Above Security (Above) launched the Synthetic Insider Threat Matrix (SITM), an extension of the Insider Threat Matrix (ITM) designed specifically to address risks associated with the agentic workforce. The ITM is a free, vendor-neutral taxonomy developed and maintained by Forscie that serves as an industry reference for understanding how insider threats can cause harm. Above has been the ITM’s inaugural sponsor since early 2026, and the SITM represents the next phase of that collaboration. Developed by researchers at Above Theory in partnership with Forscie, the SITM expands the ITM framework to address a new category of insider threats involving synthetic actors.
Above Theory built the categories in the Synthetic Insider Threat Matrix and contributed deep insights grounded in real-world agent behavior, working in conjunction with Forscie to map every synthetic-insider tactic cleanly onto corresponding techniques in the original, human-centric ITM. Above Theory’s research, drawn from what Above’s investigative agents see across live customer environments, confirms what the data suggests: synthetic insiders are already producing the kind of behavior security, legal, and HR teams have spent decades learning to investigate in people — and almost nobody had a shared language to address it before today. The SITM maps 166 knowledge objects covering detection and prevention techniques specific to agentic incidents, including unauthorized data access, autonomous exfiltration, privilege misuse, and shadow AI activity.
For the security community, the SITM provides three concrete tactical benefits:
- A common language for describing synthetic-insider behavior instead of ad hoc terminology.
- A structured framework to map that behavior against, so techniques can be compared and referenced consistently across organizations — the same role MITRE ATT&CK plays for external attackers.
- A shared basis for writing investigation reports that use terms any analyst would recognize immediately.
An estimated 28.6 million AI agents were active inside enterprises in 2025 — a number projected to surpass 2.2 billion by 2030. Many AI agents hold standing access to sensitive information found in various sources, including CRM records, source code, and finance systems. Each has the capacity to act thousands of times a day without a shift change. Yet, unlike human insiders, none of them were interviewed, onboarded, or assigned a manager.
“Synthetic insiders are a real and growing problem, and most of the industry doesn’t yet know what to do about it,” said Aviv Nahum, Co-Founder and CEO of Above Security. “We do, because our research team has been studying this behavior in live environments for months. Extending the Matrix, so the whole community has language for it, is exactly what security teams and the industry as a whole need right now.”
“Insider risk practitioners have always needed a shared, vendor-neutral language to describe how harm actually occurs inside an organization,” said James Weston, founder of Forscie and co-creator of the Insider Threat Matrix. “Advances in AI present a unique challenge to insider risk programs that does not neatly fit into the existing human-centred paradigm. To address this, we worked with Above Theory to create the Synthetic Insider Threat Matrix, like the MITRE Corporation did with the MITRE ATT&CK framework over a decade ago.”
The Insider Threat Matrix — both Human and Synthetic — is open, vendor-neutral, and freely available to, and powered by, the whole insider risk community. For more information on the Synthetic Insider Threat Matrix, read the blog here.
Related News: