Skip to main content

Aug 7, 2026

The Behavioral Answer

Piotr Wojtyla

The answer to both impersonation and insider risk is the same: knowing what normal looks like well enough to recognize when it isn't. But that definition of normal has to be built at the identity level, not the population level. An average doesn't tell you that this specific account is doing something it's never done — only a per-identity behavioral baseline can catch that.

Houston Hopkins, Abnormal AI's CISO, describes the attacker's advantage in supply chain lateral movement that comes from operating inside a trusted identity: "The aim of getting into Company A is not always just for Company A — the attacker wants to fan out to every one of Company A's customers." Once inside as a trusted identity, the interconnected SaaS fabric of a modern enterprise becomes a pivot path. Behavioral signals — new access patterns, new application interactions, anomalous timing or volume—are the only signals that cross all of these scenarios.


320+ companies were hit by North Korean IT workers in a single year — a 220% year-over-year increase. (CrowdStrike 2025 Threat Hunting Report)


Titus lands the governance call-to-action: "Immediately stop thinking of it as an IT provisioning problem. It's a behavioral problem. The access you granted six months ago is probably wrong today. If you're not continuously validating it, you're not managing the identity—you're just hoping. Hope is not a plan."


Protect Against Evolving Email Threats

See how behavioral AI detects attacks that legacy defenses miss.