Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

Help desk verification and social engineering risk: are controls keeping up?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 19563
Topic starter  

TL;DR: Social engineering drives 50 to 90% of breaches and the average global breach cost reached USD 4.45 million in IBM's 2023 data, according to Trusona, which argues that help desk verification can prevent the reset-and-enrol path attackers use to bypass technical controls. The key issue is not detection speed but stopping human-layer identity abuse before it becomes access.

NHIMG editorial — based on content published by Trusona: One prevented breach pays for Trusona for 10 years

By the numbers:

Questions worth separating out

Q: How should security teams secure help desk password resets and MFA enrolment?

A: Security teams should treat help desk recovery as a privileged identity workflow, not a routine support task.

Q: Why do help desk workflows become a fraud and account takeover risk in extended workforce environments?

A: Because the organisation often assumes every caller can complete the same identity proofing flow, but contractors, partners, and recovery cases frequently cannot.

Q: What breaks when identity recovery relies on weak caller verification?

A: Weak caller verification breaks the boundary between support and access issuance.

Practitioner guidance

  • Strengthen recovery proofing Require higher-assurance verification before any password reset, MFA re-enrolment, or device change.
  • Log every identity recovery event Capture who requested the action, what was changed, which evidence was used, and which agent approved it.
  • Segregate high-risk service desk actions Separate routine support from credential re-issuance, MFA enrolment, and account recovery.

What's in the full article

Trusona's full blog covers the operational detail this post intentionally leaves for the source:

  • The full ROI framing behind help desk verification, including the breach-cost assumptions used in the calculation.
  • The discussion of why social engineering remains a dominant attack vector and how that changes the payback period for preventive controls.
  • The examples of compliance and customer-trust impact that support the argument for stronger identity proofing.
  • The product-specific implementation context for secure identity proofing and hardware-bound MFA.

👉 Read Trusona's analysis of help desk verification ROI and breach prevention →

Help desk verification and social engineering risk: are controls keeping up?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 4 months ago
Posts: 19154
 

Help desk verification is an identity control, not an IT support nicety. When an attacker can use a service desk to reset credentials or rebind MFA, the organisation has effectively placed an access issuance point in a human conversation. That makes the workflow part of IAM governance, IGA evidence, and fraud prevention at the same time. The practical conclusion is that support operations must be treated as a controlled identity boundary, not an administrative back office.

A few things that frame the scale:

  • Only 1.5 out of 10 organisations are highly confident in their ability to secure NHIs, compared to nearly 1 in 4 for securing human identities, according to The State of Non-Human Identity Security.
  • 85% of organisations lack full visibility into third-party vendors connected via OAuth apps, which leaves delegated access paths under-governed even before a support workflow is abused.

A question worth separating out:

Q: Who is accountable when a social engineering call leads to SSO compromise?

A: Accountability is shared across identity operations, help desk governance, and security architecture. Teams that own resets, MFA recovery, browser telemetry, and identity monitoring all influence the outcome. Framework-wise, this sits under identity governance, access control, and incident response rather than only user training.

👉 Read our full editorial: Help desk verification cuts social engineering breach costs



   
ReplyQuote
Share: