Human Risk Management is not searched the way "security awareness training" is. It needs a name. HRM means managing cyber risk with a focus on people’s behavior: who is exposed, how that evolves, and what happens next.
HRM is not another course
The difference versus an awareness program is not the tooling. It is the stance. Instead of measuring who completed a course, you measure who still represents a risk and you intervene with simulations, profile-based training and analytics.
100% completion says nothing about who is still clicking. That is the metric a board already knows, and it is not enough to operate human risk. HRM changes the question: not "did they attend?" but "are they still exposed, and what do we do with that?"
The HRM glossary holds the definitions. This note exists for the query "what is human risk management" and to link the vocabulary to the product.
The cycle of a managed program
The cycle Whalemate runs is a managed program: model context, simulate, train, measure, intervene, report.
Model context. Roster, language, role and channel matter more than a generic syllabus.
Simulate. The native channel is email (phishing) and QR (QRishing), in click, credential and simulated-ransomware modalities. Smishing, vishing, USB drop, MFA attacks and deepfake run as professional services, not self-service.
Train. It is not a library for people to browse. It is the lesson that fits that person at the moment of the mistake. See adaptive training.
Measure. The risk score consolidates signals. It is used to prioritize, not to build a punitive ranking. Detail in human risk analytics.
Intervene. The awareness agent decides the next intervention within the rules the team defines. It is not a chatbot or a campaign scheduler.
Report. Exportable evidence for auditor and board. PCI DSS 12.6 and ISO/IEC 27001 ask for a program, not a one-off course.
What it is not
It is not an LMS with more titles. It is not a country ranking. It is not a hall of shame. Whalemate is certified ISO/IEC 27001:2022 (A-LIGN); the Trust Center and the DPA say that no individual metric is used for disciplinary purposes.
If you are looking for the installed category — security awareness training — the glossary term explains why HRM is what comes next. If you are looking for the platform, the brief is on the human risk platform.
Managing cyber risk with a focus on people’s behavior: who is exposed, how that evolves, and what happens next. It does not replace awareness: it turns it into a managed program.
How is it different from security awareness training?
Awareness measures who completed a course. HRM measures who still represents a risk and decides the next intervention — simulation, content, channel, difficulty — with data.
What cycle does Whalemate run?
Model context, simulate, train, measure, intervene and report. Vocabulary lives in the HRM glossary; the metric lives in human risk analytics.
Does HRM use the score to discipline people?
No. The Trust Center and the DPA state that no individual metric is used for disciplinary purposes by Whalemate. The score is for prioritization.
Would you like to go deeper on this topic?
Open this article directly in Claude or ChatGPT —
ask questions, get a summary, or explore related ideas.