Above Security (Above), the AI-native managed insider threat platform, today launched the Synthetic Insider Threat Matrix (SITM), the new extension of the Insider Threat Matrix (ITM) focused entirely on the agentic workforce. The ITM is a free, vendor-neutral taxonomy created and stewarded by Forscie that has become security industry's reference standard for how insiders cause harm. Above has served as ITM's inaugural sponsor since early 2026, and SITM is next chapter of that partnership. Built by researchers at Above Theory alongside Forscie's team, SITM extends ITM model to cover new class of insider — the synthetic one.
Building on Insider Threat Matrix, new Synthetic Insider Threat Matrix provides common language, MITRE ATT&CK-style framework, and means to investigate real and growing AI insider threats.
For security community, SITM provides three concrete tactical benefits: Common language for describing synthetic-insider behavior instead of ad hoc terminology. Structured framework to map that behavior against so techniques can be compared and referenced consistently across organizations same role MITRE ATT&CK plays for external attackers. Shared basis for writing investigation reports that use terms any analyst would recognize immediately.
An estimated 28.6 million AI agents were active inside enterprises in 2025 — number projected to surpass 2.2 billion by 2030. Many AI agents hold standing access to sensitive information found in various sources including CRM records, source code, and finance systems. Each has capacity to act thousands of times a day without shift change. Yet unlike human insiders none of them were interviewed onboarded or assigned manager.
"Synthetic insiders are real and growing problem, and most of industry doesn't yet know what to do about it," said Aviv Nahum, Co-Founder and CEO of Above Security. "We do, because research team has been studying this behavior in live environments for months. Extending Matrix, so whole community has language for it, is exactly what security teams and industry as whole need right now."
"Insider risk practitioners have always needed shared vendor-neutral language to describe how harm actually occurs inside organization," said James Weston, founder of Forscie and co-creator of Insider Threat Matrix. "Advances in AI present unique challenge to insider risk programs that does not neatly fit into existing human-centred paradigm. To address this, we worked with Above Theory to create Synthetic Insider Threat Matrix, like MITRE Corporation did with ATT&CK framework over decade ago."
Above Theory built categories in Synthetic Insider Threat Matrix and contributed deep insights grounded in real-world agent behavior, working in conjunction with Forscie to map every synthetic-insider tactic cleanly onto corresponding techniques in original human-centric ITM. Above Theory's research drawn from what Above's investigative agents see across live customer environments confirms synthetic insiders already producing kind of behavior security legal HR teams spent decades learning to investigate.
The Insider Threat Matrix — both Human and Synthetic — is open, vendor-neutral, and freely available to and powered by whole insider risk community. The Synthetic Insider Threat Matrix is live today at insiderthreatmatrix.org, credited to Forscie and Above Theory with contributions from researchers Nimer Kees and Yonatan Machluf. Above customers get added layer: every investigation Above's AI agents produce already maps directly to SITM and ITM categories inside Above portal.
About Above Security
Above Security is a managed insider risk protection service powered by a fleet of autonomous AI investigators. Instead of alerting on isolated events or anomalies, Above continuously investigates behavior across identities, SaaS, endpoints, and AI agents to understand intent, build behavioral narratives, and surface insider risk before incidents occur. Above's AI agents operate like a 24/7 insider risk team: they monitor activity in real time, reason over sequences of actions, and proactively assemble investigation-ready timelines that explain who did what, why it matters, and what to do next. When risk emerges, the platform delivers real-time behavioral guidance to steer people toward safer choices, flags emerging incidents early, and produces complete, defensible reports with recommended action plans for security, HR, and legal teams.