The Help Desk Is Doing What You Trained It to Do
Key Intel / TL;DR
  • Account recovery is where an identity system asks a person to make a judgement call, and attackers go there because judgement is the softest control in the building.
  • The agent who resets the account is measured on how fast the call ends and how satisfied the caller sounds, so speed and helpfulness are the behaviors the job rewards.
  • Telling agents to be more suspicious puts the cost of a wrong guess on them and leaves the incentives untouched.
  • Move the verification off the agent and onto something they cannot be talked out of, so refusing takes no courage.
  • Track how often verification actually fails, because a failure rate of zero means the step is decorative.

The call comes in about twenty minutes before the end of a shift. Somebody is locked out, they are traveling, their phone was replaced by the carrier this morning and the authenticator did not come across, and they have a client meeting starting in a few minutes. They are apologetic and a little embarrassed about it. They know this is a hassle and they say so twice.

The agent on the other end resets the account. Six weeks later, that reset shows up in an incident timeline as the moment somebody who did not work there got a working credential, and the report describes it as a failure to follow verification procedure.

That is a true description of what happened and a useless description of why. The agent followed the thing they were actually trained on, which was to resolve the call.

Where the Judgement Lives

Every identity system eventually reaches a point where the automation gives up and hands the decision to a person. Somebody lost the phone, somebody left the country, somebody’s token died, and the whole carefully designed chain of factors comes down to whether one human being on a headset believes another human being on a phone line.

Attackers are not going after the cryptography. They go to the counter where a person is standing, because that person can be talked to, and everything else in the stack cannot. We have written before about the psychology that makes executives such reliable targets, and the mechanism at the service desk is a close relative of it with the roles reversed. The caller supplies the urgency and the agent supplies the resolution.

What makes this specific is who the judgement is being asked of. The person holding it works in a role whose entire design pushes steadily in one direction, and the policy asking them to hesitate arrives without any of the weight that design carries.

The Incentives Nobody Wrote Down and Everybody Understands

Look at what a support role is measured on in almost any organization. Time to resolution, tickets closed per shift, and caller satisfaction scores are the usual three, and sitting alongside them is first-contact resolution rate, which is the metric that specifically punishes escalating a call to somebody else.

Now read those metrics as instructions, because that is what they become after about three weeks in the seat. Close the call yourself, do not hand it off, and leave the person on the other end feeling helped. None of that is a bad set of goals, and I would want all of it if I were the one locked out of my account at an airport.

Then a security policy arrives saying the agent should be alert to social engineering and should verify identity carefully before resetting anything. That instruction is real, but it comes with no metric attached, no cover for a call that runs long, and no defined outcome for the agent who refuses a caller who was legitimate all along and is now furious. The agent has one set of numbers on a dashboard their supervisor reviews and one paragraph in a policy document nobody reviews at all. They behave accordingly, and then we call it human error.

I spent a long time studying why people stay in or leave high-stress workplaces, and one of the most consistent things you find is that people follow the incentive they can feel over the rule they were told. Not because they are cynical. Because the incentive has a consequence attached and the rule usually does not.

Why the Pretext Works So Well Here

The stories that succeed at a service desk are almost never elaborate. They tend to be small, plausible, and slightly inconvenient for the caller, which is exactly the shape of a real support call.

A new phone from the carrier. A password manager that got wiped in a laptop refresh. A person on the road in a different time zone. Somebody who was recently promoted, or recently onboarded, or is covering for a colleague who is out. All of it sits comfortably inside the range of things that genuinely happen every week, and none of it triggers the suspicion that a dramatic story would.

The details are frequently accurate, too. An attacker can learn a reporting line, a start date, a job title, an office location, and a manager’s name without doing anything more sophisticated than reading public profiles, which is the whole reason what people share about their work publicly turns into an operational problem rather than a personal one. The caller who knows your org chart sounds like a colleague because that information used to only be available to colleagues.

Then there is the piece that gets left out of most write-ups. The caller is nice. They are patient, they apologize for the trouble, they thank the agent by name. Refusing a rude caller is easy. Refusing a pleasant one who is having a bad day requires a small act of social aggression against somebody who has given you no reason for it, and the agent has to perform that act personally, in real time, with their own voice, while their handle time counts up on a screen.

