Above mentioned in Gartner's Secure Behavior Management research
Read more
%201%201.png)
Yesterday, we announced that Above has been included in as a representative vendor in Gartner’s new research on secure behavior. Aviv shared a great perspective of the research on the market and budget side, and it got me thinking about what this would mean for an engineering org.
Buried in the research are two stories every builder in this space should read twice. In one, an AI agent generating phishing simulations spoofed the payroll team and set off panic across a company. In the other, an agent configured to deliver weekly training started messaging employees daily. Neither system was malicious, but both were confidently wrong about when to act.
Security awareness has been a point of contention for years. Employees see the training as an annual nuisance, compliance sees it as a checkbox, and security sees it as yet another line item on their to-do list. It needs to be part of their workflow in order to be relevant: highly personalized interactions, in real time, showing exactly what they’ve done wrong and what impact that can have.
The current security awareness landscape does not tell you that this person, at this moment, is doing this task, much less alerting or preventing it. So when we built inline guidance into Above, we started from the failure modes.
A coaching message built on a bad signal is worse than no message at all. It teaches people that the system doesn't understand their work. This is a great way to lose trust from your organization.
This is why coaching at Above is built on investigation context. Our AI agents baseline each user personally, with their own activity and work style rather than a general, pre-defined ruleset based on Active Directory groups. Deviation does not automatically mean malice. The agents continuously reason and re-reason on what changed to determine intent, which ensures applicability and dramatically reduces false positives.
This is also where UEBA falls short. Baselining requires history, which takes time to build, and some signals don't need history to be meaningful. Sensitive data pasted into a personal AI account on day one is worth a word on day one. Other patterns, like volume or velocity that only look strange against a person's normal, take weeks of observation to mature. We treat those differently, because the confidence behind them is different.
Traditional insider risk and security awareness tools also do not provide reliable intent data. Intent must be a critical part of your insider risk program. Above’s agents approach everything from the perspective of a human investigator, including when or if we intervene in real time. If an identity is acting with benign intent, we want to jump in immediately to teach them. If they’re acting maliciously, we want to sit back and watch. This must be reevaluated constantly, because humans are dynamic. What previously seemed harmless can quickly prove not to be.
Telling someone they did something risky and asking them not to do it again a week (or even days) after the action has occurred is almost guaranteed to be futile. Workers are doing hundreds or even thousands of actions every day thanks to their own efforts and AI agents. If they remember what you’re referring to at all, it’s likely they’ll forget when the situation presents itself again.
Above coaches at the moment of the action, because that is where the work and the decision actually happen. This is how we actually teach rather than complete a compliance exercise. Equally, the employee needs to have agency for bidirectional communication, also in real time. In the event they feel the action was intercepted in error, they have a chance to justify it. Whatever answer is determined will then be applied across the organization to avoid interruption and frustration for anyone else who attempted to do the action that would have the same level of justification as the initial one. What may be acceptable for a network administrator may raise an eyebrow if a front-end developer attempted the same thing.
“Visibility” has always been a gap in several aspects of security and risk. If we can’t even get the data to know what we’re working with, we definitely cannot make it actionable. Without seeing why the system intervened, security teams cannot learn and apply those learnings with any reasonable level of confidence, much less earn trust. These interventions are intended to change future behavior, and trust is necessary for that to occur.
Every investigation in Above carries its full reasoning. Security teams can review the complete AI reasoning logs and tune thresholds to their environment. And there is a firm line we hold: no enforcement action is taken autonomously on an AI verdict. Account-level actions like disabling access happen in the customer's own identity, SOAR or ticketing systems, where their people make the call.
[For the record, our AI runs on Amazon Bedrock inside Above's own AWS environment with zero data retention, and customer data never trains the models.]
The best coaching system is mostly silent. It watches, it understands, and it speaks only when it has earned the right to. Gartner tells buyers to test vendors live rather than trust the demo. From the engineering side, I'd add one question for every vendor you evaluate: show me a case where your system decided not to coach, and tell me why.
Gartner, Ditch Security Awareness and Adopt AI-Powered Secure Behavior Management, William Candrick, Alex Michaels, 22 September 2026. GARTNER is a registered trademark and service mark of Gartner, Inc. and/or its affiliates in the U.S. and internationally and is used herein with permission. All rights reserved. Gartner does not endorse any vendor, product or service depicted in its research publications, and does not advise technology users to select only those vendors with the highest ratings or other designation. Gartner research publications consist of the opinions of Gartner's research organization and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this research, including any warranties of merchantability or fitness for a particular purpose.
%201%201.png)

May we use analytics cookies to understand visits, clicks and demo requests? Your choice won’t affect the site. No session recordings. Privacy policy