Network Security Engineer at a tech services company with 1,001-5,000 employees
Real User
Top 10
Jun 24, 2026
A con to mention is that Mimecast Insider Risk Management and Data Protection, at times, may not capture everything. For instance, the time that Mimecast Insider Risk Management and Data Protection took to process something such as incoming email is normally fifteen to twenty seconds, which is completely normal. Though the email is released, delays of ten to twenty minutes may be experienced, which does not get captured in Mimecast Insider Risk Management and Data Protection. It may show delays on the recipient's mail server end, but creates a contradiction since in Mimecast Insider Risk Management and Data Protection I do not see any delay, while the recipient's mail server indicates a delay occurring at Mimecast Insider Risk Management and Data Protection. For testing, I whitelisted the specific domain for the sender's email. After whitelisting that, the delay disappeared, yet I wonder why Mimecast Insider Risk Management and Data Protection did not capture that in this specific log. This issue has not occurred often, maybe once or twice in the past six to seven months, but understanding that aspect has led me to reach out to OEM. They provided their views, but I was not very satisfied; they could show where it is getting captured and why it is not highlighted clearly. That is a con of Mimecast Insider Risk Management and Data Protection, but overall, it is a great tool. Mimecast Insider Risk Management and Data Protection is totally recommended. The policies are solid, they work effectively, the implementation time is not very long, integrations with SIEM are quite easy, and the Glassbreak account is something I have tested, making Mimecast Insider Risk Management and Data Protection better in this regard. Overall, it is a great tool.
Mimecast Insider Risk Management and Data Protection could be improved by providing more advanced features within the platform. If it collaborated with other different features, that would be more helpful.
I would highlight reporting and analytics improvement. While the dashboard looks great, getting highly customized reports out of the system without using an external API can be difficult. The daily dashboards are very intuitive, but native executive report features could be enhanced. If you want to create highly customized reports for C-level presentation or high-level reviews, you often have to rely on their API to export data into a third-party SIEM or BI tools. Having more out-of-the-box templates for quarterly risk summaries would be a huge time-saver and advantage for this tool. I would also mention virtual or shared environment support. It is technically specific, and there is a struggle in particular virtual desktop infrastructure environments where multiple users share a single host. One area of improvement is better out-of-the-box support for multi-user shared host environments such as Azure Virtual Desktop or AVD setups. When multiple active users share a single host simultaneously, the endpoint tracking can sometimes face performance bottlenecks or require complex workarounds to report individual data flawlessly. These are the areas where this product can improve.
There are no particular reviews on improvement from my side regarding Mimecast Insider Risk Management and Data Protection.I think the UI of Mimecast Insider Risk Management and Data Protection can be more optimized, as it feels slow and laggy at points. If that can be optimized and improved, that would be better.
Incident Response Officer at a educational organization with 1,001-5,000 employees
Real User
Top 20
Mar 23, 2023
The solution has been designed for a different approach than the one followed by other DLP solutions in the market. Most of us who come from the mindset of filtering out incidents using a content-specific approach may find this solution limited. The next updates for the solution may benefit from using some of the features provided by older solutions in the market to allow for a deep dive. There is limited support for data at rest.
Director, Cybersecurity Consulting at a tech services company with 51-200 employees
Real User
Jun 16, 2022
In a couple of instances, we had a little bit of trouble in getting it distributed throughout the organization. We ultimately managed to do it, but they talk about it being a pretty simple process, and it became a little laborious. It would just turn away. The agents were not being distributed. It was just churning and churning and churning. When we were looking for specific categories of data, it was getting bogged down, but that was not even so much Code42, although some of it was their issue. It really has to do with the overall infrastructure and what the organization is prepared to do. If the infrastructure or the networking is a little hinky or you don't have a really finely tuned network infrastructure environment and your patches aren't up to date on your servers and your endpoints, it could get a little sticky. Other than that, it was okay. We really didn't have much problem beyond that. It took a couple of days to sort that out, but it was no big deal.
Learn what your peers think about Mimecast Insider Risk Management and Data Protection. Get advice and tips from experienced pros sharing their opinions. Updated: July 2026.
