$0 Security Sprint / Practice with your team

Practice an unexpected IT support request

A caller offers to fix a work email outage. Before accepting help, can your team find an independently known way to verify the request?

Fictional discussion. Use it alone or with colleagues. No account or administrator access required.

No additional software purchase is required. Staff time and provider assistance may still have costs.

Before you begin

  • Use this alone or agree the fictional walkthrough with the responsible team and colleagues.
  • Identify where staff should find approved support and reporting instructions without relying on work email.
  • Unknown routes are discussion gaps. Confirm them with their owner before distributing a staff reminder.

Keep it fictional

  • Discuss only. Do not initiate a remote session, enter a support code, run commands or change settings.
  • Do not stage unexpected calls or send surprise incident reports.
  • If a real suspicious request or incident is occurring, stop the exercise and use your established reporting process through an independently known route.

Read or print this public discussion sheet. JavaScript is needed for staged discussion, optional notes and exports.

Discussion sheet

Purposeful Security / $0 Security Sprint

Practice an unexpected IT support request

Fictional discussion: no real calls, support codes or remote sessions.

No additional software purchase is required. Staff time and provider assistance may still have costs.

This fictional discussion can identify unclear instructions. It does not establish that staff will detect an attack or that a security control works. It is independently authored by Purposeful Security, not an official NCSC exercise.

Prepare together

Use this alone or agree the fictional walkthrough with the responsible team and colleagues.

Identify where staff should find approved support and reporting instructions without relying on work email.

Unknown routes are discussion gaps. Confirm them with their owner before distributing a staff reminder.

Keep the exercise fictional

Discuss only. Do not initiate a remote session, enter a support code, run commands or change settings.

Do not stage unexpected calls or send surprise incident reports.

If a real suspicious request or incident is occurring, stop the exercise and use your established reporting process through an independently known route.

Stage 1: Email is unavailable

Work email is unavailable. A caller says IT asked them to restore access.

Discuss before reading the guidance:

• Where would you find your known support route?

• Can you reach it without email?

Discussion guidance:

Use independently known records and an agreed alternate route.

A convincing story does not confirm the caller.

Stage 2: The caller asks for remote access

The caller adds urgency and asks you to open a remote-support tool using their code.

Discuss before reading the guidance:

• What would you do before sharing a screen or allowing control?

• Would a familiar application prove who the caller is?

Discussion guidance:

Pause and verify through your independently known support route.

Legitimate software does not authenticate an unexpected caller. Screen sharing and control are distinct permissions. Do not perform either as part of this discussion.

Stage 3: The request cannot be confirmed

The known route is unclear, or support cannot confirm the request.

Discuss before reading the guidance:

• Who owns the gap?

• How would you report the request and find approved instructions?

Discussion guidance:

Do not continue the caller’s procedure. Use the agreed reporting or alternate route.

Ask the responsible person to resolve missing instructions. Contacts supplied by the unexpected caller are not a substitute.

Discuss follow-up

Which route was hard to find?

What remained unclear?

Who should agree the next action?

Sources reviewed October 6, 2026

NCSC Exercise in a Box getting started: https://www.ncsc.gov.uk/section/exercise-in-a-box/getting-started

Microsoft Quick Assist documentation: https://learn.microsoft.com/en-us/windows/client-management/client-tools/quick-assist

Related guidance

https://purposefulsecurity.com/security-sprint/verify-support-contacts

https://purposefulsecurity.com/decision-lab/unexpected-it-support

https://purposefulsecurity.com/threat-in-practice/remote-support-phishing

https://purposefulsecurity.com/remediations/security-awareness-training

https://purposefulsecurity.com/remediations/incident-response-plan

Fictional example: not your results

A fictional small office can find its normal support instructions but has no confirmed route when work email is unavailable.

Gap: the email-outage route is not confirmed. Responsible role: office manager. Next action: agree an alternate route with the support owner and put approved instructions somewhere staff can reach without email.

This example does not populate your notes and was not run with a real team.

Sources and limits

This fictional discussion can identify unclear instructions. It does not establish that staff will detect an attack or that a security control works. It is independently authored by Purposeful Security, not an official NCSC exercise.

Sources reviewed October 6, 2026. We have not tested this exercise with a team or run a security lab test. How we prepare guidance.