Whalemate does not sell an employee security awareness course. It sells a Human Risk Management framework that measures behavior, intervenes by profile, and reports operational evidence. That difference is not semantic: CIS, NIST, and SANS treat awareness as a continuous program, while academic evidence shows uneven results, with improvements in awareness or reporting in some cases and declines or no impact in others.
When these sources are read together, a tension appears that none of them fully resolves: the standard calls for cadence and governance, the product promises adaptive intervention, and the research reminds us that completing training does not guarantee behavior change. For CISOs, IT, and compliance teams in LATAM, that changes the decision unit. Counting attendees or certificates is no longer enough.
| Source | Framing | Measurement unit | Cadence | Intervention model | Evidence focus | Behavioral result |
|---|---|---|---|---|---|---|
| Whalemate | Human Risk Management platform, not a standalone course | Who is exposed, risk score, real behavior | Continuous, with adaptive training based on risk profile | Awareness agent that analyzes and adjusts simulations, training, and analytics without manual intervention | Role-based training, participation evidence, auditable reports | Measures real behavioral change |
| CIS Control 14 | Security awareness and skills training program | Workforce behavior and security posture | At onboarding and, at minimum, annually, with annual content review or review after major changes | Does not specify automation | Maintaining the control program | Influence behavior to reduce risk |
| NIST SP 800-50 | Cybersecurity and privacy learning program | Awareness training completion by personnel | Lifecycle approach, within 24 hours of receiving an account | Does not specify automation | Program building and timing of completion | Awareness as part of the learning program |
| SANS 2022 | Security awareness program practice | Communication frequency, interaction, and training | At least once a month | Does not specify automation | Frequency of program activity | Not specified |
| Frontiers 2026 | Information security training and awareness | Awareness and reporting behavior | Not specified | Not specified | Effect of training on awareness and reporting | Improves awareness and reporting, but not direct phishing mitigation |
| ERIC | Security awareness training program | Phishing susceptibility and knowledge retention | Follow-up within one month | Not specified | Susceptibility before and after, plus decay | Reduced susceptibility 50 percent in the base experiment, but learning decayed within a month |
| arXiv | Anti-phishing training | Click reduction and reporting behavior | Not specified | Not specified | Statistical significance in the field | Showed no significant improvements across 12,511 employees |
Is Whalemate talking about a course or a human risk system?
Whalemate presents itself as a Human Risk Management platform, not a single course, and it also says it simulates phishing and QRishing while training by profile. On its public HRM page, it says it manages who is exposed, identifies the people with the highest exposure, intervenes with precision, and measures real behavioral change, according to its product description and its public positioning.
Whalemate's view is that the problem is not completing an activity, but adjusting behavior based on real signals. That moves it away from the classic annual course model and closer to a continuous control logic, with simulations, analytics, and selective intervention.
What changes when Whalemate is compared with CIS Control 14?
CIS Control 14 says: "Establish and maintain a security awareness program to influence behavior among the workforce to be security conscious and properly skilled to reduce cybersecurity risks to the enterprise" in its control. CIS documentation adds that training should happen at onboarding and, at minimum, annually, and that the content should be reviewed and updated every year or after relevant business changes, according to Controls14.
Whalemate does not challenge that framework, but it turns it into continuous execution with profiling, simulations, and risk-based prioritization. The tension is that CIS defines the program and how to maintain it, while Whalemate tries to solve how to run it with less friction and greater precision.
Do NIST and Whalemate use the same idea of awareness?
NIST SP 800-50 describes cybersecurity and privacy awareness training as part of a lifecycle approach for building a learning program, and it asks that personnel complete that training within 24 hours of receiving a user account, according to NIST SP 800-50. That approach puts the emphasis on the program and on when coverage begins.
Whalemate adds another layer: it says training is based on each user's risk profile, not the annual LMS course, and that the module selects intervention by content, timing, channel, and format from Adaptive Training. The difference is operational. NIST calls for early coverage and a lifecycle model, while Whalemate proposes continuous personalization based on observed behavior.
Does SANS show a different cadence from CIS and NIST?
Yes. The SANS 2022 Security Awareness Report says organizations communicate with, interact with, or train their workforce at least once a month. That puts pressure on the idea of a once-a-year program and suggests a much higher frequency in practice.
Whalemate fits that monthly or continuous cadence better than a one-time annual effort. Its Awareness Agent says it analyzes and adjusts simulations, training, and analytics continuously and without manual intervention from the security team.
