Human Risk Management is the practice of identifying who is exposed, measuring how that risk evolves, and deciding the next intervention —simulation, content, channel, difficulty— with data. It doesn't replace awareness: it turns it into a managed program. At Whalemate the cycle is model context, simulate, train, measure, intervene and report.
HRM glossary
Human Risk Management (HRM)
Managing cyber risk with a focus on people's behavior, not on completing a course.
Definition
ISO/IEC 27001 — International standard for information security management.
PAS (Phishing Awareness Score) — A specific metric of how much a person or area recognizes and reports phishing.
PCI DSS 12.6 — PCI DSS v4.0 requirement on awareness programs that must include phishing.
Phishing simulation — A controlled lure to measure actual behavior, not the declared one.
HRM glossary
Questions about Human Risk Management (HRM)
What is Human Risk Management (HRM)?
Managing cyber risk with a focus on people's behavior, not on completing a course.
How does Whalemate use it?
Human Risk Management is the practice of identifying who is exposed, measuring how that risk evolves, and deciding the next intervention —simulation, content, channel, difficulty— with data. It doesn't replace awareness: it turns it into a managed program. At Whalemate the cycle is model context, simulate, train, measure, intervene and report.
Want to see HRM in your organization?
Book a demo and we'll look at the program with data from your industry.