Network Security Engineer at a tech services company with 1,001-5,000 employees
Real User
Top 10
Jun 24, 2026
I manage an organization with more than five thousand employees who are all in either on-site or hybrid environments and receive multiple emails every day. The email flow on a daily basis is too much to handle manually. Emails can be sent from approved domains, or they can be spam or other unwanted messages. I cannot reveal my customer's name, but I can say that they are in the shopping business. Since they are in the shopping business, they receive multiple mail flows from the sales team and regular communications, and it becomes very crucial to differentiate which emails are useful and which are not. On a daily basis, I check whether the mail flow is within the established threshold. Unless there are end-of-season sales occurring, I do not see a high mail flow that exceeds the threshold we observe. I evaluate the detections I am seeing, and in Mimecast Insider Risk Management and Data Protection, I can see detections based on various time frames, such as twenty-four hours, forty-eight hours, or whatever custom time frame I choose. The maximum limit according to our enterprise is thirty days. Since I need to see activity in real time, I analyze whether all the respective mail flows are coming in and what category they fall under. The categories can include malware, spam, extortion campaigns, or multiple others. I analyze that data by fetching the raw logs for my customer, checking the spam scores for their emails, and reviewing statuses such as accepted, rejected, held, deferred, and more. I analyze whether Mimecast Insider Risk Management and Data Protection's policies work properly. I cannot just rely on it being a SaaS-based product with enabled policies working correctly. There are many use cases where I have seen emails being delivered that should not have been delivered. That does not make Mimecast Insider Risk Management and Data Protection a bad product; it means that I have not fine-tuned the policy to my organization's expectations. Once I work on the tool daily, I understand the mail flow, recognize which emails fall into the spam category, and compare them not only on the Mimecast Insider Risk Management and Data Protection database but also with external comparison tools like MX Toolbox or VirusTotal to analyze things. This gives an overview of what my general scenario looks.
Mimecast Insider Risk Management and Data Protection is relied upon primarily for email security, functioning as an email gateway within the company so that every email is processed through Mimecast, filtered, and then delivered to user mailboxes after security checks are completed. Day-to-day operations involve handling tickets from users stating that their email has been held and they request release. We cross-check whether SPF is matching, if SPF has passed, and if DKIM has passed. Once everything is verified and we determine the sender is trusted, we release the email. We have different types of security gateways, including impersonation protection, which is created by establishing a profile group so that if it matches any keywords, it might flag potential impersonation. We have many policy options within the system. Based on our requirements, we can set up policies, and Mimecast helps us filter emails very effectively. We can clearly check whether emails are being delivered or not. If they are undelivered, we can check the reason for non-delivery. URLs are decoded through Mimecast, allowing us to scan links and determine whether they are safe or not. Many options exist within Mimecast for these purposes.
I have used Mimecast Insider Risk Management and Data Protection for almost four and a half years for one of my clients. I use Mimecast Insider Risk Management and Data Protection for detecting and maintaining email security for my client. Mimecast gives us unmatched visibility and focuses on behavior analysis with file vector users, real-time nudges, and top-tier support. Mimecast Insider Risk Management and Data Protection uses a file-vector-user framework. Instead of just blocking everything blindly, it examines the file value, how it is moving, and which users are moving it. I can provide a real-world example of how a company uses this product to stop insider threats. My example involves departing employees and data theft. An employee resigns to take a job at a direct competitor. Before their access is cut off, they decide to download sales battle cards, customer leads, or product roadmaps to a personal USB or personal Google Drive to give themselves a head start at the new job. Mimecast manages this through HR integration by connecting to the company's HR system such as Workday or their particular HR system. The moment HR marks the employee as resigned, Mimecast automatically moves that employee to a high-risk departing employee watchlist. Additionally, behavioral monitoring tracks their activity over the last thirty days and monitors them going forward. If they suddenly try to transfer fifty gigabytes or a large amount of corporate data to a personal cloud drive or rename files to other formats to sneak them past security, Mimecast flags the mismatch instantly. The security team is alerted immediately with the exact file history, allowing them to freeze the user's account before they leave. I can provide multiple scenarios. Another scenario involves Shadow AI leak. A well-meaning product manager wants to quickly clean up a piece of unreleased proprietary code or summarize a sensitive financial presentation to save time. They paste the entire raw text into an untrusted, unapproved public AI tool such as an unsanctioned GenAI web application. Mimecast manages this through vector detection by monitoring endpoints and browsers. It detects that corporate data is moving to an unapproved browser destination or shadow IT. A real-time nudge triggers an automated response instead of locking down the computer and creating a massive IT ticket. A pop-up appears on the employee's screen saying, 'You are trying to share internal code or data with an unapproved AI tool. Please use our secure corporate enterprise AI tool instead.' This stops the leak immediately while educating the user. Another scenario involves hijacking accounts with a compromised insider. For example, a customer support agent falls for a spear-phishing email and inputs their credentials into a fake portal. A malicious external hacker now logs into that agent's account from a different country. The hacker appears to be an insider using legitimate credentials and begins silently harvesting customer personal identifiable information. Mimecast manages this through anomaly detection. Mimecast notices that this specific user is suddenly logging in at three in the morning from an unusual IP address and downloading customer data at ten times the normal rate. The system identifies that this behavior heavily deviates from the user's standard historical profile or data through context analysis. Because this is high-risk, the platform triggers an automated workflow via integration with the company's EDR tool such as Defender or CrowdStrike or an identity provider to isolate the device and force a password reset, instantly locking out the attackers.
My main use case for Mimecast Insider Risk Management and Data Protection is email security, as I have deployed it as my email gateway to protect against any kind of phishing attempts or malicious email attempts.A specific example of how Mimecast Insider Risk Management and Data Protection helped me catch or block a phishing attempt or malicious email is that we deployed some gateway policies and content-based pattern matching policies. We identified recent campaigns we were facing in the organization and created regex-based patterns on the content matching side, which helped me mitigate the threat by matching that content from the gateway policies and blocking the emails that were potentially phishing. My day-to-day use case, being a security engineer or security analyst, is to investigate the emails that users report and purge the emails. Mimecast Insider Risk Management and Data Protection gives very good functionality for purging emails or reviewing reported emails, which helps me significantly with investigation apart from blocking threats.
Incident Response Officer at a educational organization with 1,001-5,000 employees
Real User
Top 20
Mar 23, 2023
Data Leakage Protection on large scale environments. This can be to protect against leakage on endpoints and servers that consist of highly classified or propriety information. It can be added on as a control that integrates into the various egress solutions in the organization. As part of projects for general DLP I have used data classification to identify such silos and create identifiers or use predefined structured and unstructured data that flows through the environment. The most effective way to apply these controls is at tge point the data is accessed between differant parts of the organization.
Director, Cybersecurity Consulting at a tech services company with 51-200 employees
Real User
Jun 16, 2022
When I first became acquainted with Code42, we were implementing it at an employer I worked with, and that was a successful implementation. I now work for a consulting firm, and we do system implementations of a variety of different DLP tools, and Code42 is one of them. I still use it, but it is for the benefit of my clients, as opposed to the company I work for. The pedigree of Code42 came from a toolset called CrashPlan. So, CrashPlan predated Code42's product, and it was mainly in helping organizations prepare for disaster recovery and business continuity planning in significant server environments. We use it in three main areas. The primary area that we use it in is in providing identity into data loss prevention and data loss protection in terms of: * Where is that unstructured data? * Who has access to it? * How did they come to be authorized to use it? It is a broad-based area of use, and then the other area of use is discovery. Many of our clients engage either with their staff in legal battles, or some other thing, where they need to perform discovery. We support discovery with Code42 as well. Its deployment was on-premises, and that just happened to be the ecosystem that we chose to work from. It is still going fine, but I don't think it would matter one way or another. From our standpoint, it was fine. Ultimately, we'll probably move to the cloud, but at that time, we were looking for on-premises.
Learn what your peers think about Mimecast Insider Risk Management and Data Protection. Get advice and tips from experienced pros sharing their opinions. Updated: July 2026.
Chief Architect - Ethical Hacker at a tech services company with 1-10 employees
Real User
Mar 22, 2021
I took over as a security architect for my current company. They're happy to be using this solution, so I'll be learning more about it as time goes on. Code42 Next-Gen DLP is deployed company-wide.
