TL;DR: Insider-risk signals are being correlated with cloud runtime context so teams can connect identity behaviour to workload, API, and AI-service activity in one investigation, according to Above. The governance shift is that intent and impact now have to be evaluated together, because neither human identity controls nor cloud telemetry alone gives a complete security decision.
NHIMG editorial — based on content published by Above: Above + Upwind: Connecting Insider Risk to Cloud Runtime Security
By the numbers:
- When AWS credentials are exposed publicly, attackers attempt access within an average of 17 minutes.
Questions worth separating out
Q: How should teams investigate insider-risk alerts across identity and cloud telemetry?
A: Start by correlating the identity signal to the workload or data event that it touched.
Q: Why do cloud runtime tools miss part of the insider-risk picture?
A: Because cloud tools can show what happened in production but not why the identity did it.
A: They should look for clearer reasoning in alerts, fewer ambiguous findings, and faster triage cycles for analysts.
Practitioner guidance
- Correlate identity and runtime timelines Build investigations so browser, SaaS, workload, API, and AI-service events can be reviewed on one case timeline.
- Separate benign anomaly from hostile intent Create triage rules that require an identity explanation before a cloud finding is treated as malicious.
- Include AI-service activity in case design Treat AI-service calls as part of the same evidence chain as database access and object-store movement.
What's in the full article
Above's full blog post covers the operational detail this post intentionally leaves for the source:
- The specific integration workflow for pairing Above identity signals with Upwind runtime findings.
- The investigation examples that show how analysts move from suspicion to runtime confirmation.
- The customer-facing use cases for cloud-heavy organisations that need identity plus runtime evidence.
- The referenced Above integrations and related agentic AI risk material.
👉 Read Above's blog post on insider risk and cloud runtime correlation →
Insider risk and cloud runtime correlation: what teams gain?
Explore further
Identity investigations are now a correlation problem, not a single-tool problem. Above and Upwind are addressing a common failure in security operations: teams either see the person or see the workload, but not both in a decisionable timeline. That matters because insider risk is judged by intent while cloud runtime is judged by impact. Practitioners should treat this as a governance design issue, not just a telemetry integration.
A few things that frame the scale:
- Two-thirds of enterprises have endured a successful cyberattack resulting from compromised non-human identities, with a quarter encountering multiple attacks, according to The 2024 ESG Report: Managing Non-Human Identities.
- 72% of organisations have experienced or suspect they have experienced a breach of non-human identities, including 46% confirmed and 26% suspected.
A question worth separating out:
Q: Should AI-service activity be part of insider-risk investigations?
A: Yes. AI-service calls can create the same security consequences as access to databases or object stores, so they belong in the investigation chain. If an identity prompted a model, retrieved data, or triggered a downstream workflow, the runtime impact should be reviewed alongside the identity behaviour.
👉 Read our full editorial: Insider risk and cloud runtime correlation for identity investigations