Risk Fabric

Risk Fabric is a User and Entity Behavior Analytics (UEBA) platform developed by Bay Dynamics, now owned by Broadcom.

Reviewed by 7wData

On this page

Publisher review

Risk Fabric is a User and Entity Behavior Analytics (UEBA) platform developed by Bay Dynamics, now owned by Broadcom. The tool combines machine learning-based behavioral analysis with business-impact risk prioritization to detect insider threats, account compromises, and unusual data access patterns. Unlike purely rule-based UEBA systems, Risk Fabric calculates threat severity using a proprietary risk model that weighs likelihood against potential business impact, which means security teams see fewer false positives.

The platform integrates deeply with Data Loss Prevention (DLP) systems to provide context around file access—critical for distinguishing legitimate work from actual exfiltration attempts. Organizations using Risk Fabric typically reduce incident response noise by an order of magnitude while maintaining threat detection rates. The tool operates on-premises, in cloud, or as a virtual appliance.

Core strengths include automatic false-positive reduction (application owners can whitelist benign patterns before alerts reach analysts) and dynamic machine learning models that adapt to organizational behavior drift. The main trade-off is implementation complexity: Risk Fabric works best as an analytics layer atop mature security infrastructure, not as a standalone solution. As part of Broadcom's Symantec cybersecurity portfolio since 2019, the product receives updates and support, though market visibility remains lower than pure-play UEBA vendors like Exabeam or Securonix.

Get the AI & data signal, daily.

335k+ subscribers read this every morning. One email, both newsletters. Unsubscribe anytime.

How it works

  1. Behavioral Anomaly Detection

    Machine learning models establish user and system baselines, flagging deviations in real time across identity, endpoints, cloud platforms, and applications.

  2. Business-Impact Risk Prioritization

    Alerts are scored by calculated impact (asset value + vulnerability severity + threat likelihood), surfacing genuine risks before noise.

  3. Application Owner Feedback Loop

    Security alerts route to relevant app owners first, who can whitelist business-as-usual behavior; this prevents analyst re-work on the same benign patterns.

  4. DLP Context Enrichment

    Adds behavioral user data to DLP events, reducing false positives by distinguishing routine file access from exfiltration attempts.

  5. Multi-Source Data Correlation

    Ingests logs from authentication systems, EDR tools, cloud platforms, and network sources to establish comprehensive behavioral context.

  6. Privileged Account Monitoring

    Dedicated tracking for admin and service accounts, surfacing unusual access patterns that may indicate credential compromise or abuse.

  7. Insider Threat Classification

    Categorizes detected anomalies as malicious insiders, non-malicious negligence, repeat offenders, or compromised credentials to guide response.

Strengths and trade-offs

Strengths

  • False positive reduction unmatched in category—application owner whitelist mechanism prevents analyst burnout at scale.
  • Business-impact-first alert ranking means security teams address real threats before noise.
  • Deep DLP integration—uses behavioral context to dramatically reduce Data Loss Prevention alert storms.

Trade-offs

  • Requires mature security infrastructure (SIEM, DLP, identity logs); not a standalone solution for organizations with sparse tooling.
  • Implementation complexity—onboarding application owners for feedback loop governance is necessary but resource-intensive.
  • Lower market visibility than pure-play competitors (Exabeam, Securonix); fewer independent case studies and third-party reviews available.

Pricing context

Risk Fabric uses a per-employee-count subscription model, though exact pricing is not publicly disclosed. The platform is available through Azure Marketplace and OpenText Cybersecurity Marketplace, suggesting tiered subscription options and pay-as-you-go variants, but specific pricing tiers require direct vendor contact. Enterprise deployments typically negotiate volume discounts and include implementation and onboarding services.

User reviews

No user reviews yet. Be the first to write one.

Sources

Reporting on this tool draws on these publicly available sources.

  1. www.linkedin.com — Bay Dynamics founding (2001), headquarters (New York, NY), company size (51-200 employees), and parent company (Broadcom)
  2. marketplace.opentext.com — Risk Fabric listed on OpenText Cybersecurity Marketplace with deployment options and feature summary
  3. azure.microsoft.com — Risk Fabric available on Azure Marketplace as 'Bay Dynamics Risk Fabric' with cloud deployment support
  4. www.exabeam.com — Risk Fabric positioning in competitive UEBA market landscape alongside Exabeam, Securonix, and Varonis