The voice channel makes all of this worse than any equivalent over email, because a live conversation gives the caller room to react, adjust, and apply pressure, and gives the agent no room to think.

The Fix Is Not a More Suspicious Agent

The common response to an account recovery incident is more training and a stern reminder about verification. That approach asks the agent to absorb the entire cost of the problem, since they are the one who has to be tougher, slower, and more willing to be unpleasant, all while their measurements stay exactly where they were.

It also does not survive contact with a busy Tuesday. Vigilance is a resource that depletes, and the twelfth call of a shift does not get the attention the second one did.

The useful direction is to take the judgement away from the agent entirely. That reads at first like a statement about trust, and it is closer to a kindness, because an agent who has nothing to decide has nothing to be talked out of.

Verify through a channel the caller does not control

The single most effective change is to stop treating anything the caller can supply as evidence. A birthday, an employee number, a manager’s name, and the last four digits of anything are all knowable. Call the person back on the number in the HR system, or push a verification to a device already enrolled to them, or require an in-person or video confirmation for high-privilege accounts. The point is that the proof has to originate from somewhere the caller cannot reach by asking.

Give the agent a script that removes the choice

There is a real difference between “verify the caller’s identity” and “read this sentence, then do this.” A scripted path means the agent is not deciding whether this particular person deserves an exception, and that is the entire difference. Refusal becomes procedural instead of personal, and the agent gets to be genuinely sympathetic while still not resetting anything.

The line that does this work is something close to: “I can absolutely get you back in, and the way that works is a callback to the number on file. Give me thirty seconds.” The agent is still helping, which protects both the caller experience and the thing the agent is measured on.

Fix the metric before you fix the behavior

If handle time and first-contact resolution are the numbers a support supervisor reviews, then verification is a tax on the agent’s performance review. Either exclude verified recovery calls from handle-time targets or add a verification-compliance measure with the same visibility as the others. Nothing else on this list will hold if the dashboard keeps pointing the other way.

Watch the escalation rate, not the incident count

Most organizations have no idea how often their recovery process actually stops somebody, because a refused caller who hangs up generates no ticket and no record. Start logging verification failures and callback attempts that go unanswered. A verification step that has never once failed is not evidence of a clean environment, and it usually means the step is being performed as a formality on calls the agent had already decided to approve.

Make reporting the near-miss survivable

An agent who realizes an hour later that a call felt wrong is the best detection you will ever have, and they will only tell you if telling you is safe. This is the same argument as blameless incident reporting applied to a job where the mistake is a conversation rather than a click. If the last person who flagged one got written up, you have already trained the whole team on what happens next.

What This Says About the Rest of the Program

The service desk is the clearest example of a pattern that runs through most security programs, which is a control that exists on paper and lives in the gap between what the policy asks and what the job rewards.

You see the same shape in awareness training that measures clicks instead of behavior, and in access reviews where the manager approving forty entitlements has ten minutes and no context. In every case, the person is doing something reasonable inside the system they were handed, and the system is what needs the attention. It is worth walking your own identity and access practices with that question in mind, because the recovery path is usually the least examined part of a well-built identity program.

The agent on that call was the last person in a long chain who still had any discretion left, and they used it exactly the way the job had spent months teaching them to. Everybody upstream of them had already handed the decision along.

If you want help pressure-testing how your own recovery process behaves when somebody friendly and plausible calls at the end of a shift, contact Grab The Axe. You can also take our free Human Attack Surface Score to see where the people-shaped gaps sit in your organization.

Marie Welch is Director of Behavioral Security Operations at Grab The Axe.

Distribute Intel
Marie Welch
Director of Behavioral Security Operations
Marie Welch
The Operational Backbone.

With a dual background in I/O Psychology (PhD Candidate) and Business Management (MBA), Marie bridges the gap between clinical rigor and operational strategy. She oversees B2B relations, compliance, and the 'business' of risk management.

View Author Page →