Your Help Desk Is the Easiest Way Into Your Firm
I'll tell you how a recent engagement actually went, because the result deserves to be uncomfortable.
We were engaged to test a firm's defences. We didn't defeat the firewall. We didn't crack multi-factor authentication. We didn't exploit a single vulnerability, because we didn't need to.
We called the help desk. We said we were a partner, locked out of our account, due in a hearing within the hour. We answered a couple of verification questions using details anyone can assemble from LinkedIn and public records in a few minutes. And the account was reset for us.
Total elapsed time: under ten minutes. Every piece of technology the firm had paid for performed exactly as designed. The process wrapped around that technology is what failed — and the process is the part nobody had ever tested.
This post is about why that keeps working, what the call actually looks like from my side of the phone, and what fixes it. Spoiler: the fix isn't a product.
Why This Works Now
For a decade, firms have been hardening the network. Firewalls, endpoint detection, email filtering, MFA everywhere. That investment worked — and attackers responded the way attackers always respond. They stopped attacking the hardened thing and moved to the soft thing next to it.
The soft thing is the human process for getting back into an account when you're locked out. The FBI has warned that criminal groups targeting law firms use exactly this technique — they don't break in, they phone in and ask to be let in. The same playbook sits behind several of the largest breaches of the past few years: not a zero-day, just a convincing phone call to a help desk.
The reset process is uniquely exposed because of what it was built for. It was designed for genuinely locked-out staff, under pressure, who need to be working again in minutes. It's optimised for speed and sympathy. Every incentive on that call pushes towards helping — the help desk is measured on resolution time, the caller is stressed and senior, and saying no feels like a career risk.
That's exactly the shape of process that bends when someone hostile leans on it. And in most firms it has never once been stress-tested, because pen tests have historically pointed at the network, not the phone.
Anatomy of the Call
Here's how the engagement actually unfolds, step by step, because seeing the mechanics is what makes the fixes obvious.
The research takes an afternoon, not a heist. The firm's website gives me the partner list. LinkedIn gives me each partner's history, practice area, and often their assistant's name. Court lists tell me who has matters on this week. Old data breaches — freely traded — fill in dates of birth and past passwords. By the time I dial, I know more about the partner I'm impersonating than the help desk operator I'm about to speak to does.
The pretext supplies its own pressure. I'm not a stranger asking for a favour. I'm a partner, I'm locked out, and I'm due in front of a judge at 2pm. Urgency plus seniority is the whole trick: it makes the operator want to skip steps, and it makes them frightened to insist on the ones that remain.
The verification verifies nothing. "Can you confirm your date of birth and your employee start year?" I can. So could anyone who did the afternoon of research. Knowledge-based verification only proves the caller can look things up — and everything it relies on is lookup-able.
The reset is handed over. Password reset, and often the MFA enrolment reset with it. From the firm's perspective, a partner was helped quickly. From mine, I'm now inside the mailbox of someone with access to trust account correspondence and settlement instructions — and nothing anywhere has flagged that anything happened.
No step in that chain involves defeating technology. Which is why buying more technology doesn't close it.
"But We Have MFA"
This is the objection I hear in every debrief, so let's deal with it directly.
MFA is essential and you should have it everywhere. But MFA is only as strong as the process that resets it. If a phone call to the help desk can re-enrol MFA to a new device, then your MFA doesn't protect against an attacker — it protects against an attacker who doesn't know your help desk's number.
Think of it like this: you've installed a vault door, and the reset process is a side entrance with a doorbell. The quality of the vault door is irrelevant to someone standing at the side entrance. Attackers know this, which is why the reset path — not the login page — is where the serious groups now spend their effort.
What Actually Fixes It
The good news: everything here is process and training. There's nothing to procure.
1. Out-of-band confirmation for every reset. Before any password or MFA reset, the help desk contacts the account owner through a channel the caller doesn't control — the mobile number already on file, or their supervisor, or in person. A callback to a known number is hard to fake. If the caller is genuine, this costs them two minutes. If they're not, it ends the attack. This single control would have stopped our engagement cold.
2. Kill knowledge-based verification. Date of birth, employee ID, start date, manager's name — retire all of it. If a fact can be assembled from LinkedIn and breach data, it isn't verification. Anything the process keeps should be something only the firm and the real person could know, and even then it should support the out-of-band check, not replace it.
3. Treat urgency as a red flag, not a reason. Flip the instinct. Pressure to skip verification is precisely the signature of an attack, so the more urgent the caller, the more important the process becomes. Put that sentence in the help desk script verbatim.
4. Harden the privileged paths hardest. Resets for partners, finance staff, IT administrators, and anyone who can touch trust accounts should carry extra friction by design — mandatory callback plus a second approver. These are the accounts attackers actually want; make their reset path the slowest, not the fastest.
5. Script it, and give the help desk permission to say no. Operators bend under pressure from senior voices because nobody has told them the firm will back them when they hold the line. Write the script, train it, and have a partner say out loud — ideally in the training session — that a delayed reset will never be a disciplinary matter but a skipped verification might be. Culture is the control here; the script just documents it.
If you outsource IT, all five of the above are questions for your MSP, and "we have a robust process" is not an answer — ask them to walk you through the exact steps between a caller claiming to be a partner and a completed reset.
How to Find Out Where You Stand
Two ways, one cheap and one thorough.
The cheap one: this week, ask your IT lead or MSP a single question — what exactly does someone have to do to get a partner's password reset over the phone? Then look at the answer through the lens of this post. If the verification relies on lookup-able facts and there's no out-of-band step, you already know what a tester would find.
The thorough one: put a social-engineering component in your next penetration test and let someone make the call for real. Firms are often surprised by which door opens first — and it's far better to be surprised by a tester than by the person who calls next.
Because after all the investment in the network, the front door of most firms isn't the firewall anymore.
It's the phone.
If you'd like your reset process tested the way an attacker would test it — or a tabletop walk-through of the reset path with your IT provider in the room — reach out for a confidential conversation → Cyber Chat
The Legal Cyber Brief — monthly cyber intelligence for law firm leaders. Threats, regulatory shifts, and practical tools from the field. No fluff.
The Legal Cyber Brief — monthly cyber intelligence for law firm leaders.


