Insider risk teams spent a decade learning to watch people. Now the fastest-moving insider in your environment isn't one. AI agents hold legitimate credentials, touch sensitive systems, act at machine speed, and change their behavior completely from a single prompt (aka no code push, no access request, no ticket). Above co-founder and CPTO Amir Boldo sat down with Information Security Media Group (ISMG) at Black Hat to make the case that: 🤖 Agentic AI isn't a new category of threat, it's a new category of insider 🙈 Most programs can't see it because they were designed to watch human employees 🔍 Insider risk was never really an identity problem, it's an investigation problem Watch the full conversation ⬇️ https://lnkd.in/eeZviBY6
About us
Above Security is building the insider risk platform for a world where both humans and AI agents have access to your most sensitive systems and data. Above continuously investigates the behavior of people and agents across identities, applications, endpoints, and data environments to understand what they are doing, why it matters, and when behavior becomes risk. Instead of relying on static rules or flooding security teams with alerts, Above turns behavioral signals into complete investigations with context, timelines, reasoning, and recommended actions. When risk can be prevented, Above acts in real time through precise controls and contextual coaching, helping people work safely without getting in their way. From negligent behavior and compromised identities to malicious insiders and autonomous agents behaving in unexpected ways, Above gives organizations one continuous system to investigate, prevent, and respond to insider risk. From alerts to investigations. From monitoring to prevention. From protecting against risky users to protecting against risky behavior, human or machine. Insider Risk. Finally Operationalized.
- Website
-
https://above.security/
External link for Above Security
- Industry
- Computer and Network Security
- Company size
- 11-50 employees
- Type
- Privately Held
- Founded
- 2025
- Specialties
- Insider Threat, Risk, and Cybersecurity
Employees at Above Security
Updates
-
Today, we’re releasing Evidence Graph for Above Investigations and Risk Score. Most security products evaluate risk as a collection of events. Above looks at the relationships between them. Evidence Graph gives our investigative agents a live model of the people, AI agents, applications, data, companies, and other objects involved in an investigation. The graph is built dynamically as new evidence appears, rather than from a schema or set of relationships defined in advance. That means a risk score is no longer based only on isolated signals like “large CRM read” or “external share.” Above can understand that an AI agent acting for an employee accessed a specific Salesforce object, pulled information from a customer conversation, created a new artifact, and moved it to an external destination, while that same employee was interacting with a competitor. Those relationships change both the investigation and the risk. Evidence Graph makes that context native to Above, from how we investigate activity to how we determine risk. Available today.
-
-
"Our biggest challenge was piecing together user activity across scattered systems." —Matt Wilmot, CISO at Merlin Entertainments 🎢 🎡 🎠 Merlin operates LEGOLAND, Madame Tussauds, the London Eye, and 140+ other attractions worldwide. That means tons of intellectual property, millions of guests, thousands of staff, a seasonally-changing workforce, and user activity scattered across numerous systems. The makings of a potential #insiderrisk nightmare. But not with Above, because Above connects those disparate systems, provides investigations with full timelines, and has transformed Merlin's insider risk program from reactive to proactive. Hear more in Matt's own words ⬇️
-
Every #BlackHat has a soundtrack; some years it's ransomware, some years it's zero trust, etc. This year you couldn't walk the Business Hall without hearing someone talk about #insiderrisk. The new edition of our weekly newsletter, A Move Ahead, covers what actually came out of Vegas last week: 🤝 Our strategic investment from the CrowdStrike Falcon Fund, and what the Falcon integration actually does 🔍 The best insider risk research of the week, which wasn't even filed under insider risk 5️⃣ Phil Venables's five-stage insider risk maturity model, and why most programs stall at stage three 📦 Why every major vendor shipped an agent governance product this year Read our Black Hat recap here 👇
-
Above Security reposted this
Amir Boldo, CPTO & Co-Founder, Above Security joins Michael Novinson at the #ISMGStudio at #BHUSA2026. They are discussing insider risk and why the same behavioral lens has to cover humans and AI agents alike. They deep dive into 'The Synthetic Insider' and why #AI agents need Identity, Governance, and Investigation. AI agents have credentials, read email, touch source code, and act inside business systems - and the insider risk program can't see any of it. Full interview going live soon on the #ISMGMediaNetwork #ISMGStudio #Cybersecurity #ISMGatBHUSA #InsiderThreat
-
-
Above Security reposted this
Had a great time joining Security LIVE! at Amazon Web Services (AWS) x Above Security. We discussed how insider risk is evolving in the age of AI, why behavioral investigations matter more than alerts, and why we’re partnering with CrowdStrike to bring AI-powered insider risk investigations into Falcon Next-Gen SIEM. Thanks for having me! Looking forward to sharing the full conversation soon.
