Technology Partners
Mimecast

Introducing Mimecast
The Human Risk Management Platform
Securing the People Behind Every Attack
What is Mimecast?
Mimecast has been protecting organisations from email-based threats since 2003. Over more than two decades, it has evolved from a cloud email security gateway into something more ambitious and more relevant: the world’s leading Human Risk Management platform. The shift reflects a fundamental truth that the cyber security industry has been slow to fully acknowledge. Technology does not fail organisations. People do. And every piece of technology that addresses the technical vector of an attack leaves the human vector largely untouched.
Mimecast’s 2025 Global Threat Intelligence Report, drawing on data from over 42,000 customers and 18 billion security events processed every day, found that phishing now accounts for 77% of all attacks, up from 60% the previous year. The reason is straightforward: AI has made it trivially easy for attackers to craft convincing, personalised phishing messages at scale. The perimeter can be hardened, the email gateway can be tuned, and the endpoint can be protected, but if a person clicks a link, opens an attachment, or pastes sensitive data into an AI tool, all of that technology is bypassed in an instant.
Mimecast’s answer is a connected platform that addresses both the technical threat, through market-leading email and collaboration security, and the human threat, through behavioural analytics, risk scoring, targeted training and real-time intervention. It is the only platform to have been named a Leader in both the 2025 Gartner Magic Quadrant for Email Security and the Gartner Magic Quadrant for Digital Communications Governance and Archiving Solutions, while also being recognised as a Strong Performer in the Forrester Wave for Human Risk Management Solutions. One platform. Two categories. One of only three vendors worldwide to lead in both.
Talk to Pure Networks About Mimecast
The greatest threat to your organisation is not a technical vulnerability. It is the person who clicks the link, shares the password, or sends the file to the wrong address. Mimecast is the platform built to manage that risk, and Pure Networks is the partner to deploy and support it.
Whether you are looking to strengthen email security, build a genuine security awareness programme, protect your collaboration platforms, or gain real visibility into human risk across your organisation, we can help you get there.
Key Benefits of Mimecast
Human Risk Management – You Cannot Firewall Your Way Out of Human-Targeted Attacks Learn More ›
Email Security – Twenty Years of Protection – Now Powered by AI Learn More ›
Security Awareness Training – Turn Your People From Your Greatest Vulnerability Into Your First Line of Defence Learn More ›
Collaboration Security – The Threat Has Moved Beyond Email – So Has Mimecast Learn More ›
Data Loss Prevention and Insider Risk – Stop Data Leaving Before It Becomes a Breach Learn More ›
Archiving and Compliance – Never Lose an Email. Prove It in Seconds. Learn More ›
DMARC and Brand Protection – Stop Attackers Using Your Domain to Attack Your Customers Learn More ›
Human Risk Management
The Problem
Most organisations have invested heavily in technical security controls. Firewalls, endpoint protection, email gateways, multi-factor authentication. The technology has improved substantially. And yet breaches keep happening, and in the overwhelming majority of cases, a person played a role. They clicked the link. They shared the password. They sent the attachment to the wrong address. They pasted the contract into a public AI tool. They did not do these things maliciously. They did them because they were busy, distracted, untrained, or simply unaware that what they were doing represented a risk.
Traditional security awareness training addresses this partially, but poorly. Annual compliance training modules that employees click through without reading do not change behaviour. A one-size-fits-all approach to security education fails to account for the fact that different people, in different roles, with different behaviours, represent fundamentally different levels of risk. And without visibility into how individuals actually behave, security teams cannot know which employees represent the greatest exposure, or intervene before a breach rather than after one.
The Mimecast Approach
Mimecast Human Risk Management (HRM) takes a different approach, built on three principles: measure risk at the individual level, intervene in the moment when risky behaviour is detected, and improve security posture continuously through targeted, behaviour-driven education. It treats human risk the way a mature organisation treats technical vulnerability: with visibility, prioritisation, and systematic remediation.
The platform’s central capability is the Human Risk Command Center, launched in 2025, which brings together data from Mimecast’s own email and collaboration security products with intelligence from third-party security tools to generate individual risk scores for every user in the organisation. These scores are dynamic, updating in real time as behaviour changes, and they give security teams something they have never had before: a clear, evidence-based view of who in the organisation represents the greatest human risk, and why.
