Security awareness for public agencies
The public sector needs auditable evidence, content in the local language, and a vendor that can operate within the timelines and controls of a public tender.
Where to focus the program
The Agent orchestrates the program. The security team sets the rules; it doesn't build campaigns by hand.
What's collected, why, and confirmation that no individual metric is used for disciplinary purposes.
Exportable, by period, with scope and results. Ready for whoever audits.
References that guide the program
The exact scope depends on the jurisdiction and the controls that apply to each organization.
Evidence from real customers
See how organizations across the region measured and reduced human risk with Whalemate.
Scale, public procurement, and the duty to document that the program exists
The public sector needs auditable evidence, content in the language of the operation, and a vendor that can work within the timelines and controls of a tender.
An agency with thousands of people does not build campaigns by hand. Phishing arrives as a procedure, a government vendor, a memo, or a “help desk” link. Whoever serves the public is exposed differently from whoever runs an internal system. The program has to be orchestrated: rules, not a twenty-person awareness team sending email. The Agent runs the day to day. Security sets the frame. That is what makes scale viable.
Front desks, call centers, procurement, officials, and staff on rotating contracts are exposed. Joiners and leavers in government do not wait for the annual course. If the roster is not synced, the control is lying. So is whoever is not on payroll but uses the agency mailbox. Scope is declared: who is in and who is not. Data transparency: what is collected, why, and that no individual metric is used for disciplinary purposes.
The oversight body and internal audit want a report by period, with scope and outcome. ISO/IEC 27001 orients the awareness control. Local cybersecurity regulation — whichever applies to that agency — asks that the program exists and can be shown. Public procurement asks for a vendor that documents its own security and does not promise a badge it does not have. Whalemate declares ISO/IEC 27001:2022. The rest is discussed in the tender pack and the DPA, not in a brochure.
Three entries an agency already knows
The campaign has to speak the language of a procedure, not of a startup.
Procurement and vendor phishing
Invoices, tender packs, “update your details to get paid.” Procurement is trained to unblock payments. The lure uses that urgency. The simulation trains the second verification channel. The report…
Social engineering of service desks
Whoever serves the public resets access, receives attachments, and works with little time. The attacker poses as an insider or an urgent citizen. The program includes that desk with its own…
Compromise of official accounts
An email that looks like the office of the principal, a request for a transfer or for information. The vector is BEC with an institutional stamp. The exercise does not ridicule the official: it…
Questions about government
What do I give the oversight body?
How do you cover a roster of thousands?
Can you take part in a tender, and what do you certify?
What does this module not cover?
Other industries
Government — Security awareness and human risk
The program calibrates the same way. We'll show you in the demo.