Service Desks: Cyber Security's Overlooked Front Door
Service desks are usually seen as an operational necessity rather than a security control. Recent high-profile breaches show why that thinking needs to change, and what leaders can do about it.
For most organisations, the service desk is where day-to-day IT problems get solved. It resets passwords, unlocks accounts and keeps people working. It is rarely thought of as part of the cyber security perimeter, yet the person answering that call often holds the keys to your entire digital estate. When those keys are handed over too easily, the consequences can be severe.
Every breach has a human moment, the point at which someone says yes when they should have said no. Understanding where and why that moment happens is the first step towards closing the gap.
A Costly Lesson from Recent Breaches
Earlier this year, Marks & Spencer's systems were compromised after attackers reportedly exploited weaknesses in a third-party support provider. Analysts have linked the attack to the Scattered Spider group, known for social engineering and deepfake impersonation, who are believed to have manipulated help desk processes to gain initial access. The fallout was significant: operational disruption, sensitive data exposure and reported profits down by 99%.
The pattern is not isolated. Jaguar Land Rover suffered a similar fate more recently, and comparable attacks have hit retailers, telcos and government agencies, often through outsourced service desks. Organisations that invest heavily in prevention technology can still be undone by a single well-crafted phone call. The human layer remains the easiest route in.
Why Service Desks Are Often Left Exposed
Cyber security budgets tend to flow towards detection and response tools, data loss prevention and automation. Meanwhile, the people trusted to verify identities, reset credentials and manage multi-factor authentication (MFA) are often working from outdated procedures with minimal training and basic tooling.
It is an easy oversight to make. Service desks exist to help, solving problems quickly and keeping the business moving. Attackers understand this and exploit it directly. They research internal structures, mimic email signatures, spoof phone numbers and increasingly use deepfake audio to impersonate staff. When an agent hears what sounds like a senior colleague urgently requesting an MFA reset, the instinct to help can override the instinct to verify.
MFA Is Only as Strong as the Process Behind It
Multi-factor authentication remains one of the strongest controls available, but it is not infallible, and tools already exist to bypass it. This is why conditional access policies at the front end of authentication are so important in today's threat landscape.
Attackers know they rarely need to defeat MFA outright if they can simply persuade a service desk agent to disable or override it. The locked-out employee scenario has become one of the most effective ways to bypass otherwise robust defences.
The problem extends beyond MFA. Many service desks still verify users with information that is easy to find or steal, such as email addresses, job titles or phone numbers pulled from old breach dumps or LinkedIn profiles. Without standardised verification protocols, one agent might request an employee ID and a secondary code, while another waves through access on a name and department alone. That inconsistency is exactly what attackers look for.
Where the Service Desk Sits in the Attack Chain
Mapped against a typical attack, the service desk often sits in the middle of the sequence. First, the attacker gathers intelligence on names, job titles and schedules. Next comes a spoofed email or call designed to sound familiar. Delivery is the help desk interaction itself, the point where deception meets process.
Once trust is exploited and a password reset or MFA disablement is granted, the attacker holds a valid credential. From there, privilege escalation and data exfiltration follow quickly. By the time unusual activity is flagged, the attacker has often already walked through a door that was opened in good faith. Reframing the service desk as part of the security perimeter, rather than a purely operational function, is essential to closing that gap.
What Service Desk Best Practices Look Like
Service desks need to operate with the same rigour as any other security-sensitive function. In practice, this means:
Layered identity verification. No single piece of information should be enough to confirm who someone is.
A second pair of eyes on every MFA override. Manager approval or peer verification adds vital friction to a high-risk action.
True least-privilege access. Service desk staff should hold only the access they need, when they need it, not blanket admin rights.
Full audit trails. Every identity-related action should be logged, supporting accountability and visibility rather than blame.
Ongoing training. Simulated social engineering exercises, run regularly rather than as an annual webinar, are the most effective way to build and test awareness.
This is not bureaucracy for its own sake. It is operational hygiene, the digital equivalent of washing your hands before surgery.
Questions Every Leadership Team Should Be Asking
Whether your service desk is managed in-house or by a third party, it should be held to the same standard as your internal security team. Ask the uncomfortable questions:
How are identities verified, and is that process consistent across every agent and shift?
How often are staff tested against real-world social engineering scenarios?
Are suspicious calls logged, escalated and analysed?
Do service desk engineers have the authority, and the confidence, to say no to a senior-sounding voice?
Your organisation's cyber resilience depends on the honesty of those answers.
Rethinking the Service Desk
The service desk has evolved well beyond a convenience layer for users. It is now a critical control point for identity, access and response. The most mature organisations are integrating their service desks directly with threat intelligence feeds and security operations workflows, turning them from reactive support into active defence.
That shift takes investment, process maturity and, above all, respect for the people answering the “I’m locked out” calls. They are often the first, and sometimes the last, line of defence between your business and the next headline-grabbing breach. Treating the service desk as peripheral to security is no longer an option: it is one of the guardians of your organisation, and it deserves to be resourced and governed accordingly.
If you'd like to learn more about our secure-by-design service desk, contact a member of our team today.

)
)
)
)