Help desk agents are the softest target in most organisations because their entire job is to say yes to people they've never met. Train them properly and a caller pretending to be the CFO's assistant walks away empty-handed. Skip the training and you get MGM Resorts 2023 — a help desk reset that led to a multi-day operational shutdown.
TL;DR
- Train help desk staff on social engineering with scripted verification steps, not vague awareness — Cyber Aware's approach starts with call-back verification for every credential reset.
- The MGM Resorts breach in 2023 began with a single help desk call impersonating an employee — verification protocol, not technology, was the gap.
- Run monthly vishing simulations, not annual ones; skill decay on phone-based social engineering happens faster than on email phishing.
- Escalation paths matter more than initial detection — agents need a named person to call when a request feels wrong, not a policy PDF.
Why this matters
Email phishing training gets most of the budget because it's easy to simulate and easy to measure. Voice-based social engineering — vishing, pretexting, MFA fatigue calls — gets a fraction of that attention despite being the entry point for some of the costliest breaches of the past three years.
Help desk agents face a structural problem: their performance metrics reward speed and first-call resolution, not scepticism. A script that says "verify caller identity before any password reset" competes directly against a call-time KPI. Unless training addresses that tension directly, agents will default to the metric that gets measured.
Cyber Aware treats help desk teams as a distinct training segment for this reason — the content, cadence, and simulation format differ from general staff awareness training. A generic phishing module doesn't prepare someone for a caller who knows the CEO's travel schedule and is asking for an urgent MFA reset.
What you'll need
- A documented identity-verification procedure for password resets, MFA re-enrolment, and account unlocks
- A list of pretext scenarios specific to your industry (finance staff impersonation, vendor callback fraud, IT support impersonation)
- Call recording or simulation software to run mock vishing attempts against agents
- A named escalation contact agents can reach within minutes, not hours
- Management buy-in to protect verification time against call-handling KPIs
- A cyber security training platform that supports voice-based and role-specific modules, not just email simulations
The steps
1. Map every credential-related request type your help desk handles
List out password resets, MFA re-enrolment, account unlocks, and access-level changes — these are the four request types attackers impersonate most often because they lead directly to account takeover. Agents can't apply consistent verification if they don't know which requests carry the highest risk.
Pull ticket data from the last 90 days and tag each request type by volume. In most SMB and mid-market help desks, password resets and MFA re-enrolments account for well over half of all tickets — that concentration is exactly why attackers target them.
Common mistake: treating all tickets as equal risk. A printer driver request and an MFA re-enrolment request need different verification depth.
2. Build a mandatory verification script for each high-risk request type
Write a script that requires at least two independent verification points before any credential action — something the person knows (employee ID, manager name) plus something you can verify against a system of record (call-back to a registered number, not the number the caller provides).
The call-back step is non-negotiable. Attackers routinely spoof caller ID and will happily give you a number to "verify" against — that number belongs to them. Verification only works if the agent calls a number pulled from HR records or the directory, never one supplied mid-call.
Common mistake: allowing email verification as a standalone step. Corporate email accounts are frequently the thing already compromised.
3. Run baseline vishing simulations before any training
Measure where agents currently stand before you teach anything — a baseline lets you show real improvement and identifies which agents need one-on-one coaching. Use a controlled simulation service or an internal red-team call to attempt a password reset using urgency and authority pretexts.
Record the outcome for each agent: did they follow the script, skip a step, or comply fully. This baseline becomes the number you compare against in 2026's follow-up simulations.
Common mistake: announcing the simulation window in advance. Agents perform to the test, not to their actual habits.
4. Train on the psychological pressure tactics, not just the technical script
Agents need to recognise urgency ("I'm about to miss a board call"), authority ("this is the CFO's EA"), and false rapport ("we spoke last week, remember?") as manipulation techniques, not just memorise a checklist. Understanding why the tactic works makes agents more resistant to variations they haven't seen scripted.
Run a 30-minute session covering the four most common pretexts your industry sees, each with a real (anonymised) call transcript or recreation. How to train staff to identify vishing and voice phishing calls covers the specific call patterns to include.
Common mistake: framing this as a one-off lunch-and-learn. Pressure tactics need repetition to stick.
5. Give agents explicit permission to say no and escalate
Agents comply with pressure partly because no one has told them that refusing a caller — even an angry one claiming to be a director — is the correct outcome. Management needs to state, in writing, that a delayed reset due to failed verification will never result in disciplinary action.
Pair this with a real escalation path: a named security contact, a Slack or Teams channel, or a hotline number an agent can reach inside two minutes. How to design an escalation path for repeat phishing clickers has a workable template you can adapt for voice incidents.
Common mistake: an escalation path that only exists on paper — test it by having an agent actually call it during a drill.
6. Run recurring, unannounced vishing drills every 30-60 days
Skill decay on voice-based social engineering is faster than on email phishing because agents get far fewer real vishing attempts than real phishing emails to practise against. A monthly or bi-monthly cadence keeps the verification habit active rather than theoretical.
Vary the pretext each round — one month it's urgency from a fake executive, the next it's a fake vendor callback requesting a payment detail change. Track pass rates by agent and by scenario type, and feed repeat failures into targeted coaching rather than generic retraining.
Common mistake: reusing the same scenario every time. Agents pattern-match the drill instead of the underlying tactic.
7. Fold outcomes into onboarding for every new help desk hire
New hires are the highest-risk group because they don't yet know internal norms, don't recognise employee names, and want to be helpful. Build vishing-specific content into their first-week training, not just generic phishing awareness.
Cyber security training for new employee onboarding outlines a sequencing approach — put verification-script training before the new hire takes their first live call, not after.
Common mistake: relying on shadowing alone. A new agent watching a senior agent skip a verification step for speed learns the wrong lesson fast.
Troubleshooting
Agents skip verification when queues are long. Set a hard rule: verification steps are never optional regardless of queue length, and make that rule visible on the ticket screen itself, not buried in a policy doc.
Agents can't tell a real urgent request from a fake one. Legitimate urgent requests from executives should route through a separate, pre-verified channel (a known assistant, a ticketing tag) rather than relying on the agent's judgement mid-call.
Simulation pass rates plateau after the first few drills. Increase pretext sophistication — combine urgency with a partial correct answer (attacker knows the employee ID but not the manager's name) to test whether agents catch partial verification failures.
Agents flag too many legitimate calls as suspicious, slowing service. How to handle false positive phishing reports from staff applies directly here — the goal is calibrated scepticism, not blanket refusal.
Management pushes back on verification slowing call times. Present the baseline drill data next to the average cost and downtime of a credential-based breach; a two-minute call-back step is cheap against a multi-day incident.
Tools and resources
- A documented, mandatory verification script covering every credential-related request type
- Vishing simulation capability, run unannounced on a recurring schedule
- A named escalation contact reachable within minutes
- How to train staff to recognise cyber security threats for the broader awareness baseline every agent should already have
- Call recording or a redacted transcript library of real attempted pretexts, updated as attackers change tactics
Train your help desk against real vishing tactics
See how Cyber Aware runs vishing simulations and verification scoring for support teams.
What to do next
Once the verification script and drill cadence are running, the next gap is usually measurement — knowing whether pass rates are actually improving or just look better because agents recognise the drill format. Build a scoring baseline now so 2026's quarterly reviews have something concrete to compare against.
FAQ
How do you train help desk staff to spot social engineering?
Train help desk staff with a mandatory two-point verification script for every credential request, backed by unannounced vishing drills every 30-60 days. Scripted call-backs to a number from HR records, not one the caller supplies, close the gap that phone-based attacks exploit.
What is vishing and how is it different from email phishing?
Vishing is voice-based social engineering where an attacker calls and impersonates an employee, executive, or vendor to extract credentials or trigger a password reset. It differs from email phishing because it relies on real-time pressure and improvisation rather than a static message a filter can catch.
How often should help desk vishing simulations run?
Run vishing simulations every 30 to 60 days, unannounced, because voice-based skill decay happens faster than email phishing skill decay. Vary the pretext each round so agents learn to recognise the underlying tactic rather than a specific scenario.
What caused the MGM Resorts 2023 breach?
The MGM Resorts breach in September 2023 began with a social engineering call to the company's IT help desk, where attackers impersonated an employee to reset credentials. The incident led to multi-day operational disruption across casino and hotel systems.
Should help desk agents be allowed to refuse a caller's request?
Yes, agents should have explicit written permission to refuse or delay a request that fails verification, even from someone claiming to be a senior executive. Management needs to confirm in advance that a delayed reset due to failed verification carries no disciplinary consequence.
What's the biggest mistake in help desk social engineering training?
The biggest mistake is treating verification as optional under time pressure, since call-handling KPIs often conflict directly with scepticism. Fix this by making the verification step visible on the ticket screen itself so it can't be skipped without a record.
Can email-based verification replace call-back verification?
No, email verification alone is unreliable because corporate email accounts are often already compromised in the same attack. Call-back verification to a number pulled from a system of record, not one supplied by the caller, is the more reliable check.
How do you measure if help desk social engineering training is working?
Measure it with a baseline vishing drill before training, then repeat unannounced drills every 30-60 days and track pass rates by agent and pretext type. Improvement should show up as fewer full compliance events and faster escalation, not just faster call handling.
One last thing
The MGM Resorts breach didn't involve a technical exploit — it involved one help desk agent, one phone call, and no call-back verification step. That's the entire gap most organisations are still leaving open in 2026, and it costs nothing to close beyond the discipline to enforce a script during a busy shift.