Human Risk Management is the practice of identifying who is exposed, measuring how that risk evolves, and deciding the next intervention —simulation, content, channel, difficulty— with data. It doesn't replace awareness: it turns it into a managed program. At Whalemate the cycle is model context, simulate, train, measure, intervene and report.
HRM glossary
Human Risk Management (HRM)
Managing cyber risk with a focus on people's behavior, not on completing a course.
Definition
ISO/IEC 27001 — International standard for information security management.
KnowBe4 and Human Risk Management — KnowBe4 markets its platform as HRM+ and defines Human Risk Management as a people-centered framework to measure and reduce security risk.
PAS (Phishing Awareness Score) — A specific metric of how much a person or area recognizes and reports phishing.
PCI DSS 12.6 — PCI DSS v4.0 requirement on awareness programs that must include phishing.
HRM glossary
Questions about Human Risk Management (HRM)
What is Human Risk Management (HRM)?
Managing cyber risk with a focus on people's behavior, not on completing a course.
How does Whalemate use it?
Human Risk Management is the practice of identifying who is exposed, measuring how that risk evolves, and deciding the next intervention —simulation, content, channel, difficulty— with data. It doesn't replace awareness: it turns it into a managed program. At Whalemate the cycle is model context, simulate, train, measure, intervene and report.
Want to see HRM in your organization?
Book a demo and we'll look at the program with data from your industry.