By NHI Mgmt Group Editorial TeamBased on Abnormal AI: “Abnormal AI Secures Spot on Forbes 2025 Cloud 100 for Third Year Running” (September 3, 2025)

TL;DR: AI-era security is increasingly judged on detection of compromised accounts and socially engineered abuse, not just platform breadth, while Abnormal AI says it was named to the Forbes 2025 Cloud 100 for the third year in a row and entered the top 20 for the first time, citing 3,200-plus customers and 25% of the Fortune 500 as evidence of growth.


At a glance

What this is: Abnormal AI says its Cloud 100 ranking reflects continued market attention on AI-native human behavior security, with the company highlighting third-year inclusion, a first top-20 placement, and scale claims tied to customer adoption.

Why it matters: For IAM and security teams, this shows that account compromise detection and socially engineered abuse are increasingly treated as core identity-security requirements, especially where human identity and connected applications intersect.

By the numbers:

  • Abnormal AI says it was named to the Forbes 2025 Cloud 100 for the third year in a row and entered the top 20 for the first time.
  • Abnormal AI says it is trusted by more than 3,200 organizations.
  • Abnormal AI says it is used by 25% of the Fortune 500.
  • The Cloud 100 reviewed submissions from hundreds of cloud startups and private companies worldwide.

Context

AI-native human behavior security focuses on spotting anomalous user behavior, compromised accounts, and socially engineered abuse across email and connected applications. In practice, that places the control problem inside human identity operations, because the threat is no longer only unauthorized login but suspicious action that looks legitimate until it is correlated across signals.

This article is primarily a recognition and positioning update, but the governance signal is broader than the award itself. Security teams are being pushed to measure whether account abuse detection can keep pace with AI-assisted phishing, cross-application compromise, and user behavior that evades simple rule-based controls.

For identity programmes, the relevant question is whether detection can connect human identity, mailbox activity, and application context fast enough to change response. That is typical of modern SaaS environments, where the real risk is not just initial compromise but the speed with which an attacker can blend into normal user activity.


Key questions

Q: How should security teams detect identity compromise after authentication?

A: They should monitor what each identity actually does after login, including privilege use, command patterns, unusual data access, and cross-system movement. Authentication confirms entry, but post-authentication telemetry reveals misuse. The best programmes correlate behaviour across cloud and on-premises systems so analysts can tell normal activity from compromised or abused identity sessions.

Q: Why do socially engineered attacks remain hard to stop in cloud environments?

A: They succeed by exploiting trust relationships that already exist between users, mailboxes, and connected applications. Once the attacker operates as a legitimate account, simple perimeter controls lose visibility, and the defensive challenge shifts to spotting behaviour that no longer matches the account’s normal pattern.

Q: What are the signs that human-behavior security controls are too narrow?

A: A narrow programme usually sees phishing or login anomalies but misses what happens next inside SaaS workflows. If the team cannot connect email signals to application activity, then compromised accounts can move through normal business processes without triggering a meaningful response.

Q: How should IAM and SOC teams decide where to focus behaviour analytics first?

A: Start with the user journeys that combine high business value, frequent external contact, and multiple connected applications. Those paths create the highest payoff for behaviour analytics because attackers can pivot from initial deception into trusted workflows quickly, and the business impact is usually immediate.


Technical breakdown

How AI-native behavior detection works across email and SaaS apps

AI-native human behavior security systems build a baseline from contextual signals, then compare each cloud email event and connected-application action against that baseline. The value is not just spotting one malicious message, but correlating account state, sender relationships, and downstream application behavior. That matters because modern abuse rarely stays inside a single channel. A mailbox compromise often becomes the entry point for application access, internal forwarding, or business process abuse. In identity terms, the control is watching for behaviour that is plausible for the account but inconsistent with the user’s normal operating pattern.

Practical implication: teams should evaluate whether their detection stack correlates email and application activity before an attacker can pivot across SaaS.

Why compromised accounts and social engineering remain the core risk

Compromised accounts are often the real payload after phishing, invoice fraud, or consent abuse. Once a legitimate account is taken over, the attacker inherits trust relationships, inbox history, and application access that make malicious activity look routine. That is why a pure authentication control does not finish the job. The security challenge becomes distinguishing ordinary business activity from malicious use of a valid identity. For IAM and SOC teams, this is where identity telemetry, behavior scoring, and workflow context must meet, because the attacker is operating inside the trust boundary rather than outside it.

Practical implication: treat account compromise as an identity governance problem, not just an email security problem.

What Cloud 100 recognition signals about buyer expectations

Recognition in a cloud-company ranking is not a security control, but it does signal how the market is valuing platforms that sit between identity, email, and application risk. Buyers are clearly rewarding tools that can address cloud-native abuse patterns rather than relying only on static rules or isolated message filtering. For practitioners, the lesson is to separate market visibility from operational fit: the relevant test is whether the platform reduces exposure to socially engineered compromise across the applications that matter most to the business.

Practical implication: benchmark platforms on cross-application identity protection outcomes, not on brand momentum or list placement.


Threat narrative

Attacker objective: The attacker aims to turn a trusted human identity into a reliable foothold for business email compromise, application abuse, or broader cloud access.

