TL;DR: Traditional UEBA, SIEM, and DLP programmes still leave insider risk buried in false positives and workflow noise, even after years of implementation, because they model behaviour poorly rather than operationalising it, according to Above. The core implication is that insider threat now spans both humans and AI counterparts, so governance has to move from static detection to identity-aware investigation and response.
NHIMG editorial — based on content published by Above: Above Security: What I wanted UEBA to Be Years Ago
By the numbers:
- Lack of credential rotation is cited as the top cause of NHI-related attacks by 45% of organisations, followed by inadequate monitoring and logging at 37% and over-privileged accounts at 37%.
Questions worth separating out
Q: How should teams manage insider risk when AI agents have legitimate access to sensitive data?
A: Treat AI agents as governed non-human identities, not as ordinary tools.
Q: Why do UEBA and SIEM often fail to reduce insider risk?
A: They often fail because they produce signal without enough context to explain intent, delegation, or business justification.
Q: What is the difference between behavioural detection and evidentiary investigation?
A: Behavioural detection identifies patterns that may be unusual, while evidentiary investigation assembles the sequence, context, and ownership needed to decide what happened.
Practitioner guidance
- Define insider scope across human and AI counterparts Document which identities are in scope for insider risk review, including humans, service accounts, and AI-driven systems that can influence access or activity.
- Replace alert volume with case-quality metrics Track whether your programme can produce a complete evidentiary timeline, clear ownership, and a defensible disposition.
- Test behavioural rules against delegated access Run scenarios where activity is legitimate but unusual, such as delegated machine action, shared credentials, or cross-system workflows.
What's in the full article
Above's full blog post covers the personal origin story and product framing this post intentionally leaves for the source:
- The narrative behind the insider risk problem the vendor is trying to solve, including the marketing and market-positioning context.
- The launch framing around the Synthetic Insider Threat Matrix and how the vendor wants practitioners to interpret it.
- The company story, founder background, and brand-building details that are not part of the analytical summary here.
- The product walkthrough cues and demo-oriented context that sit outside this editorial analysis.
👉 Read Above's analysis of why UEBA fell short for insider risk →
Synthetic insider threat matrix: what changes for insider risk teams?
Explore further
Insider risk has outgrown a human-only operating model: Behavioural security programmes were built for employees, contractors, and other human actors. That assumption fails when AI counterparts can participate in the same access paths and decision loops. The implication is not simply broader monitoring. It is that the identity model itself now needs to distinguish human intent, delegated machine action, and mixed investigative context.
A few things that frame the scale:
- 85% of organisations lack full visibility into third-party vendors connected via OAuth apps, according to The State of Non-Human Identity Security.
- Only 1.5 out of 10 organisations are highly confident in their ability to secure NHIs, which underlines how immature identity governance still is across machine access estates.
A question worth separating out:
Q: What should security teams do first when insider signals are overwhelming?
A: Start by defining the minimum evidence needed for a case to be actionable. Then map which workflows create that evidence today and which ones only generate alerts. If the team cannot reconstruct incidents, more detection will not fix the programme.
👉 Read our full editorial: Above’s synthetic insider threat matrix reframes UEBA limits