A client ran an unannounced security test against our platform and took it down for everyone else
We run a multi-tenant platform. One of our customers, without telling us, had a security assessment run against it. The first phase was an enormous volume of requests from an unauthenticated source, which we initially treated as an attack, and which degraded the service for our other customers during business hours.
We now know who it was, because they told us afterwards while asking for the findings to be addressed.
I am trying to work out how to respond. I am annoyed, other customers were affected, and I also want to keep this client. What is the reasonable position here?
@blue_team_bora · 6d ago
For the forward-looking part: offering a customer testing policy proactively is worth more than it costs.
Enterprise customers increasingly want to test their suppliers, and a supplier who says "here is the process, here is the window, here is the staging environment" looks far more mature than one who has never considered it. It also means the next customer who wants this asks you first, which is the actual outcome you want.
Many platforms publish exactly such a policy. It turns an awkward request into a form.
Reply
Report