CASE STUDY

How Osome Ditched Manual Processes, Reduced Risk and Strengthened Its Security Culture With Human Risk Management

Osome is an AI-enabled business management platform that has supported 40,000+ global startups & small and medium-sized businesses (SMBs). The company provides Incorporation, Accounting, Bookkeeping, Tax filing, and Corporate Secretarial services through proprietary technology that blends automation with human expertise.

Operating across Singapore, Hong Kong, the United Kingdom, and the United Arab Emirates, Osome handles sensitive financial and corporate information at scale. Information security is therefore a foundational requirement. The responsibility sits with the IT and Security department, led by Murali Krishna, IT and Security Manager.

INDUSTRY AI-enabled business management & corporate services
FOUNDED 2017
HEADQUARTERS Singapore
OPERATIONAL REACH Serves clients across the globe

Challenges

Like many growing technology organizations, Osome operates in an environment where technical controls alone are not enough to mitigate risk. A key challenge for the IT and Security team was ensuring cybersecurity threats were effectively controlled while maintaining reliable day-to-day IT operations.

With a small team covering all IT and security responsibilities, balancing operational support with proactive security initiatives required careful prioritization.

Security awareness efforts were largely informal. Murali describes the earlier process clearly: “Before Right-Hand, our process was mostly manual, ad hoc, and communicated during team meetings without centralized tracking or data-driven insights.”

Without a dedicated platform, it was difficult to deliver consistent training, track engagement, measure behavioral improvements, or demonstrate tangible risk reduction over time.

Solution

Right-Hand was the Human Risk Management (HRM) platform of choice for Osome. The team learned about the platform in November 2022 and selected it for its structured, data-driven approach to security awareness.

Murali adds, “Right-Hand’s solution has helped centralize our security and risk efforts, providing a data-driven view of our security posture and giving a measurable risk and security culture score.”

Implementation was quick, allowing the team to get up and running without delays. The HRM platform was integrated into the company’s Learning & Development calendar and became the platform for managing training, awareness campaigns, reporting, and compliance requirements.

After implementation, the team gained a measurable view of its security posture, including risk scores. This visibility enabled them to track improvements over time, identify users most susceptible to attack, and better understand user behavior trends and threat landscapes, including emerging risks related to generative AI.

Murali notes that Right-Hand’s Customer Success team has been “essential” to the program’s success, highlighting the value of monthly review meetings, campaign planning support, and overall guidance, which ensured initiatives were strategically aligned while saving valuable time for the internal team.

Success

Over time, the impact of the platform extended beyond simple compliance metrics. Osome experienced measurable risk reduction, improved security awareness, and a stronger security culture across the organization.

The team successfully launched multiple campaigns, including custom content that provided valuable insights into user behavior and engagement patterns. Initiatives such as Cybersecurity Awareness Month in October proved particularly impactful in reinforcing awareness at scale.

Reflecting on the investment, Murali notes: “Yes, it was worthwhile because it centralizes our security awareness efforts, provides measurable insights, saves time, and strengthens our overall security culture.”

As Murali describes, security awareness at Osome has moved from being manual and ad hoc to becoming centralized and measurable. It is structured, measurable, and embedded into how the organization manages cyber risk, turning security into a shared responsibility across the business.

Why Right-Hand

Beyond the platform itself, Murali highlights the value of the synergy between key factors. “We love that it combines structured training, reporting, and managed services, making it easy to improve security awareness and understand user behavior, all while reducing operational risk.”

As for advice for other companies facing similar challenges, Murali notes, “Investing in a platform like Right-Hand is invaluable. Centralizing awareness, providing actionable insights, and embedding security into your company culture makes managing cyber risk far more efficient and effective, organization-wide.”

About Right-Hand’s Human Risk Management (HRM) Platform

Right-Hand’s HRM platform integrates with existing security tools to identify employee risks and deliver real-time, contextual training nudges.

Powered by adaptive AI agents across phishing, vishing, and training workflows, the platform responds to behavioral signals, reinforces secure decisions at the moment of risk, and provides measurable insight into human-related exposure. This approach reduces avoidable alerts, changes behavior, and strengthens security culture over time.

About Right-Hand Cybersecurity

Right-Hand is a Human Risk Management organization that helps companies reduce cyber risk through behavior change. Leveraging Agentic AI and security stack integration, the company delivers adaptive training and behavioral insights that help security teams identify risky behaviors and intervene in real time. By integrating with existing security tools and workflows, Right-Hand enables organizations to strengthen security culture, improve resilience against social engineering, and reduce human-related security incidents at scale.