-
-
Our CEO and Co-Founder, Aviv Nahum, is in SC Media today on what #BlackHat USA 2026 made obvious: insider risk needs a different approach now that AI is everywhere in the enterprise. The piece covers Phil Venables's 5-stage insider risk maturity model. As the former CISO of Goldman Sachs and Google Cloud, Phil understands firsthand why AI agents don't need a second, dedicated program, because whether the identity belongs to a person or an agent, the question is the same: what does it do, and should anyone care? ➡️ Learn more about Phil's insider risk maturity model: https://lnkd.in/e3Y5NSFm Read the full article: https://lnkd.in/eHyHPz7J
-
Day 3. Last moves. It's the last day at #BlackHat 2026! Come find us at Booth 5332 to: ♟️ Play a round of chess with the team 🎁 Grab the last of the swag 🔍 See a real Above investigation report: the actual output our AI investigative agents produce Insider risk isn't a policy problem. It's an investigation problem. Come see the difference in 5 minutes. Checkmate, insider threat. ♟️ https://lnkd.in/edHPwb_t #BHUSA #BHUSA2026 #insiderrisk #insiderthreat
-
-
The booth is up, the doors are open, and we're ready for #BlackHat USA 2026. Come say hi! Here's what we've got on the docket today, all at 📍 Booth 5332: 1️⃣ 11:30 AM | Aviv Nahum | Rethinking Insider Risk for the Agentic Era The framing argument the rest of the day builds on. 2️⃣ 12:30 PM | tricia howard | The State of Insider Risk in 2026 What actually changed this year, and which assumptions security teams are still carrying that no longer hold. 3️⃣ 1:30 PM | Phil Venables, ex-CISO, Goldman Sachs and Google Cloud | The AI Trust Gap: Governing Humans and AI Agents He walks the insider risk maturity curve from rule-based DLP up to governing agentic workflows, and lands on the question that repeats at every level: not what left, but why. If you attend one thing today, this is it. 4️⃣ 2:30 PM | Amir Boldo | The Synthetic Insider: Why AI Agents Need Identity Your agents have credentials and no accountability. That's a problem nobody's org chart accounts for. 5️⃣ 3:30 PM | Aviv Nahum and Amir Boldo | Fireside Chat on building security for the agentic era. 6️⃣ 4:30 PM | Kevin Alparone | Live Investigation: First Signal to Full Timeline in 5 Minutes Real incident, real timeline, no slides. 📣 Plus: An agentic insider risk investigation by Aviv Nahum on the Amazon Web Services (AWS) Security Live! stage at 4 PM PT. Aviv will make the case that insider risk is an investigation problem, not a policy problem. Can't be there in person? Stream it live: https://lnkd.in/eFyX7A-H Between sessions: ♟️ chess board's out, and the 🖥️ portable monitor giveaway is open. Check out our full lineup of speaking sessions today and tomorrow here: https://lnkd.in/edHPwb_t #BHUSA #BHUSA2026 #insiderrisk #insiderthreat
-
-
Come play chess with us at booth 5332 ♟️ #BlackHat2026