Articles on HRM
What we publish on HRM for CISOs, IT and compliance teams in LATAM.
Articles on Human Risk Management: the practice of measuring human cyber risk as a managed program, not a series of courses. We cover what sets HRM apart from traditional security awareness training, how a risk score gets built to be comparable across people and teams, and which decisions —simulation, content, channel, difficulty— get automated once the program stops being measured by completion rate. It's the reference category for understanding the full framework before drilling into a specific topic like PCI DSS, analytics or audit.

APWG and PCI DSS: Smishing Is Rising
Smishing is growing on mobile channels while PCI DSS v4.0 requires annual awareness training and explicit phishing and social engineering content.
Read more
Security awareness training: measure clicks, not courses
NIST, UC San Diego, Frontiers, Verizon and SANS agree that annual training alone is not enough. The useful metric is sustained behavior.
Read more
Whalemate and HRM in security awareness
Whalemate frames security awareness as Human Risk Management, not a standalone course. CIS, NIST, SANS, and recent studies show mixed results.
Read more