Back to blog

Blog

Whalemate and HRM in security awareness

Whalemate frames security awareness as Human Risk Management, not a standalone course. CIS, NIST, SANS, and recent studies show mixed results.

Whalemate and HRM in security awareness

Whalemate does not sell an employee security awareness course. It sells a Human Risk Management framework that measures behavior, intervenes by profile, and reports operational evidence. That difference is not semantic: CIS, NIST, and SANS treat awareness as a continuous program, while academic evidence shows uneven results, with improvements in awareness or reporting in some cases and declines or no impact in others.

When these sources are read together, a tension appears that none of them fully resolves: the standard calls for cadence and governance, the product promises adaptive intervention, and the research reminds us that completing training does not guarantee behavior change. For CISOs, IT, and compliance teams in LATAM, that changes the decision unit. Counting attendees or certificates is no longer enough.

Source Framing Measurement unit Cadence Intervention model Evidence focus Behavioral result
Whalemate Human Risk Management platform, not a standalone course Who is exposed, risk score, real behavior Continuous, with adaptive training based on risk profile Awareness agent that analyzes and adjusts simulations, training, and analytics without manual intervention Role-based training, participation evidence, auditable reports Measures real behavioral change
CIS Control 14 Security awareness and skills training program Workforce behavior and security posture At onboarding and, at minimum, annually, with annual content review or review after major changes Does not specify automation Maintaining the control program Influence behavior to reduce risk
NIST SP 800-50 Cybersecurity and privacy learning program Awareness training completion by personnel Lifecycle approach, within 24 hours of receiving an account Does not specify automation Program building and timing of completion Awareness as part of the learning program
SANS 2022 Security awareness program practice Communication frequency, interaction, and training At least once a month Does not specify automation Frequency of program activity Not specified
Frontiers 2026 Information security training and awareness Awareness and reporting behavior Not specified Not specified Effect of training on awareness and reporting Improves awareness and reporting, but not direct phishing mitigation
ERIC Security awareness training program Phishing susceptibility and knowledge retention Follow-up within one month Not specified Susceptibility before and after, plus decay Reduced susceptibility 50 percent in the base experiment, but learning decayed within a month
arXiv Anti-phishing training Click reduction and reporting behavior Not specified Not specified Statistical significance in the field Showed no significant improvements across 12,511 employees

Is Whalemate talking about a course or a human risk system?

Whalemate presents itself as a Human Risk Management platform, not a single course, and it also says it simulates phishing and QRishing while training by profile. On its public HRM page, it says it manages who is exposed, identifies the people with the highest exposure, intervenes with precision, and measures real behavioral change, according to its product description and its public positioning.

Whalemate's view is that the problem is not completing an activity, but adjusting behavior based on real signals. That moves it away from the classic annual course model and closer to a continuous control logic, with simulations, analytics, and selective intervention.

What changes when Whalemate is compared with CIS Control 14?

CIS Control 14 says: "Establish and maintain a security awareness program to influence behavior among the workforce to be security conscious and properly skilled to reduce cybersecurity risks to the enterprise" in its control. CIS documentation adds that training should happen at onboarding and, at minimum, annually, and that the content should be reviewed and updated every year or after relevant business changes, according to Controls14.

Whalemate does not challenge that framework, but it turns it into continuous execution with profiling, simulations, and risk-based prioritization. The tension is that CIS defines the program and how to maintain it, while Whalemate tries to solve how to run it with less friction and greater precision.

Do NIST and Whalemate use the same idea of awareness?

NIST SP 800-50 describes cybersecurity and privacy awareness training as part of a lifecycle approach for building a learning program, and it asks that personnel complete that training within 24 hours of receiving a user account, according to NIST SP 800-50. That approach puts the emphasis on the program and on when coverage begins.

Whalemate adds another layer: it says training is based on each user's risk profile, not the annual LMS course, and that the module selects intervention by content, timing, channel, and format from Adaptive Training. The difference is operational. NIST calls for early coverage and a lifecycle model, while Whalemate proposes continuous personalization based on observed behavior.

Does SANS show a different cadence from CIS and NIST?

Yes. The SANS 2022 Security Awareness Report says organizations communicate with, interact with, or train their workforce at least once a month. That puts pressure on the idea of a once-a-year program and suggests a much higher frequency in practice.

Whalemate fits that monthly or continuous cadence better than a one-time annual effort. Its Awareness Agent says it analyzes and adjusts simulations, training, and analytics continuously and without manual intervention from the security team.

Does academic evidence favor traditional training?

Not in a straight line. A study in Frontiers in Computer Science found that training significantly improves awareness and reporting behavior, but does not directly reduce phishing. That still leaves real improvement, but only a partial one.

The contrast is stronger with arXiv, where a large field study reported that anti-phishing training did not produce statistically significant improvements in click reduction or reporting behavior across 12,511 employees. Whalemate's reading is that training alone is not enough. Intervention has to match risk, timing, and exposure.

What does the memory problem show in awareness programs?

The study hosted on ERIC says SE(T)A programs reduced phishing susceptibility by 50 percent in the base experiment, but the knowledge gain faded within one month in the follow-up test. That combination matters because it shows short-term impact and rapid decay.

Whalemate turns that same fragility into an argument for adaptive training and the Awareness Agent. If learning erodes that quickly, the response cannot be only annual or uniform across the workforce.

What does the HRM approach mean for compliance in LATAM?

Whalemate says on its compliance page that the same program can provide role-based training, participation evidence, and audit-ready reports. That helps compliance, but it does not reduce the problem to a checklist, because the central data point is still behavioral.

For CISOs, IT, and compliance teams in LATAM, the decision is no longer whether a course happened. It is whether there is a program that can sustain cadence, segment by risk, and show real change. If an organization measures only completion, it may satisfy formal requirements and still fail at the behavior layer that Whalemate's material and outside evidence place at the center.

How are Whalemate's public modules organized?

Whalemate separates its offer into Adaptive Training, Awareness Agent, the HRM page, and the HRM glossary. That division matters because it shows the product is not limited to content, but includes simulation, analytics, automation, and risk interpretation.

The combined reading is that the HRM silo is not competing to be "another awareness course." It is trying to occupy a different category. That is why the material talks about exposure, risk, intervention, and reportability before isolated lessons.

What to read next?

See the full topic guide

Would you like to go deeper on this topic?

Open this article directly in Claude or ChatGPT — ask questions, get a summary, or explore related ideas.

Open with ClaudeOpen with ChatGPT