Right Hand
Entrepreneur First '19Singapore, SG · Founded 2019 · 44 employees on LinkedIn · 3 known investors
Find your way into Right Hand
232 people in our graph share verified history with the Right Hand team — schools, employers, funds. One of them is your warm intro.
Right-Hand provides an AI-powered security awareness and human risk management platform that simulates modern social engineering attacks—including deepfake voice, phishing, and omnichannel threats—and delivers behavior-based training and interventions. It serves enterprise security teams looking to measure and reduce human cyber risk using behavioral intelligence and integrations with their existing security stack.
Also known as Right-Hand · Right-Hand Cyber Security · Right-Hand Cybersecurity
Founders & leadership
Right Hand was founded in 2019 by Theo Nasser and Uzair Ahmed.


Investors · 3
Company profile
researched Aug 2026Right-Hand (also referenced as Right-Hand Cyber Security / Right-Hand Cybersecurity) offers a SaaS platform for security awareness training and human risk management aimed at reducing employee-induced cyber risk. The product is positioned around modern social engineering threats, including deepfake voice attacks, business email compromise and phishing, omnichannel social engineering, shadow AI and AI governance, and sensitive data exposure.
The platform is organized around three capability areas. Training readiness covers AI-enabled awareness training with a content library, AI-generated content, role-based modules, automated reinforcement and gamification, and SCORM compatibility. Phishing readiness covers AI-generated phishing simulation campaigns using organization-specific scenarios, a user report button and email triage workflow, behavioral risk insights and dynamic teachable moments. Behavioral intelligence covers human risk scoring, integrations with the customer's existing security stack, behavioral analytics, risk-based prioritization and automated nudges. A partner description also cites compliance and policy assessments as part of the offering, framed around improving awareness, behaviour and culture across a workforce.
Right-Hand markets a "fleet" of AI agents: a deepfake vishing agent that simulates voice attacks using cloned executive voices in CXO scenarios, a phishing email agent that generates simulation templates informed by organizational context and attacker tactics, techniques and procedures, and a training agent that converts policies, threat intelligence and documentation into custom training content and videos.
Business model
Software-as-a-service platform sold to organizations, delivered as training, simulation and risk-scoring modules that integrate with a customer's existing security tooling; also distributed through technology/reseller partners such as Root Security in Singapore.
Traction
Public sources provide only qualitative traction signals: anonymized customer testimonials from a financial institution, a marketing technology organization and a utilities organization, and a Singapore reseller relationship. No customer counts, revenue or user figures are disclosed.
Latest developments
The company's current positioning centers on "agentic" security awareness, marketing a fleet of AI agents for deepfake vishing, phishing email generation and automated training content creation, alongside SOC 2 Type II certification and a published trust center.
▸Full profile — market position, technology, go-to-market, geography, risks & controversies
Market position
Competes in the security awareness training and human risk management category; the company's site cites a customer that evaluated more than a dozen vendors in that market before selecting Right-Hand. It differentiates against traditional, compliance-oriented awareness programs.
Positions against static, periodic, compliance-driven awareness training by offering continuously adapting, AI-generated simulations: deepfake vishing simulations rather than email-only tests, coordinated multi-vector campaigns rather than isolated email testing, OSINT/organization-context-informed phishing rather than generic templates, training generated in minutes rather than on quarterly cycles, risk scoring based on real-world behavioral and security-stack signals rather than closed-loop simulation results, and real-time nudges in Slack and Teams rather than delayed remediation.
Technology
AI agents that generate and run deepfake voice (vishing) simulations with cloned executive voices, phishing email templates informed by organizational context and attacker TTPs, and automatically produced training content from policies and documents. The platform ingests live signals from a customer's security stack to compute human risk scores, prioritize risk, adapt simulations and trigger real-time behavioral nudges in Slack, Teams and email. Enterprise controls include SOC 2 Type II certification, AES-256 encryption at rest, TLS 1.3 in transit, key rotation, SAML SSO, MFA and audit logging.
Go-to-market
Direct demo-request motion via the company website, supplemented by channel/technology partnerships, for example with Root Security in Singapore, which promotes the platform to its own customers.
Enterprise and mid-market security teams and CISOs; testimonials on the company site are attributed to a CISO at a financial institution, a security program manager at a marketing technology organization, and a CISO at a utilities organization.
Geography
Sources indicate customers described as security leaders "around the globe" and a Singapore-based technology partner; a partner page describes the company as backed by Singapore government investors.
Risks & controversies
No controversies are reported in the available sources. Publicly available information is limited to the company's own website and a partner page, so financial, headcount and customer metrics are unverified.
Compiled by commissioned research from 8 cited public sources — announcements, filings, and press listed under research sources below.
Key figures
latest reportedCompany-reported or press-reported figures, each dated to when it was claimed — not independently audited.
Timeline · 1
launches, deals, and filingsSingapore-based Root Security lists Right-Hand Cyber Security as a technology partner and resells/promotes its agentic security awareness, human risk management training, phishing simulation and triage, and HRM integration offerings.
Dated company events from announcements, filings, and press; legal rows summarize public dockets and regulator releases.
In the news
▸Research sources · 8
primary sources listed
- Right Handright-hand.ai · web
8 public sources were cited for this profile; the first-party ones are listed here.
Frequently asked questions
- What does Right Hand do?
- Right-Hand sells an AI-agent-based security awareness and human risk management platform for enterprise security teams.
- Who founded Right Hand?
- Right Hand was founded by Theo Nasser, Uzair Ahmed in 2019.
- Who are Right Hand's investors?
- Right Hand's investors include Copper Sky Capital, Entrepreneur First, Tri-Valley Ventures.
- Where is Right Hand headquartered?
- Right Hand is headquartered in Singapore, SG.




