MDR Customer Penetration Testing Expectations Policy
-
Executive Summary
This policy establishes clear expectations for how our Managed Detection and Response (MDR) service handles customer-initiated penetration testing. It outlines how often and under what conditions customers may conduct penetration tests, outlines communication requirements, and describes how tests are classified and handled within MDR workflows.
The goal is to balance realistic, valuable security testing with operational stability. The policy ensures our MDR service can focus on genuine threats while still providing customers meaningful opportunities to assess detection, response and incident management capabilities.
Purpose
This policy sets expectations for how Sophos Managed Detection and Response (MDR) service will handle customer-initiated penetration tests, both human-led and automated, and outlines the shared responsibilities for communication, frequency, and collaboration.
By setting clear expectations, we prevent misaligned assumptions, minimize unnecessary escalations, and maintain clarity and confidence across customers, partners, and internal teams throughout the testing process.
Relationship to MDR Service Description
This policy is intended to operate as a standalone MDR policy document and will be referenced by the MDR Service Description.
1. Notification & Communication
We do not require prior notification for human-led or automated penetration tests. We welcome realistic, unannounced scenarios to fully test MDR's detection, response and incident management capabilities.
Although advanced notice is not required; the customer should provide prompt confirmation and collaboration once a test is detected to ensure the activity is correctly identified and managed.
This policy applies to penetration testing activities intended to assess MDR detection and response capabilities. Continuous or non-MDR-focused testing (for example, ongoing BAS or EDR validation) is subject to the additional coordination requirements in Section 6.
2. Collaboration
Effective collaboration between the customer and the Sophos MDR team is essential to ensure accurate detection, timely response, and minimal operational disruption during penetration testing activities.
It also underpins meaningful improvement: by working together and treating the exercise as if it were a real threat, simulating realistic attacker behaviour and real-world communication patterns, both parties can accurately test processes, identify gaps, and agree to develop concrete actions to strengthen detection, response, and collaboration moving forward.
During penetration testing, the Sophos MDR team will perform as follows:
- Detect, investigate, and respond to suspected malicious activity using the same workflows and playbooks applied to genuine threats.
- As part of this standard workflow, escalate to the customer in line with the escalation policy and contact details defined in the customer's configured Threat Response mode(s).
-
Once the customer confirms that the activity is authorized penetration testing, the Sophos MDR team will:
- Cease standard investigation, threat response actions, and further containment or recovery activities relating to that test activity.
- Classify and tag the associated case and underlying detections as penetration testing activity.
- Continue to detect and correlate subsequent test-related alerts into the same (or related) case for visibility, without initiating further outreach or escalation to the customer for the duration of that test, unless a separate, unrelated threat is identified.
Customers are expected to maintain prompt and clear communication throughout the test lifecycle. For the purposes of this policy, prompt communication is defined as:
- Immediate phone confirmation, if contact is made via telephone or voice call.
- Response within one (1) hour, if initial outreach is made via email or other asynchronous channel.
Customers are expected to:
- Confirm that the observed activity is authorized penetration testing, upon request from the MDR team.
- Notify the MDR team when the test has concluded, enabling proper closure of related detections and normalization of behavioural baselines.
- Provide supporting artifacts (e.g., assessment reports, tools used, payload samples) where analysis gaps are identified, to assist the MDR team in accurately classifying and resolving activity.
This collaborative approach ensures that Sophos MDR Team can initially act as though activity is a genuine threat, then safely transition to a penetration testing-handling mode once confirmed, driving both realistic assessment and operational efficiency for both parties.
Customers who do not adhere to this sub-policy will be deemed to be in a non-compliant state. See Appendix.
3. Frequency Expectations
The customer should conduct no more than two (2) penetration testing simulations per 12-month period.
If we detect additional penetration tests beyond this frequency and have a high degree of confidence that the activity is test-related, these will be:
- Detected and acknowledged in our systems, classified as testing activity.
- Handled outside of standard SLAs, meaning they will not trigger the usual response, triage, or escalation workflows.
These frequency expectations apply to discrete penetration tests designed to evaluate MDR. Properly coordinated Continuous and Non-MDR-Focused Testing, as described in Section 6, is excluded from this limit but may be subject to tuning or suppression and is not handled under standard MDR SLAs.
