TL;DR: Social engineering drives 50 to 90% of breaches and the average global breach cost reached USD 4.45 million in IBM's 2023 data, according to Trusona, which argues that help desk verification can prevent the reset-and-enrol path attackers use to bypass technical controls. The key issue is not detection speed but stopping human-layer identity abuse before it becomes access.
NHIMG editorial — based on content published by Trusona: One prevented breach pays for Trusona for 10 years
By the numbers:
- MGM Resorts' 2023 breach cost about US$100 million.
- 50 to 90% of attacks involve social engineering, according to Trusona's analysis.
Questions worth separating out
Q: How should security teams secure help desk password resets and MFA enrolment?
A: Security teams should treat help desk recovery as a privileged identity workflow, not a routine support task.
A: Because the organisation often assumes every caller can complete the same identity proofing flow, but contractors, partners, and recovery cases frequently cannot.
Q: What breaks when identity recovery relies on weak caller verification?
A: Weak caller verification breaks the boundary between support and access issuance.
Practitioner guidance
- Strengthen recovery proofing Require higher-assurance verification before any password reset, MFA re-enrolment, or device change.
- Log every identity recovery event Capture who requested the action, what was changed, which evidence was used, and which agent approved it.
- Segregate high-risk service desk actions Separate routine support from credential re-issuance, MFA enrolment, and account recovery.
What's in the full article
Trusona's full blog covers the operational detail this post intentionally leaves for the source:
- The full ROI framing behind help desk verification, including the breach-cost assumptions used in the calculation.
- The discussion of why social engineering remains a dominant attack vector and how that changes the payback period for preventive controls.
- The examples of compliance and customer-trust impact that support the argument for stronger identity proofing.
- The product-specific implementation context for secure identity proofing and hardware-bound MFA.
👉 Read Trusona's analysis of help desk verification ROI and breach prevention →
Help desk verification and social engineering risk: are controls keeping up?
Explore further
Help desk verification is an identity control, not an IT support nicety. When an attacker can use a service desk to reset credentials or rebind MFA, the organisation has effectively placed an access issuance point in a human conversation. That makes the workflow part of IAM governance, IGA evidence, and fraud prevention at the same time. The practical conclusion is that support operations must be treated as a controlled identity boundary, not an administrative back office.
A few things that frame the scale:
- Only 1.5 out of 10 organisations are highly confident in their ability to secure NHIs, compared to nearly 1 in 4 for securing human identities, according to The State of Non-Human Identity Security.
- 85% of organisations lack full visibility into third-party vendors connected via OAuth apps, which leaves delegated access paths under-governed even before a support workflow is abused.
A question worth separating out:
Q: Who is accountable when a social engineering call leads to SSO compromise?
A: Accountability is shared across identity operations, help desk governance, and security architecture. Teams that own resets, MFA recovery, browser telemetry, and identity monitoring all influence the outcome. Framework-wise, this sits under identity governance, access control, and incident response rather than only user training.
👉 Read our full editorial: Help desk verification cuts social engineering breach costs