Mimecast Incydr protects organizations against insider risk and data exfiltration, whether accidental, negligent, or malicious. It monitors endpoint, cloud, browser, and email activity to see when files move to places you don't trust, without requiring policies, proxies, or content classification to work. Administrators get a single dashboard for data flow visibility, adaptive controls ranging from education to blocking, and integrations with HR, endpoint detection, and identity systems to...
I manage an organization with more than five thousand employees who are all in either on-site or hybrid environments and receive multiple emails every day. The email flow on a daily basis is too much to handle manually. Emails can be sent from approved domains, or they can be spam or other unwanted messages. I cannot reveal my customer's name, but I can say that they are in the shopping business. Since they are in the shopping business, they receive multiple mail flows from the sales team and regular communications, and it becomes very crucial to differentiate which emails are useful and which are not. On a daily basis, I check whether the mail flow is within the established threshold. Unless there are end-of-season sales occurring, I do not see a high mail flow that exceeds the threshold we observe. I evaluate the detections I am seeing, and in Mimecast Insider Risk Management and Data Protection, I can see detections based on various time frames, such as twenty-four hours, forty-eight hours, or whatever custom time frame I choose. The maximum limit according to our enterprise is thirty days. Since I need to see activity in real time, I analyze whether all the respective mail flows are coming in and what category they fall under. The categories can include malware, spam, extortion campaigns, or multiple others. I analyze that data by fetching the raw logs for my customer, checking the spam scores for their emails, and reviewing statuses such as accepted, rejected, held, deferred, and more. I analyze whether Mimecast Insider Risk Management and Data Protection's policies work properly. I cannot just rely on it being a SaaS-based product with enabled policies working correctly. There are many use cases where I have seen emails being delivered that should not have been delivered. That does not make Mimecast Insider Risk Management and Data Protection a bad product; it means that I have not fine-tuned the policy to my organization's expectations. Once I work on the tool daily, I understand the mail flow, recognize which emails fall into the spam category, and compare them not only on the Mimecast Insider Risk Management and Data Protection database but also with external comparison tools like MX Toolbox or VirusTotal to analyze things. This gives an overview of what my general scenario looks.
Mimecast Insider Risk Management and Data Protection is relied upon primarily for email security, functioning as an email gateway within the company so that every email is processed through Mimecast, filtered, and then delivered to user mailboxes after security checks are completed. Day-to-day operations involve handling tickets from users stating that their email has been held and they request release. We cross-check whether SPF is matching, if SPF has passed, and if DKIM has passed. Once everything is verified and we determine the sender is trusted, we release the email. We have different types of security gateways, including impersonation protection, which is created by establishing a profile group so that if it matches any keywords, it might flag potential impersonation. We have many policy options within the system. Based on our requirements, we can set up policies, and Mimecast helps us filter emails very effectively. We can clearly check whether emails are being delivered or not. If they are undelivered, we can check the reason for non-delivery. URLs are decoded through Mimecast, allowing us to scan links and determine whether they are safe or not. Many options exist within Mimecast for these purposes.
