Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

Help desk resets and account takeover risk: are your controls enough?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 19565
Topic starter  

TL;DR: Help desk password resets cost about $70 per call, but Trusona’s analysis shows the bigger issue is that the same verification flow can be used by impersonators who know the answers, turning a routine support transaction into an account takeover path. The real problem is broken identity assurance at the moment of reset, not help desk efficiency.

NHIMG editorial — based on content published by Trusona: The $70 Call: A Help Desk Story About the Math We Ignore

By the numbers:

Questions worth separating out

Q: How should organisations secure help desk password reset workflows against impersonation?

A: Use device-bound or cryptographic verification for all high-risk recovery events, and remove approval authority from the same agent who receives the call.

Q: Who is accountable when a help desk reset enables account takeover?

A: Accountability sits with the identity governance model that allowed the override, not just with the individual support agent.

Q: What breaks when account recovery relies on verbal verification?

A: Verbal verification breaks when the attacker can sound credible, use public information, or pressure staff into acting quickly.

Practitioner guidance

  • Replace knowledge-based reset checks Move high-risk password and MFA recovery away from questions that can be researched from public sources.
  • Measure fraudulent-call exposure Review ticket logs, escalation paths, and after-hours handling to identify where resets depend on human judgment alone.
  • Segment recovery by risk level Apply stricter verification for privileged users, finance roles, and accounts with access to sensitive systems.

What's in the full article

Trusona's full blog post covers the operational detail this post intentionally leaves for the source:

  • The full cost model behind the $70 reset estimate, including help desk labour and productivity loss assumptions.
  • The MGM and Marks and Spencer examples used to show how fraudulent calls translate into account takeover and downstream disruption.
  • The comparison between legitimate reset cost and risk-adjusted breach cost, useful for internal budgeting conversations.
  • The out-of-band verification mechanism described as the practical alternative to verbal identity checks.

👉 Read Trusona's analysis of help desk password resets and account takeover risk →

Help desk resets and account takeover risk: are your controls enough?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 4 months ago
Posts: 19156
 

Help desk password resets are now identity assurance events, not support events. The old model assumes that a caller who can answer a few questions is the legitimate user. That assumption is weak once employee data is widely exposed and impersonation tooling is cheap. IAM teams need to treat the reset workflow as part of the authentication boundary, not as an administrative afterthought.

A few things that frame the scale:

  • Only 5.7% of organisations have full visibility into their service accounts, according to the Ultimate Guide to NHIs.
  • 96% of organisations store secrets outside of secrets managers in vulnerable locations including code, config files, and CI/CD tools, according to the Ultimate Guide to NHIs.

A question worth separating out:

Q: Who should be accountable for fraudulent password resets?

A: Accountability should sit with the identity and access team, the service desk owner, and any third-party support provider that can complete recovery. If a reset can grant access to a regulated or privileged account, the organisation needs a clear owner for proofing standards, audit trails, and exception handling.

👉 Read our full editorial: Help desk identity verification fails when attackers know the answers



   
ReplyQuote
Share: