
Above Security (Above), the AI-native managed insider threat platform, has launched the Synthetic Insider Threat Matrix (SITM), an extension of the Insider Threat Matrix™ (ITM) designed specifically to address risks associated with the agentic workforce.
The ITM is a free, vendor-neutral taxonomy developed and maintained by Forscie that has established itself as a reference framework for understanding how insiders can cause harm within organizations. Above has been the ITM’s inaugural sponsor since early 2026, and the SITM represents the latest development in that collaboration. Researchers at Above Theory worked with the Forscie team to develop the SITM, extending the existing model to address a new category of insider: synthetic insiders.
Above Theory developed the categories that form the Synthetic Insider Threat Matrix and provided research based on observed agent behavior. In collaboration with Forscie, the team mapped each synthetic-insider tactic to corresponding techniques within the original human-focused ITM. Research conducted by Above Theory, based on activity observed by Above’s investigative agents across live customer environments, indicates that synthetic insiders are already exhibiting behaviors similar to those that security, legal, and HR teams have historically investigated in human insiders. Until now, the industry has lacked a common framework and terminology for addressing these behaviors.
The SITM currently maps 166 knowledge objects focused on detection and prevention techniques for agentic incidents. These include unauthorized data access, autonomous exfiltration, privilege misuse, and shadow AI activity.
For security teams and the broader insider risk community, the SITM offers three primary tactical benefits:
- A common terminology for describing synthetic-insider behavior, replacing inconsistent or ad hoc language.
- A structured framework for mapping and comparing synthetic-insider techniques consistently across organizations, serving a similar purpose to MITRE ATT&CK for external threat actors.
- A common foundation for developing investigation reports using terminology that security analysts can readily understand and apply.
An estimated 28.6 million AI agents were active inside enterprises in 2025, with that figure projected to exceed 2.2 billion by 2030. Many of these agents maintain persistent access to sensitive enterprise resources, including CRM records, source code, and financial systems. Unlike human employees, AI agents can perform actions continuously and at a scale of thousands of operations per day, without traditional work schedules or shift changes. At the same time, they are not subject to conventional employee processes such as interviews, onboarding, or managerial oversight.
“Synthetic insiders are a real and growing problem, and most of the industry doesn’t yet know what to do about it,” said Aviv Nahum, Co-Founder and CEO of Above Security. “We do, because our research team has been studying this behavior in live environments for months. Extending the Matrix, so the whole community has language for it, is exactly what security teams and the industry as a whole need right now.”
“Insider risk practitioners have always needed a shared, vendor-neutral language to describe how harm actually occurs inside an organization,” said James Weston, founder of Forscie and co-creator of the Insider Threat Matrix. “Advances in AI present a unique challenge to insider risk programs that does not neatly fit into the existing human-centred paradigm. To address this, we worked with Above Theory to create the Synthetic Insider Threat Matrix, like the MITRE Corporation did with the MITRE ATT&CK framework over a decade ago.”
The Insider Threat Matrix, encompassing both Human and Synthetic categories, is designed as an open, vendor-neutral resource that is freely accessible to and supported by the broader insider risk community.
For more information on the Synthetic Insider Threat Matrix, visit: www.above.security/blog-posts/synthetic-insider-threat-matrix.
Join our LinkedIn group Information Security Community!











