Employee Security Responsibilities
Verify the caller before you trust the request.
What Is Employee Security Responsibilities?
A caller claiming to be a doctor reaches the patient management desk with a dying patient and a locked account. He offers the first digits of an employee ID as proof, then walks the agent to a lookalike portal to authorise a password reset. Three hours later thousands of patient records are gone. You will trace the attack chain, pinpoint the moment it could have been stopped, reset the password, enrol in multi-factor authentication and file the report. Caller ID and a partial ID number are not identity verification.
What You'll Learn in Employee Security Responsibilities
- Verify an unexpected caller's identity using a number from the internal directory rather than any detail the caller supplies
- Recognize urgency, claimed authority and appeals to compassion as the pressure pattern that precedes a credential request
- Identify a lookalike portal domain before entering credentials, and treat any password reset prompted by an inbound caller as hostile
- Contain a confirmed credential compromise by changing the password immediately and enrolling in app-based multi-factor authentication
- File an incident report that captures the caller's claims, the spoofed domain and the records at risk so the security team can act
Employee Security Responsibilities — Training Steps
-
A Normal Monday at Meridian Healthcare
It's a normal Monday morning. You've just settled in with your coffee and logged into the patient management portal.
-
An Urgent Phone Call
Alice's phone rings. The caller ID shows 'Dr. Rajan Mehta - Cardiology.' A man's voice comes through — urgent, almost panicked. He says a patient is coding in the ER and he desperately needs access to their records, but his portal account is locked out.
-
The Verification Trick
The caller offers to 'verify' his identity. He gives Alice the first few digits of his employee ID and asks her to look up and read back the rest. It feels like proof — but he just tricked Alice into completing his identity for him.
-
Directed to the "Quick-Reset Tool"
Now that Alice believes the caller is legitimate, he directs her to an 'IT quick-reset tool' at meridianhc-portal.net/reset. He says she needs to enter her own credentials to authorize the reset for his account.
-
Entering Credentials on the Phishing Page
Alice opens the URL the caller provided. The page looks like a Meridian Healthcare IT tool — but the domain is meridianhc-portal.net, not the real meridianhc.com. She doesn't notice the difference in her rush to help the 'dying patient.'
-
"Processing" the Authorization
The page shows a 'Processing Authorization' message and says Alice will receive a confirmation email within 24 hours. It looks routine — but her credentials have just been captured by the attacker.
-
Consequences Revealed
Three hours later, an urgent email arrives from the CISO. Unauthorized access has been detected on the patient management system. 2,300 patient records — names, Social Security numbers, insurance data, medical histories — have been exported to an external server. The credentials used: Alice's.
-
The Breach Investigation
Alice's stomach drops. She clicks the link to the breach investigation dashboard and logs in to see the full scope of the damage.
-
Understanding the Attack Chain
The breach dashboard reveals the full attack chain. Every step is laid out: the spoofed caller ID, the fake verification trick, the phishing URL on an external domain, and the credential capture.
-
What Should Alice Have Done?
Now that the full attack chain is visible, let's reflect on the critical moment where Alice could have stopped this.
Security Framework Coverage
CIS Controls
- CIS 14.1 Establish and Maintain a Security Awareness Program
- CIS 14.2 Train Workforce Members to Recognize Social Engineering Attacks
NIST CSF
- PR.AT-01 Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind