Above Security and Forscie Launch the Synthetic Insider Threat Matrix

August 27, 2026 9:00 AM EDT

Building on the Insider Threat Matrix, the new Synthetic Insider Threat Matrix provides common language, MITRE ATT&CK-style framework, and means to investigate real and growing AI insider threats

SAN FRANCISCO, Aug. 27, 2026 /PRNewswire/ -- Above Security (Above), the AI-native managed insider threat platform, today launched the Synthetic Insider Threat Matrix (SITM), the new extension of the Insider Threat Matrix™ (ITM) focused entirely on the agentic workforce. The ITM is a free, vendor-neutral taxonomy created and stewarded by Forscie that has become the security industry's reference standard for how insiders cause harm. Above has served as the ITM's inaugural sponsor since early 2026, and the SITM is the next chapter of that partnership. Built by researchers at Above Theory alongside Forscie's team, the SITM extends the ITM's model to cover a new class of insider — the synthetic one.

Above Security

Above Theory built the categories in the Synthetic Insider Threat Matrix and contributed deep insights grounded in real-world agent behavior, working in conjunction with Forscie to map every synthetic-insider tactic cleanly onto corresponding techniques in the original, human-centric ITM. Above Theory's research, drawn from what Above's investigative agents see across live customer environments, confirms what the data suggests: synthetic insiders are already producing the kind of behavior security, legal, and HR teams have spent decades learning to investigate in people — and almost nobody had a shared language to address it before today. The SITM maps 166 knowledge objects covering detection and prevention techniques specific to agentic incidents, including unauthorized data access, autonomous exfiltration, privilege misuse, and shadow AI activity.

For the security community, the SITM provides three concrete tactical benefits:

  • A common language for describing synthetic-insider behavior instead of ad hoc terminology.
  • A structured framework to map that behavior against, so techniques can be compared and referenced consistently across organizations — the same role MITRE ATT&CK plays for external attackers.
  • A shared basis for writing investigation reports that use terms any analyst would recognize immediately.

An estimated 28.6 million AI agents were active inside enterprises in 2025 — a number projected to surpass 2.2 billion by 2030. Many AI agents hold standing access to sensitive information found in various sources, including CRM records, source code, and finance systems. Each has the capacity to act thousands of times a day without a shift change. Yet, unlike human insiders, none of them were interviewed, onboarded, or assigned a manager.

"Synthetic insiders are a real and growing problem, and most of the industry doesn't yet know what to do about it," said Aviv Nahum, Co-Founder and CEO of Above Security. "We do, because our research team has been studying this behavior in live environments for months. Extending the Matrix, so the whole community has language for it, is exactly what security teams and the industry as a whole need right now."

"Insider risk practitioners have always needed a shared, vendor-neutral language to describe how harm actually occurs inside an organization," said James Weston, founder of Forscie and co-creator of the Insider Threat Matrix. "Advances in AI present a unique challenge to insider risk programs that does not neatly fit into the existing human-centred paradigm. To address this, we worked with Above Theory to create the Synthetic Insider Threat Matrix, like the MITRE Corporation did with the MITRE ATT&CK framework over a decade ago."

The Insider Threat Matrix — both Human and Synthetic — is open, vendor-neutral, and freely available to, and powered by, the whole insider risk community. For more information on the Synthetic Insider Threat Matrix, visit: www.above.security/blog-posts/synthetic-insider-threat-matrix.

About Above Theory

Above Theory is Above Security's insider risk research group, responsible for the company's original threat research. For the Synthetic Insider Threat Matrix, Above Theory's researchers built the framework's categories and contributed additional content based on real-world agent behavior observed across Above's customer environments, working directly with Forscie's team to fold that research into the ITM community's structure. The team is led by Above researchers Nimer Kees and Yonatan Machluf, both credited as contributors on insiderthreatmatrix.org.

The release follows Above's recently announced strategic investment from the CrowdStrike Falcon Fund, a milestone in the company's mission to democratize elite insider risk management. Contributing Above Theory's research to the community, in the open and at no cost, is the next step in that same mission: rather than keeping this research inside a product, Above is giving it back to the practitioners who need it most.

The Synthetic Insider Threat Matrix is free to reference regardless of what platform an organization runs. Above customers get an added layer: every investigation Above's AI agents produce already maps directly to SITM and ITM categories inside the Above portal, so teams get the shared industry language and a fully worked investigation in the same report.

The Synthetic Insider Threat Matrix is live today at insiderthreatmatrix.org, credited to Forscie and Above Theory, Above's insider risk research group, with contributions from Above researchers Nimer Kees and Yonatan Machluf. A companion post detailing the research behind the SITM is available at above.security/blog.

About Above Security

Above Security is a managed insider risk protection service powered by a fleet of autonomous AI investigators. Instead of alerting on isolated events or anomalies, Above continuously investigates behavior across identities, SaaS, endpoints, and AI agents to understand intent, build behavioral narratives, and surface insider risk before incidents occur. Above's AI agents operate like a 24/7 insider risk team: they monitor activity in real time, reason over sequences of actions, and proactively assemble investigation-ready timelines that explain who did what, why it matters, and what to do next. When risk emerges, the platform delivers real-time behavioral guidance to steer people toward safer choices, flags emerging incidents early, and produces complete, defensible reports with recommended action plans for security, HR, and legal teams. Learn more at above.security.

Forward-Looking Statements

This press release may include discussion of unreleased services or features. Any unreleased services or features referenced here are still in development and subject to change. Customers should make their purchase decisions based upon services and features that are currently available.

Media Contact
ICR for Above Security
[email protected] 

 

Cision View original content to download multimedia:https://www.prnewswire.com/news-releases/above-security-and-forscie-launch-the-synthetic-insider-threat-matrix-302861440.html

SOURCE Above Security



Serious News for Serious Traders! Try StreetInsider.com Premium Free!

You May Also Be Interested In





Related Categories

PRNewswire, Press Releases