Services · Threat Intel & Incident Response

Unit 42
Services

Palo Alto Networks' elite threat intelligence, incident response, and cyber risk practice — 200+ responders, 1,000+ engagements a year. The full catalog, plus how to sell it, package it, and attach it to every deal.

Emergency IR hotline (NA): 866.486.4842 (866.4.UNIT42) · unit42-investigations@paloaltonetworks.com — available 24/7/365.

Why Unit 42

The Services Layer That De-Risks the Platform

Customers buy the platform; Unit 42 makes sure it actually protects them. Attaching services is what makes premium platform pricing defensible — and it's the fastest, stickiest, recurring revenue in the portfolio.

200+
Threat responders & consultants
1,000+
IR engagements / year
24/7
Global response coverage
30M+
Malware samples analyzed daily

How It's Organized

Three Service Families + The Retainer

Everything Unit 42 offers falls into Respond (reactive), Assess (proactive), or Managed — all fundable through one commercial anchor: the Retainer.

Retainer

The anchor. Credits flex between IR and proactive services. Easiest recurring attach.

Respond

Reactive IR & digital forensics. 24/7 breach response, ransomware, BEC.

Assess

Proactive Cyber Risk Management — assessments, pen test, tabletop, advisory.

Managed

MDR, Managed Threat Hunting, Managed XSIAM — built on Cortex telemetry.

Complete Catalog · As of Today

Every Unit 42 Service

Each card includes what it is and a one-line "how to sell it" hook.

Retainer — the anchor vehicle

Anchor

Unit 42 Retainer

Pre-purchased credits with pre-negotiated SLAs. Credits flex between reactive Incident Response and proactive Cyber Risk Management scoped during the term.

Sell it: The easiest recurring "yes." It locks IR SLAs, gives the customer peace of mind, and funds the assessments that open every follow-on service.

Respond — Incident Response & Digital Forensics

Reactive

Incident Response

24/7 investigate, contain, eradicate, and remediate even the most advanced attacks, using Palo telemetry across endpoint, network, and cloud.

Sell it: "Who responds in the first hour if you're hit tomorrow?" Position via the Retainer for faster SLAs.
Reactive

Digital Forensics (DFIR)

Litigation- and insurance-grade forensic investigation and evidence handling, delivered globally with Cortex XDR, Xpanse, and Prisma Cloud telemetry.

Sell it: Essential where legal, cyber insurance, or regulators are involved.
Reactive

Ransomware Investigation

Contain, determine root cause and window of compromise, quantify exposure; if needed, negotiate, validate decryption keys, and drive recovery.

Sell it: The nightmare scenario every exec fears — the highest-urgency trigger.
Reactive

BEC Investigation

Respond to business email compromise: contain, root cause, window of compromise, attacker activity, and quantify data exposed.

Sell it: The most common incident type — broadly relatable to any customer.
Reactive

Web App Compromise

Contain web-application attacks, analyze logs and code, quantify loss of sensitive data, and recommend design-hardening countermeasures.

Sell it: Pairs with app-heavy / e-commerce accounts.
Reactive

Structured Data Investigation

Collection and analysis of SQL and NoSQL database environments, including external logs.

Sell it: For data-breach scoping where DB exposure is in question.
Reactive

M&A Cyber Due Diligence

Identify hidden cybersecurity red flags and risks in the context of a merger or acquisition.

Sell it: Target corp-dev and PE-backed accounts; ties to deal timelines.

Managed Services

Managed

Managed Detection & Response (MDR)

Unit 42 experts detect and respond 24/7, built on Cortex XDR Pro across endpoint, identity, cloud, network, and SaaS — with dramatically reduced alert volume.

Sell it: The natural managed expansion once Cortex/XDR lands. No added SOC headcount for the customer.
Managed

Managed Threat Hunting (MTH)

Continuous proactive hunting to uncover attackers hiding in the environment, across Palo and third-party telemetry.

Sell it: Upsell for customers who want proactive hunting beyond automated detection.
Managed

Managed XSIAM

Cortex XSIAM (the #1 SOC transformation platform) combined with Unit 42 expertise for 24/7 expert-led defense across every attack surface.

Sell it: The premium managed tier — pairs with an XSIAM platform play.

Assess — Proactive Cyber Risk Management

Proactive

Cyber Risk Assessment

Assess risks, identify gaps, and build a strategic improvement plan aligned to industry or regulatory frameworks (NIST CSF, CIS, ISO 27001).

Sell it: The classic land-and-expand — findings justify every follow-on service.
Proactive

Attack Surface Assessment

Identify external attack-surface risks and remediate issues before attackers can exploit them.

Sell it: Great discovery hook — shows unknown internet-exposed assets; pairs with Xpanse.
Proactive

Ransomware Readiness Assessment

Control enhancements, remediation recommendations, and a best-practice playbook to reach a target ransomware-readiness state.

Sell it: Board-level topic; ties to cyber-insurance requirements.
Proactive

Breach Readiness Review

Assess people, processes, and technology to respond effectively, with a strategic roadmap to a target breach-readiness state.

Sell it: Frames a multi-service roadmap in one engagement.
Proactive

BEC Readiness Assessment

Targeted assessment of controls and the people, processes, and technology needed to defend against BEC and other email-based attacks.

Sell it: Follow-up to any BEC incident; broadly relevant.
Proactive

SOC Assessment

Measure defenses against evolving threats and improve SOC maturity.

Sell it: Pairs with an XSIAM SOC-transformation motion.
Proactive

Supply Chain Risk Assessment

Evaluate vendor-based supply-chain cybersecurity risk to identify and mitigate supply-chain attack threats.

