PagerDuty configuration hardening security checks
Vendor-recommended secure defaults, patch levels and housekeeping settings that drift as tenants grow and admins change.
On PagerDuty, Black Cat runs 7 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the PagerDuty connector needs.
Checks (7)
severity: high User Without Notification Rules fix difficulty: easy #
Configure notification rules for PagerDuty users so they receive incident alerts
- Sign in to PagerDuty as an Admin or Account Owner
- Navigate to People > Users and click on the affected user
- Select the "Notification Rules" tab
- Click "Add Notification Rule" and configure a high-urgency rule (e.g., immediately via phone or SMS)
- Add a low-urgency rule as well if applicable
- Save the notification rules
Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10
severity: high User Without Contact Methods fix difficulty: easy #
Add contact methods (phone, SMS, email) to PagerDuty users so they can be reached during incidents
- Sign in to PagerDuty as an Admin or Account Owner
- Navigate to People > Users and click on the affected user
- Select the "Contact Information" tab
- Click "Add Phone Number" or "Add SMS Number" and enter the contact details
- Verify the contact method by following the confirmation steps
- Save the contact information
Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10
severity: medium Empty Team fix difficulty: easy #
Add members to empty PagerDuty teams or delete them if no longer needed
- Sign in to PagerDuty as an Admin or Account Owner
- Navigate to People > Teams and find the empty team
- If the team is still needed, click on it and add members using the "Add Members" button
- If the team is no longer needed, click "Delete Team"
- Confirm the change
Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10
severity: medium Service Without Integrations fix difficulty: easy #
Add integrations to PagerDuty services so they can receive events and trigger incidents
- Sign in to PagerDuty as a Manager, Admin, or Account Owner
- Navigate to Services > Service Directory and click on the affected service
- Select the "Integrations" tab
- Click "Add Integration" and choose the appropriate monitoring tool or event source
- Configure the integration with the required credentials or webhook URL
- Save and test the integration by sending a test event
Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10
severity: medium Service Without Acknowledgement Timeout fix difficulty: easy #
Set an acknowledgement timeout on PagerDuty services to auto-escalate unacknowledged incidents
- Sign in to PagerDuty as a Manager, Admin, or Account Owner
- Navigate to Services > Service Directory and click on the affected service
- Select the "Settings" tab
- Under "Incident Settings", locate the "Acknowledgement Timeout" option
- Set a timeout value (e.g., 30 minutes) appropriate for the service
- Save the service configuration
Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10
severity: low Escalation Policy Without Services fix difficulty: easy #
Attach orphaned escalation policies to services or remove them if no longer needed
- Sign in to PagerDuty as a Manager, Admin, or Account Owner
- Navigate to People > Escalation Policies and find the unattached policy
- If the policy is still needed, navigate to Services > Service Directory
- Edit the appropriate service and assign this escalation policy under "Assign and Notify"
- If the policy is no longer needed, delete it from the Escalation Policies page
Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10
severity: low Schedule Not Linked to Escalation Policy fix difficulty: easy #
Link orphaned on-call schedules to escalation policies or remove them if unused
- Sign in to PagerDuty as a Manager, Admin, or Account Owner
- Navigate to People > On-Call Schedules and find the unlinked schedule
- If the schedule is still needed, navigate to People > Escalation Policies
- Edit the appropriate escalation policy and add this schedule as a target
- If the schedule is no longer needed, delete it from the On-Call Schedules page
Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10