TL;DR: Insider risk is still being managed as a stream of alerts rather than as behavioural context, according to Above, and says its Synthetic Insider Threat Matrix is meant to help security teams reconstruct intent across human activity and AI counterparts. The core issue is that identity and activity trails now span human, NHI, and AI-driven behaviour, so alert-only programmes miss the story that matters.
At a glance
What this is: This is Above's take on insider risk as a behavioural context problem, with a new matrix aimed at understanding human and AI-associated insider activity.
Why it matters: It matters because identity teams now have to govern insider behaviour across human users, non-human identities, and AI-assisted workflows without assuming alerts alone can explain intent.
By the numbers:
- 80% of attack models could be categorized as insider threats.
- 72% of organisations have experienced or suspect they have experienced a breach of non-human identities.
- When AWS credentials are exposed publicly, attackers attempt access within an average of 17 minutes.
👉 Read Above's analysis of the Synthetic Insider Threat Matrix and insider risk
Context
Insider risk is a governance problem as much as a detection problem. Security teams often see isolated events, but identity programmes need to understand whether those events form a pattern that indicates legitimate access being used in an unexpected way. That becomes harder when human activity, service access, and AI-assisted behaviour are all present in the same workflow.
The primary gap is not the lack of alerts. It is the lack of context that connects access, behaviour, and intent into a usable narrative for investigation and response. For identity practitioners, that puts insider risk squarely inside IAM, IGA, PAM, and non-human identity governance rather than treating it as a separate silo.
Key questions
Q: How should security teams investigate insider risk when alerts look harmless on their own?
A: They should correlate identity, HR, endpoint, and authentication events into one timeline before deciding whether the activity is normal. Separate alerts hide escalation patterns that only appear when privilege changes, login timing, and workstation behaviour are viewed together. The fastest path to clarity is to reconstruct the actor’s sequence, not to triage each alert independently.
Q: Why does AI-assisted work create new insider risk for IAM teams?
A: Because the same user session can now include human decisions and machine-mediated actions that are difficult to separate with standard identity controls. IAM teams need to know which workflows involve AI so they can judge whether the resulting activity still reflects the user's intent or has been amplified by automation.
Q: What are the signs that an insider-risk programme is too alert-driven?
A: Common signs include many isolated detections, long investigation times, repeated escalation of low-context cases, and weak handoff to legal or HR. If analysts cannot explain why the behaviour mattered beyond the alert itself, the programme is producing noise rather than actionable evidence.
Q: What should organisations do when insider cases involve both humans and AI counterparts?
A: They should investigate the full workflow, not just the user login, and assign ownership across security, identity, legal, and HR. The key decision is whether the organisation can explain how access, prompts, and downstream actions interacted. That is what determines accountability and response quality.
Technical breakdown
Why alert-centric insider detection misses behavioural intent
Alert-centric monitoring breaks when the event itself is not the problem but the sequence is. A file download, login, prompt, or data upload may be benign in isolation, yet together they can describe a shift in intent. Insider-risk programmes therefore need behavioural correlation across identity, device, application, and data activity. Without that correlation, the analyst gets fragments instead of an evidentiary chain, and the organisation ends up investigating noise rather than risk.
Practical implication: Correlate identity events with data movement and application context before escalating an insider case.
How AI-assisted insider activity complicates identity governance
AI-assisted activity changes the boundary between user intent and system execution. A human may prompt a model, but the downstream actions, summarisation, drafting, and data handling can amplify risk in ways traditional user monitoring does not model. That creates a governance issue for both human identity and NHI oversight because the same account can now drive activity through multiple execution layers. The result is not just more volume, but less interpretability.
Practical implication: Map which workflows include AI assistance so investigations can separate human intent from machine-mediated execution.
Why evidentiary timelines matter more than isolated detections
An evidentiary timeline is the sequence of actions, interactions, and artifacts that explain what happened and why it mattered. In insider-risk cases, that timeline is more valuable than a single high-severity alert because legal, HR, security, and leadership each need different proof thresholds. The technical challenge is stitching together access, communications, content, and behavioural signals into one chain of evidence that is understandable and defensible.
Practical implication: Build case workflows around timelines, not single alerts, so response teams can support investigation and accountability.
Threat narrative
Attacker objective: The objective is to use legitimate access and behavioural camouflage to move sensitive information or operational advantage out of the organisation without early detection.
- Entry happens through legitimate identity use, social engineering, or AI-assisted access that does not look suspicious on its own.
- Escalation occurs when the actor combines routine access with behavioural changes such as data staging, competitor interest, or misuse of trusted tools.
- Impact follows when internal knowledge, sensitive documents, or customer information is exposed, exfiltrated, or used to enable fraud or competitive harm.
Breaches seen in the wild
- Cisco DevHub NHI breach — IntelBroker exploited exposed Cisco credentials, API tokens and keys in DevHub.
- Meta AI Instagram Account Takeover — 20,225 Instagram accounts hijacked via compromised Meta AI support chatbot with overprivileged access.
Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Alerting is not the same as understanding insider risk. Traditional monitoring tells teams that something happened, but insider governance needs to explain whether that behaviour forms a meaningful sequence. When organisations treat detection as the finish line, they end up with more triage and less confidence. The practitioner conclusion is that insider risk must be governed as a context problem, not a volume problem.
