Proactive insider risk instead of reactive reconstruction
Insider risk usually lands on Security after the incident has already occurred. Something happens, HR or Legal raises a concern, and your analysts are asked to reconstruct three months of activity across half a dozen systems to work out what a person was actually doing. You end up running digital forensics after the fact instead of managing risk before it. Above changes the order of operations.
Phil Venables, former CISO of Goldman Sachs and Google Cloud, created a practical blueprint for what to stand up first, how to maintain employee trust, and KPIs to measure to prove program success.
Scroll — watch a risky prompt meet a real Above nudge in the flow of work.
Security’s key insider risk challenges
You’re not staffed properly
Insider risk programs have historically belonged to banks, intelligence agencies, and heavily regulated enterprises because they could fund dedicated investigative teams. Everyone else runs insider risk out of the SOC, on top of everything else. Gartner puts the increase in insider attacks at 48%, against headcount that hasn't moved.
Your tools can’t tell the difference between deviation and real risk
UEBA baselines flag the promotion, the new project, the deadline sprint, and the person quietly staging a repo all the same way. Every one of them lands on an analyst who has to work out what is normal deviation from the norm and what is truly risky. The tuning never converges, because the thing you're tuning against is human behaviour, and that keeps changing.
Insider risk
The evidence you need lives in twelve places
Identity, endpoint, SaaS, email, code repos, collaboration tools, HR systems. Building one defensible timeline means pulling from all of them by hand, in the right order, with the right context, over and over again. The average containment time is 81 days. Most of that is correlation work.
Your coverage scope now also includes AI agents
Shadow AI, personal GPTs, OAuth-scoped agents acting on company data. Your insider population now includes non-human identities that never signed a policy and never sat through training. Verizon's DBIR still puts the human element in 62% of breaches; the difference is that "human" now includes the agents humans point at your data.
The cost of inefficient or no action
Security becomes a service desk for other teams
When insider risk is reactive, your analysts aren't managing risk. They're producing evidence on request for HR and Legal. It's unplanned, unbudgeted, and it comes out of detection engineering time.
The bill continues to climb
Ponemon puts the average annual cost of insider risk at $19.5M per organisation and $676,517 per incident, across roughly 13.5 incidents a year. Reactive programs pay all of it, because nothing was intercepted early enough to mitigate.
It’s too late to prevent, so you’re forced to react
Pre-departure staging is the most common critical insider pattern, and leavers are around 69% more likely to take data with them. Discovering it during offboarding means the data is already gone and your options are legal and reactive.
Weak evidence limits your options
A log export isn't a case. When the record can't show sequence, context, and intent, Legal can't act on it confidently, HR can't hold a fair conversation, and the response gets calibrated to what you can prove rather than what happened.
What’s my organization’s level of insider risk?
Determine your level of risk across 5 critical security pillars in 10 minutes or less. You get your score, plus optimization recommendations.
Arbiter Engine is the AI-native workflow layer underneath detection, investigation, and prevention.
With Above, insider risk is a standing capability with no rule library to write, tune, or maintain as the environment changes. It’s insider risk, finally operationalized.
A fleet of specialised AI agents- Shadow AI & IT, Data Exfiltration, Flight Risk, Inappropriate Use, Communications- reasoning continuously across identity, SaaS, endpoint, and data access.
An alert is a start, not a story. With Above, every signal arrives as a finished case. Behavioral timeline, context, the reasoning behind the classification, and a recommended action before you open it.
Company-approved guidance surfaced inside email, SaaS, and AI tools at the moment a risky move takes shape.
The incident you never have to investigate. Most insider risk is a well-meaning shortcut; Above steps in to correct it in the flow of work. Costs a second, not a case file.
Find finished cases, evidence, collaboration, and handoff in one place, The Investigation Workspace.
One workspace and narrative for Security, Legal, and HR instead of three partial ones. Above creates a seamless handoff while maintaining role-based access and evidence level.
Continuous investigations that update with new evidence
Evidence Graph follows the evidence, not the other way around. Activity is mapped across people, AI agents, applications, and data when it becomes relevant, and connects them as evidence arrives.
Above gives live models of the people, AI agents, applications, data, companies, and other objects involved in an investigation. Above understands that new evidence can change both the investigation and the risk.
Connections across cloud, identity, endpoint, SaaS, HR, AI, workplace tools, and more.
Above runs on the telemetry you already generate, querying your sources rather than duplicating them. No ripping and replacing, just investigations with full context.
The shift is the point. Rules become continuous investigation. Alerts become investigations. Security stops being the forensics service and starts being the function that saw it forming.
Turn insider risk into a security advantage
See how Above helps security teams detect, investigate and prevent insider threats -- without the manual work.
How is this different from the DLP and UEBA we already run?
DLP enforces policy on data movement; UEBA flags deviation from a statistical baseline. Both assume insider risk can be defined in advance, as a rule or as an anomaly. Above starts from a different premise: insider risk is an investigation problem, not a policy problem. Instead of asking whether an action broke a rule or looked unusual, Above's agents investigate what a person was doing across systems and over time, and reason about whether it indicates risk. You keep DLP for the compliance job it does well. Above answers the question it was never built for. Learn more about DLP and UEBA’s blind spots
Does this mean monitoring every employee?
Above investigates behaviour, not people, and it's built to be privacy-aware- no keystroke logging, no screen recording. The platform builds an understanding of role context, team patterns, and activity sequences precisely so it can tell benign change apart from negligence, circumvention, and genuine risk. That's what stops a case being opened on someone who simply changed projects. Most of what surfaces is coachable, and a good share of it gets corrected in the moment without becoming a case at all.
How does Above work with my existing security stack?
Above queries your existing sources at runtime rather than pre-ingesting everything, so it doesn't duplicate your data lake or compete with your SIEM. It integrates across cloud, identity, endpoint, SaaS, HR, AI, workplace tools, and more. Where a browser sensor is deployed it adds visibility into in-browser activity, but it's one telemetry source among several rather than a dependency.
How does Above change the security team’s day-to-day?
Less manual correlation. Fewer signals that need a human to interpret them. Faster resolution, because the timeline and context are assembled before the case opens. And a shared record when Legal and HR get involved, so the handoff is a decision rather than a second investigation. Strategically it moves security out of reactive forensics and into proactive risk management.
Every endgame starts with the right opening.
Most insider threats are preventable. The difference is how you develop your material.