Blog
Human risk and cybersecurity blog
Guides and analysis for CISOs, IT and compliance teams in LATAM who need to explain the human factor — and decide what to do about it.

HRM
Sep 11, 2026By Federico Hombre
APWG and PCI DSS: Smishing Is Rising
Smishing is growing on mobile channels while PCI DSS v4.0 requires annual awareness training and explicit phishing and social engineering content.
Read more
HRM
Sep 7, 2026By Federico Hombre
Security awareness training: measure clicks, not courses
NIST, UC San Diego, Frontiers, Verizon and SANS agree that annual training alone is not enough. The useful metric is sustained behavior.
Read more
Awareness
Sep 7, 2026By Federico Hombre
ISO, NIST, SANS, Verizon on phishing training
ISO calls for a continuous program for all employees, NIST and SANS make it measurable, and Verizon shows the risk happens in seconds.
Read more
HRM
Sep 3, 2026By Federico Hombre
Whalemate and HRM in security awareness
Whalemate frames security awareness as Human Risk Management, not a standalone course. CIS, NIST, SANS, and recent studies show mixed results.
Read more