Human Risk Management glossary

Phishing, Human Risk Score, awareness and the rest of the words that show up when you build a human-risk program. Definitions for CISOs, compliance and People.

2FA / MFA

Second authentication factor, native for platform administrators.

Awareness Agent

The intelligence that decides the next intervention without manual work from the security team.

Completion rate

Percentage of people who finished a course. The metric HRM stops using as the main KPI.

Deepfake

Audiovisual impersonation of a real person, used as a social engineering vector.

ISO/IEC 27001

International standard for information security management.

PCI DSS 12.6

PCI DSS v4.0 requirement on awareness programs that must include phishing.

QRishing

Phishing via QR code: the lure asks you to scan, not to click a link.

Ransomware (simulated)

A simulated attachment that would encrypt files, to measure the act of opening it without checking.

Report rate

Percentage of simulated (or real) threats that staff report using the phishing button.

Risk score

A comparable index of the human risk of a person, a team or the company.

SCIM 2.0

Protocol for automatic user provisioning between the directory and Whalemate.

SIEM

The system where the security team centralizes events and incidents.

Smishing

Phishing via SMS. At Whalemate it runs as a professional service, not a native channel.

Social engineering

Manipulating a person, not a system, to get an action or a piece of data.

USB Drop

Leaving a physical device (USB) to see who plugs it in.

Vishing

Phishing via voice call, including voice cloning.

Want to see HRM in your organization?

Book a demo and we'll look at the program with data from your industry.