One of my teammates and I got into a debate about this. One of our users was attempting to download software for an old plotter, while on the phone with the vendor. Their tech directed the user to a site, but the user flopped a / for a period and ended up on a lovely spoofed version of the site that had all the drivers, as well as some malware goodies within the zip. Our A/V nuked it immediately, user tries 5 more bloody times, same result. Here is where our disagreement starts.
I hit up our help desk team to go down to the user and help them install this thing so my alert inbox stops squawking. I also email the user to verify the situation and tell them what happened with the spoofed site after I verified it was a malicious zip, told them to not try again, and someone from the help desk would be by soon.
My partner tells me I should have instead of having the help desk do that, I should have gone myself to their desk to do the verification, and that the HD shouldn't be involved at all as they don't have the proper training or mentality to view this from a security front, won't ask the right questions and in general just aren't qualified.
I can agree with the first part, I should have headed over to the user and chatted, but I was working another issue and this seemed like some basic tier 1 support so I tossed it over. Any help desk tech worth their salt should be able to handle something like this and not need handholding, plus I trust my teams. Is my partner too jaded, or am I too trusting?
[link] [comments]