Sell it: Timely for regulated and manufacturing verticals.
Proactive

Cloud Security Assessment

Assess cloud posture and controls against real-world cloud attack techniques.

Sell it: Attach to any Cortex Cloud / Prisma Cloud opportunity.
Proactive

AI Security Assessment

Empower secure GenAI adoption across employee usage and AI application development.

Sell it: Rides the AI wave; pairs with Prisma AIRS and Koi (AES).
Proactive

Compromise Assessment

Determine whether an environment is currently or was previously compromised.

Sell it: Low-friction entry point that often uncovers real findings.
Proactive

Penetration Testing

Stress-test cybersecurity controls using tactics, techniques, and procedures used by real threat actors.

Sell it: Recurring annual need; often compliance-driven.
Proactive

Purple Team Exercises

Collaborate with Unit 42 to identify alerting gaps, tune defenses, and enhance security operations practices.

Sell it: Upsell for mature SOCs; validates detection efficacy.
Proactive

Tabletop Exercises

Simulate response to a severe incident with key stakeholders using customized, industry-specific scenarios based on real breaches.

Sell it: Executive-friendly; a common first proactive engagement.
Proactive

Incident Response Plan Development

Advisory service building your team's readiness to prevent, detect, respond to, and recover from attacks.

Sell it: Natural companion to a Retainer or tabletop.
Proactive

Zero Trust Advisory

Expert guidance on Zero Trust — from alignment and strategy to implementation and policy design.

Sell it: Strategic advisory that pulls through platform architecture.
Proactive

Deep and Dark Web Service

Design governance frameworks, operating models, and an InfoSec program roadmap — policies, control framework, and a defense-in-depth strategy.

Sell it: Program-level advisory for maturing security orgs.

Seller Playbook

How to Sell Unit 42 Services

Why it has value, when to lead with it, and the attach sequence that turns one small "yes" into a services annuity.

The value story (say this)

"Palo is priced for the platform — and the platform only pays off if it's operated and defended. A Unit 42 Retainer proves that: IR SLAs baked in, plus proactive credits to harden posture before an incident." This reframes premium platform price from an objection into a justification, and positions services as the adoption insurance the economic buyer actually wants.

The attach ladder

1

Lead with the Retainer

At the point of any Cortex/Strata deal. Small, recurring, low-friction — the easiest "yes" and the anchor for everything else.

2

Burn credits into an Assessment

A Cyber Risk, Compromise, or Ransomware Readiness assessment surfaces concrete gaps — unrun platform, detection holes, skills shortfalls.

3

Findings justify delivery services

Those gaps become the case for deployment, tuning, and day-to-day operations — the operate-the-platform work.

4

Expand at renewal

Move to MDR / Managed Threat Hunting / Managed XSIAM, and attach Koi (AES) as the net-new bundle add-on.

Who buys what

BuyerCares aboutLead with
CISOBoard-ready risk posture, breach readiness, cyber-insuranceCyber Risk Assessment, Breach Readiness, Retainer
SOC / Security Ops leadAlert fatigue, coverage, staffing gapsMDR, Managed Threat Hunting, SOC Assessment
Incident / crisis ownerFast response, forensic depth, recoveryRetainer, IR/DFIR, Tabletop
Compliance / riskFramework alignment, audits, pen-test mandatesPenetration Testing, Supply Chain, Cyber Risk Assessment
Cloud / platform teamCloud posture, AI/GenAI adoptionCloud Security Assessment, AI Security Assessment

Discovery questions

  • If you had a serious incident tomorrow, who responds in the first hour — and do you have a retainer with pre-negotiated SLAs?
  • When did you last validate your controls against real-world attack techniques (pen test, purple team, tabletop)?
  • Are you being measured against a framework — NIST CSF, CIS, ISO 27001 — or an audit deliverable?
  • Do you have the staff to operate the security platform you've invested in, 24/7?
  • Does your cyber-insurance policy require ransomware readiness or IR retainer evidence?
  • Which Cortex products are deployed today (XDR, XSIAM)? That determines MDR/MTH fit.
  • Any recent breach, near-miss, or compliance finding driving urgency right now?

Objection handling

"We already have an MSSP / IR provider."
Unit 42 is built on the same Palo telemetry the customer already owns (Cortex, Xpanse, Prisma Cloud), so response is faster and better-informed. A Retainer can coexist — many customers keep it as their escalation tier of last resort.
"It's too expensive."
Reframe around the cost of an unoperated platform and a slow breach response. The Retainer is a small, fixed commitment whose credits are usable proactively — it's insurance that also improves posture, not sunk cost.
"We'll deal with incidents if/when they happen."
Response time is everything — retainer customers get pre-negotiated SLAs and faster containment. Without one, hour zero is spent on paperwork and scoping instead of stopping the attacker.
"We don't have budget for services this cycle."
Start with the smallest Retainer to lock SLAs, then use its credits for a proactive assessment later in the term. It gets services into the deal without a large net-new line item.

Deal Economics

Unit 42 Multiplies the Deal

Services aren't a side item — they change the size, stickiness, and win-rate of the whole opportunity.

Counts as a product family

Unit 42 is one of the four eligible families (Firewall, Unit 42, Prisma SASE, Cortex) — every attach earns incentive points and feeds the Cross-Selling Bonus. See Deal Playbook.

Recurring & sticky

Retainers and managed services are subscription revenue that renews — the annuity that anchors the account year over year.

Raises platform win-rate

Services de-risk the customer's platform bet, reducing "no-decision" losses and making premium pricing defensible.

Get named on the deal reg early. Services attach at the point of the platform sale, not after. Bring Unit 42 into discovery so it's part of the deal architecture — and so the incentive credit lands. See the Partner Architects page for how to engage.