Human risk and cybersecurity blog
Guides and analysis for CISOs, IT and compliance teams in LATAM who need to explain the human factor — and decide what to do about it.

PCI DSS 12.6: Vishing and Smishing Scope
Vishing and smishing are no longer just phishing variants. Under PCI DSS 12.6, they require a formal program, channel metrics, and steady improvement.
Read more
PCI DSS 12.6 Requires Vishing Coverage
Vishing and smishing are voice and SMS phishing. Under PCI DSS 12.6, measuring only email or course completion leaves a compliance gap.
Read more
APWG and PCI DSS: Smishing Is Rising
Smishing is growing on mobile channels while PCI DSS v4.0 requires annual awareness training and explicit phishing and social engineering content.
Read more
Security awareness training: measure clicks, not courses
NIST, UC San Diego, Frontiers, Verizon and SANS agree that annual training alone is not enough. The useful metric is sustained behavior.
Read more
ISO, NIST, SANS, Verizon on phishing training
ISO calls for a continuous program for all employees, NIST and SANS make it measurable, and Verizon shows the risk happens in seconds.
Read more
Whalemate and HRM in security awareness
Whalemate frames security awareness as Human Risk Management, not a standalone course. CIS, NIST, SANS, and recent studies show mixed results.
Read more