Security awareness for technology companies

Software companies need a program that doesn't treat them like beginners, and that integrates with Entra ID, Google Workspace, Okta and their SIEM via API.

How it works

Where to focus the program

Real difficulty

The Agent raises the bar for whoever stops falling for it. There's no single campaign for support and for engineering.

IT integrations

SSO SAML, SCIM, 2FA. The technical question is answered on the integrations page.

Reporting API

The risk score flows to the dashboard the team already uses — it doesn't stay locked inside Whalemate.

Regulatory framework

References that guide the program

The exact scope depends on the jurisdiction and the controls that apply to each organization.

ISO 27001Customer's own SOC 2NIST CSF
Industry case

Evidence from real customers

See how organizations across the region measured and reduced human risk with Whalemate.

Technology

Teams that already “know security” and still fall for a Slack thread

A software company needs a program that does not treat them like beginners, and that integrates with Entra ID, Google Workspace, Okta, and the SIEM via API.

The lure is not a Nigerian prince. It is a repo that looks internal, a fake OAuth prompt, a Slack or Teams thread impersonating platform, a ticket that “CI is broken.” Engineering and support fall for context, not ignorance. An annual beginner phishing course creates rejection and does not measure that risk. The Agent has to raise the bar for whoever has stopped falling for it, and leave alone whoever the scenario does not help. One campaign for support and for staff engineers is a waste.

Whoever has production access, secrets, and the desk that resets access is exposed. So is the contractor who enters through SCIM and leaves in three months. IT will not accept an endpoint agent for an awareness program. SSO, SCIM, and API are not a nice-to-have: they are the condition for the program to exist in a company that already has a serious IdP. The risk score has to be able to leave for the dashboard they already use — not stay locked in.

ISO 27001 asks for awareness tied to the role. The customer’s own SOC 2 — theirs, not ours — asks whether a program exists and whether it is measured. NIST CSF places awareness in Identify and Protect, and measurement in Detect. Whalemate is not selling its own SOC 2 badge. It declares ISO/IEC 27001:2022. The program gives you evidence for the questionnaire you already answer for enterprise customers.

Sector vectors

Three lures a technical team will actually open

If difficulty does not rise, the program becomes noise and is ignored.

Fake repo and supply chain

A GitHub that looks internal, a package, an “urgent fix.” Whoever clones or installs has privileges. The simulation works that gesture. It is not a dependency scanner. It is the habit of verifying…

Impersonation in Slack or Teams

A thread that looks like platform, an approval request, a “logs” link. Chat is the work channel. The campaign has to be able to speak to that risk even if the module’s native send is another channel:…

OAuth, fake SSO, and credentials

A login screen that looks like Okta or Google, one OAuth consent too many. Technical staff are exposed precisely because they live on those screens. The exercise trains verifying the domain and the…

Questions about technology

What evidence do I give a SOC 2 auditor or an enterprise customer?
Period reports: roster covered, simulations, training, and index evolution. That feeds your folder. It is not Whalemate’s SOC 2. If the auditor asks about the vendor, the Trust Center and the DPA are the material. We do not invent a SOC 2 report of ours to close a questionnaire.
How does a contractor join and leave?
Through SCIM or the employees API, same as a full-time hire. The day the IdP deprovisions them, they stop being program population. If the contractor lives in another directory, that is declared in implementation. We do not keep orphaned accounts to inflate coverage.
Do you have SOC 2?
We do not declare it. The certification we show is ISO/IEC 27001:2022. “Customer SOC 2” on this card is your organization’s report — the one you answer to your customers. Mixing those badges would be inventing a credential.
What does this module not cover?
It is not a CASB, it does not scan repos, and it does not replace the IdP. It does not install an agent on laptops. It does not use the score for a PIP. It is also not a secure-coding course: it is human risk — phishing, impersonation, OAuth — not an AppSec program. AppSec stays in your pipeline.

Technology — Security awareness and human risk

The program calibrates the same way. We'll show you in the demo.