Customers who do not adhere to this sub-policy will be deemed to be in a non-compliant state. See Appendix.
4. Minimum Interval & Duration of Tests
Penetration tests should be conducted at intervals no less than three (3) months apart. This cadence allows sufficient time for remediation, tuning, and ongoing improvement between assessments.
Additionally, the maximum duration of any individual test engagement should not exceed five (5) consecutive days. Extended testing beyond this threshold may lead to challenges in detection clarity, alert fatigue, and operational disruption.
Customers who do not adhere to this sub-policy will be deemed to be in a non-compliant state. See Appendix.
5. Quality and Realism of Pen Tests
Penetration tests should aim to simulate realistic attack scenarios.
We expect tests to model genuine adversarial behaviours, such as gaining initial access, privilege escalation, and lateral movement, rather than relying on default administrative access or artificially simplified entry methods.
This approach ensures our MDR service can assess real-world detection and response effectiveness.
The presence of existing vulnerabilities within a customer environment could significantly influence the outcome of the penetration test and may impact the MDR response.
Customers who do not adhere to this sub-policy will be deemed to be in a non-compliant state. See Appendix.
Detection and Case Generation Expectations
Sophos MDR is designed to identify, investigate, and respond to security activity that meets MDR detection, correlation, severity, and investigation thresholds. Customers should not assume that every Pen Test activity will result in a case, escalation, or analyst-led investigation.
Examples of activity that may not generate an MDR case include, but are not limited to:
- basic port scanning or service enumeration;
- low-volume or non-impactful reconnaissance;
- certain brute-force attempts that do not meet detection or escalation thresholds;
- vulnerability scanning without associated exploit activity;
- benign or expected administrative activity;
- isolated tool execution that is blocked, low severity, or lacks sufficient malicious context.
6. Continuous and Non-MDR-Focused Testing
Some customers may wish to conduct continuous or high-frequency testing activities that are not primarily intended to assess Sophos MDR, but instead focus on validating their own infrastructure, endpoint protection, hardening, or wider IT estate.
For the purposes of this policy, Continuous and Non-MDR-Focused Testing includes, but is not limited to:
- Ongoing or scheduled use of breach-and-attack simulation (BAS) platforms
- Automated red-team or purple-team tooling configured to run regularly
- Repeated or continuous testing of EDR/AV configurations and controls
- High-frequency internal security validation exercises that generate repeated or predictable detections
These activities are distinct from the customer-initiated penetration tests described in Sections 2–5, which are explicitly intended to test MDR's detection, response, and incident management capabilities.
6.1 Notification Requirements
Because continuous or automated testing has the potential to generate sustained volumes of security telemetry, advance notification is required when customers intend to perform Continuous and Non-MDR-Focused Testing that may trigger MDR-visible alerts.
Customers are expected to:
- Provide reasonable advance notice (e.g., at least five (5) business days) before enabling or significantly changing such testing.
- Share a high-level description of tools, techniques, and expected behaviours (for example: tooling name, approximate schedule/frequency, typical alert patterns, and primary targets).
- Identify which activities are out of scope for MDR response (for example: specific test accounts, hosts, or domains used by the tool).
This notification enables Sophos MDR to:
- Implement appropriate tuning, tagging, or suppression to avoid unnecessary investigation of known test activity.
- Preserve MDR capacity and focus for genuine threats.
- Reduce the risk of alert fatigue or desensitisation caused by constant test-generated activity.
6.2 Relationship to Penetration Testing Limits
When properly coordinated in advance and clearly identified as Continuous and Non-MDR-Focused Testing:
- These activities will not count towards the penetration test frequency limits described in Section 3; and
- The interval and duration expectations in Section 4 do not apply to such testing.
However, Sophos MDR will not commit to standard SLAs or full investigation workflows for activity that has been explicitly agreed as Continuous and Non-MDR-Focused Testing and may be subject to tuning, tagging, or suppression.
6.3 Uncoordinated Continuous Testing
Where continuous or high-frequency testing is introduced without prior coordination and results in persistent or repetitive alerts observable by Sophos MDR:
- The activity may be classified as non-compliant under this policy and handled in accordance with the Appendix.
