Nine o'clock and the client's operations team
Testing starts on a Monday morning. Your tester is supposed to email the client's IT lead and their managed service provider before starting, so that anyone watching their alerts knows the unusual traffic is expected. They remember on Monday. On Tuesday they start straight in, and the client's MSP raises an incident about suspicious activity, wakes a director, and asks your firm why nobody warned them.
On Wednesday, the tester finds something serious: a critical issue on an internet-facing system that the client will want to know about now, not in the report in two weeks. Your firm's process says a critical finding is escalated immediately. The tester searches their email for the escalation contact from the kick-off call. The contact on file is on leave. It takes an hour to reach someone.
Each step is simple. Each step depends on one tester remembering, and on contacts that were agreed once in a call.
At the end of the engagement, nobody can easily show which notices were sent, to whom, and when, if the client later asks.
Why notices and escalations are inconsistent
- Start and stop notices are written by hand from each tester's own inbox.
- Who should receive them (client IT, their MSP, their SOC) varies per engagement.
- Escalation contacts are captured in the kick-off call and saved in notes.
- Critical findings are escalated by whatever route the tester thinks of, and not always recorded.
- When testers change mid-engagement, the new tester does not know the arrangements.
What counts as a critical finding for immediate notice, and how it should be communicated, is set by your own methodology and agreed with each client. We build to those rules.
What inconsistency costs
| Slip | Consequence |
|---|---|
| Start notice missed | Client's monitoring team raises a false incident |
| Notice sent to wrong people | Confusion, lost trust |
| Escalation contact unavailable | Delay on a finding the client needed now |
| Escalation not recorded | No evidence it was raised, if asked later |
| Handover between testers | Arrangements lost mid-engagement |
The engagement notifications we build
- Contacts for each engagement are recorded by role in the pre-test pack: notice recipients, primary and backup escalation contacts, with phone numbers and hours, confirmed by the client before testing.
- Testers send start and stop notices with one tap from their phone or a button in the engagement record. Notices use your template, include the tester's name and source IP addresses, and go to the right recipients automatically.
- If no start notice has been sent by a set time on a testing day, the tester and operations get a reminder.
- A critical finding is raised through a short form: summary, affected system, and whether testing continues. It is sent to the escalation contacts by email and SMS, with a phone call prompt to the tester, and escalates to the backup contact if not acknowledged within the time you set.
- Every notice and escalation is recorded against the engagement with times and acknowledgements.
- If a different tester takes over, they see all contacts and arrangements in the engagement record.
Messages go out from your firm's domain and through an SMS service such as Twilio, and the content of a critical finding notice is kept to what is needed to act, with detail shared by phone or through your portal.
A testing week with it in place
Start and stop notices go out every day, to the right people, with the right source addresses, whichever tester is on the job. The client's monitoring team is never surprised. When a critical finding appears, the tester raises it in a minute and the right person hears quickly, with a backup if they do not. The engagement record shows every notice and escalation, which is useful for the client's own records too.
Operations can see, across all live engagements, that notices have gone out today, and are told when they have not.
Is this your firm?
- Testers send start and stop notices from their own inboxes.
- A client's monitoring team has raised an incident about your testing.
- Escalation contacts are found by searching old emails.
- Critical finding escalations are not recorded consistently.
- Arrangements are lost when testers change mid-engagement.