Security Decision Lab

Would you trust this IT support request?

An unexpected message. A convincing offer of help. Make the decisions and see where they lead.

Free. No account. Your choices stay in this browser tab and clear when the page reloads.

Case 01 / The unexpected helper

Your inbox is flooded.
Someone offers to fix it.

You work in a small business. There is no security team down the hall. An unexpected support request puts the next decision in your hands.

Fictional exercise. No real calls or remote sessions. No software is installed or commands run.

Simulated support message

IT Helpdesk

External contact

“We have seen the spam issue. I can clear it for you now. Are you at your computer?”

You did not open a support ticket.

Make this useful at work

Agree a known support contact and a reporting route before anyone needs them. Discuss the scenario with colleagues, then review which remote tools your team approves and how staff verify a support request. These steps use your existing processes; the lab requires no new license.

Sources and exercise limits

This fictional scenario draws on Microsoft's reporting on support impersonation and its Quick Assist documentation. The people, dialogue and choices are invented; it does not recreate a specific incident. Screen sharing and remote control are separate permissions in Quick Assist.

Sources reviewed October 6, 2026. We have not lab-tested the attack or recovery steps. Completing the exercise does not show that staff are ready for an attack or that your organization is secure. How we prepare guidance

Already dealing with a suspicious remote session? Contact your trusted support team and follow your incident process. This exercise does not connect you to an incident responder.

Turn this into a trusted-contact task →

Practice this with your team →