I have used Mimecast Insider Risk Management and Data Protection for almost four and a half years for one of my clients. I use Mimecast Insider Risk Management and Data Protection for detecting and maintaining email security for my client. Mimecast gives us unmatched visibility and focuses on behavior analysis with file vector users, real-time nudges, and top-tier support. Mimecast Insider Risk Management and Data Protection uses a file-vector-user framework. Instead of just blocking everything blindly, it examines the file value, how it is moving, and which users are moving it. I can provide a real-world example of how a company uses this product to stop insider threats. My example involves departing employees and data theft. An employee resigns to take a job at a direct competitor. Before their access is cut off, they decide to download sales battle cards, customer leads, or product roadmaps to a personal USB or personal Google Drive to give themselves a head start at the new job. Mimecast manages this through HR integration by connecting to the company's HR system such as Workday or their particular HR system. The moment HR marks the employee as resigned, Mimecast automatically moves that employee to a high-risk departing employee watchlist. Additionally, behavioral monitoring tracks their activity over the last thirty days and monitors them going forward. If they suddenly try to transfer fifty gigabytes or a large amount of corporate data to a personal cloud drive or rename files to other formats to sneak them past security, Mimecast flags the mismatch instantly. The security team is alerted immediately with the exact file history, allowing them to freeze the user's account before they leave. I can provide multiple scenarios. Another scenario involves Shadow AI leak. A well-meaning product manager wants to quickly clean up a piece of unreleased proprietary code or summarize a sensitive financial presentation to save time. They paste the entire raw text into an untrusted, unapproved public AI tool such as an unsanctioned GenAI web application. Mimecast manages this through vector detection by monitoring endpoints and browsers. It detects that corporate data is moving to an unapproved browser destination or shadow IT. A real-time nudge triggers an automated response instead of locking down the computer and creating a massive IT ticket. A pop-up appears on the employee's screen saying, 'You are trying to share internal code or data with an unapproved AI tool. Please use our secure corporate enterprise AI tool instead.' This stops the leak immediately while educating the user. Another scenario involves hijacking accounts with a compromised insider. For example, a customer support agent falls for a spear-phishing email and inputs their credentials into a fake portal. A malicious external hacker now logs into that agent's account from a different country. The hacker appears to be an insider using legitimate credentials and begins silently harvesting customer personal identifiable information. Mimecast manages this through anomaly detection. Mimecast notices that this specific user is suddenly logging in at three in the morning from an unusual IP address and downloading customer data at ten times the normal rate. The system identifies that this behavior heavily deviates from the user's standard historical profile or data through context analysis. Because this is high-risk, the platform triggers an automated workflow via integration with the company's EDR tool such as Defender or CrowdStrike or an identity provider to isolate the device and force a password reset, instantly locking out the attackers.
My main use case for Mimecast Insider Risk Management and Data Protection is email security, as I have deployed it as my email gateway to protect against any kind of phishing attempts or malicious email attempts.A specific example of how Mimecast Insider Risk Management and Data Protection helped me catch or block a phishing attempt or malicious email is that we deployed some gateway policies and content-based pattern matching policies. We identified recent campaigns we were facing in the organization and created regex-based patterns on the content matching side, which helped me mitigate the threat by matching that content from the gateway policies and blocking the emails that were potentially phishing. My day-to-day use case, being a security engineer or security analyst, is to investigate the emails that users report and purge the emails. Mimecast Insider Risk Management and Data Protection gives very good functionality for purging emails or reviewing reported emails, which helps me significantly with investigation apart from blocking threats.
Data Leakage Protection on large scale environments. This can be to protect against leakage on endpoints and servers that consist of highly classified or propriety information. It can be added on as a control that integrates into the various egress solutions in the organization. As part of projects for general DLP I have used data classification to identify such silos and create identifiers or use predefined structured and unstructured data that flows through the environment. The most effective way to apply these controls is at tge point the data is accessed between differant parts of the organization.
When I first became acquainted with Code42, we were implementing it at an employer I worked with, and that was a successful implementation. I now work for a consulting firm, and we do system implementations of a variety of different DLP tools, and Code42 is one of them. I still use it, but it is for the benefit of my clients, as opposed to the company I work for. The pedigree of Code42 came from a toolset called CrashPlan. So, CrashPlan predated Code42's product, and it was mainly in helping organizations prepare for disaster recovery and business continuity planning in significant server environments. We use it in three main areas. The primary area that we use it in is in providing identity into data loss prevention and data loss protection in terms of: * Where is that unstructured data? * Who has access to it? * How did they come to be authorized to use it? It is a broad-based area of use, and then the other area of use is discovery. Many of our clients engage either with their staff in legal battles, or some other thing, where they need to perform discovery. We support discovery with Code42 as well. Its deployment was on-premises, and that just happened to be the ecosystem that we chose to work from. It is still going fine, but I don't think it would matter one way or another. From our standpoint, it was fine. Ultimately, we'll probably move to the cloud, but at that time, we were looking for on-premises.
I took over as a security architect for my current company. They're happy to be using this solution, so I'll be learning more about it as time goes on. Code42 Next-Gen DLP is deployed company-wide.
We primarily use the solution as a backup.