Security awareness by industry

Each industry cites its own attack and its own regulation. It is not the same card with the name swapped out.

Solutions by industry

The opening problem changes. The product is not copy-pasted.

Each industry cites its regulation and its case. It is not the same module with a swapped logo. The solutions directory exists so you pick the problem that is yours — not a generic “sectors we serve” landing.

A bank does not open the program for the same reason as a hospital or a retail chain. The auditor at a financial institution asks for evidence for BCRA, PCI, and ISO. In healthcare the roster does not fit in one room, and the lure disguises itself as a lab. In government you must document that the program exists and operate on public-procurement timelines. Recycling the same threat paragraph and changing the icon is what a thin catalog does. Here each card starts from that sector’s opening problem.

Who is exposed is not the same profile either. In banking it is often sales, treasury, and the help desk. In insurance, agents and whoever settles claims. In retail, the register and the store. In technology, people who already “know security” and still open a fake repo. The program is calibrated to the roster: channel, difficulty, and timing. The Agent does not send the same email to the whole headcount. If your industry is not in the list, calibration is discussed in the demo: the product does not require a landing page to exist.

What the auditor wants to see also changes in shape, not in substance. They want awareness evidence, roster coverage, and a way to show evolution. The substance is the same system: simulations, training, analytics, and the agent that connects them. The shape is the mapping to the rule you already cite and the report you can export. This hub does not sell six products. It sells a way of not pretending every industry fails the same way.

How it works

How to use this directory

Directory

Pick the industry that describes your opening problem. Read the threat, the vectors, and the rules that card declares. Do not look for a badge that says “specialists in your vertical.” Look for whether the problem matches yours.

Simulations

The program is played in the lures that operation actually receives: payroll, claims, appointments, store QR codes, Slack threads. The industry card names typical vectors. Campaign design is closed with your team — not with a downloadable pack.

Evidence

End the path on what you will export: period, scope, participation, and behavior. That is what audit and leadership will ask for. The rule on the card orients; the concrete scope is agreed in implementation.

Questions about industry solutions

Does the product change by industry?
The platform is the same. What changes is the opening problem, the lures that matter, and the rules the team already cites. There is no “banking module” separate from a “retail module.” There is a program you calibrate: roster, channel, difficulty, and evidence. If someone offers you six products with the same screenshot, ask what actually changes.
How is the program calibrated to my sector?
In implementation: directory, scenarios, languages, and what audit expects to see. The industry card previews vectors and references. It does not replace the work of building the first campaign. People brings the roster. IT brings the IdP. Security sets the rules. The Agent orchestrates after that — it does not guess the sector from a logo.
My industry is not on the list. Does it still work?
Yes. The list covers the sectors where the opening problem is clearest. Logistics, education, or another vertical are worked the same way: real threat, roster, evidence. We look at it in the demo. We do not invent a landing to close a conversation. If human risk sits in people, the system applies.
Are the rules on each card a Whalemate certification?
No. They are references organizations in that sector already use to orient the program. The only certification we declare for Whalemate is ISO/IEC 27001:2022. We do not sell BCRA, PCI, LGPD, or the customer’s SOC 2 as our badge. The mapping helps you build evidence; it does not replace the auditor.
Is there a case study for every industry?
There are published cases when the customer and the narrative are validated. We do not fill every card with an invented sector story. If there is a nearby case — banking, fintech, logistics — we link it. If not, the card stands on the problem and the way of working, not on a generic testimonial.

Don't see your industry?

The program calibrates the same way. We'll show you in the demo.