United Kingdom
Phishing simulation for the UK’s
tax, parcel and Teams lures.
In the UK, employees see tax-refund texts, parcel-redelivery fees, and Microsoft Teams or Microsoft 365 messages from external “IT support”, often followed by a helpdesk-style phone call.
- Regulators & frameworks
- UK GDPR and the Data (Use and Access) Act 2025, Cyber Governance Code of Practice, ISO/IEC 27001:2022
- Channels to rehearse
- Microsoft Teams, email, SMS, voice calls and Slack
- Local lure patterns
- Tax refunds, parcel redelivery fees, Microsoft 365 and IT-helpdesk pretexts
- KeenSec evidence
- Simulation results, reporter logs, certificates, policy acknowledgements
Simulated UK lures
Refunds, parcels and IT support:
the pretexts to rehearse.
Simulated examples of the refund, delivery and IT-support pretexts familiar to anyone with a UK phone or inbox.
Courier desk
We missed you
We tried to deliver your parcel today. Pay the redelivery fee to book a new slot: redelivery.example
- Fee for a missed delivery
- Unknown short link
External · IT Service Desk
Microsoft 365 password expires today
Your password expires in 2 hours. Keep your current password by signing in here, or expect a call from us to help.
- External tenant posing as IT
- Offer of a “helpful” call
Regulators and frameworks
The UK frameworks
your evidence supports.
| Framework | Applies to | KeenSec evidence |
|---|---|---|
| UK GDPR, as amended by the Data (Use and Access) Act 2025 | Organisations processing personal data in the UK | Data-handling training, simulation results and policy acknowledgements |
| Cyber Governance Code of Practice (April 2025) | Boards and directors: board cyber training and assurance, using metrics, that awareness training works | Board training records, simulation and reporting metrics over time |
| ISO/IEC 27001:2022 | Organisations certified or certifying | Evidence for the awareness, education and training control |
KeenSec helps you produce evidence for your awareness obligations: simulation results, report logs, training completions and certificates, and policy acknowledgements. Your auditor decides compliance. Cyber Essentials is a technical-controls scheme and sits alongside, not in place of, an awareness programme.
Questions buyers ask
Frequently asked questions.
Which UK frameworks does KeenSec help with?
KeenSec helps produce awareness evidence for UK GDPR, the Cyber Governance Code of Practice and ISO/IEC 27001:2022. FCA operational resilience rules do not set training requirements, and the Cyber Security and Resilience Bill is still before Parliament. Your auditor decides compliance.
Does Cyber Essentials require security awareness training?
No. Cyber Essentials is a technical-controls scheme. Awareness evidence supports other obligations, such as ISO/IEC 27001’s awareness, education and training control.
Can we simulate external Microsoft Teams phishing?
Yes. KeenSec sends simulated Teams messages from an external sender, records who responds or reports, and shows a lesson in the moment.
Let’s connect the dots
Past the inbox.
Into Teams and the phone.
Bring your awareness program, your reporting workflow, or the question your current metrics cannot answer.
Book a demo