Discussion sheet
Purposeful Security / $0 Security Sprint
Practice an unexpected IT support request
Fictional discussion: no real calls, support codes or remote sessions.
No additional software purchase is required. Staff time and provider assistance may still have costs.
This fictional discussion can identify unclear instructions. It does not establish that staff will detect an attack or that a security control works. It is independently authored by Purposeful Security, not an official NCSC exercise.
Prepare together
Use this alone or agree the fictional walkthrough with the responsible team and colleagues.
Identify where staff should find approved support and reporting instructions without relying on work email.
Unknown routes are discussion gaps. Confirm them with their owner before distributing a staff reminder.
Keep the exercise fictional
Discuss only. Do not initiate a remote session, enter a support code, run commands or change settings.
Do not stage unexpected calls or send surprise incident reports.
If a real suspicious request or incident is occurring, stop the exercise and use your established reporting process through an independently known route.
Stage 1: Email is unavailable
Work email is unavailable. A caller says IT asked them to restore access.
Discuss before reading the guidance:
• Where would you find your known support route?
• Can you reach it without email?
Discussion guidance:
Use independently known records and an agreed alternate route.
A convincing story does not confirm the caller.
Stage 2: The caller asks for remote access
The caller adds urgency and asks you to open a remote-support tool using their code.
Discuss before reading the guidance:
• What would you do before sharing a screen or allowing control?
• Would a familiar application prove who the caller is?
Discussion guidance:
Pause and verify through your independently known support route.
Legitimate software does not authenticate an unexpected caller. Screen sharing and control are distinct permissions. Do not perform either as part of this discussion.
Stage 3: The request cannot be confirmed
The known route is unclear, or support cannot confirm the request.
Discuss before reading the guidance:
• Who owns the gap?
• How would you report the request and find approved instructions?
Discussion guidance:
Do not continue the caller’s procedure. Use the agreed reporting or alternate route.
Ask the responsible person to resolve missing instructions. Contacts supplied by the unexpected caller are not a substitute.
Discuss follow-up
Which route was hard to find?
What remained unclear?
Who should agree the next action?
Sources reviewed October 6, 2026
NCSC Exercise in a Box getting started: https://www.ncsc.gov.uk/section/exercise-in-a-box/getting-started
Microsoft Quick Assist documentation: https://learn.microsoft.com/en-us/windows/client-management/client-tools/quick-assist
Related guidance
https://purposefulsecurity.com/security-sprint/verify-support-contacts
https://purposefulsecurity.com/decision-lab/unexpected-it-support
https://purposefulsecurity.com/threat-in-practice/remote-support-phishing
https://purposefulsecurity.com/remediations/security-awareness-training
https://purposefulsecurity.com/remediations/incident-response-plan