HRM glossary

Social engineering

Manipulating a person, not a system, to get an action or a piece of data.

Definition

The category that covers phishing, QRishing, smishing, vishing, USB Drop and deepfake. The platform natively covers the first two; the rest run as a service.

HRM glossary

SSO / SAML 2.0Single sign-on using the SAML 2.0 protocol.

USB DropLeaving a physical device (USB) to see who plugs it in.

VishingPhishing via voice call, including voice cloning.

2FA / MFASecond authentication factor, native for platform administrators.

HRM glossary

Questions about Social engineering

What is Social engineering?
Manipulating a person, not a system, to get an action or a piece of data.
How does Whalemate use it?
The category that covers phishing, QRishing, smishing, vishing, USB Drop and deepfake. The platform natively covers the first two; the rest run as a service.
Blog

Articles, guides and analysis on human risk management,
awareness and security culture

Guides and analysis for CISOs, IT and compliance teams in LATAM who need to explain the human factor — and decide what to do about it.

PCI DSS 12.6: what the auditor wants to see (and what an annual course doesn't prove)
PCI DSS, audit
Apr 2, 2026By Federico Hombre

PCI DSS 12.6: what the auditor wants to see (and what an annual course doesn't prove)

The requirement asks for a formal awareness program that includes phishing and social engineering. The evidence isn't a screenshot.

Read more

Want to see HRM in your organization?

Book a demo and we'll look at the program with data from your industry.