HRM glossary

Human Risk Management (HRM)

Managing cyber risk with a focus on people's behavior, not on completing a course.

Definition

Human Risk Management is the practice of identifying who is exposed, measuring how that risk evolves, and deciding the next intervention —simulation, content, channel, difficulty— with data. It doesn't replace awareness: it turns it into a managed program. At Whalemate the cycle is model context, simulate, train, measure, intervene and report.

HRM glossary

ISO/IEC 27001International standard for information security management.

PAS (Phishing Awareness Score)A specific metric of how much a person or area recognizes and reports phishing.

PCI DSS 12.6PCI DSS v4.0 requirement on awareness programs that must include phishing.

Phishing simulationA controlled lure to measure actual behavior, not the declared one.

HRM glossary

Questions about Human Risk Management (HRM)

What is Human Risk Management (HRM)?
Managing cyber risk with a focus on people's behavior, not on completing a course.
How does Whalemate use it?
Human Risk Management is the practice of identifying who is exposed, measuring how that risk evolves, and deciding the next intervention —simulation, content, channel, difficulty— with data. It doesn't replace awareness: it turns it into a managed program. At Whalemate the cycle is model context, simulate, train, measure, intervene and report.

Want to see HRM in your organization?

Book a demo and we'll look at the program with data from your industry.