Home
Tech Grid
News Room
Interviews
Think Stack
Articles
  • Agentic AI

Above Security and Forscie Launch Synthetic Insider Threat Matrix


Above Security and Forscie Launch Synthetic Insider Threat Matrix
  • by: PR Newswire
  • |
  • September 1, 2026

Above Security (Above), the AI-native managed insider threat platform, today launched the Synthetic Insider Threat Matrix (SITM), the new extension of the Insider Threat Matrix (ITM) focused entirely on the agentic workforce. The ITM is a free, vendor-neutral taxonomy created and stewarded by Forscie that has become security industry's reference standard for how insiders cause harm. Above has served as ITM's inaugural sponsor since early 2026, and SITM is next chapter of that partnership. Built by researchers at Above Theory alongside Forscie's team, SITM extends ITM model to cover new class of insider — the synthetic one.

Building on Insider Threat Matrix, new Synthetic Insider Threat Matrix provides common language, MITRE ATT&CK-style framework, and means to investigate real and growing AI insider threats.

Quick Intel

  • Above Security and Forscie launch Synthetic Insider Threat Matrix extension of Insider Threat Matrix focused entirely on agentic workforce.
  • Provides common language MITRE ATT&CK-style framework and means to investigate real growing AI insider threats mapping 166 knowledge objects.
  • Built by Above Theory alongside Forscie team extending model to cover synthetic insider mapping tactics cleanly onto corresponding human-centric ITM techniques.
  • Research grounded in real-world agent behavior observed across live customer environments confirming synthetic insiders produce behavior security legal HR investigate in people.
  • SITM maps detection prevention techniques specific to agentic incidents including unauthorized data access autonomous exfiltration privilege misuse shadow AI activity.
  • Estimated 28.6M AI agents active inside enterprises 2025 projected surpass 2.2B by 2030 many hold standing access to sensitive CRM source code finance systems.

Common Language Structured Framework Shared Basis for Investigation Reports

For security community, SITM provides three concrete tactical benefits: Common language for describing synthetic-insider behavior instead of ad hoc terminology. Structured framework to map that behavior against so techniques can be compared and referenced consistently across organizations same role MITRE ATT&CK plays for external attackers. Shared basis for writing investigation reports that use terms any analyst would recognize immediately.

An estimated 28.6 million AI agents were active inside enterprises in 2025 — number projected to surpass 2.2 billion by 2030. Many AI agents hold standing access to sensitive information found in various sources including CRM records, source code, and finance systems. Each has capacity to act thousands of times a day without shift change. Yet unlike human insiders none of them were interviewed onboarded or assigned manager.

"Synthetic insiders are real and growing problem, and most of industry doesn't yet know what to do about it," said Aviv Nahum, Co-Founder and CEO of Above Security. "We do, because research team has been studying this behavior in live environments for months. Extending Matrix, so whole community has language for it, is exactly what security teams and industry as whole need right now."

"Insider risk practitioners have always needed shared vendor-neutral language to describe how harm actually occurs inside organization," said James Weston, founder of Forscie and co-creator of Insider Threat Matrix. "Advances in AI present unique challenge to insider risk programs that does not neatly fit into existing human-centred paradigm. To address this, we worked with Above Theory to create Synthetic Insider Threat Matrix, like MITRE Corporation did with ATT&CK framework over decade ago."

Above Theory Research Grounded in Real-World Agent Behavior Live Environments

Above Theory built categories in Synthetic Insider Threat Matrix and contributed deep insights grounded in real-world agent behavior, working in conjunction with Forscie to map every synthetic-insider tactic cleanly onto corresponding techniques in original human-centric ITM. Above Theory's research drawn from what Above's investigative agents see across live customer environments confirms synthetic insiders already producing kind of behavior security legal HR teams spent decades learning to investigate.

The Insider Threat Matrix — both Human and Synthetic — is open, vendor-neutral, and freely available to and powered by whole insider risk community. The Synthetic Insider Threat Matrix is live today at insiderthreatmatrix.org, credited to Forscie and Above Theory with contributions from researchers Nimer Kees and Yonatan Machluf. Above customers get added layer: every investigation Above's AI agents produce already maps directly to SITM and ITM categories inside Above portal.

 

About Above Security

Above Security is a managed insider risk protection service powered by a fleet of autonomous AI investigators. Instead of alerting on isolated events or anomalies, Above continuously investigates behavior across identities, SaaS, endpoints, and AI agents to understand intent, build behavioral narratives, and surface insider risk before incidents occur. Above's AI agents operate like a 24/7 insider risk team: they monitor activity in real time, reason over sequences of actions, and proactively assemble investigation-ready timelines that explain who did what, why it matters, and what to do next. When risk emerges, the platform delivers real-time behavioral guidance to steer people toward safer choices, flags emerging incidents early, and produces complete, defensible reports with recommended action plans for security, HR, and legal teams.

  • MITREATTACKAgentic AIAbove Theory
News Disclaimer
Want to reach B2B tech decision-makers through TechIntelPro? Get our Media Kit
  • Share
Enterprise Tech News