The category that covers phishing, QRishing, smishing, vishing, USB Drop and deepfake. The platform natively covers the first two; the rest run as a service.
HRM glossary
Social engineering
Manipulating a person, not a system, to get an action or a piece of data.
Definition
SSO / SAML 2.0 — Single sign-on using the SAML 2.0 protocol.
USB Drop — Leaving a physical device (USB) to see who plugs it in.
Vishing — Phishing via voice call, including voice cloning.
2FA / MFA — Second authentication factor, native for platform administrators.
HRM glossary
Questions about Social engineering
What is Social engineering?
Manipulating a person, not a system, to get an action or a piece of data.
How does Whalemate use it?
The category that covers phishing, QRishing, smishing, vishing, USB Drop and deepfake. The platform natively covers the first two; the rest run as a service.
Blog
Articles, guides and analysis on human risk management,
awareness and security culture
Guides and analysis for CISOs, IT and compliance teams in LATAM who need to explain the human factor — and decide what to do about it.

PCI DSS, audit
Apr 2, 2026By Federico Hombre
PCI DSS 12.6: what the auditor wants to see (and what an annual course doesn't prove)
The requirement asks for a formal awareness program that includes phishing and social engineering. The evidence isn't a screenshot.
Read moreWant to see HRM in your organization?
Book a demo and we'll look at the program with data from your industry.