Above Security and Forscie Launch the Synthetic Insider Threat Matrix
Building on the Insider Threat Matrix, the new Synthetic Insider Threat Matrix provides common language, MITRE ATT&CK-style framework, and means to investigate real and growing AI insider threats
Above Theory built the categories in the Synthetic Insider Threat Matrix and contributed deep insights grounded in real-world agent behavior, working in conjunction with Forscie to map every synthetic-insider tactic cleanly onto corresponding techniques in the original, human-centric ITM. Above Theory's research, drawn from what Above's investigative agents see across live customer environments, confirms what the data suggests: synthetic insiders are already producing the kind of behavior security, legal, and HR teams have spent decades learning to investigate in people — and almost nobody had a shared language to address it before today. The SITM maps 166 knowledge objects covering detection and prevention techniques specific to agentic incidents, including unauthorized data access, autonomous exfiltration, privilege misuse, and shadow AI activity.
For the security community, the SITM provides three concrete tactical benefits:
- A common language for describing synthetic-insider behavior instead of ad hoc terminology.
- A structured framework to map that behavior against, so techniques can be compared and referenced consistently across organizations — the same role MITRE ATT&CK plays for external attackers.
- A shared basis for writing investigation reports that use terms any analyst would recognize immediately.
An estimated 28.6 million AI agents were active inside enterprises in 2025 — a number projected to surpass 2.2 billion by 2030. Many AI agents hold standing access to sensitive information found in various sources, including CRM records, source code, and finance systems. Each has the capacity to act thousands of times a day without a shift change. Yet, unlike human insiders, none of them were interviewed, onboarded, or assigned a manager.
"Synthetic insiders are a real and growing problem, and most of the industry doesn't yet know what to do about it," said
"Insider risk practitioners have always needed a shared, vendor-neutral language to describe how harm actually occurs inside an organization," said
The Insider Threat Matrix — both Human and Synthetic — is open, vendor-neutral, and freely available to, and powered by, the whole insider risk community. For more information on the Synthetic Insider Threat Matrix, visit: www.above.security/blog-posts/synthetic-insider-threat-matrix.
About Above Theory
Above Theory is Above Security's insider risk research group, responsible for the company's original threat research. For the Synthetic Insider Threat Matrix, Above Theory's researchers built the framework's categories and contributed additional content based on real-world agent behavior observed across Above's customer environments, working directly with Forscie's team to fold that research into the ITM community's structure. The team is led by Above researchers
The release follows Above's recently announced strategic investment from the CrowdStrike Falcon Fund, a milestone in the company's mission to democratize elite insider risk management. Contributing Above Theory's research to the community, in the open and at no cost, is the next step in that same mission: rather than keeping this research inside a product, Above is giving it back to the practitioners who need it most.
The Synthetic Insider Threat Matrix is free to reference regardless of what platform an organization runs. Above customers get an added layer: every investigation Above's AI agents produce already maps directly to SITM and ITM categories inside the Above portal, so teams get the shared industry language and a fully worked investigation in the same report.
The Synthetic Insider Threat Matrix is live today at insiderthreatmatrix.org, credited to Forscie and Above Theory, Above's insider risk research group, with contributions from Above researchers
About Above Security
Above Security is a managed insider risk protection service powered by a fleet of autonomous AI investigators. Instead of alerting on isolated events or anomalies, Above continuously investigates behavior across identities, SaaS, endpoints, and AI agents to understand intent, build behavioral narratives, and surface insider risk before incidents occur. Above's AI agents operate like a 24/7 insider risk team: they monitor activity in real time, reason over sequences of actions, and proactively assemble investigation-ready timelines that explain who did what, why it matters, and what to do next. When risk emerges, the platform delivers real-time behavioral guidance to steer people toward safer choices, flags emerging incidents early, and produces complete, defensible reports with recommended action plans for security, HR, and legal teams. Learn more at above.security.
Forward-Looking Statements
This press release may include discussion of unreleased services or features. Any unreleased services or features referenced here are still in development and subject to change. Customers should make their purchase decisions based upon services and features that are currently available.
Media Contact
ICR for Above Security
[email protected]
View original content to download multimedia:https://www.prnewswire.com/news-releases/above-security-and-forscie-launch-the-synthetic-insider-threat-matrix-302861440.html
SOURCE Above Security
Serious News for Serious Traders! Try StreetInsider.com Premium Free!
You May Also Be Interested In
- Award-Winning Hilton Garden Inn Wayne Reveals a Fresh, Modern Look
- QuEra Computing Uses AI to Automate a Critical Quantum Computer Subsystem, Enabling the Acceleration of Commercial-Grade Quantum Computing Deployments from QuEra
- Scottsdale TMS Therapy Built Solely Around TMS and Spravato Services
Create E-mail Alert Related Categories
PRNewswire, Press ReleasesSign up for StreetInsider Free!
Receive full access to all new and archived articles, unlimited portfolio tracking, e-mail alerts, custom newswires and RSS feeds - and more!



Tweet
Share