Security awareness for banks

In financial institutions the program can't be a once-a-year course. It has to produce evidence for BCRA, PCI DSS and ISO 27001, and an index the board can actually read.

How it works

Where to focus the program

Evidence, not screenshots

The awareness report exports by period. No more building a folder of screenshots before every audit.

Sales is the most exposed area

The team with the least time is the one that gets the most lures. The Agent adjusts difficulty and timing — it doesn't send the same email to treasury and to branches.

Payroll and vendor phishing

Templates that mimic a bank's real flows: payroll, vendors, tokens, help desk.

Regulatory framework

References that guide the program

The exact scope depends on the jurisdiction and the controls that apply to each organization.

BCRAPCI DSS 12.6ISO/IEC 27001 A.6.3
Industry case

Evidence from real customers

See how organizations across the region measured and reduced human risk with Whalemate.

Banking and finance

The auditor asks for evidence. The CISO needs to know who is still clicking.

In a financial institution the program cannot be a once-a-year course. It has to produce evidence for BCRA, PCI DSS, and ISO/IEC 27001, and an index the board can read.

The phishing that reaches a bank is not a spam contest. It mimics payroll, vendors, tokens, and the help desk. The people with the least time — sales, the branch, the analyst who approves a payment — are the ones who get the most lures. The same course for the whole roster does not change that asymmetry. The program has to adjust channel, difficulty, and timing. If treasury and the branch network get the same email, the exercise is not measuring the risk that matters.

Whoever touches money, identity, and support tickets is exposed. So is whoever works from a phone with WhatsApp mixed into work email. LATAM adds that channel to the table. The CISO already knows this; what is missing is a live roster and an index that is not assembled the week before the audit. People has to enroll the new hire on day one. IT has to connect the directory without an endpoint agent.

What the auditor wants to see is awareness evidence, not a folder of screenshots. PCI DSS 12.6 asks for a program that covers phishing and social engineering, with review. ISO/IEC 27001 A.6.3 asks for awareness tied to the role. BCRA and local rules ask that the control exists and can be shown. The report exports by period. It stops being built by hand. That does not certify the institution: it gives material for the conversation you already have to have.

Sector vectors

Three lures a bank has already seen

This is not an exhaustive threat list. It is the kind of campaign the program has to know how to run.

Payroll and token phishing

Emails that mimic payslips, recalculation, an access token, or a password expiry. Sales opens them on a phone between one customer and the next. The campaign has to look like the institution’s real…

Vendor fraud and BEC

Account-change requests, altered invoices, a thread that looks like treasury. The damage is not a click: it is a transfer. The simulation trains the habit of verifying on a second channel. We do not…

Help-desk social engineering

The attacker does not always aim at the CEO. They aim at whoever resets a user or hands over a token. The lure disguises itself as an internal incident. The program has to include support with its…

Questions about banking and finance

What evidence can I show the auditor?
Participation, simulation results, and index evolution by period — exportable. The report says who was on the roster and what they received. It is not an LMS screenshot. The auditor is still the one who interprets the control. We do not sign a BCRA or PCI opinion. We deliver the raw material so the folder is not improvised.
How do we cover branches, sales, and headquarters in one roster?
The directory syncs joiners, leavers, and org unit. The Agent adjusts scenario and timing. You do not need a parallel program per channel. People and security set the rules; the platform does not require everyone to get the same email on the same Tuesday. If a network is outside the IdP, that gap shows up in implementation — it is not hidden.
Does this make us BCRA- or PCI-compliant by itself?
No. The program produces evidence aligned to those asks. Compliance belongs to the institution and its auditor. Nobody should sell you “we fulfill BCRA” as a toggle. The card names the rules so you know which folder you will be able to build — not so you inherit our certification.
What does this module not cover?
It is not a SOC, it does not monitor transactions, and it does not replace channel anti-fraud. It does not install an endpoint agent. It does not use the score for an HR file: that stays outside the data-use contract. It is also not an annual course with a forty-minute certificate presented as the full control.

Banking and finance — Security awareness and human risk

The program calibrates the same way. We'll show you in the demo.