Saudi Arabia
Phishing simulation in Saudi Arabia,
beyond the email test.
Many Saudi organisations already run basic email phishing tests.
- Regulators & frameworks
- NCA ECC-2:2024 (control 1-10-3), NCA NCNICC-1:2025, SAMA Cyber Security Framework, PDPL
- Channels to rehearse
- Voice calls, WhatsApp, SMS, plus email and Teams
- Local lure patterns
- Government-portal and payment-service lures, delivery fees, Arabic-language pretexts
- KeenSec evidence
- Multi-channel results, reporter analysis, certificates, policy acknowledgements
Simulated Saudi lures
Portals, payments and parcels:
pretexts built for the Kingdom.
Simulated examples of lure patterns seen in Saudi Arabia.
“Payments desk” · unknown number
Bill payment failed
Your latest bill payment did not go through. Re-enter your card details today to avoid a late penalty: pay-bills.example
- Card details requested in chat
- Penalty pressure
Courier desk (automated)
Delivery on hold
“Your shipment is on hold. Press 1 to pay the redelivery fee, then enter the code we send to your phone.”
- IVR asks for a one-time code
- Unexpected delivery
Regulators and frameworks
What Saudi frameworks expect,
and the evidence you can show.
| Framework | People-side relevance | KeenSec evidence |
|---|---|---|
| NCA ECC-2:2024 | Control 1-10-3 requires awareness on secure email handling, especially phishing emails, plus mobile devices, browsing and social media. | Email simulation results and reporter logs; SMS and WhatsApp results for mobile devices; training certificates |
| SAMA Cyber Security Framework | Section 3.1.6: awareness for staff, third parties and customers throughout the year, including spear-phishing, with effectiveness measured. | Simulation results by team, training completions, policy acknowledgements |
| PDPL | In force since 14 September 2023; breaches reported to SDAIA within 72 hours. | Data-handling training and policy acknowledgements |
KeenSec helps you produce evidence for your awareness obligations: simulation results, report logs, training completions and certificates, and policy acknowledgements. Your auditor decides compliance.
Questions buyers ask
Frequently asked questions.
We already run email phishing tests. Why add KeenSec?
Because attacks don’t stop at email. KeenSec adds voice, WhatsApp and SMS rehearsals, automated analysis of reported emails, and policy and training evidence in one record.
What does NCA ECC-2:2024 control 1-10-3 cover?
It expects the cybersecurity awareness programme to cover secure handling of email, especially phishing emails, as well as mobile devices and browsing. KeenSec helps you produce evidence for that programme; your auditor decides compliance.
Does KeenSec work for SAMA-regulated institutions?
Yes. KeenSec helps banks and financial institutions produce awareness evidence for the SAMA Cyber Security Framework: simulation results, training records and policy acknowledgements.
Let’s connect the dots
Beyond the email test.
Evidence for every channel.
Bring your awareness program, your reporting workflow, or the question your current metrics cannot answer.
Book a demo