HomeOur Blog
Blog Posts

The Next Security Awareness Budget Is an Insider Risk Budget

Aviv Nahum

Aviv Nahum

Table of contents
Above included in Gartner’s Secure Behavior Management research, with chess pieces and an illustrative inline coaching message.
Aviv Nahum

Aviv Nahum

Above Security is included in the representative list of secure behavior management vendors in Gartner’s September 22, 2026 research, Ditch Security Awareness and Adopt AI-Powered Secure Behavior Management, by William Candrick and Alex Michaels. We’re pleased to be included. For me, it also raises a bigger question about where this market is going.

I don’t believe the most consequential shift will be companies moving their existing awareness budget to another awareness platform with better AI features. I believe that spend will increasingly move into a broader insider risk budget, as detection, investigation, data protection, and coaching converge.

That is my view of the market, rather than a prediction attributed to Gartner. It is also why Above belongs in this conversation: we are an insider risk platform. We approach behavior change from the investigation outward.

The expensive part is understanding what happened

A useful intervention requires a surprising amount of work before anyone sends a message.

Who acted? What were they trying to accomplish? Which information was involved? Where was it going? Was this an approved business process, an unsafe shortcut, or something that warranted a deeper investigation? What would a safer way of completing the task look like?

A generic reminder can skip those questions. Relevant guidance cannot.

Consider an illustrative example: a customer success employee shares credentials in a customer record so colleagues can finish a handoff. A policy violation is visible. The business problem behind it is more interesting. The team may be working around missing access, an impractical workflow, or a process everyone assumes is acceptable.

Telling that employee to take another security course might leave the underlying problem untouched. An investigation can connect the credential sharing to the handoff, identify the affected access, and give the organization enough context to fix the workflow as well as coach the employee.

The same reasoning matters when an action initially looks suspicious but turns out to be legitimate. If the platform understands how that peer group normally works, it has a better basis for deciding whether to intervene at all. Interrupting legitimate work is a cost, too.

Once you have the investigation, coaching is a natural next step

At Above, our starting point is continuous insider risk investigation. Our AI agents connect activity across supported sources, assemble evidence, and build the business context needed to understand a sequence of events. That foundation also supports contextual employee coaching.

The work that makes an investigation useful makes an intervention useful: understanding the identity, the task, the surrounding activity, and the reason an action creates risk. The communication channels already connected to that workflow give the platform a way to act on that understanding.

That changes the economics. An organization evaluating a separate behavior platform should ask how much of its proposed value depends on rebuilding context the insider risk platform already has. The integration work, identity mapping, policy interpretation, and operational ownership all count toward the purchase.

It also changes the experience. A message grounded in an actual task can explain the issue and offer an approved route forward. It can invite clarification when the context is incomplete. Security can then distinguish an employee who needs help from a workflow that needs redesign, or a case where coaching is the wrong response.

The goal is a connected process: detect, investigate, intervene appropriately, and examine what happens next. Sending the message is only one step.

The recipient might be an employee. Or an AI agent.

This is where the category boundary becomes especially difficult to defend.

An employee can export customer records. An AI agent working on that employee’s behalf can do the same. Both can use legitimate access in a way that creates risk. The investigation needs to understand the action, the authority behind it, and its business purpose in either case.

The next recipient of a security intervention may be an AI agent.

Of course, an agent does not need a training video. The response has to fit the system: a policy decision returned through a supported control point, a request for human approval, a restriction on a tool or destination, or guidance that redirects the workflow toward an approved action. Which response is possible depends on the integration and the controls available.

Sending an agent a natural-language instruction also does not guarantee enforcement. Consequential restrictions need to hold at the runtime, tool, identity, or destination where the action can actually be constrained. The responsible human still needs visibility and accountability.

Above’s approach to agentic insider risk puts the person, delegated access, and agent activity into the same investigative picture. My broader point is that a behavior program built exclusively around educating employees is incomplete once software is also performing their work.

The operating question becomes: how do we help the actor carrying out this task behave safely, and how do we verify the result?

Awareness, DLP, and insider risk are converging around the same work

These categories have historically been purchased separately. One team runs training. Another configures data controls. Another investigates incidents. Yet they frequently need to answer questions about the same action.

Awareness and coaching help someone choose a safer action. Data loss prevention provides technical mechanisms to detect or restrict sensitive data use and movement. Insider risk investigation establishes the wider context needed to choose a proportionate response.

DLP is valuable technology. But a match against a data rule is one input into a decision. It does not, by itself, explain why the data was accessed, whether the destination makes sense for the task, or what the surrounding activity suggests.

Likewise, knowing that someone completed a course does not establish that the next customer handoff will be safe. And producing an excellent investigation without a practical route to intervention leaves another gap.

This is why we are bringing these capabilities together at Above. A shared investigative foundation can support several responses: contextual coaching, escalation, evidence preservation, or an appropriate technical control. It can also uncover a broken business process that no amount of individual training will repair.

Convergence does not require replacing every enforcement tool. A platform can use the controls an organization already owns. The value lies in connecting evidence and business context to the decision about when, where, and how to act.

Follow the outcome when you follow the budget

I expect the budget collision to happen when buyers compare the full operational cost of these separate programs.

If an insider risk platform already supplies the investigation, context, and intervention workflow, the case for paying another platform to reconstruct those foundations becomes harder to make. Awareness spend can become part of the investment in reducing insider risk across employees and agents.

This will not happen uniformly or overnight. Required training, completion records, specialist simulations, and other obligations still need an owner and appropriate capabilities. A company should establish which functions it can consolidate before retiring a contract. A strong investigation platform is not automatically a substitute for every training requirement.

But that does not mean the budget category has to remain fixed forever. At renewal, I would ask vendors to demonstrate one connected case:

  • Can you show the evidence and business context behind the intervention?
  • Can you explain why this response fits this employee or agent and this task?
  • Can you use an appropriate communication or enforcement channel without creating unnecessary disruption?
  • Can you establish whether the risky behavior recurred, the workflow improved, or the intervention was unnecessary?

Those questions move the conversation beyond how much content a platform generates or how many messages it sends. They expose whether it can support a real operating process.

The measure is what changes afterward

A completed course, a delivered nudge, and a blocked transfer each describe an activity. None alone tells the whole story of risk reduction.

I want to know whether the same unsafe practice keeps recurring, how quickly security can reach an evidence-backed decision, how often legitimate work is interrupted, and whether the recommended safe path actually works. For agents, I also want to know whether the restriction held and the downstream action matched the approved task.

That is the direction we are building toward at Above: an insider risk platform where investigations inform interventions, and the results of those interventions inform the next investigation.

Our inclusion in Gartner’s representative vendor list is welcome. The larger opportunity is to make the existing category boundaries less important to the customer. Employees and AI agents are doing the work. Security needs the context to understand it and the means to make it safer. I believe the budget will follow that capability.


Research reference: Gartner, Ditch Security Awareness and Adopt AI-Powered Secure Behavior Management, William Candrick and Alex Michaels, September 22, 2026, ID G00860839, Table 1. Above Security appears in an alphabetized representative vendor list; inclusion is not a ranking or endorsement. The budget-convergence argument in this article is Above’s perspective.

Share

Contact us

You've made a great move.
We'll be in touch shortly

Close
Watch Now