United Kingdom

Phishing simulation for the UK’s
tax, parcel and Teams lures.

In the UK, employees see tax-refund texts, parcel-redelivery fees, and Microsoft Teams or Microsoft 365 messages from external “IT support”, often followed by a helpdesk-style phone call.

Regulators & frameworks
UK GDPR and the Data (Use and Access) Act 2025, Cyber Governance Code of Practice, ISO/IEC 27001:2022
Channels to rehearse
Microsoft Teams, email, SMS, voice calls and Slack
Local lure patterns
Tax refunds, parcel redelivery fees, Microsoft 365 and IT-helpdesk pretexts
KeenSec evidence
Simulation results, reporter logs, certificates, policy acknowledgements

Simulated UK lures

Refunds, parcels and IT support:
the pretexts to rehearse.

Simulated examples of the refund, delivery and IT-support pretexts familiar to anyone with a UK phone or inbox.

Simulated example
SMS

Courier desk

We missed you

We tried to deliver your parcel today. Pay the redelivery fee to book a new slot: redelivery.example

  • Fee for a missed delivery
  • Unknown short link
Simulated example
Microsoft Teams

External · IT Service Desk

Microsoft 365 password expires today

Your password expires in 2 hours. Keep your current password by signing in here, or expect a call from us to help.

  • External tenant posing as IT
  • Offer of a “helpful” call

Regulators and frameworks

The UK frameworks
your evidence supports.

FrameworkApplies toKeenSec evidence
UK GDPR, as amended by the Data (Use and Access) Act 2025Organisations processing personal data in the UKData-handling training, simulation results and policy acknowledgements
Cyber Governance Code of Practice (April 2025)Boards and directors: board cyber training and assurance, using metrics, that awareness training worksBoard training records, simulation and reporting metrics over time
ISO/IEC 27001:2022Organisations certified or certifyingEvidence for the awareness, education and training control

KeenSec helps you produce evidence for your awareness obligations: simulation results, report logs, training completions and certificates, and policy acknowledgements. Your auditor decides compliance. Cyber Essentials is a technical-controls scheme and sits alongside, not in place of, an awareness programme.

Questions buyers ask

Frequently asked questions.

Which UK frameworks does KeenSec help with?

KeenSec helps produce awareness evidence for UK GDPR, the Cyber Governance Code of Practice and ISO/IEC 27001:2022. FCA operational resilience rules do not set training requirements, and the Cyber Security and Resilience Bill is still before Parliament. Your auditor decides compliance.

Does Cyber Essentials require security awareness training?

No. Cyber Essentials is a technical-controls scheme. Awareness evidence supports other obligations, such as ISO/IEC 27001’s awareness, education and training control.

Can we simulate external Microsoft Teams phishing?

Yes. KeenSec sends simulated Teams messages from an external sender, records who responds or reports, and shows a lesson in the moment.

Let’s connect the dots

Past the inbox.
Into Teams and the phone.

Bring your awareness program, your reporting workflow, or the question your current metrics cannot answer.

Book a demo