HRM glossary

PCI DSS 12.6

PCI DSS v4.0 requirement on awareness programs that must include phishing.

Definition

It requires at least an annual review and evidence that the program specifically covers phishing and social engineering, not just generic security content.

HRM glossary

Phishing simulationA controlled lure to measure actual behavior, not the declared one.

QRishingPhishing via QR code: the lure asks you to scan, not to click a link.

Ransomware (simulated)A simulated attachment that would encrypt files, to measure the act of opening it without checking.

Report ratePercentage of simulated (or real) threats that staff report using the phishing button.

HRM glossary

Questions about PCI DSS 12.6

What is PCI DSS 12.6?
PCI DSS v4.0 requirement on awareness programs that must include phishing.
How does Whalemate use it?
It requires at least an annual review and evidence that the program specifically covers phishing and social engineering, not just generic security content.
Blog

Articles, guides and analysis on human risk management,
awareness and security culture

Guides and analysis for CISOs, IT and compliance teams in LATAM who need to explain the human factor — and decide what to do about it.

PCI DSS 12.6: what the auditor wants to see (and what an annual course doesn't prove)
PCI DSS, audit
Apr 2, 2026By Federico Hombre

PCI DSS 12.6: what the auditor wants to see (and what an annual course doesn't prove)

The requirement asks for a formal awareness program that includes phishing and social engineering. The evidence isn't a screenshot.

Read more

Want to see HRM in your organization?

Book a demo and we'll look at the program with data from your industry.