Ask

A client ran an unannounced security test against our platform and took it down for everyone else

The practical sequence that keeps the relationship while making the point, which is what you asked for:

  1. Handle it as an incident first. Whatever your process is for a suspected attack, follow it, including any notification you owe your other customers. Do not skip that because you now know the source.
  2. Contact the client at a senior level, calmly, in writing. State what happened, what the impact on other customers was, and that testing requires prior written authorisation from you.
  3. Say yes to the underlying request. They wanted assurance about your security. That is a legitimate thing for a customer to want and the answer should be a process, not a refusal.
  4. Put that process in writing and offer it to everyone: a defined testing window, a staging environment, scope limits, a contact, and rate limits. Ask for notice.
  5. Get it into the contract at renewal, along with the corresponding prohibition on unauthorised testing.

Step 3 is what converts this from a dispute into an improvement, and it is the difference between keeping the account and winning an argument.

27 · in/client-work ·