Your Client's Biggest Cyber Risk Isn't a Zero-Day — It's Their Help Desk

Your Client's Biggest Cyber Risk Isn't a Zero-Day — It's Their Help Desk

Attackers have stopped breaking in and started phoning in. Here's why help desks and vendor access have become the top initial access vector — and the verification workflows your SME can put in place this week.

Tony Brown
By Tony Brown ·

A caller rings your help desk on a Tuesday afternoon. They know the finance manager's name, they know she's on annual leave, and they sound genuinely stressed about a locked-out account and a payment run that's due. The agent, wanting to be helpful, resets the password and reads out a temporary one. Fifteen minutes later, the attacker is inside the finance system.

There was no exploit. No malware. No clever piece of code slipping past the firewall. Someone simply asked, and got a yes.

A support agent wearing a headset at a computer, representing a help desk as a security weak point

This is where most breaches actually start now, and it's rarely the story that gets told. The industry loves a zero-day — an unknown flaw, a race against the clock, a patch shipped at midnight. It's dramatic. It's also increasingly beside the point for the average UK SME. The people trying to get into your systems have worked out that it's far cheaper to trick a human than to find a vulnerability nobody else has spotted.

The help desk is the softest door in the building

Think about what a help desk is designed to do. Its entire purpose is to remove friction — to get a frustrated person back to work quickly. Agents are measured on how fast they resolve tickets and how happy the caller is. Those incentives are the exact opposite of the ones you'd want in a security gatekeeper.

Attackers understand this perfectly. They don't need to defeat your multi-factor authentication if they can convince someone to reset it for them. They don't need to crack a password if they can get a helpful agent to hand one over 'just this once' because someone claims to be locked out before an important meeting.

The 2026 wave of breaches made this painfully clear. The DentaQuest incident, which exposed data belonging to millions of members, wasn't a masterclass in technical wizardry — investigators pointed to compromised access that flowed through account recovery and support pathways rather than a novel software flaw. It followed a pattern seen across the healthcare vendor chain that year: attackers targeting the seams between organisations, where one company's staff hold credentials for another company's systems, and where a support desk on either side can be talked into opening a door.

That vendor chain angle matters enormously for SMEs, because you are almost certainly somebody's vendor, and somebody is almost certainly yours. When a healthcare provider gets breached through a claims processor, or a law firm through its document management supplier, the initial foothold was often a phone call or an email to a help desk asking for a reset, an access grant, or a 'quick favour'. The technical controls held. The human layer folded.

Why more tooling won't fix a talking problem

When a client gets nervous about security, the instinct is usually to buy something. A new endpoint product. A shinier email filter. Another dashboard with a red-amber-green traffic light on it. There's comfort in a purchase order — it feels like progress.

But none of those tools answer the question the attacker is exploiting: how does your help desk know the person on the phone is who they claim to be? If the honest answer is 'they sound legitimate and they knew a few details', then no amount of software is protecting you. The attacker has simply moved the fight to the one place your tooling doesn't reach — a conversation between two people, one of whom is lying.

The details attackers use to sound convincing are cheap to obtain. A LinkedIn profile tells them who works where and who reports to whom. A company website lists the senior team. A previous, smaller breach elsewhere leaks a date of birth or a partial address. By the time they call, they can perform being your colleague quite convincingly. Knowledge-based questions — 'what's your employee number?', 'confirm your date of birth' — are worthless when the answers are already for sale.

What actually works: verify the person, not the story

The fix is not glamorous, but it is concrete, and most SMEs can put it in place without spending a penny on new software. The principle is simple: stop verifying that someone knows things, and start verifying that they are someone, through a channel the attacker doesn't control.

Here are the workflows worth implementing straight away.

1. Out-of-band callback for any sensitive request. If someone contacts the help desk asking for a password reset, MFA reset, or access change, the agent does not act on the inbound contact. Instead, they call the person back on the number already held in the HR or directory system — not a number the caller supplies. This single step defeats the majority of impersonation attempts, because the attacker can talk all day but can't answer the phone on the real employee's desk.

2. A verification code pushed to a known device. For remote workers, send a one-time code to the app or number registered in your identity system and require the caller to read it back. Again, the point is that it lands on a device the real person controls. If they can't produce the code, the request stops there.

3. Manager or second-person approval for high-risk actions. Resetting MFA, granting admin rights, or changing bank details should never rest on one agent's judgement during a single call. Require a second person to approve, ideally through a ticketing workflow that leaves a record. This slows things down by minutes and removes the pressure a lone agent feels when someone is being urgent and forceful.

4. Treat urgency and authority as red flags, not reasons to hurry. Train your team on the actual tactics: the caller who name-drops a director, invents a deadline, or gets irritated when asked to verify. The natural human response is to comply and de-escalate. The correct security response is that pressure to skip verification is itself the strongest signal something is wrong. Give agents explicit permission — in writing — to say no and follow the process, even to someone claiming to be a senior manager.

5. Extend the same rules to your vendors. Ask your suppliers how their help desks verify identity before they'll act on a request from your staff, and tell them how yours works. Agree that neither side will reset credentials or grant access on an unverified call. The DentaQuest-style chain attacks succeed precisely because these agreements don't exist and everyone assumes the other party is being careful.

Make it a policy, then rehearse it

Writing these steps down is the easy part. The harder work is making them stick under pressure. Run a test: have someone your team doesn't recognise phone the help desk with a plausible, urgent request and see what happens. You'll learn more from that ten-minute exercise than from any vendor demo. Do it regularly, share the results without blame, and celebrate the agents who refused politely and followed the process.

The attackers targeting UK businesses in 2026 aren't cracking your defences. They're being helped through the front door by someone doing their job well. Fix that, and you close the gap that the most expensive tooling on the market was never designed to reach.

If you'd like help designing verification workflows for your help desk — or stress-testing the ones you already have — that's exactly the kind of practical, human-layer work we do at Cloudworks. Get in touch and we'll walk through your current process and where the gaps are.

Request a no obligation callback