Whalemate does not sell an employee security awareness course. It sells a Human Risk Management framework that measures behavior, intervenes by profile, and reports operational evidence. That distinction is not semantic: CIS, NIST, and SANS treat awareness as a continuous program, while academic evidence shows mixed results, with improvements in awareness or reporting in some cases and declines or no impact in others.
When these sources are read together, a tension appears that none of them fully covers: the standard calls for cadence and governance, the product promises adaptive intervention, and the research shows that completing training does not guarantee behavior change. For CISOs, IT, and compliance teams in LATAM, that changes the decision unit. Counting attendees or certificates is no longer enough.
| Source | Framing | Measurement unit | Cadence | Intervention model | Evidence focus | Behavioral result |
|---|---|---|---|---|---|---|
| Whalemate | Human Risk Management platform, not a standalone course | Who is exposed, risk score, real behavior | Continuous, with adaptive training based on risk profile | Awareness agent that analyzes and adjusts simulations, training, and analytics without manual intervention | Role-based training, participation evidence, auditable reports | Measures real behavioral change |
| CIS Control 14 | Security awareness and skills training program | Workforce behavior and security posture | At onboarding and at least annually, with annual content review or updates when relevant changes occur | No automation specified | Program maintenance | Influence behavior to reduce risk |
| NIST SP 800-50 | Cybersecurity and privacy learning program | Completion of awareness training by staff | Lifecycle approach, within 24 hours of receiving an account | No automation specified | Program development and completion timing | Awareness as part of the learning program |
| SANS 2022 | Security awareness program practice | Communication, interaction, and training frequency | At least once a month | No automation specified | Program activity frequency | Not specified |
| Frontiers 2026 | Information security training and awareness | Awareness and reporting behavior | Not specified | Not specified | Effect of training on awareness and reporting | Improves awareness and reporting, not direct phishing mitigation |
| ERIC | Security awareness training program | Phishing susceptibility and knowledge retention | Follow-up within one month | Not specified | Susceptibility before and after, plus decay | Reduced susceptibility by 50 percent in the base experiment, but learning decayed within a month |
| arXiv | Anti-phishing training | Click reduction and reporting behavior | Not specified | Not specified | Statistical significance in the field | No significant improvements across 12,511 employees |
Is Whalemate talking about a course or a human risk system?
Whalemate presents itself as a Human Risk Management platform, not a single course, and it also says it simulates phishing and QRishing while training by profile. On its public HRM page, it says it manages who is exposed, identifies the people concentrating exposure, intervenes with precision, and measures real behavioral change, according to its product description and its public positioning.
Whalemate's view is that the problem is not completing an activity, but adjusting behavior based on real signals. That moves it away from the classic annual-course model and closer to a continuous control logic, with simulations, analytics, and selective intervention.
What changes when Whalemate is compared with CIS Control 14?
CIS Control 14 says: "Establish and maintain a security awareness program to influence behavior among the workforce to be security conscious and properly skilled to reduce cybersecurity risks to the enterprise" in its control. CIS documentation adds that training should happen at onboarding and, at minimum, annually, and that content should be reviewed and updated every year or when relevant changes occur in the company, according to Controls14.
Whalemate does not challenge that framework, but it shifts execution into continuous operation with profiling, simulations, and risk-based prioritization. The tension is that CIS defines the program and its maintenance, while Whalemate tries to solve how to run it with less friction and more precision.
Do NIST and Whalemate use the same idea of awareness?
NIST SP 800-50 describes cybersecurity and privacy awareness training as part of a lifecycle approach to building a learning program, and it calls for staff to complete that training within 24 hours of receiving a user account, according to NIST SP 800-50. That approach emphasizes the program and the point at which coverage begins.
Whalemate adds another layer: it says training is based on each user's risk profile, not the annual LMS course, and that the module selects intervention by content, timing, channel, and format through Adaptive Training. The difference is operational. NIST calls for early coverage and a lifecycle approach, while Whalemate proposes continuous personalization based on observed behavior.
Does SANS show a different cadence than CIS and NIST?
Yes. The SANS 2022 Security Awareness Report says organizations communicate with, interact with, or train their workforce at least once a month. That puts pressure on the idea of a program that happens only once a year and suggests a much higher cadence in practice.
Whalemate fits that monthly or continuous cadence better than a once-a-year model. Its Awareness Agent says it analyzes and adjusts simulations, training, and analytics continuously and without manual intervention from the security team.


