Reducing the visibility of individual officers is a sensible friction point, but I have found that the more durable control is redesigning business processes so staff, citizens, and suppliers stop treating a recognisable name or government email address as proof of authority.
The next pressure point will be agency workflows that still rely on email approvals and direct officer-to-citizen interactions, and those processes will be replaced with authenticated service portals, verifiable callback mechanisms, and transaction-specific verification for higher risk requests because the attackers will simply shift to impersonating the remaining trusted channels.
Reducing the visibility of individual officers is a sensible friction point, but I have found that the more durable control is redesigning business processes so staff, citizens, and suppliers stop treating a recognisable name or government email address as proof of authority.
The next pressure point will be agency workflows that still rely on email approvals and direct officer-to-citizen interactions, and those processes will be replaced with authenticated service portals, verifiable callback mechanisms, and transaction-specific verification for higher risk requests because the attackers will simply shift to impersonating the remaining trusted channels.