Skip to content
Aspire SAT
Transportation / Use case

Keep a routine service request from becoming an access risk.

Phishing simulations for transit agency IT staff. Practice verifying service notices, support requests and credential prompts without disrupting operational work.

A decision to practiceIllustrative scenario
01 / The request

A maintenance notice requests administrator access.

“A service update is due tonight. Confirm your administrator credentials at this link.”
Pause and verify

Verify the maintenance request in the approved system before providing access.

Built around the work

Different responsibilities.
A shared security habit.

IT staff supporting transit services work across vendor communications, access requests and operational deadlines. Train the verification decision without presenting awareness exercises as a replacement for operational security controls.

Who this supports
  • Service-desk staff
  • System administrators
  • Vendor-facing IT teams
Recognizable situations

Practice the moment that matters.

Illustrative examples for transportation. Agree the audience, scope and procedures before using a scenario.

Scenario 01

A maintenance notice requests administrator access.

A service update is due tonight. Confirm your administrator credentials at this link.

What to notice
A vendor-style notice sends privileged users to an unfamiliar sign-in page.
A safer next step
Verify the maintenance request in the approved system before providing access.
Scenario 02

A support ticket arrives outside the normal channel.

Please reset this account immediately; the usual approver is offline.

What to notice
Operational urgency used to bypass identity and approval checks.
A safer next step
Follow the agency’s account-reset and escalation procedure.
A practical program

Give every activity
a clear purpose.

01

Choose the access workflow

Identify help-desk and administrator decisions that the exercise should reinforce.

02

Run a controlled campaign

Prepare approved vendor-notice or service-desk scenarios and target the relevant IT group.

03

Review the response

Examine reporting and click behavior, then reinforce independent verification with focused training.

Before you get started

Useful answers.
Clear expectations.

Explore scope and rollout questions for your awareness program.

Does this test transit operational systems?

No. This use case describes employee awareness and controlled phishing practice, not penetration testing or a test of operational technology.

Can scenarios reflect vendor communications?

Administrators can prepare phishing templates and targeting around approved learning objectives, including suspicious vendor notices and support requests.

What can a program owner review?

Review campaign behavior, training completion and reporting activity against your own baseline. Use those observations to choose the next learning step for each team.

Make it relevant

Bring your team’s questions.

Explore an awareness program for transportation, with scenarios and learning that fit your work.