  1. Entry begins with socially engineered abuse or message-based deception that targets a human user and the trust relationships around their account.
  2. Credential or session abuse follows when the compromised identity is used to access email or connected applications as a legitimate user.
  3. Impact occurs when the attacker uses that trusted access to manipulate business workflows, exfiltrate information, or extend compromise into additional cloud services.

NHI Mgmt Group analysis

Human behavior security is becoming an identity control, not just a threat-detection category. The article’s framing matters because the real risk sits inside the human identity boundary, where compromised accounts and normal-looking actions overlap. That shifts the discussion from message filtering to identity governance across email and connected applications. Practitioners should treat behavior analytics as part of the identity plane, not an adjacent security add-on.

AI is raising the value of contextual abuse detection faster than it is raising the value of perimeter controls. Social engineering at scale makes static indicators less useful because the attacker’s first move is often to inherit a valid trust relationship. The governance implication is that teams need controls that can interpret post-authentication behavior, not just authenticate the user once. Practitioners should re-evaluate whether their current controls can see trust being misused after login.

Named concept: identity behavior coverage gap. This is the gap between authenticating a user and understanding what that user does once trust has been granted. The article points to a market that increasingly rewards platforms able to cover that gap across email, collaboration tools, and line-of-business apps. Practitioners should measure whether their programme can detect abuse after access is already legitimate.

Cloud recognition now tracks whether a platform can absorb AI-era abuse patterns across the full workflow, not whether it can flag isolated anomalies. That reflects a broader shift in identity security buying criteria. The more connected the application estate becomes, the less useful single-surface controls are on their own. Practitioners should align procurement with cross-application identity risk outcomes, not category slogans.

For human identity programmes, compromised-account detection is increasingly the operational proof point for modern security maturity. The article links market visibility to the ability to stop socially engineered attacks and detect compromised accounts at scale. That reinforces a simple point: if an organisation cannot see how trusted identities are abused across SaaS, its IAM and SOC functions are still partially blind. Practitioners should prioritise visibility into post-authentication misuse.

What this signals

Identity behaviour coverage gap: security teams are still too quick to treat post-authentication abuse as a separate SOC problem. The better model is to see compromised-account detection as an extension of human identity governance, because the malicious action usually begins after legitimate access is established.

As enterprise workflows spread across email and SaaS applications, defenders need visibility into the transition from trusted access to suspicious use. That means aligning identity telemetry, response playbooks, and account-risk scoring so the control stack can see misuse inside normal business activity.


For practitioners

  • Prioritise post-authentication detection Assess whether your controls detect suspicious action after a user has already authenticated, not just failed logins or blocked messages.
  • Correlate email and SaaS activity Join mailbox telemetry with connected-application events so account abuse can be traced across business workflows instead of handled as isolated alerts.
  • Map high-value user journeys Identify the user journeys most likely to be abused through social engineering, then tune behavioural baselines and response playbooks around those paths.
  • Test for compromised-account blind spots Simulate a trusted account being used normally at first and maliciously later, then measure whether the control stack catches the shift in context.

Key takeaways

  • The article’s real security signal is not the Cloud 100 ranking itself, but the growing importance of detecting compromised human identities and socially engineered abuse across connected applications.
  • The article ties that market signal to scale claims of more than 3,200 organisations and use by 25% of the Fortune 500, which suggests buyers are treating identity-behaviour monitoring as mainstream.
  • For practitioners, the practical lesson is to test whether post-authentication behaviour, not just login events, is visible to the control stack.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK addresses the attack and risk surface, while NIST SP 800-63, NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST SP 800-63SP 800-63B — AuthenticationThe article centres on trusted human identities and post-authentication abuse.
Recommendation — Use strong authentication and session monitoring to reduce the value of compromised human accounts.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsBehavioral abuse across connected apps depends on active permissions and trusted access.
Recommendation — Review entitlements so user access stays aligned with actual business need and risk.
MITRE ATT&CKTA0006;TA0009 — Credential Access; CollectionThe article’s threat pattern centres on account abuse after social engineering or compromise.
Recommendation — Map suspicious account use to credential access and collection tactics to improve detection coverage.
CIS Controls v8CIS-5 — Account ManagementCompromised-account detection depends on disciplined account governance across SaaS.
Recommendation — Apply account-management controls to identify abnormal use of trusted identities.

Key terms

  • AI Native Human Behavior Security: AI native human behavior security uses machine learning and behavioral context to detect suspicious actions tied to user accounts, email activity, and connected applications. The model focuses on abnormal patterns that suggest phishing, account takeover, or fraud rather than relying only on static indicators or signature based detection.
  • Compromised Account: A compromised account is a legitimate identity that an attacker has taken over and is using for malicious purposes. In healthcare email fraud, the risk is not only unauthorised access but also the attacker inheriting the trust, context, and communication patterns that make abuse difficult to spot.
  • Post-Authentication Monitoring: Post-authentication monitoring is the practice of watching identity behaviour after a login, token exchange, or session start. It matters because successful authentication does not prove trustworthiness for the rest of the session, especially when attackers use valid credentials or trusted flows.
  • Behavior Baseline: A record of normal activity for a non-human identity, including typical consumers, resources, and actions over time. Baselines help security teams detect when an identity is being used in an unusual way and provide the context needed to enforce least privilege safely in dynamic environments.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 27, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org