity Reserve holds 36 million euros for 2025 to 2027. It is divided equally among member states regardless of their assessed needs, and it is not transferable between them (paras. 53, 56 and 57). What one state does not use does not become available to a state that does.

The auditors also note that unused response capacity can be converted into preparation activities, which carries the risk that a reserve created for response ends up mainly funding preparation - the opposite of its purpose (paras. 60 and 61).

Two things generalise from this to any pooled budget, including an internal one split across business units:

  • Equal division is not the same as division proportional to need, and it only looks fair until the first incident lands on the unit with the smallest share.
  • A budget line that can be repurposed will be repurposed, and it will drift toward the easier activity. Preparation produces deliverables on a schedule. Response produces nothing at all in a good year.

What readiness actually requires

A retainer is a contract. Readiness is a practice. The contract is the cheaper half and it is the half most organisations stop at.

If you hold response capacity of any kind - contracted, internal, or a favour owed by a consultancy you trust - these are the things that separate it from shelfware:

  • Exercise it. A tabletop at least once a year, with the provider actually in the room or on the call. Not a review of the runbook, a run of it.
  • Verify the contacts on a schedule. Quarterly is not excessive. Phone numbers and on-call rotations decay faster than any other part of the arrangement.
  • Run a test escalation that genuinely reaches the other side. An escalation path that has only ever been read is an escalation path with unknown latency.
  • Agree in advance what counts as an activation. If that conversation happens for the first time during an incident, you will spend the first hour negotiating instead of responding.
  • Measure time to first human response and keep the number. It is the only figure that tells you whether the arrangement works, and you can only get it by trying.

None of that is a purchase. All of it is operational work, and it is work that the buying decision tends to hide.

The general form

The pattern is not specific to incident response, and once you see it you find it everywhere in infrastructure. Backups that are never restored. Failover that is never triggered. A disaster recovery site that has never served a request. An alert that has never fired and is therefore assumed to be working.

In every one of those cases the organisation owns the thing and does not know whether it functions, and finds out on the day when finding out is most expensive. Capacity that is not operated is not capacity. It is a line item that resembles one.


Source: European Court of Auditors, Special Report 19/2026, "Detecting and responding to cybersecurity incidents", adopted 16 June 2026. Available at eca.europa.eu under CC BY 4.0. Paragraph numbers in the text refer to the report so the findings can be checked.

The NIS2 Clock Starts When You Notice: Why Detection Decides Whether You Can Comply
The 24-hour early warning is measured from the moment you become aware, not from the moment you are breached.