
Founded in 2017 and headquartered in Singapore, impress.ai is an AI-powered recruiting software provider serving large enterprises globally.
Operating at enterprise scale and handling sensitive candidate and client data, the company must uphold rigorous security standards across its workforce.
At this level, information security is a foundational requirement. The responsibility sits with the Infosec Team who reports to the Head of GRC.
The team ensures that employees across the organization align with ISO and SOC standards while overseeing the delivery of comprehensive security training.
INDUSTRY AI-powered recruiting platform
FOUNDED 2017
HEADQUARTERS Singapore
OPERATIONAL REACH Clients across the U.S., Europe and APAC
Like many modern SaaS organizations, impress.ai operates in an environment where a solid tech stack alone is not enough to mitigate risk. The InfoSec team identified employee exposure to phishing and social engineering as one of the most persistent and high-impact challenges.
“A significant challenge is educating employees to recognize phishing emails and understand the evolving social engineering tactics used by external threat actors,” according to the Senior IS Analyst. The risk was not theoretical. Attackers were actively attempting to exploit human behavior as a path into the organization.
Security awareness efforts were largely informal. The team relied on Slack messages to alert employees. The Senior IS Analyst describes the earlier approach plainly: “We relied on general Slack messages to inform employees about attack vectors and global incidents related to phishing and hacking. We lacked a dedicated platform for targeted training.”
Without a reliable and responsive program in place, it was difficult to deliver consistent training, tailor learning to real employee behavior, or measure whether awareness efforts were actually reducing risk.
Right-Hand has been the company’s choice for Security Awareness and Human Risk Management platform throughout the evolution of its security program.
“Right-Hand is the first solution of this kind that we have used. It was our first choice for a Human Risk Management partner, and we have never looked back or considered another vendor since,” the Senior IS Analyst remarks. Over time, the platform became deeply embedded in impress.ai awareness programs and training.
Today, impress.ai runs a structured and continuous security program designed to promote behavior change with real-time learning interventions. With Right-Hand as a trusted training partner, the team delivers quarterly security training to all employees and runs monthly phishing simulations to validate how that learning holds up in real-world decision-making.
One of the most impactful changes was how the team handled phishing simulations and their learning interventions. Initially, employees who engaged in risky behaviors during a simulation were assigned a generic five-minute training module. That approach has since evolved. “We now use dynamic landing pages,” the Senior IS Analyst says. “These pages provide capsule information relevant to the specific error, teaching employees exactly what to look for before clicking links or attachments.”
This shift allowed learning to happen in real time, making training relevant and memorable. The team also integrated Right-Hand’s platform with Slack, enabling reminders and training interventions to reach employees within their workflow, in the tools they use for their work.
Beyond the platform itself, the InfoSec team credits Right-Hand’s customer support as a critical factor in the program’s success.
“Our Customer Support Manager has been instrumental, addressing all our queries with utmost care and importance,” says the Senior IS Analyst. The Right-Hand team holds regular monthly meetings with impress.ai to update the team on the latest threat landscape and training content and help refine campaigns over time.
That partnership has also proven valuable when technical issues arise. In one instance, the organization needed help to set up phishing simulation campaigns properly. “They proactively resolved the issue,” she recalls, ensuring campaigns reached users as intended without disrupting the training schedule.

Over time, the impact of Right-Hand extended well beyond compliance metrics.
From a governance perspective, the platform has played a key role in helping impress.ai achieve and maintain ISO and SOC requirements related to information security training. But it’s more than just compliance: the platform has driven a visible improvement in employee behavior.
“We have seen a cultural shift where employees now actively identify and report real phishing emails to the InfoSec team,” shares the Senior IS Analyst.
When real attacks occur, employees frequently flag them, and often reference the simulations as the reason they recognized the threat. “They inform us and thank us for the phishing campaigns, noting that the practice helped them avoid clicking real links.”
Security awareness has become a shared mindset rather than a checklist activity. “It has transformed security from being the responsibility of a single person into a collective responsibility for all employees,” she adds, highlighting how training content and real-time interventions have strengthened the organization’s overall security posture.
When reflecting on the platform’s strengths, ease of use and flexibility stand out.
“One of the biggest advantages is the ease of configuration of training campaigns,” the Senior IS Analyst notes. The team values having access to a broad content offer, combined with Right-Hand’s support to tailor that content to their specific environment. “There is a vast library of training content already available, and the team is highly flexible in customizing that content to meet our specific needs.”
Automated reminders and Slack-based notifications further reduce administrative overhead while keeping employees engaged and accountable. These two changes in training delivery brought more engagement and made behavior change felt across the organization.
For organizations considering a Human Risk Management platform, the advice from impress.ai is straightforward.
“Every company must have a training partner like Right-Hand to ensure employees understand that security is the responsibility of the whole organization,” the Senior IS Analyst says. In an era dominated by social engineering and phishing, ongoing training, timely interventions, and realistic simulations are no longer optional.
”InfoSec training and phishing simulation campaigns are essential to reduce human-related security risks by building employee awareness of evolving threats,” the Senior IS Analyst adds. By helping employees identify, avoid, and report attacks before damage occurs, Right-Hand supports the creation of a lasting security-first culture.
Right-Hand’s HRM platform integrates with existing security tools to identify employee risks and deliver real-time, contextual training nudges.
Powered by adaptive AI agents across phishing, vishing, and training workflows, the platform responds to behavioral signals, reinforces secure decisions at the moment of risk, and provides measurable insight into human-related exposure. This approach reduces avoidable alerts, changes behavior, and strengthens security culture over time.
Right-Hand is a Human Risk Management organization that helps companies reduce cyber risk through behavior change. Leveraging Agentic AI and security stack integration, the company delivers adaptive training and behavioral insights that help security teams identify risky behaviors and intervene in real time. By integrating with existing security tools and workflows, Right-Hand enables organizations to strengthen security culture, improve resilience against social engineering, and reduce human-related security incidents at scale.