Security awareness for technology companies
Software companies need a program that doesn't treat them like beginners, and that integrates with Entra ID, Google Workspace, Okta and their SIEM via API.
Where to focus the program
The Agent raises the bar for whoever stops falling for it. There's no single campaign for support and for engineering.
SSO SAML, SCIM, 2FA. The technical question is answered on the integrations page.
The risk score flows to the dashboard the team already uses — it doesn't stay locked inside Whalemate.
References that guide the program
The exact scope depends on the jurisdiction and the controls that apply to each organization.
Evidence from real customers
See how organizations across the region measured and reduced human risk with Whalemate.
Teams that already “know security” and still fall for a Slack thread
A software company needs a program that does not treat them like beginners, and that integrates with Entra ID, Google Workspace, Okta, and the SIEM via API.
The lure is not a Nigerian prince. It is a repo that looks internal, a fake OAuth prompt, a Slack or Teams thread impersonating platform, a ticket that “CI is broken.” Engineering and support fall for context, not ignorance. An annual beginner phishing course creates rejection and does not measure that risk. The Agent has to raise the bar for whoever has stopped falling for it, and leave alone whoever the scenario does not help. One campaign for support and for staff engineers is a waste.
Whoever has production access, secrets, and the desk that resets access is exposed. So is the contractor who enters through SCIM and leaves in three months. IT will not accept an endpoint agent for an awareness program. SSO, SCIM, and API are not a nice-to-have: they are the condition for the program to exist in a company that already has a serious IdP. The risk score has to be able to leave for the dashboard they already use — not stay locked in.
ISO 27001 asks for awareness tied to the role. The customer’s own SOC 2 — theirs, not ours — asks whether a program exists and whether it is measured. NIST CSF places awareness in Identify and Protect, and measurement in Detect. Whalemate is not selling its own SOC 2 badge. It declares ISO/IEC 27001:2022. The program gives you evidence for the questionnaire you already answer for enterprise customers.
Three lures a technical team will actually open
If difficulty does not rise, the program becomes noise and is ignored.
Fake repo and supply chain
A GitHub that looks internal, a package, an “urgent fix.” Whoever clones or installs has privileges. The simulation works that gesture. It is not a dependency scanner. It is the habit of verifying…
Impersonation in Slack or Teams
A thread that looks like platform, an approval request, a “logs” link. Chat is the work channel. The campaign has to be able to speak to that risk even if the module’s native send is another channel:…
OAuth, fake SSO, and credentials
A login screen that looks like Okta or Google, one OAuth consent too many. Technical staff are exposed precisely because they live on those screens. The exercise trains verifying the domain and the…
Questions about technology
What evidence do I give a SOC 2 auditor or an enterprise customer?
How does a contractor join and leave?
Do you have SOC 2?
What does this module not cover?
Other industries
Technology — Security awareness and human risk
The program calibrates the same way. We'll show you in the demo.