Back to the library
Agencies & Professional Services
2026-07-17 10 min read

Cybersecurity Retainer Billing: Merchant Account Guide

A client breached under a security retainer can dispute the charge. With breach costs averaging $4.44M globally, that's the real figure behind the claim.

GM

By Gray Merchants Team

cybersecurity merchant accountMSSP billingincident responsehigh-risk merchant accountschargeback defense
Cybersecurity Retainer Billing: Merchant Account Guide
Key takeaways
  • IBM's Cost of a Data Breach Report puts the global average breach cost at $4.44 million (2025), with the US average at $10.22 million, the real dollar figure that sits behind a breach-triggered dispute.
  • A client breached while under a security retainer can dispute the charge as a failed service, a subjective claim a card network cannot independently judge.
  • Cybersecurity billing blends recurring subscriptions with infrequent high-ticket audit and incident-response fees ($75,000-$300,000 for containment work), a pattern that reads as an anomaly to standard fraud models.
  • The managed security services market is growing at an 11.4% CAGR toward $87.9 billion by 2033, meaning many MSSPs are outgrowing the account limits they started with.
  • Monitoring logs, reports, and engagement deliverables tied to each charge are the core defense, since they document service performed rather than an outcome the contract never guaranteed.

Cybersecurity firms are otherwise low-drama clients for a bank, but one pattern pushes them out of standard underwriting. A client who suffers a breach while under a security retainer can dispute the charge on the theory that the service failed to protect them. That is a subjective, outcome-based claim. A card network has no way to independently judge whether a breach happened because a control failed or because the client ignored a recommendation.

Why standard accounts flag security billing

Managed detection, monitoring, and compliance subscriptions bring the same recurring-billing scrutiny any subscription model draws, including involuntary churn from failed card renewals. Layer in large, infrequent charges for penetration tests, security audits, and incident response engagements, and a security firm's billing pattern looks like two different businesses to a fraud model built around one predictable pattern.

Long enterprise sales cycles compound this. A $40,000 audit invoice that lands once a quarter reads as an anomaly next to a steady $3,000 monthly monitoring fee, even though both are normal for the same firm.

The dollar figures behind a breach dispute

It's worth understanding the actual scale of what's at stake when a client disputes a security retainer after a breach, because the numbers explain why these disputes get filed at all. IBM's Cost of a Data Breach Report puts the average global breach cost at $4.44 million, with the US average running significantly higher, around $10.22 million once downtime, reputation damage, and regulatory fines are factored in.

Even for a smaller client, direct breach costs typically range from $150,000 to $500,000, and downtime alone can run $50,000 to $150,000 per day depending on revenue exposure. A ransomware incident specifically tends to cause around 24 days of operational disruption. Against numbers like that, a client's monthly retainer fee looks small, and disputing it as a symbolic gesture after a costly breach is, unfortunately, a predictable reaction, even when the security firm did everything the contract actually promised.

Structuring the account around the real risk

A cybersecurity services merchant account gets underwritten for the blended pattern: a recurring subscription base plus occasional high-ticket project fees, rather than sizing limits to only one of the two. ACH processing is worth pairing with card acceptance specifically for large audit and incident-response invoices, where a flat transfer fee beats a percentage-based card fee at that ticket size, especially on engagements in the $75,000-plus range.

The more important structural fix is documentation, not billing mechanics. Tying monitoring logs, scan reports, and engagement deliverables to each charge means a dispute gets contested with a record of the actual work performed, not a promise about outcomes the contract never guaranteed. That documentation habit is the same foundation any chargeback defense program is built on, just applied to a services business instead of a retail one.

Defending a breach-triggered dispute

A scope-of-work that distinguishes the service performed from a guaranteed security outcome is the foundation. Most security contracts already say this in the fine print. The practical fix is surfacing it clearly enough in client communication that it holds up when a client is frustrated after a breach.

When a dispute is filed, representment under card network dispute rules comes down to documented service delivery: monitoring activity logs, delivered reports, and evidence the engagement ran as scoped.

For firms delivering compliance-driven work like SOC 2 audits, the audit report and evidence package double as both the deliverable and the strongest possible representment record, since it is already built to withstand third-party scrutiny.

A growing category means more billing volume to underwrite

The managed security services market's growth trajectory matters for a reason beyond general context. A market growing at an 11.4% CAGR, from roughly $41.3 billion in 2026 toward $87.9 billion by 2033, means MSSPs that were appropriately sized for a merchant account two years ago are, for many of them, already outgrowing it.

A firm that started with a handful of monitoring clients and one occasional audit engagement per quarter looks very different once it's running dozens of retainers alongside multiple concurrent incident-response engagements. Revisiting account limits and reserve terms as that growth happens, rather than waiting for a processor to flag the volume change first, keeps the payment side from becoming the bottleneck on an otherwise healthy growth curve.

Frequently asked questions

Can we bill monthly monitoring and large one-off audits on the same account?

Yes. Blended recurring-plus-project billing is normal for this category, and the account gets sized for both the subscription base and the occasional large engagement rather than just one.

How do we defend a chargeback after a client we monitored gets breached?

With service records, not outcome guarantees. Monitoring logs, delivered reports, and engagement deliverables tied to each charge show the work performed, which is what representment is judged against.

Does PCI compliance apply to a cybersecurity firm's own merchant account?

Yes, the same PCI DSS framework applies to any business accepting card payments, separate from any PCI assessment work the firm might perform for its own clients.

Why do large audit or incident-response invoices sometimes trigger extra underwriting scrutiny?

Because they arrive infrequently and at a much higher ticket size than a firm's recurring monitoring revenue, which can look like an anomaly to a risk model calibrated on the smaller, steadier charges rather than the occasional large one. Incident response work specifically often runs $75,000 to $300,000 per engagement.

Why do breach-triggered disputes happen even when the security firm delivered the contracted service?

Breach costs are large enough, averaging $4.44 million globally and over $10 million in the US, that a frustrated client sometimes disputes a comparatively small retainer fee as a reaction to the incident itself rather than a genuine claim the service wasn't delivered. That's exactly why documented service delivery matters more than a promised outcome in the contract.

See the full cybersecurity industry page for the underwriting checklist, or explore related high-risk industries if security services are one of several offerings the business runs.

Ready to structure an account around your actual retainer-plus-engagement billing mix? Apply free for a same-week underwriting decision.

GM

Gray Merchants Team

Gray Merchants is a payment ISO that places merchant accounts across every risk level — from low-risk retail and e-commerce to 67+ high-risk verticals. The editorial team writes on high-risk merchant accounts, chargeback defense, MATCH/TMF remediation, and ACH processing — whether you are new, scaling, switching processors, or rebuilding after a decline.

Talk to a specialist

Tell us about your business

Share a few details and a specialist reviews your industry, volume, and processing history, then comes back with the right path — no obligation.

  • Underwriting decision in 24–48 hours
  • $0 setup fee, dedicated MID
  • Specialist replies within 4 business hours
  • Every term disclosed in writing before you sign

Request a call from a specialist

Are you currently processing?

No obligation. A specialist replies within 4 business hours, Mon–Fri 9:00–18:00 EST.

Cybersecurity Retainer Billing: Merchant Account Guide | Gray Merchants