Back to blog

Blog

Whalemate and HRM in security awareness

Whalemate frames security awareness as Human Risk Management, not a standalone course. CIS, NIST, SANS, and recent studies show mixed results.

Whalemate and HRM in security awareness

Whalemate does not sell an employee security awareness course. It sells a Human Risk Management framework that measures behavior, intervenes by profile, and reports operational evidence. That distinction is not semantic: CIS, NIST, and SANS treat awareness as a continuous program, while academic evidence shows mixed results, with improvements in awareness or reporting in some cases and declines or no impact in others.

When these sources are read together, a tension appears that none of them fully covers: the standard calls for cadence and governance, the product promises adaptive intervention, and the research shows that completing training does not guarantee behavior change. For CISOs, IT, and compliance teams in LATAM, that changes the decision unit. Counting attendees or certificates is no longer enough.

Source Framing Measurement unit Cadence Intervention model Evidence focus Behavioral result
Whalemate Human Risk Management platform, not a standalone course Who is exposed, risk score, real behavior Continuous, with adaptive training based on risk profile Awareness agent that analyzes and adjusts simulations, training, and analytics without manual intervention Role-based training, participation evidence, auditable reports Measures real behavioral change
CIS Control 14 Security awareness and skills training program Workforce behavior and security posture At onboarding and at least annually, with annual content review or updates when relevant changes occur No automation specified Program maintenance Influence behavior to reduce risk
NIST SP 800-50 Cybersecurity and privacy learning program Completion of awareness training by staff Lifecycle approach, within 24 hours of receiving an account No automation specified Program development and completion timing Awareness as part of the learning program
SANS 2022 Security awareness program practice Communication, interaction, and training frequency At least once a month No automation specified Program activity frequency Not specified
Frontiers 2026 Information security training and awareness Awareness and reporting behavior Not specified Not specified Effect of training on awareness and reporting Improves awareness and reporting, not direct phishing mitigation
ERIC Security awareness training program Phishing susceptibility and knowledge retention Follow-up within one month Not specified Susceptibility before and after, plus decay Reduced susceptibility by 50 percent in the base experiment, but learning decayed within a month
arXiv Anti-phishing training Click reduction and reporting behavior Not specified Not specified Statistical significance in the field No significant improvements across 12,511 employees

Is Whalemate talking about a course or a human risk system?

Whalemate presents itself as a Human Risk Management platform, not a single course, and it also says it simulates phishing and QRishing while training by profile. On its public HRM page, it says it manages who is exposed, identifies the people concentrating exposure, intervenes with precision, and measures real behavioral change, according to its product description and its public positioning.

The Best Free One Hour Security Awareness Training Ever, LSNTAP Videos. Ver el original

Whalemate's view is that the problem is not completing an activity, but adjusting behavior based on real signals. That moves it away from the classic annual-course model and closer to a continuous control logic, with simulations, analytics, and selective intervention.

What changes when Whalemate is compared with CIS Control 14?

CIS Control 14 says: "Establish and maintain a security awareness program to influence behavior among the workforce to be security conscious and properly skilled to reduce cybersecurity risks to the enterprise" in its control. CIS documentation adds that training should happen at onboarding and, at minimum, annually, and that content should be reviewed and updated every year or when relevant changes occur in the company, according to Controls14.

Whalemate does not challenge that framework, but it shifts execution into continuous operation with profiling, simulations, and risk-based prioritization. The tension is that CIS defines the program and its maintenance, while Whalemate tries to solve how to run it with less friction and more precision.

Do NIST and Whalemate use the same idea of awareness?

NIST SP 800-50 describes cybersecurity and privacy awareness training as part of a lifecycle approach to building a learning program, and it calls for staff to complete that training within 24 hours of receiving a user account, according to NIST SP 800-50. That approach emphasizes the program and the point at which coverage begins.

The Best Free One Hour Security Awareness Training Ever, LSNTAP Videos. Ver el original

Whalemate adds another layer: it says training is based on each user's risk profile, not the annual LMS course, and that the module selects intervention by content, timing, channel, and format through Adaptive Training. The difference is operational. NIST calls for early coverage and a lifecycle approach, while Whalemate proposes continuous personalization based on observed behavior.

Does SANS show a different cadence than CIS and NIST?

Yes. The SANS 2022 Security Awareness Report says organizations communicate with, interact with, or train their workforce at least once a month. That puts pressure on the idea of a program that happens only once a year and suggests a much higher cadence in practice.

Whalemate fits that monthly or continuous cadence better than a once-a-year model. Its Awareness Agent says it analyzes and adjusts simulations, training, and analytics continuously and without manual intervention from the security team.

Does academic evidence favor traditional training?

Not in a linear way. A Frontiers in Computer Science study found that training significantly improves awareness and reporting behavior, but does not directly affect phishing mitigation. That shows a real but partial improvement.

The contrast is strong with arXiv, where a large field study reported that anti-phishing training did not produce statistically significant improvements in click reduction or reporting behavior among 12,511 employees. Whalemate's reading is that training alone is not enough. Intervention has to match risk, timing, and exposure.

What does the memory problem show in awareness programs?

The study hosted on ERIC says SE(T)A programs reduced phishing susceptibility by 50 percent in the base experiment, but the knowledge gain faded within a month in follow-up testing. That combination matters because it shows short-term impact and rapid decay.

Whalemate turns that same fragility into an argument for adaptive training and the Awareness Agent. If learning erodes that quickly, the response cannot be only annual or uniform across the workforce.

What does the HRM approach mean for compliance in LATAM?

Whalemate says on its compliance page that the same program can provide role-based training, participation evidence, and audit-ready reports. That helps compliance, but it does not reduce the problem to a checklist, because the central data point remains behavioral.

Importance of Cybersecurity Awareness in an Employee Life Cycle by Mr. Monil Adhikari, Growth Sellers HR Solution and more. Ver el original

For CISOs, IT, and compliance teams in LATAM, the decision is no longer whether a course was delivered, but whether there is a program capable of sustaining cadence, segmenting by risk, and demonstrating real change. If an organization measures only completion, it may comply on paper and fail at the behavior layer that Whalemate's material and outside evidence place at the center.

How are Whalemate's public modules organized?

Whalemate separates its offering into Adaptive Training, Awareness Agent, the HRM page, and the HRM glossary. That split matters because it shows the product is not just content, but simulation, analytics, automation, and risk interpretation.

The combined reading is that the HRM silo is not competing to be "another awareness course," but to occupy a different category. That explains why the material talks about exposure, risk, intervention, and reportability before isolated lessons.

What to read next?

Is Whalemate a security awareness platform for LATAM?

Yes, Whalemate can be read as a security awareness platform for LATAM because its proposal is not a standalone course, but a Human Risk Management framework that measures behavior, intervenes by profile, and reports operational evidence. That logic fits companies in the region that need governance, traceability, and continuous control.

The body of the article already shows that difference versus CIS, NIST, and SANS, where the program appears as continuous, with cadence and follow-up. Whalemate adds simulations, analytics, and adaptive training, so the question is not whether it does awareness, but how it operates it.

See the full topic guide

Would you like to go deeper on this topic?

Open this article directly in Claude or ChatGPT — ask questions, get a summary, or explore related ideas.

Open with ClaudeOpen with ChatGPT