Scenario library / Social engineering

Helpdesk Social Engineering Intrusion: a tabletop exercise scenario

A caller convinces the service desk to reset MFA for a senior engineer. Twenty minutes later that account is enumerating privileged systems.

60–75 min · Executive + IT operations + HR

Abstract graphic representing helpdesk social engineering intrusion

What this is modelled on

Modelled on intrusions where an attacker calls the service desk posing as an employee, has an authentication factor reset, and then moves quickly into privileged systems using ordinary access.

Why it matters

The weakest link is a helpful process, not a missing product. This exercise puts the identity verification standard, and the pressure to bypass it, on the table.

Exercise objectives

  • Test identity verification standards for resets and exceptions
  • Rehearse rapid account containment with HR and IT together
  • Assess privileged access blast radius from one standard account
  • Review call recording and audit evidence quality

Decision points tested

  • Disable the account and disrupt the engineer's team, or monitor
  • How to handle a possible wrongful suspicion of an employee
  • Immediate control changes at the service desk
  • Law enforcement and insurer engagement

Sample inject timeline

  1. T+0

    Reset request

    The service desk logs a successful MFA reset for a named engineer who is on leave.

  2. T+15

    Unusual access

    The account accesses a privileged access management console for the first time.

  3. T+35

    Data movement

    A large archive is copied to a personal cloud storage domain.

  4. T+55

    Attribution pressure

    Leadership asks whether the named employee is responsible.

What the after-action report should capture

  • Verification standard adherence and exceptions
  • Detection latency for first privileged access
  • HR and security coordination
  • Control changes agreed with owners

Run this scenario with your team

Tailor it to your environment with AI, run the injects live, and export a web or PDF after-action report when the exercise ends.