- Detection and case generation related to that activity may be suppressed, deprioritized, or excluded from standard MDR SLAs to preserve operational efficiency.
- The customer will be notified and asked to either coordinate the testing under Section 6.1 or adjust its scope, frequency, or configuration.
This approach ensures customers can obtain the benefits of continuous assurance and tooling-driven testing, while Sophos MDR remains focused on true threats and maintains high-quality, reliable detection and response for the production environment.
Appendix: Non-Compliance Handling
The following outlines how non-compliant penetration testing activity will be managed within the MDR service framework.
A. Identification of Non-Compliance
A customer may be deemed non‑compliant if they fail to adhere to any of the sub‑policies defined in this document. Specifically, non‑compliance includes (but is not limited to):
- Exceeding the permitted frequency: conducting more than two (2) customer‑initiated penetration tests within a rolling 12‑month period.
- Violating interval or duration requirements: initiating tests less than three (3) months apart or running engagements that exceed five (5) consecutive days in duration.
- Failing to meet quality and realism expectations, including tests that do not adhere to the realism requirements outlined in Section 5.
- Insufficient customer collaboration, such as failing to confirm test activity when requested, failing to notify when testing concludes, or not providing reasonable artifacts necessary for accurate analysis.
- Operating continuous or high-frequency testing that generates sustained MDR-visible alerts without the advance coordination described in Section 6.
B. Initial Notification
Upon identifying non‑compliant activity:
- The MDR team will notify the customer's designated contacts, outlining the nature of the non‑compliance and requesting confirmation of the activity along with a plan to realign with this policy.
- If the MDR team attempts to contact all designated contacts on two separate occasions without receiving a response or acknowledgement, the activity will be treated as unconfirmed test behaviour and will activate temporary suppression.
C. Temporary Suppression
While in a non-compliant state:
- Detection and case generation related to repeated test activity may be suppressed or deprioritized to preserve operational efficiency.
- Standard SLAs will not apply to detections identified as part of non-compliant testing.
D. Reinstatement to Compliance
To return to a compliant state, the customer must:
- Cease all uncoordinated or excessive test activity.
- Acknowledge the non-compliance and confirm corrective measures.
- Allow at least three (3) months before resuming any new penetration testing activity.
Once compliance is confirmed, full MDR detection, response, and SLA processes will continue.
E. Escalation
Continued disregard for these requirements may result in:
- Formal notice of breach of MDR service terms.
- Restriction or suspension of MDR services related to detection or case handling.
- Referral to account management or contractual review.
Summary Table: Penetration Testing Compliance Expectations
| Category | Compliant Behaviour | Non-Compliant Behaviour |
|---|---|---|
| Test Frequency | Up to two (2) customer-initiated penetration tests within a rolling 12-month period | More than two (2) customer-initiated penetration tests within a 12-month period |
| Test Interval | At least three (3) months between penetration tests | Penetration tests initiated less than three (3) months apart |
| Test Duration | Individual penetration tests last no more than five (5) consecutive days | Penetration tests that exceed five (5) consecutive days |
| Test Confirmation | Prompt confirmation and end-of-test notification provided by the customer | No confirmation or delayed confirmation; failure to acknowledge test completion |
| Test Quality | Realistic attack simulation (e.g., privilege escalation, lateral movement, etc.) | Simplistic or artificial scenarios (e.g., default credentials, unrealistic assumptions) |
| Collaboration | Clear communication and reasonable artifact sharing (e.g., reports, tools, payload samples) to support accurate analysis | Little or no collaboration; refusal or failure to share reasonable supporting details necessary for accurate analysis |
| Reinstatement | Ceases non-compliant activity and aligns to policy; minimum three (3) month reset period before resuming penetration testing | Repeated excessive or uncoordinated testing; no corrective action taken to address identified non-compliance |
| Continuous Testing | Continuous or high-frequency testing coordinated in advance per Section 6; MDR informed of tools, scope and frequency; MDR tuning/suppression agreed as needed | Continuous or high-frequency testing that generates sustained MDR-visible alerts without prior coordination as described in Section 6; activity may be suppressed, deprioritized, or treated as non-compliant |