Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

Zero trust and help desk identity risk: what teams are missing


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 19563
Topic starter  

TL;DR: Zero Trust controls have matured for systems, but human workflows such as help desk resets and device enrolment still let attackers bypass the front door, according to Trusona. The broken assumption is that technical verification alone can secure access decisions once a conversation becomes the trust anchor.

NHIMG editorial — based on content published by Trusona: Zero Trust and the Rise of Human Identity First Security

By the numbers:

Questions worth separating out

Q: How should security teams handle password resets and recovery workflows in a zero trust programme?

A: Security teams should treat recovery workflows as high-risk identity events and require verification outside the same conversation that initiated the request.

Q: Why do help desk recovery workflows increase identity risk?

A: Help desk recovery workflows often rely on procedural checks that are easier to socially engineer than cryptographic factors are to steal.

Q: What do security teams get wrong about Zero Trust and identity governance?

A: They often treat Zero Trust as an integration label rather than a continuous operating requirement.

Practitioner guidance

  • Map all human-mediated access restoration paths Inventory password reset, device enrolment, urgent approval, and account recovery workflows across the service desk, identity team, and business support functions.
  • Separate verification from the support conversation Require an out-of-band verification step for high-risk actions so the person requesting help is validated through a channel that is not the same phone call or chat session.
  • Apply no-exception policy to high-risk actions Remove executive fast lanes, urgency overrides, and informal manager approvals from recovery workflows.

What's in the full article

Trusona's full article covers the operational detail this post intentionally leaves for the source:

  • Human identity verification workflow design for help desk and recovery channels
  • Practical guidance for gating password reset, device enrolment, and urgent approval actions
  • How to measure blocked impersonation attempts and quantify the control gap
  • Why support agents need repeatable verification steps instead of subjective judgment

👉 Read Trusona's analysis of zero trust and human identity verification →

Zero trust and help desk identity risk: what teams are missing?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 4 months ago
Posts: 19154
 

Zero Trust is structurally incomplete when identity decisions move into human support workflows. The model was built for evaluated access requests, but help desk recovery reverses the trust sequence and hands attackers a different path into the environment. Once the verification step becomes conversational, the programme is no longer applying Zero Trust consistently. The implication is that organisations must treat support channels as part of identity architecture, not as operational exceptions.

A few things that frame the scale:

  • 92% of organisations expose NHIs to third parties, raising concerns about supply chain security, according to Ultimate Guide to NHIs.
  • 79% of organisations have experienced secrets leaks, and 77% of those incidents resulted in tangible damage, according to Ultimate Guide to NHIs.

A question worth separating out:

Q: Who is accountable when a social engineering attack succeeds through support channels?

A: Accountability sits with the organisation’s identity governance and service ownership, not just the individual agent who handled the call. Frameworks such as NIST Cybersecurity Framework 2.0 and Zero Trust both imply that exception paths must be governed, measured, and reviewed. If support can create access, it belongs inside the control system.

👉 Read our full editorial: Human identity verification closes the zero trust gap attackers exploit



   
ReplyQuote
Share: