Skip to content

PagerDuty configuration hardening security checks

Vendor-recommended secure defaults, patch levels and housekeeping settings that drift as tenants grow and admins change.

On PagerDuty, Black Cat runs 7 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the PagerDuty connector needs.

Checks (7)

severity: high User Without Notification Rules fix difficulty: easy #

Configure notification rules for PagerDuty users so they receive incident alerts

  1. Sign in to PagerDuty as an Admin or Account Owner
  2. Navigate to People > Users and click on the affected user
  3. Select the "Notification Rules" tab
  4. Click "Add Notification Rule" and configure a high-urgency rule (e.g., immediately via phone or SMS)
  5. Add a low-urgency rule as well if applicable
  6. Save the notification rules

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: high User Without Contact Methods fix difficulty: easy #

Add contact methods (phone, SMS, email) to PagerDuty users so they can be reached during incidents

  1. Sign in to PagerDuty as an Admin or Account Owner
  2. Navigate to People > Users and click on the affected user
  3. Select the "Contact Information" tab
  4. Click "Add Phone Number" or "Add SMS Number" and enter the contact details
  5. Verify the contact method by following the confirmation steps
  6. Save the contact information

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: medium Empty Team fix difficulty: easy #

Add members to empty PagerDuty teams or delete them if no longer needed

  1. Sign in to PagerDuty as an Admin or Account Owner
  2. Navigate to People > Teams and find the empty team
  3. If the team is still needed, click on it and add members using the "Add Members" button
  4. If the team is no longer needed, click "Delete Team"
  5. Confirm the change

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: medium Service Without Integrations fix difficulty: easy #

Add integrations to PagerDuty services so they can receive events and trigger incidents

  1. Sign in to PagerDuty as a Manager, Admin, or Account Owner
  2. Navigate to Services > Service Directory and click on the affected service
  3. Select the "Integrations" tab
  4. Click "Add Integration" and choose the appropriate monitoring tool or event source
  5. Configure the integration with the required credentials or webhook URL
  6. Save and test the integration by sending a test event

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: medium Service Without Acknowledgement Timeout fix difficulty: easy #

Set an acknowledgement timeout on PagerDuty services to auto-escalate unacknowledged incidents

  1. Sign in to PagerDuty as a Manager, Admin, or Account Owner
  2. Navigate to Services > Service Directory and click on the affected service
  3. Select the "Settings" tab
  4. Under "Incident Settings", locate the "Acknowledgement Timeout" option
  5. Set a timeout value (e.g., 30 minutes) appropriate for the service
  6. Save the service configuration

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: low Escalation Policy Without Services fix difficulty: easy #

Attach orphaned escalation policies to services or remove them if no longer needed

  1. Sign in to PagerDuty as a Manager, Admin, or Account Owner
  2. Navigate to People > Escalation Policies and find the unattached policy
  3. If the policy is still needed, navigate to Services > Service Directory
  4. Edit the appropriate service and assign this escalation policy under "Assign and Notify"
  5. If the policy is no longer needed, delete it from the Escalation Policies page

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: low Schedule Not Linked to Escalation Policy fix difficulty: easy #

Link orphaned on-call schedules to escalation policies or remove them if unused

  1. Sign in to PagerDuty as a Manager, Admin, or Account Owner
  2. Navigate to People > On-Call Schedules and find the unlinked schedule
  3. If the schedule is still needed, navigate to People > Escalation Policies
  4. Edit the appropriate escalation policy and add this schedule as a target
  5. If the schedule is no longer needed, delete it from the On-Call Schedules page

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

More PagerDuty checks

The information on this page is provided for general informational purposes and is believed to be accurate as of its most recent update. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Descriptions of third-party applications and of compliance frameworks are based on publicly available documentation and may change over time.

See these checks run on your stack

Start a free 14-day trial — no credit card required.

Start Free Trial