CrowdStrike’s Latest Investment Targets One of Cybersecurity’s Biggest Blind Spots

Above Security announced a strategic investment from the CrowdStrike Falcon Fund and an integration with the CrowdStrike Falcon platform, extending the companies’ existing partnership around insider risk management.

Above describes its service as an AI-native managed insider threat platform that uses continuously reasoning AI agents to analyze behavior across identities, applications, data movement and workflow context.

Insider Risk Becomes An Investigation Problem

The release frames insider risk as more than a rules-and-alerts problem. Above said its platform builds investigation narratives that include behavioral timelines, contextual analysis, reasoning behind risk classifications and recommended actions.

That matters because many insider risk programs struggle with noisy signals and incomplete context. Activity that looks suspicious in isolation may be benign, while genuinely risky behavior can be missed when identity, endpoint, SaaS and workflow data are reviewed separately.

Falcon Integration Adds Telemetry

Through the integration, CrowdStrike customers will be able to use Falcon Next-Gen SIEM telemetry to power insider risk investigations. Above said it will correlate endpoint, identity and third-party data into investigation-ready cases and stream completed investigations back into Falcon.

CrowdStrike President Michael Sentonas said the Falcon Fund invests in companies developing technologies that solve meaningful cybersecurity challenges, and described Above as taking an agentic approach to insider risk management.

A Startup Partnership Expands

Above was selected earlier this year for the CrowdStrike Cybersecurity Startup Accelerator, presented with Amazon Web Services and NVIDIA, and was named runner-up at the RSAC 2026 live finals. The Falcon Fund investment follows a recent $50 million funding round led by Ballistic Ventures, Merlin Ventures and Norwest.

The company is positioning the Falcon integration as a way to make insider risk a native outcome of the security platform organizations already use, rather than a separate manual review process.

The Bottom Line

Above Security is betting that insider risk management will move toward continuous AI-assisted investigations instead of static policy alerts. For enterprise security teams, the interesting question is whether agentic investigation can reduce noise while producing evidence that security, HR and legal teams can actually use.