Key Capabilities
- Individual human risk scoring that assigns a dynamic risk score to every user based on real behaviour, including clicks on simulated phishing, engagement with training, email behaviour patterns, and data handling activities
- The Human Risk Command Center providing a single dashboard view of human risk across the entire organisation, with drill-down into individual user risk profiles and the specific behaviours driving elevated scores
- Real-time intervention, automatically enrolling high-risk users in targeted training, temporarily restricting access, or triggering alerts when risky behaviour is detected, before a breach can occur
- Third-party security integration, ingesting signals from SIEM, XDR, identity and endpoint tools to enrich risk scoring with a complete picture of each user’s security behaviour across all systems
- Mihra AI, Mimecast’s intelligent human risk agent, which has demonstrated up to 7x improvement in threat investigation times and provides automated insights, recommendations, and response actions across the platform
- Behavioural analytics that identify patterns associated with elevated risk, including unusual data access, shadow AI usage, and changes in email behaviour that may indicate compromise or insider risk
- Measurable risk reduction, allowing security teams to demonstrate to leadership and regulators that human risk is actively managed, tracked and improving over time
Why It Matters for Your Organisation
Human risk is now the number one cybersecurity challenge, outranking every technical vulnerability in Mimecast’s annual survey of over 1,100 security leaders. Every organisation has people who are more likely than others to click a phishing link, share sensitive data inappropriately, or fall for a social engineering attack. Without visibility into who those people are, you cannot prioritise your effort or intervene before the damage is done. Mimecast Human Risk Management gives you that visibility, and the tools to act on it. By 2027, Gartner predicts that 50% of large enterprise CISOs will have adopted human-centric security design practices. The organisations that build this capability now will be better protected and better positioned for the regulatory scrutiny that is coming.
Email Security
What Is It?
Email remains the single most exploited attack vector in cyber security, and Mimecast has been at the forefront of email security for over twenty years. Its email security platform protects over 42,000 organisations globally, processing and analysing trillions of emails and applying AI-powered detection engines that have been trained and refined over two decades of real-world threat data.
Mimecast offers both a Secure Email Gateway (SEG) model, where all email traffic flows through Mimecast’s inspection infrastructure, and an API-based model for organisations using Microsoft 365 or Google Workspace who want protection without redirecting mail flow. Both models benefit from the same underlying detection capability and threat intelligence.
Key Capabilities
- Multi-layer threat detection combining AI and machine learning with signature-based detection, sandboxing, static file analysis and behavioural analysis to identify and block malware, phishing, ransomware, business email compromise and advanced persistent threats
- URL Protect rewrites and inspects every link in every email at the time of click, blocking access to malicious sites even if they were safe at the time of delivery but have since been weaponised
- Attachment Protect converts suspicious attachments to safe formats for immediate delivery, or sandboxes them for analysis before release, eliminating the delay and risk of malicious attachments
- Impersonation Protect defends against email attacks that spoof executives, suppliers and trusted partners, detecting the subtle social engineering signals that pattern-matching alone misses
- Internal Email Protect extends detection to email traffic within the organisation, identifying threats that originate from compromised internal accounts and malicious insiders
- Anomaly detection using social graphing to identify unusual communication patterns that may indicate account compromise or targeted attack activity
- Seamless integration with SIEM, XDR, SOAR and other security platforms including Palo Alto Networks, Microsoft Sentinel, CrowdStrike, Splunk,
- Netskope and Rapid7, enabling bi-directional threat intelligence sharing and automated response
- Guaranteed SLAs including 100% email processing uptime, 99% spam detection with under 0.0001% false positive rate, and archive search within 7 seconds
Why It Matters for Your Organisation
Despite decades of investment in email security, phishing attacks increased to 77% of all cyber attacks in 2025. The reason is AI: attackers can now generate convincing, personalised phishing emails at industrial scale, and the volume and quality of attacks is increasing faster than signature-based defences can keep up. Mimecast’s AI-driven detection, built on 20 years of threat data and updated continuously across 42,000 customer environments, provides a defence that learns and adapts in ways that traditional gateway solutions cannot. For organisations on Microsoft 365 or Google Workspace that rely solely on the built-in email security, independent research consistently shows that a dedicated email security platform such as Mimecast catches significantly more threats than native controls alone.
