Security awareness for public agencies

The public sector needs auditable evidence, content in the local language, and a vendor that can operate within the timelines and controls of a public tender.

How it works

Where to focus the program

Scale without a huge team

The Agent orchestrates the program. The security team sets the rules; it doesn't build campaigns by hand.

Data transparency

What's collected, why, and confirmation that no individual metric is used for disciplinary purposes.

Reports for the oversight body

Exportable, by period, with scope and results. Ready for whoever audits.

Regulatory framework

References that guide the program

The exact scope depends on the jurisdiction and the controls that apply to each organization.

ISO/IEC 27001Local cybersecurity regulationsPublic procurement
Industry case

Evidence from real customers

See how organizations across the region measured and reduced human risk with Whalemate.

Government

Scale, public procurement, and the duty to document that the program exists

The public sector needs auditable evidence, content in the language of the operation, and a vendor that can work within the timelines and controls of a tender.

An agency with thousands of people does not build campaigns by hand. Phishing arrives as a procedure, a government vendor, a memo, or a “help desk” link. Whoever serves the public is exposed differently from whoever runs an internal system. The program has to be orchestrated: rules, not a twenty-person awareness team sending email. The Agent runs the day to day. Security sets the frame. That is what makes scale viable.

Front desks, call centers, procurement, officials, and staff on rotating contracts are exposed. Joiners and leavers in government do not wait for the annual course. If the roster is not synced, the control is lying. So is whoever is not on payroll but uses the agency mailbox. Scope is declared: who is in and who is not. Data transparency: what is collected, why, and that no individual metric is used for disciplinary purposes.

The oversight body and internal audit want a report by period, with scope and outcome. ISO/IEC 27001 orients the awareness control. Local cybersecurity regulation — whichever applies to that agency — asks that the program exists and can be shown. Public procurement asks for a vendor that documents its own security and does not promise a badge it does not have. Whalemate declares ISO/IEC 27001:2022. The rest is discussed in the tender pack and the DPA, not in a brochure.

Sector vectors

Three entries an agency already knows

The campaign has to speak the language of a procedure, not of a startup.

Procurement and vendor phishing

Invoices, tender packs, “update your details to get paid.” Procurement is trained to unblock payments. The lure uses that urgency. The simulation trains the second verification channel. The report…

Social engineering of service desks

Whoever serves the public resets access, receives attachments, and works with little time. The attacker poses as an insider or an urgent citizen. The program includes that desk with its own…

Compromise of official accounts

An email that looks like the office of the principal, a request for a transfer or for information. The vector is BEC with an institutional stamp. The exercise does not ridicule the official: it…

Questions about government

What do I give the oversight body?
An exportable report by period: roster scope, participation, simulation results, and index evolution. Ready for whoever audits. It is not an opinion. It is evidence that the program existed on those dates. The agency writes the report its rule asks for.
How do you cover a roster of thousands?
Directory, rules, and the Agent. Security does not build each campaign by hand. Joiners and leavers follow the identity source. If the agency has several IdPs, that is declared in implementation. We do not promise a weekend rollout on a roster nobody unifies.
Can you take part in a tender, and what do you certify?
Vendor security material is in the Trust Center. The certification we declare is ISO/IEC 27001:2022. We do not invent SOC 2 or other badges. Participation in a procurement process is evaluated case by case. This page is not an offer or a tender pack.
What does this module not cover?
It is not a government SOC, it does not classify information, and it does not replace the agency’s cyber-incident desk. It does not install an endpoint agent. It does not use individual metrics for a disciplinary regime. It also does not write the regulatory report: it delivers data so security can.

Government — Security awareness and human risk

The program calibrates the same way. We'll show you in the demo.