Solusec: Solutions for Cyber Security

Operated by Solusec Ltd
CREST accredited · IASME Certification Body

How it runs

What a white-labelled engagement looks like, week by week

The commercial arrangement is the easy part. What partners want to know is who says what to whom, and at which point it stops being your problem or becomes it again.

Penetration testing for MSPs › White-label mechanics

White-label is described everywhere as a branding arrangement. It is mostly a choreography arrangement. The logo on the front of the report takes about ten minutes to sort out. What takes thought is the sequence of conversations between three parties, one of whom does not know the third exists, and deciding in advance who leads each one.

Below is the full run of a typical resold engagement, in order. It assumes a mid-sized client, a contained scope and a report going out under your brand. Timings are indicative rather than contractual.

Week zero: the email that starts it

A client forwards you something. An insurer’s renewal condition, a customer’s security questionnaire, a tender clause, or a board minute. They ask you to deal with it, because you are the people whose number they have.

The first decision is whether you take that to a provider straight away or spend twenty minutes with the client first. Take it straight away and you will get a quote for the wrong thing, because the forwarded email almost never contains a scope. Spend the twenty minutes and you can usually answer half the provider’s scoping questions yourself, which is the difference between a quote in a day and a quote in a week.

What you need out of that twenty minutes is small: what is driving it, what the deadline actually is, and a rough list of what the client considers to be in scope. Not a technical inventory. You will fill that in yourself.

Week zero to one: the scoping conversation

This is the first branch point and it is worth deciding deliberately rather than by default.

You scope it and pass it on. Works when the target is something you built and run, where you can name the hosts, the applications, the user roles and the hosting arrangement without asking anybody. Fastest route, and the one where white-label is genuinely invisible.

You put us on the call with the client, introduced as your testing team. Works when the target is a third-party application, a SaaS platform you do not administer, or anything where the client’s own developers hold the knowledge. Slower to arrange, much faster to get right.

You put us on the call as a named subcontractor. Some partners prefer this and their clients are perfectly comfortable with it. It removes a category of awkwardness later.

All three work. What does not work is leaving it unresolved until the day of the call, at which point somebody improvises an introduction in front of the client.

Week one: quote, authorisation and dates

The quote comes to you, stating the tester-days and how they split across the scope. You price it to your client however you price things. From our side the quote is to you; from the client’s side there is one supplier and one number.

Then the authorisation, which is where partner-placed tests stall more often than anywhere else. The rules of engagement have to be signed by a person at the end client with the authority to commit the business. Not you on their behalf, however long you have run their estate and however clearly they asked you to sort it. Testing without that signature is not a paperwork failure. It is unauthorised access.

So identify the signatory early and warn them it is coming. It is frequently a director or a finance person who has not been in any of the conversations so far and will want to read it properly. Where you hold a broad services agreement, check what it actually says about acting for them; in most cases it does not extend this far.

Standard lead time from agreed scope to testing is two to three weeks. For a contained scope at short notice it is often inside a week, but the constraint in that case is usually the signature rather than tester availability.

Week two or three: the testing window

During the window the tester works to the agreed scope and the agreed hours. Three things are worth settling before it opens.

What the tester does and does not say

Partners ask this more than any other question, so here it is directly. On a white-labelled engagement the tester answers technical questions about the target and the findings. They do not comment on who should be running the client’s IT, do not volunteer opinions about the incumbent provider, and do not offer to fix anything, because we do not sell the fixing.

What they will not do is lie. If a client asks a direct question about who is doing the testing and whether the firm is accredited, the answer is truthful. That is a requirement of the accreditation, and it is also the whole reason your client’s tender clause is satisfied. Putting your brand on a deliverable is legitimate. Misrepresenting who holds the credential is not, and a provider willing to do the second would be a liability to you rather than an asset.

Weeks three to four: report, review and delivery

The report is written, then reviewed by a second person before it goes anywhere. That review is not a formality and it takes real time, which is why the report does not arrive the morning after testing finishes. Reports and submissions are written by people, never by AI.

It is then produced in your house template, carrying your brand and your contact details, and delivered to you rather than to the client. You release it. That ordering matters: it means you read the findings before your client does, and you get to decide how the conversation opens.

The handover points, in one place

Who holds the engagement at each stage
StageHeld byWhat goes wrong if it is unclear
Requirement to scopeYou, usuallyA quote for work the client did not need
Scope to quoteUsNothing, this is the easy part
AuthorisationThe client, signed personallyThe test cannot start, whatever the date says
Access and credentialsYou, or the client via youDay one is spent on access instead of testing
Mid-test escalationUs to you, you to the clientA critical finding sits unactioned overnight
Report deliveryUs to you, you to the clientYour client reads findings about your estate before you do
Debrief callWhichever you chose at scopingAn improvised introduction in front of the client
RemediationYouNothing, this is the part you wanted
RetestUs, scheduled by youClosure is never evidenced and the insurer asks again

Where partners get caught out

Five patterns, all of them avoidable, and all of them common enough to be worth naming.

  1. Promising a date before the signatory is identified. The single most frequent cause of a missed deadline on partner-placed work. Find the person who can sign before you commit to a week.
  2. Quoting from the client’s description rather than your own knowledge. Clients describe their systems the way they experience them. You know what is actually there. Use that.
  3. Not reading the report before forwarding it. On a managed client the findings are frequently about work you did. Reading it first costs an hour and changes the entire conversation.
  4. Treating the retest as optional. The insurer or the customer asking for the test generally wants evidence that findings were closed, not evidence that they were found.
  5. Leaving branding until the report is ready. Send the template, the logo and your severity wording at the start. Retrofitting a house style to a finished document wastes days on an engagement that usually has a deadline.

When white-label is not the right answer

If the client already has a direct relationship with a testing firm they trust, or if their procurement requires the testing supplier to contract with them directly, or if the deliverable has to name the testing entity for a regulatory reason, then reselling adds a layer without adding value. Refer it instead, keep the remediation, and spend your effort where it pays. We would rather tell you that on the first call than build a resale that creates problems for you at delivery.

Can we keep the testing provider completely invisible to the client?

In practice, usually yes, and plenty of partners run it that way. The limit is honesty: if the client asks directly who is doing the testing or whether the firm is accredited, the answer will be truthful. That is a condition of the accreditation and it is also what makes the report satisfy a tender clause naming CREST. Your brand goes on the document; the credential stays where it was earned.

Who signs the rules of engagement on a resold test?

A person at the end client with authority to commit the business. Not you, even under a broad managed services agreement, and even when the client has explicitly asked you to handle the whole thing. The authorisation is what makes the engagement lawful, so it has to come from the party whose systems are being tested. Identify that person in week one rather than week three.

How much of our time does a placed engagement actually take?

For a contained scope on an estate you run, expect two to four hours across the whole thing: the scoping conversation, chasing the signature, getting credentials working, and reading the report before you release it. For a client with a third-party application and no internal owner, it is more, and most of the extra is coordination rather than technical work.

What happens if a critical finding turns up mid-test?

It is reported immediately rather than held for the document, which means a call to whoever was named at scoping. On a white-labelled engagement that is normally you first, so you can decide how it reaches the client. Agree the order and the out-of-hours contacts before the window opens, because a critical finding at four o’clock on a Friday is a bad time to be working out who to ring.

Ask how it would run for your client

Tell us what the client is, what is driving the test and how visible you want us to be. You will get partner terms and a realistic sequence back in writing, usually within one business day.