Plan requirement
| Subscription | Any plan |
| Access | Admin |
Zendesk scans attachments and blocks what it identifies as malicious. What that covers, and what still needs your judgement.
What Zendesk does
Incoming attachments are scanned. Files identified as malicious are blocked rather than delivered to your agents, and the ticket carries a note that something was removed.
That covers known malware. It does not cover a file that is technically clean but part of an attempt to get an agent to do something, which is the more common shape of an attack on a support team.
What your agents still need to know
- An attachment being present does not mean it is safe to open. Scanning reduces risk; it does not remove it.
- Documents asking you to enable content are the classic route in. That prompt exists because the file wants to run something.
- Urgency plus an attachment is the pattern worth pausing on. Support teams are targeted precisely because they are helpful and quick.
- Anything asking an agent to sign in to see a file should be treated as suspicious, whatever it appears to be from.
Agents are a route into your business. They open files from strangers all day, which is exactly what everyone else is told not to do. Agree what happens when something looks wrong, and make sure nobody feels awkward about not opening a file.
Reducing exposure
Two things help beyond scanning. Suspended tickets keep most unsolicited mail away from agents entirely, and comment flags mark messages whose sender could not be verified, which is where spoofed mail shows up.
Comments
0 comments
Article is closed for comments.