Above Theory

Every checkmate starts with Theory

Every checkmate starts with Theory

Above Theory is the research arm of Above Security, exploring how human behavior and autonomous AI create insider risk, and turning those insights into actionable security intelligence.
Real-time guidance

Guide the move.
The moment
it matters

Above steps in the instant a risky move takes shape — guiding your people to the company-approved way, before it happens. Not another alert after the fact.
Trusted by
Featured Research

Synthetic Insider Threat Matrix™

AI agents are insiders with access, permissions, memory, and the ability to act. Developed with Forscie, the Synthetic Insider Threat Matrix™ provides an open framework for understanding how those agents can create insider risk.
213+ knowledge objects
Open framework
 Built with Forscie
Explore the Matrix
See it in action

Operationalizing the SITM

Above turns the common SITM language into continuous behavioral investigations. Above's fleet of AI investigators connect behavior by a single person, an AI collaborator, several identities, and hundreds of automated actions to build the narrative, explain what happened, why it matters, and what to do next.
That is the difference between alerting on activity and understanding the position.
Every investigation maps to the relevant ITM and SITM categories, giving security, legal, and HR teams a consistent way to understand and act on risk.
View More
That is the difference between alerting on activity and understanding the position.
Every investigation maps to the relevant ITM and SITM categories, giving security, legal, and HR teams a consistent way to understand and act on risk.
See it in action

Guidance, the moment it matters

Scroll — watch a risky prompt meet a real Above nudge in the flow of work.

We study risk from the inside

Our research focuses on the behaviors, systems, and decisions that shape insider risk across all identities, organic and synthetic.

Insider Risk

Understanding how trusted access turns into accidental, negligent, or malicious risk.

Agentic AI Risk

Exploring what changes when autonomous agents converge with humans to become trusted users inside enterprise systems.

Behavioral Intelligence

Finding the signals and patterns that reveal intent behind activity.

Investigations

Developing better ways to reconstruct, understand, and respond to insider incidents.

The people behind the Theory

Behavioral scientists, threat researchers, security practitioners, and engineers working together to understand how risk actually behaves.
Nimer Kees
AI Research Lead
Nimer Kees is a security researcher working where offensive security meets AI, researching how systems are meant to reason and how easily they can be talked out of it. He has over a decade in the field. He started in red teaming, breaking into networks, applications, and the assumptions holding them together, before moving into security research, insider threat, and AI research. He has built research capabilities from scratch at startups and large enterprises, hiring teams, building tooling, and turning scattered findings into a research practice that ships results. Much of that work has focused on insider threat and advanced attackers, understanding how trusted access is abused and what it looks like before it happens. At Above Security, he leads AI and research, applying an attacker's instincts to insider threat detection. The goal is technology built not on how people and systems should behave, but on how they actually behave when someone tests the edges.
Yonatan Machluf
Head of Solutions
Yonatan Machluf is a security professional who came up through offensive security, learning how systems fail by making them fail, and carried that perspective into building solutions that hold up against the people he used to be. He has spent more than a decade in the field, moving between breaking things and building them. For much of that time he has led solutions and product strategy at companies ranging from early-stage startups to large enterprises, working the full span between a product and its customers: sitting with security teams to understand what actually hurts, running deployments in complex environments, and carrying those answers back to shape the roadmap. At Above Security, he leads solutions, sitting between the research, the product, and the customer's real environment. The job is making sure the technology answers the problems security teams face in practice, not the ones written in a datasheet.

Questions teams ask when comparing

Who is this research for?
Security teams building or running insider risk programs, threat researchers, and practitioners working on human and agentic risk. We also collaborate directly with researchers and security organizations on frameworks grounded in real-world threats.
What's the difference between activity and behavior?
Activity is what happened: a file downloaded, a credential used, an agent accessing sensitive data. Behavior is the context around it: the sequence, the timing, the intent it points to. The same action can be harmless or high-risk depending on that context, which is why activity alone rarely tells you whether something is a problem.
What is a synthetic insider?
A synthetic insider is an autonomous AI agent operating inside enterprise systems with access, identity, memory, and the ability to act. Those are the same properties that make a human employee a trusted user, and they create the same category of risk. As people and agents increasingly work through shared identities, systems, and data, human and synthetic insider risk converge.
What is the Synthetic Insider Threat Matrix™?
An open framework, developed with Forscie, for understanding how AI agents can create insider risk. It contains 213+ knowledge objects and gives security teams a common language for mapping, investigating, and communicating agentic insider threats — extending insider threat research from humans to autonomous systems.

Learn more Theory

New research, frameworks, and observations on human and synthetic insider risk

Thank You!

You’re successfully subscribed. We’ll keep you informed with our latest news and updates.

Contact us

You've made a great move.
We'll be in touch shortly

Close