TL;DR: Insider risk is still being managed as a stream of alerts rather than as behavioural context, according to Above, and says its Synthetic Insider Threat Matrix is meant to help security teams reconstruct intent across human activity and AI counterparts. The core issue is that identity and activity trails now span human, NHI, and AI-driven behaviour, so alert-only programmes miss the story that matters.
NHIMG editorial — based on content published by Above: Above Theory and Forscie unveil the Synthetic Insider Threat Matrix™
By the numbers:
- 80% of attack models could be categorized as insider threats.
- 72% of organisations have experienced or suspect they have experienced a breach of non-human identities.
- When AWS credentials are exposed publicly, attackers attempt access within an average of 17 minutes.
Questions worth separating out
Q: How should security teams investigate insider risk when alerts look harmless on their own?
A: They should correlate identity, HR, endpoint, and authentication events into one timeline before deciding whether the activity is normal.
Q: Why does AI-assisted work create new insider risk for IAM teams?
A: Because the same user session can now include human decisions and machine-mediated actions that are difficult to separate with standard identity controls.
Q: What are the signs that an insider-risk programme is too alert-driven?
A: Common signs include many isolated detections, long investigation times, repeated escalation of low-context cases, and weak handoff to legal or HR.
Practitioner guidance
- Correlate identity and data signals into a single case view Link authentication, file activity, collaboration tools, and data movement so investigators can see whether events form a pattern rather than a one-off alert.
- Separate human intent from AI-mediated execution Tag workflows that involve AI assistance, delegated drafting, or automated follow-on actions so reviewers can distinguish user decisions from machine amplification.
- Build evidentiary timelines for high-risk insider cases Capture the sequence of access, communications, content creation, and exfiltration indicators in one chronology that legal, HR, and security can all use.
What's in the full article
Above's full blog post covers the operational detail this post intentionally leaves for the source:
- The vendor's full behavioral narrative examples show how cases are assembled from identity, content, and activity signals.
- It also outlines how its AI investigators support in-the-moment coaching and evidentiary timelines for response teams.
- The post gives more context on the Synthetic Insider Threat Matrix and how Above is positioning the framework for practitioner use.
👉 Read Above's analysis of the Synthetic Insider Threat Matrix and insider risk →
Synthetic insider threat matrix: what does it change for teams?
Explore further
Alerting is not the same as understanding insider risk. Traditional monitoring tells teams that something happened, but insider governance needs to explain whether that behaviour forms a meaningful sequence. When organisations treat detection as the finish line, they end up with more triage and less confidence. The practitioner conclusion is that insider risk must be governed as a context problem, not a volume problem.
A few things that frame the scale:
- The average organisation believes more than 1 in 5 of their non-human identities are insufficiently secured, according to The 2024 ESG Report: Managing Non-Human Identities.
- Enterprises that have experienced a compromised NHI averaged 2.7 separate incidents in the past 12 months, according to the same report.
A question worth separating out:
Q: What should organisations do when insider cases involve both humans and AI counterparts?
A: They should investigate the full workflow, not just the user login, and assign ownership across security, identity, legal, and HR. The key decision is whether the organisation can explain how access, prompts, and downstream actions interacted. That is what determines accountability and response quality.
👉 Read our full editorial: Synthetic insider risk exposes the limits of alert-first security