The practical sequence that keeps the relationship while making the point, which is what you asked for:
- Handle it as an incident first. Whatever your process is for a suspected attack, follow it, including any notification you owe your other customers. Do not skip that because you now know the source.
- Contact the client at a senior level, calmly, in writing. State what happened, what the impact on other customers was, and that testing requires prior written authorisation from you.
- Say yes to the underlying request. They wanted assurance about your security. That is a legitimate thing for a customer to want and the answer should be a process, not a refusal.
- Put that process in writing and offer it to everyone: a defined testing window, a staging environment, scope limits, a contact, and rate limits. Ask for notice.
- Get it into the contract at renewal, along with the corresponding prohibition on unauthorised testing.
Step 3 is what converts this from a dispute into an improvement, and it is the difference between keeping the account and winning an argument.