
Human Risk Management That Actually Changes Behavior
COMPANY OVERVIEW
Fable Security was founded by Nicole Jiang-Gibson, Co-Founder and CEO, and Sanny Liao, Co-Founder and CPO, who previously led product and data science at Abnormal AI. Working on email security, they watched sophisticated detection technology stop the attack and still lose to the person who clicked — and concluded that security awareness training had become a checkbox: ineffective, outdated, and blind to how people actually behave.
The company has raised $31 million from Greylock Partners and Redpoint Ventures, and works with security teams at organizations including Genesys, Red Hat, SanDisk, Bill.com, Pennymac, Sisense, Amwins, and Dayton Children's Hospital. Its stated goal is to eliminate the human attack surface by rebuilding human risk management around engineering, behavioral science, and AI.
CORE FOCUS
Fable secures the human layer at the moment of risk rather than on an annual training calendar. The platform synthesizes third-party security telemetry with its own engagement data, layering in each employee's role, access, behavior, environment, and exposure to identify who is actually driving risk across the workforce — instead of treating every user as an identical training target.
When risky behavior or a live threat is detected, Fable intervenes in the flow of work with AI-generated video, chat, and email nudges tailored to the cohort that needs them. The differentiator is borrowed from adtech and consumer technology: mass-customized, repeated, just-in-time interventions that run until new behaviors become habits, with reporting that ties each campaign back to measurable risk reduction.
PRODUCTS & TOOLS
Behavior Shaping – Deploys hyper-targeted, in-the-moment interventions via video, chat, and email to transform risky employee habits into durable secure behavior.
Human Risk Reporting – Unifies identity, email, device, and behavior signals into workforce-wide visibility over who carries real risk, and shows the pathways that reduce it.
Phishing Resilience – Runs phishing simulations against the threats employees actually face, with campaign metrics, bot detection, and automatic follow-up training.
Security-Aware Teams – Replaces generic annual training with targeted, bite-sized briefings delivered to the cohorts that need each topic.
Threat Response – Turns an emerging threat into a same-day briefing, generating and delivering content to at-risk teams while the campaign is still active.
Secure AI Enablement – Surfaces sanctioned versus shadow AI use and coaches employees toward safe AI adoption without blocking productivity.
Human Behavior Data Lakehouse – The underlying data architecture and agentic workflow engine that powers cohort segmentation, content generation, and delivery orchestration at enterprise scale.














