It Depends on What You're Trying to Measure

Whether to notify your IT team and employees before a penetration test depends on your objectives. There are good reasons to go either way, and the right answer often involves partial disclosure — telling some people but not others.

The Case for Notifying IT Staff

Notifying your IT team allows them to: be prepared to assist if needed, avoid unnecessarily responding to testing activity as a real incident, and handle automated blocking systems (IPS, EDR, SIEM alerts) appropriately. Most network penetration tests involve notifying at least a small group of IT leadership who serve as points of contact.

The Case for Blind Testing

If one of your objectives is to test your incident detection and response capabilities — how quickly your team notices an attacker, and how effectively they respond — then notifying IT defeats the purpose. Blind or "red team" engagements specifically withhold information from IT staff to assess real detection capability.

Social Engineering: The Notification Decision Matters Most

For social engineering assessments, the decision is particularly consequential. Notifying employees before a phishing campaign eliminates its value entirely. Most clients choose not to notify staff prior to social engineering testing — but do notify HR and select leadership so they can manage any employee concerns that arise.

Our Recommendation

For most network penetration tests: notify a small group of IT leadership but not the broader team. For social engineering: don't notify staff, but notify HR and select leadership. We'll discuss the right approach for your specific engagement before testing begins.

Not sure how to set up your engagement?

We're happy to walk through the options and help you design the most valuable test for your organization.

Talk to an Expert →