HomeOur Blog
Blog Posts

The Next Step for Above: CrowdStrike’s Falcon Fund

Aviv Nahum

Aviv Nahum

Amir Boldo

Amir Boldo

Table of contents
Aviv Nahum

Aviv Nahum

Amir Boldo

Amir Boldo

We are thrilled today to announce the next step of our partnership with CrowdStrike: an investment from the Falcon Fund.

CrowdStrike has done something almost no one else in this industry has managed: They redefined a legacy. Endpoint protection was cybersecurity’s poster child for a commodity product until CrowdStrike transformed what we thought was possible. Honestly, the similarities between their early days and our mission of solving insider risk today make this partnership seem almost too on the nose. 

This investment isn’t just moving the needle in democratizing insider risk programs for the masses, it's also a neon sign pointing to where the industry is going. CrowdStrike is strategic about their investments and resources, and they’re giving us both. On top of the Falcon Fund investment, we're also entering a technology partnership with the leader in modern, AI-native security. That’s something to pay attention to.

Above and CrowdStrike: Sharper together

Insider risk was already one of the most expensive, least operationalized problems in security, then the adversary industrialized the insider vector itself. CrowdStrike's own threat hunters exposed FAMOUS CHOLLIMA, a DPRK-nexus group that plants operatives inside organizations worldwide as remote employees. Not attackers at the perimeter, employees on the payroll. CrowdStrike’s Insider Risk Services were built to help organizations confront the growing risk of negligent employees, malicious insiders, and adversaries wearing a badge.

And it's still compounding. Your people now work across hundreds of SaaS apps and identities. Worse (or more interesting, depending on the day), AI agents are becoming insiders in everything but name. These “synthetic insiders” have access, can take action, and operate at machine speed. If much of the human-created insider risk is already invisible to the security team, imagine how detrimental unchecked AI-powered risk created is? 

Behavior doesn’t sit in a policy

The security industry has spent a decade trying to engineer its way around a truth it doesn't like: The people you trust most are also your greatest source of risk. Not because they're villains — most of the time, it's a good employee having a bad month, or a rushed shortcut, or someone on their way out the door who "just wants a copy of their own work." Risk is a behavior. And behavior refuses to sit still inside a policy.

So the industry did what it always does. It wrote more rules. More DLP policies. More UEBA baselines. More thresholds, more SIEM tuning, more exceptions. All of it resting on one quietly broken assumption, that you can define insider risk in advance. You can't. You have to be continuously monitoring. 

Human behavior is dynamic, and agentic behavior is even more so. That means every static rule is out of date the moment you ship it.

Replacing rules with reason

Above’s Arbiter engine replaces static rules with a fleet of AI investigative agents that continuously observe and reason about behavior the way a human investigator would. They capture activity across identities, SaaS, endpoints, data access, and AI workflows 24x7 — but instead of firing an alert when a threshold trips, they ask the questions a three-letter agency-trained analyst would ask:

  • Who is this person?
  • What's normal for them, their role, their team?
  • What changed, and why?
  • Does this indicate risk, or is it just life?

This isn’t another piece of shelfware generating thousands of false alerts, it's a full-service insider risk investigation platform. We’re building a behavioral timeline, the context, the reasoning behind the risk call, and recommended actions based on this information. This allows us to be there for all steps of the insider risk process before an event becomes an incident. If behavior starts trending the wrong way, Above can step in before the incident, with real-time guidance to steer people toward the safer choice instead of blocking their work.

No policies to write. No baselines to tune. No exceptions to maintain. This is the future of insider risk, finally solved.

What this means

If you're a customer of Above and CrowdStrike: You'll be able to extend your existing Falcon investment into Above’s full-spectrum insider risk. This partnership brings you a single point of visibility into insider use cases: data misuse, inappropriate access, policy circumvention, overemployment, coercion, negligence, malicious insiders, you name it. All handled without writing a single policy.

Above correlates data from CrowdStrike Falcon® Next-Gen SIEM, which includes endpoint, identity, and third-party data, into investigation-ready cases and streams completed investigations back into Falcon,

If you're building an insider risk program from scratch: You no longer have to choose between an expensive, analyst-heavy insider risk program or doing nothing at all. The agents do the correlation, the case-building, the reasoning. Your team makes the decisions.

Where we go from here

We’ve believed the industry is moving from reactive rule-based monitoring to proactive continuous reasoning from day 1 of founding Above, and CrowdStrike's investment tells us we read the board right. Getting to build the next chapter alongside the company that defined AI-native security is a badge of honor we wear proudly.

To our customers, our partners, and our team: Thank you for betting on this with us. This is just the opening move.

Checkmate, insider threat.

Want to learn more about the Above and CrowdStrike integration? Request access to our Trust Center.

Share

Contact us

You've made a great move.
We'll be in touch shortly

Close
Watch Now