$0 Security Sprint

Verify your trusted support contacts

Give staff a known way to verify unexpected IT support requests and report concerns, including when email is unavailable.

No additional software purchase for the starting steps. Your time, storage and provider support may still have costs.

Entries stay in this tab and clear on reload. Do not enter passwords, secrets or confidential information.

01 / Tailor your starting point

What do you already know?

Choose “Not sure” when you need help. Changing any selection clears your observations and reported outcome.

Who provides your IT support?
Can you perform the checks with permission?
How would you like to begin?

02 / Work through your task

Before you begin

Part 1 of 6. Moving through the steps does not mark a check as complete.

  • Identify who is responsible for your IT support, or who can confirm that responsibility.
  • Use records or a relationship you already trust, rather than details supplied in an unexpected message.

03 / Record what you found

Your observations, kept in this tab

All fields are optional, up to 300 characters each. Use synthetic or non-sensitive summaries. No passwords, tokens, confidential data or personal contact details.

Optional role or approved route. Leave personal contact details out.

Who should staff contact?

A role or procedure is enough.

Optional observations or questions. Keep confidential details out.

What can you report for the stated result?

Identifying contacts does not establish that staff will detect a future attack. Contact details entered here are not checked by this website. Preparation results do not verify operational protections.

$0 Security Sprint / Purposeful Security

Verify your trusted support contacts

Prepare your trusted support routes

A caller can sound convincing. Staff need an independently known way to check who is helping.

No additional software purchase for the starting steps. Your time, storage and provider support may still have costs.

  • Access: Not sure
  • Approach: Prepare first
  • Environment: Not sure

Local outcome: Not checked

Self-reported only. This website has not verified the result.

Identifying contacts does not establish that staff will detect a future attack. Contact details entered here are not checked by this website.

Costs and permissions

Use existing records and services. No new software purchase is required to prepare; staff time and provider support may have costs.

Prerequisites

  • Identify who is responsible for your IT support, or who can confirm that responsibility.
  • Use records or a relationship you already trust, rather than details supplied in an unexpected message.

Actions

  1. Find your existing support agreement, staff directory or approved internal instructions. If ownership is unclear, ask the responsible manager.
  2. Ask for the approved support contact, the route for reporting suspicious requests, and an alternate contact route if work email is unavailable.
  3. Ask the responsible team to confirm the routes and where staff should find them. Do not distribute an unconfirmed number as trusted.

What to verify

  • Record which routes were confirmed and which remain unknown. This preparation path does not test the contact procedure.
  • Arrange an agreed fictional walkthrough with the responsible team when the routes are confirmed.

Recovery if something fails

  • If records disagree or a contact cannot be confirmed, mark Needs follow-up and ask the responsible manager to resolve it.
  • Do not start a remote session or send a surprise incident report to test a route.

Request for the responsible team

Please confirm our approved IT support contact, suspicious-request reporting route, and alternate route if work email is unavailable. Where should staff find these? Can we agree a fictional walkthrough before testing the procedure?

Optional observations

Known support route
Not recorded
Suspicious-request reporting route
Not recorded
Alternate route when email is unavailable
Not recorded
Notes
Not recorded

Sources and related guidance

Sources reviewed October 6, 2026. Operational steps have not been lab-tested by Purposeful Security.

Store this card privately if it contains internal details. Review those details before sharing.

Keep your next move

Download, copy or print locally. Review any internal details before sharing the card. The public mission link contains none of your entries.

Sources and testing

Sources reviewed October 6, 2026. These steps have not been lab-tested by Purposeful Security. We have not tested your systems or independently checked your result. How we prepare guidance.