Mimecast Incydr protects organizations against insider risk and data exfiltration, whether accidental, negligent, or malicious. It monitors endpoint, cloud, browser, and email activity to see when files move to places you don't trust, without requiring policies, proxies, or content classification to work. Administrators get a single dashboard for data flow visibility, adaptive controls ranging from education to blocking, and integrations with HR, endpoint detection, and identity systems to...
A con to mention is that Mimecast Insider Risk Management and Data Protection, at times, may not capture everything. For instance, the time that Mimecast Insider Risk Management and Data Protection took to process something such as incoming email is normally fifteen to twenty seconds, which is completely normal. Though the email is released, delays of ten to twenty minutes may be experienced, which does not get captured in Mimecast Insider Risk Management and Data Protection. It may show delays on the recipient's mail server end, but creates a contradiction since in Mimecast Insider Risk Management and Data Protection I do not see any delay, while the recipient's mail server indicates a delay occurring at Mimecast Insider Risk Management and Data Protection. For testing, I whitelisted the specific domain for the sender's email. After whitelisting that, the delay disappeared, yet I wonder why Mimecast Insider Risk Management and Data Protection did not capture that in this specific log. This issue has not occurred often, maybe once or twice in the past six to seven months, but understanding that aspect has led me to reach out to OEM. They provided their views, but I was not very satisfied; they could show where it is getting captured and why it is not highlighted clearly. That is a con of Mimecast Insider Risk Management and Data Protection, but overall, it is a great tool. Mimecast Insider Risk Management and Data Protection is totally recommended. The policies are solid, they work effectively, the implementation time is not very long, integrations with SIEM are quite easy, and the Glassbreak account is something I have tested, making Mimecast Insider Risk Management and Data Protection better in this regard. Overall, it is a great tool.
Mimecast Insider Risk Management and Data Protection could be improved by providing more advanced features within the platform. If it collaborated with other different features, that would be more helpful.
I would highlight reporting and analytics improvement. While the dashboard looks great, getting highly customized reports out of the system without using an external API can be difficult. The daily dashboards are very intuitive, but native executive report features could be enhanced. If you want to create highly customized reports for C-level presentation or high-level reviews, you often have to rely on their API to export data into a third-party SIEM or BI tools. Having more out-of-the-box templates for quarterly risk summaries would be a huge time-saver and advantage for this tool. I would also mention virtual or shared environment support. It is technically specific, and there is a struggle in particular virtual desktop infrastructure environments where multiple users share a single host. One area of improvement is better out-of-the-box support for multi-user shared host environments such as Azure Virtual Desktop or AVD setups. When multiple active users share a single host simultaneously, the endpoint tracking can sometimes face performance bottlenecks or require complex workarounds to report individual data flawlessly. These are the areas where this product can improve.
There are no particular reviews on improvement from my side regarding Mimecast Insider Risk Management and Data Protection.I think the UI of Mimecast Insider Risk Management and Data Protection can be more optimized, as it feels slow and laggy at points. If that can be optimized and improved, that would be better.
The solution has been designed for a different approach than the one followed by other DLP solutions in the market. Most of us who come from the mindset of filtering out incidents using a content-specific approach may find this solution limited. The next updates for the solution may benefit from using some of the features provided by older solutions in the market to allow for a deep dive. There is limited support for data at rest.
In a couple of instances, we had a little bit of trouble in getting it distributed throughout the organization. We ultimately managed to do it, but they talk about it being a pretty simple process, and it became a little laborious. It would just turn away. The agents were not being distributed. It was just churning and churning and churning. When we were looking for specific categories of data, it was getting bogged down, but that was not even so much Code42, although some of it was their issue. It really has to do with the overall infrastructure and what the organization is prepared to do. If the infrastructure or the networking is a little hinky or you don't have a really finely tuned network infrastructure environment and your patches aren't up to date on your servers and your endpoints, it could get a little sticky. Other than that, it was okay. We really didn't have much problem beyond that. It took a couple of days to sort that out, but it was no big deal.
As a newcomer into a business that is running this software, what I think could be improved is how I get support.
There doesn't seem to be any feature that is lacking.