Before you sign an incident response retainer, ask about SLA definitions, scope, hidden costs, threat profile fit, and post-incident support. Here is what to look for.