AI-assisted behaviour collapses the old boundary between human identity and system activity. A single user session can now include prompts, generated content, delegated actions, and data movement that look normal in isolation. That means human IAM, NHI oversight, and case investigation can no longer be separated cleanly by tool ownership. The practitioner conclusion is that governance models need to follow the workflow, not just the login.
Synthetic insider risk is a useful concept because it names behaviour that is neither purely human nor purely machine-driven. That matters for security architecture because existing insider programmes were built around a human actor assumption. Once AI counterparts participate in the same workstream, the organisation needs a wider evidentiary model for intent, context, and accountability. The practitioner conclusion is to define where the insider boundary now sits in mixed human-machine operations.
Behavioural narratives are becoming the control plane for insider investigations. Security teams cannot prove intent with raw telemetry alone if they cannot connect events into a narrative that business stakeholders can understand. This is where identity governance and investigation design intersect. The practitioner conclusion is that programme maturity now depends on whether the team can explain the story, not just record the event.
From our research:
- The average organisation believes more than 1 in 5 of their non-human identities are insufficiently secured, according to The 2024 ESG Report: Managing Non-Human Identities.
- Enterprises that have experienced a compromised NHI averaged 2.7 separate incidents in the past 12 months, according to the same report.
- The 72% breach-experience rate in that study shows why NHI visibility and lifecycle control remain programme-level issues, not edge cases.
What this signals
Synthetic insider risk will force identity teams to widen the definition of the controlled actor. When human activity and AI-mediated execution appear in the same workflow, the investigation boundary moves from account ownership to behavioural ownership. Practitioners should expect their IAM and insider-risk programmes to be judged on whether they can explain mixed-origin activity, not just detect anomalies.
Context will become the differentiator in insider governance. The organisations that mature fastest will be the ones that can tie identity, data, and collaboration signals into one explainable chronology. That makes [NIST Cybersecurity Framework 2.0](https://www.nist.gov/cyberframework) relevant for governance, detection, and response alignment, not just compliance language.
With 72% of organisations saying they have experienced or suspect an NHI breach, the governance lesson is clear: insider-risk programmes and NHI programmes are converging whether teams plan for it or not. The practical move is to stop treating trust, access, and behaviour as separate review cycles and start governing them as one control surface.
For practitioners
- Correlate identity and data signals into a single case view Link authentication, file activity, collaboration tools, and data movement so investigators can see whether events form a pattern rather than a one-off alert.
- Separate human intent from AI-mediated execution Tag workflows that involve AI assistance, delegated drafting, or automated follow-on actions so reviewers can distinguish user decisions from machine amplification.
- Build evidentiary timelines for high-risk insider cases Capture the sequence of access, communications, content creation, and exfiltration indicators in one chronology that legal, HR, and security can all use.
- Review privileged workflows for hidden insider exposure Focus on accounts that can reach sensitive content, approve transfers, or handle strategic documents because those paths often carry the highest insider risk.
Key takeaways
- Insider risk is increasingly a context problem, not an alert problem, because isolated detections do not explain intent.
- AI-assisted workflows blur the line between human identity and machine-mediated action, which changes how investigations and accountability work.
- Identity teams need behavioural narratives and evidentiary timelines if they want insider governance to produce decisions rather than noise.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | DE.CM-1 | Behavioural monitoring and anomaly correlation are central to insider-risk investigation. |
| NIST SP 800-53 Rev 5 | AU-6 | Audit review and correlation support the evidentiary timelines discussed in the post. |
| NIST Zero Trust (SP 800-207) | Zero Trust thinking applies where trust must be continuously re-evaluated across identities. |
Use DE.CM-1 to align identity, data, and user activity monitoring into one investigative view.
Key terms
- Insider Risk Signal: An insider risk signal is a recurring behaviour pattern that may indicate misuse, negligence, or process breakdown involving sensitive information. It is not proof of malicious intent on its own, but it does show where identity, behaviour, and data handling controls may be misaligned.
- Behavioral Narrative: A behavioral narrative is the connected account of what an identity did, when it did it, and why the sequence mattered. It turns scattered telemetry into a defensible story that investigation, legal, and leadership teams can use to judge intent and impact.
- Evidentiary Timeline: An evidentiary timeline is a structured sequence of events, artifacts, and interactions assembled to support investigation or response. It matters because insider cases often require more than a single alert, and the timeline helps explain causality, accountability, and escalation.
- AI-Mediated Execution: AI-mediated execution is work where a human initiates action but an AI system helps generate, transform, or carry out the next steps. In identity governance, this creates a mixed control problem because the user owns the session while the machine amplifies the behaviour.
What's in the full article
Above's full blog post covers the operational detail this post intentionally leaves for the source:
- The vendor's full behavioral narrative examples show how cases are assembled from identity, content, and activity signals.
- It also outlines how its AI investigators support in-the-moment coaching and evidentiary timelines for response teams.
- The post gives more context on the Synthetic Insider Threat Matrix and how Above is positioning the framework for practitioner use.
👉 Above's full post adds the behavioural examples and context behind its insider-risk framing.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on September 3, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org