SANS Rocky Mountain Fall is Live Online! Join us Nov 2-7 MT for 17 interactive courses + NetWars. Save $300 thru 10/7.


Subscribe to SANS Newsletters

Join the SANS Community to receive the latest curated cyber security news, vulnerabilities and mitigations, training opportunities, and our webcast schedule.

SANS Announces Start of Help Desk Security Survey

Respondents eligible to enter drawing for an iPad 4!

  • Bethesda, MD
  • January 17, 2013

SANS Institute is asking managers and analysts in help desk and similar end-user support services to take a 10-minute survey to reveal their approaches to the security risks faced by their teams.

"For decades, attackers have used social engineering techniques to use help desk staff as unwitting allies in their efforts to subvert networked systems. We want to quantify how IT organizations are addressing this challenge," says Deb Radcliff, executive editor of the SANS Analyst Program. "We're also hoping to learn from the experiences of help desk and support managers, and pinpoint the areas that need the most attention."

Help desk and other support operations can be weak spots in the armor of an IT operation, given the tools at their disposal.

"In many organizations, the help desk effectively holds the 'keys to the kingdom.' These can include the powers of password generation and reset, sensitive apps and data exposed in troubleshooting," explains Barbara Filkins, SANS analyst and author of the survey. "The people working on the help desk are highly trusted, but are subject to social engineering attacks from both casual and deliberate intruders."

The survey, sponsored by RSA, The Security Division of EMC, aims to identify the methods that help desk and support staff verify their bona fides to end users, and how to validate that end users are who they claim to be.

"The help desk is still a major point of vulnerability in most organizations. Even the best technology in the world cannot stop an agent from being socially engineered," said Sam Curry, CTO, Identity and Data Protection Group at RSA. "We hope that this research will bring attention to these concerns, shed light on the risks, and demonstrate the need for improved security in identity proofing for employees calling the help desk."

The survey will be open until March 10, 2013. Results will be released during a webcast held on June 26, at 1 PM EDT. (Registration for the webcast is open now: Those who register for the webcast will be among the first to receive an advance copy of the survey results, in a white paper developed by Filkins.

Not only will respondents help shape industry practices, they can also register to be entered into our iPad 4 drawing! Follow this survey link to begin:

SANS Media Contact

About SANS Institute

The SANS Institute was established in 1989 as a cooperative research and education organization. Today, SANS is the most trusted and, by far, the largest provider of cyber security training and certification to professionals in government and commercial institutions worldwide. Renowned SANS instructors teach more than 60 courses at In-Person and Live Online cyber security training events, and more than 50 courses are available anytime, anywhere with our OnDemand platform. GIAC, an affiliate of the SANS Institute, validates practitioner skills through more than 35 hands-on, technical certifications in cyber security. The SANS Technology Institute, a regionally accredited independent subsidiary, offers a master’s degree, graduate certificates, and an undergraduate certificate in cyber security. SANS Security Awareness, a division of SANS, provides organizations with a complete and comprehensive security awareness solution, enabling them to easily and effectively manage their ‘human’ cybersecurity risk. SANS also delivers a wide variety of free resources to the InfoSec community including consensus projects, research reports, webcasts, podcasts, and newsletters; it also operates the Internet's early warning system – the Internet Storm Center. At the heart of SANS are the many security practitioners, representing varied global organizations from corporations to universities, working together to support and educate the global information security community. (