TL;DR: Help desk password resets cost about $70 per call, but Trusona’s analysis shows the bigger issue is that the same verification flow can be used by impersonators who know the answers, turning a routine support transaction into an account takeover path. The real problem is broken identity assurance at the moment of reset, not help desk efficiency.
At a glance
What this is: This is an analysis of the real cost of help desk password resets and how verbal verification can fail under social engineering, with account takeover as the hidden risk.
Why it matters: It matters because IAM teams need to treat help desk reset flows as identity assurance controls, not just support operations, especially where human identity, MFA recovery, and delegated verification intersect.
By the numbers:
- Forrester Research estimates the average IT labor cost of a single help desk password reset at $70.
- Gartner says password-related issues account for 20 to 50 percent of all help desk call volume.
👉 Read Trusona's analysis of help desk password resets and account takeover risk
Context
Help desk password resets are often treated as a support metric, but they are also an identity assurance checkpoint. When the reset process relies on verbal answers or knowledge-based verification, it can be repurposed by an attacker who has already assembled enough employee data from public sources to pass as legitimate.
For human identity programmes, the issue is not just cost per ticket. It is whether the reset workflow still proves that the caller is the real user, especially when MFA recovery, offboarding gaps, and delegated support processes are involved. For teams looking at modern identity assurance patterns, the NIST SP 800-63 Digital Identity Guidelines are a useful baseline for thinking about verifier strength and recovery flows.
The broader lesson is that operational friction and security assurance are not the same thing. A process can close quickly, stay within budget, and still create an account takeover path if the identity proofing step no longer distinguishes a genuine employee from a well-prepared impersonator.
Key questions
Q: How should organisations secure help desk password reset workflows against impersonation?
A: Use device-bound or cryptographic verification for all high-risk recovery events, and remove approval authority from the same agent who receives the call. Help desk scripts should not decide identity on the basis of public data, urgency, or tone. Where a reset can affect MFA, federation, or privileged access, the recovery path needs the same assurance as initial authentication.
Q: Who is accountable when a help desk reset enables account takeover?
A: Accountability sits with the identity governance model that allowed the override, not just with the individual support agent. If reset workflows are not approved, logged, and reviewed, the organisation has accepted a privileged access pathway without equivalent controls. That is an IAM and PAM governance issue, not a single-user mistake.
Q: What breaks when account recovery relies on verbal verification?
A: Verbal verification breaks when the attacker can sound credible, use public information, or pressure staff into acting quickly. It is difficult to audit, easy to spoof, and rarely strong enough for high-value access. Organisations that depend on it are effectively placing critical access decisions inside a conversation instead of inside a controlled identity process.
Q: Who should be accountable for fraudulent password resets?
A: Accountability should sit with the identity and access team, the service desk owner, and any third-party support provider that can complete recovery. If a reset can grant access to a regulated or privileged account, the organisation needs a clear owner for proofing standards, audit trails, and exception handling.
Technical breakdown
Why help desk resets become an identity weakness
A password reset is supposed to re-establish control over a human identity after credentials are lost or forgotten. In practice, many reset flows depend on information that is easy to discover or infer, such as manager names, job titles, or onboarding details. Once those fields are public, the help desk is no longer verifying identity so much as verifying research. That creates a mismatch between the control’s design and the attacker’s current tooling, especially when social engineering is combined with AI voice cloning and fast data gathering.
Practical implication: replace knowledge-based reset checks with stronger, out-of-band identity verification for recovery workflows.
Why the $70 figure hides the real risk
The $70 estimate captures labour, not assurance. It measures the cost of taking a call, not the cost of a fraudulent call that results in account takeover. That distinction matters because the same process can be both operationally expensive and security-ineffective at the same time. The reset ticket closes either way, but only one outcome preserves trust in the account. For IAM teams, support economics and identity risk need to be evaluated together, not as separate problems.
Practical implication: model reset cost alongside takeover impact, not as an isolated service desk KPI.
Out-of-band verification changes the recovery trust model
Out-of-band verification moves the trust decision away from verbal answers and toward a verified device or enrolled channel. That changes the security property of the workflow. A legitimate user can complete the reset faster, while an impersonator cannot satisfy the independent challenge without access to the enrolled device. In identity terms, the proof moves from what the caller knows to what the caller controls. That is a much stronger basis for recovery in environments where employee data is already exposed.
Practical implication: use device-bound or enrolled-channel verification as the default for high-risk password and MFA recovery.
Threat narrative
Attacker objective: The attacker’s objective is to obtain valid access through a trusted support workflow and use it to take over an employee account.
- Entry occurs when an attacker places a help desk call and impersonates a legitimate employee using publicly available personal and organisational details.
- Credential access follows when the agent completes the reset or MFA change, giving the attacker a fresh path into the account.
- Impact occurs when the newly reset account is used for account takeover, lateral movement, or broader disruption.
Breaches seen in the wild
- MITRE ATT&CK Enterprise Matrix — MITRE ATT&CK Enterprise — adversary tactics and techniques, threat detection, attack chain mapping, credential access, lateral movement, privilege escalation.
- Cisco DevHub NHI breach — IntelBroker exploited exposed Cisco credentials, API tokens and keys in DevHub.
Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Help desk password resets are now identity assurance events, not support events. The old model assumes that a caller who can answer a few questions is the legitimate user. That assumption is weak once employee data is widely exposed and impersonation tooling is cheap. IAM teams need to treat the reset workflow as part of the authentication boundary, not as an administrative afterthought.
Knowledge-based recovery is a brittle human identity control. It was designed for a world where the attacker lacked enough context to answer verification prompts. That assumption fails when public sources, breached data, and voice synthesis make the caller’s story easy to rehearse. The implication is that human identity recovery needs stronger proof than memory or persuasion.
Reset cost and takeover cost are the same control problem at different scales. The operational line item and the breach scenario both originate in the same identity decision point. A low-cost reset that can be abused by an impostor is not a cheap control, it is an underpriced risk transfer. Practitioners should evaluate recovery flows as a single governance domain, not as service desk efficiency plus security after the fact.
Out-of-band recovery is the named concept that matters here. The core issue is not password resets themselves, but the recovery trust gap between caller identity and caller control. Out-of-band verification closes that gap by requiring a separate, enrolled channel before the reset is granted. For identity programmes, that is the point where support process becomes access governance.
Delegated support creates an extended trust perimeter that many IAM programmes still ignore. When third-party help desks or outsourced support teams handle resets, the identity assurance boundary moves outside the core enterprise. That widens the place where impersonation can succeed and makes oversight harder. Practitioners should re-evaluate who is allowed to complete recovery, and under what proofing standard.
From our research:
- Only 5.7% of organisations have full visibility into their service accounts, according to the Ultimate Guide to NHIs.
- 96% of organisations store secrets outside of secrets managers in vulnerable locations including code, config files, and CI/CD tools, according to the Ultimate Guide to NHIs.
- For a lifecycle view of how identity trust degrades across provisioning, rotation, and offboarding, see NHI Lifecycle Management Guide.
What this signals
Help desk recovery is becoming part of the identity perimeter. Once attackers can research employee details and mimic voices, the recovery workflow itself becomes a control surface that must be governed like any other access pathway. Teams that still treat resets as a back-office service will miss where the trust decision is actually happening. The next step is to align recovery assurance with stronger identity standards such as NIST SP 800-63 Digital Identity Guidelines.
Identity proofing debt is the right way to think about this problem. Every reset method that depends on static or easily discoverable information creates a growing trust deficit as data exposure increases. That debt shows up as more impersonation risk, more escalation handling, and more audit friction when incidents occur. Organisations should review recovery flows with the same discipline they apply to privileged access and lifecycle offboarding.
For practitioners
- Replace knowledge-based reset checks Move high-risk password and MFA recovery away from questions that can be researched from public sources. Use device-bound verification or another enrolled second channel before any reset is completed.
- Measure fraudulent-call exposure Review ticket logs, escalation paths, and after-hours handling to identify where resets depend on human judgment alone. Track how often the workflow records identity proof beyond verbal confirmation.
- Segment recovery by risk level Apply stricter verification for privileged users, finance roles, and accounts with access to sensitive systems. Keep low-risk self-service flows separate from high-impact resets.
- Review third-party help desk controls If outsourced support can reset credentials, require the same proofing standard, audit trail, and escalation controls used internally. Delegated support should not weaken the recovery boundary.
Key takeaways
- Help desk resets can be operationally normal and security-dangerous at the same time when the proofing method no longer distinguishes a real employee from an impersonator.
- The cost of a reset is small compared with the impact of a successful takeover, so the right metric is assurance at the decision point, not ticket volume alone.
- Out-of-band verification and stricter recovery governance are the controls that change the risk equation for human identity recovery.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-63, NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the technical controls, while GDPR define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-63 | SP 800-63A | Recovery and identity proofing are central to the reset workflow. |
| NIST CSF 2.0 | PR.AC-1 | Identity proofing and access enforcement are core access-control concerns. |
| NIST SP 800-53 Rev 5 | IA-5 | Authenticator management applies directly to password and MFA recovery. |
| GDPR | Art.32 | Human identity recovery can affect the security of personal data access. |
Use stronger recovery proofing and enrolled-channel checks before approving password or MFA resets.
Key terms
- Service Desk Identity Proofing: Service desk identity proofing is the set of checks used to confirm a caller before a support analyst performs a sensitive action such as a password reset or account unlock. It should be consistent, auditable, and resistant to social engineering, because it functions as a control boundary.
- Out-Of-Band Verification: A confirmation step that uses a different channel or method than the original request. It reduces the chance that a single spoofed email, voice call, or video session can authorize privileged activity or financial transfer.
- Identity Assurance: The confidence an organisation has that a person or system is truly who it claims to be before access or action is granted. In modern IAM, assurance depends on evidence quality, channel trust, and the strength of verification around high-risk decisions.
- Recovery Trust Boundary: The line between preserving data and reintroducing it into operations. In identity-heavy environments, that boundary must account for credentials, permissions, and system state, because a restore can bring back compromise as easily as it brings back availability.
What's in the full article
Trusona's full blog post covers the operational detail this post intentionally leaves for the source:
- The full cost model behind the $70 reset estimate, including help desk labour and productivity loss assumptions.
- The MGM and Marks and Spencer examples used to show how fraudulent calls translate into account takeover and downstream disruption.
- The comparison between legitimate reset cost and risk-adjusted breach cost, useful for internal budgeting conversations.
- The out-of-band verification mechanism described as the practical alternative to verbal identity checks.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on August 25, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org