Above Security and Forscie Launch the Synthetic Insider Threat Matrix
In a groundbreaking move for the security sector, Above Security, an AI-driven managed insider threat platform, has officially unveiled its new Synthetic Insider Threat Matrix (SITM) on August 27, 2026. This innovative tool is designed to extend the existing Insider Threat Matrix™ (ITM), focusing specifically on the nuanced challenges posed by AI-driven insiders, also known as synthetic insiders.
The original ITM, a freely accessible and vendor-neutral reference for understanding how insiders can inflict harm, has garnered significant respect in the industry, thanks to its stewardship by Forscie. Since early 2026, Above Security has proudly sponsored the ITM, and the launch of SITM marks a significant next step in this ongoing collaboration.
What is the Synthetic Insider Threat Matrix?
The SITM is an advanced framework developed collaboratively by Above Theory, the research division of Above Security, and Forscie. It addresses a pressing need within the security community as AI agents increasingly become embedded in company infrastructures. According to research, an estimated 28.6 million AI agents were operational within enterprises in 2025, and this number is projected to soar past 2.2 billion by 2030.
Each of these AI agents typically has direct access to sensitive information such as customer relationship management records, source code, and various financial documents. Unlike their human counterparts, these agents do not undergo formal onboarding processes, making it essential for security teams to understand the specific behaviors that could pose risks.
Key Features of the SITM
The SITM provides significant advantages for security professionals dealing with the challenge of synthetic insiders:
1.
Unified Language: The SITM offers a standardized vocabulary for describing synthetic insider behaviors, eliminating the confusion that often arises from ad hoc terminologies.
2.
Structured Framework: It allows for systematic mapping of behaviors, enabling security teams to compare and reference techniques consistently across varying organizational contexts. This structured approach mimics the MITRE ATTCK framework used for evaluating external threats.
3.
Consistent Reporting: The SITM lays down a common foundation for writing investigation reports, ensuring that all analysts can easily comprehend the terminology and findings presented.
Bridging the Knowledge Gap
Before the introduction of SITM, the fast-evolving realm of AI insider risks lacked a cohesive language or structured framework for understanding the threats posed. This new matrix coherently maps 166 knowledge objects relating to detection and prevention techniques specifically tailored to agentic incidents, encompassing unauthorized data access, autonomous data exfiltration, privilege misuse, and shadow AI activities.
“Synthetic insiders represent a crucial and growing threat,” stated Aviv Nahum, Co-Founder and CEO of Above Security. “Most organizations are still grappling with how to tackle this issue effectively. Our research team has delved into these behaviors in real-world scenarios, and producing this matrix will facilitate a level of communication that the industry sorely needs.”
James Weston, founder of Forscie, echoed these sentiments, highlighting the necessity for insider risk practitioners to adopt a shared, vendor-neutral language that encapsulates the nuances of harm caused internally within an organization. He underscored how the surge of AI introduces complexities that are not efficiently captured by traditional human-centric paradigms.
A Community Initiative
Both the SITM and its predecessor, the ITM, are open-access resources available for all members of the insider risk community. This initiative champions the cooperative ethos prevalent in today's technology landscape, shedding light on advanced security protocols and fostering an industry-wide commitment to understanding the risks posed by synthetic insiders.
As organizations increasingly adopt AI technologies, the Synthetic Insider Threat Matrix stands as a vital resource. It empowers security teams to preemptively manage insider risks, lead insightful investigations, and contribute to a safer corporate environment.
To learn more about the Synthetic Insider Threat Matrix, visit
Above Security's blog.
Conclusion
The evolution of the Synthetic Insider Threat Matrix represents an undeniable step forward in the ongoing battle against insider risks, especially as AI continues to proliferate in corporate settings. The collaborative efforts between Above Security and Forscie not only provide essential tools for current practitioners but also lay a foundation for future innovations in the field of cybersecurity. With unprecedented access and capabilities, the SITM is poised to become a cornerstone for security teams navigating the increasingly complex landscape of insider threats.