Strengthening Your Defences: Why Robust Password Reset Policies Matter
In the wake of a concerning warning from the UK’s National Cyber Security Centre (NCSC), businesses across the country are being urged to review their IT helpdesks password reset policies. This follows a recent wave of sophisticated cyber attacks targeting major British retailers such as Marks & Spencer, Co-op, and Harrods—where attackers impersonated IT support staff to gain access to internal systems.
These incidents are believed to involve social engineering tactics, where hackers pose as employees or IT personnel to manipulate help desk staff into revealing sensitive login information or resetting passwords for unauthorised users. The NCSC’s guidance is clear: the way organisations verify staff identity before making account changes is critical.
What’s Happening?
Cyber criminals—many believed to be part of loosely coordinated groups like the so-called Scattered Spider or DragonForce—have used tools like Discord and Telegram to plan and execute attacks that involve phishing, impersonation, and credential theft. By pretending to be locked-out employees or trusted helpdesk agents, these attackers bypass traditional login processes and gain access to sensitive systems, often with devastating consequences.
How Eitex Stays Ahead with their Password Reset Policies
At Eitex, we take these risks seriously. That’s why we’ve put rigorous password reset and user authentication policies in place to protect both our business and our clients.
Our approach includes:
✅ Multi-Layered Identity Verification
Before any password reset is approved by our IT helpdesk, users must pass a series of identity checks. This includes multiple validation steps such as known device confirmation, secondary email or mobile verification, and in some cases, unique code word authentication.
✅ No Reset Without Logging & Authorization
All password resets are tracked, logged, and subject to internal authorisation. This ensures there’s always accountability and traceability—especially for high-level or privileged accounts.
✅ Training Against Social Engineering
Our team is trained to detect and reject suspicious requests, especially those that display common red flags associated with social engineering. No matter how convincing the caller may sound, policies come first.
What This Means for Our Clients
If you’re a business relying on Eitex for IT support, rest assured that we are not only aware of the rising threat landscape—we’re ahead of it. We continually review and improve our security protocols to align with national guidance from the NCSC and industry best practices.
As the NCSC notes, cyber criminals are becoming more sophisticated, and the battle against cyber threats requires a layered defence. That’s why we’re committed to keeping our clients protected, informed, and supported at every level.
Need help reviewing your company’s password policies or securing your helpdesk processes?
Get in touch with the Eitex team today. Your security is our priority.