Security Awareness Training
What Is It?
Mimecast Security Awareness Training, delivered through the Engage platform, is the training component of the Human Risk Management platform. It goes well beyond the compliance tick-box training that most employees associate with cyber security education, delivering continuous, behaviour-driven training that is targeted to the individual based on their actual risk profile and adjusted automatically as their behaviour changes.
Engage uses real threat data from Mimecast’s email security platform to make training immediately relevant. When an employee clicks on a simulated phishing link, they receive contextual guidance at the exact moment they need it, not in a quarterly training module three months later. This just-in-time approach to education is demonstrably more effective at changing behaviour than periodic compliance training, and it means the organisation is continuously improving its human security posture rather than relying on annual snapshots.
Key Capabilities
- Hundreds of engaging, video-based training modules available in 27 languages, covering phishing, social engineering, password security, data handling, AI tool risks, regulatory compliance and more
- Phishing simulations using real-world templates based on current threat intelligence, including simulation of attachment-based attacks as well as link-based phishing, ensuring employees are tested against the attacks they are actually likely to encounter
- Individual risk scorecards that track each employee’s security behaviour over time, including simulation results, training completion, real phishing reports and other behavioural signals, giving security teams a genuine measure of human risk
- Automated just-in-time training triggered by risky behaviour, enrolling employees in targeted modules immediately when a risky action is detected rather than waiting for the next scheduled training cycle
- Contextual security reminders delivered through email, Slack or Microsoft Teams, bringing security guidance into the tools employees use every day rather than requiring them to log into a separate training platform
- Management reporting that quantifies training effectiveness, tracks risk score improvement over time, and provides the evidence needed to demonstrate a structured, measurable security awareness programme to auditors and regulators
- Integration with the Human Risk Command Center, ensuring that training data feeds directly into individual risk scores and contributes to the organisation-wide view of human risk
Why It Matters for Your Organisation
Security awareness training is often treated as a compliance requirement rather than a security control. The difference between treating it as a tick-box exercise and treating it as a genuine behaviour change programme is the difference between an organisation where employees vaguely know that phishing exists and one where employees actively identify and report threats. Mimecast Engage is designed for the latter. For organisations with NIS2 obligations, GDPR accountability requirements, or sector-specific regulatory frameworks that demand demonstrable security awareness programmes, Mimecast provides both the training capability and the reporting evidence to demonstrate compliance. And for any organisation that has experienced a breach where a person played a role, the case for genuinely effective awareness training does not need to be made twice.
Collaboration Security
What Is It?
The communication landscape has changed fundamentally. Email remains the primary attack vector, but Microsoft Teams, Slack, SharePoint, OneDrive and other collaboration platforms have become significant secondary channels through which threats enter organisations and sensitive data leaves them. Mimecast’s acquisition of Aware in 2024 extended the platform’s protection into these collaboration environments, providing the same level of visibility, control and threat detection that Mimecast brings to email.
Mimecast’s 2025 Global Threat Intelligence Report documented a 500% surge in ClickFix attacks, where attackers use fake error messages in web pages and collaboration tools to trick users into executing malicious commands. The threat is no longer confined to email, and security that stops at the email gateway leaves organisations with a significant and growing blind spot.
Key Capabilities
- Microsoft Teams protection, detecting and blocking malicious links, files and social engineering attacks delivered through Teams messages and channels
- SharePoint and OneDrive monitoring, providing visibility into file access, sharing behaviour and potential data exfiltration through Microsoft’s collaboration infrastructure
- Slack security, extending threat detection and data loss prevention to Slack workspaces where sensitive business data is increasingly shared and stored
- Collaboration data archiving for compliance and e-discovery, ensuring that communications across Teams, Slack and other platforms are retained and searchable in accordance with regulatory requirements
- Behavioural analytics across collaboration platforms, identifying unusual patterns such as mass file downloads, unexpected external sharing, or communication with unknown external parties that may indicate compromise or insider risk
- Unified visibility across email and collaboration platforms within the Human Risk Command Center, giving security teams a single view of human risk regardless of which communication channel it involves
Why It Matters for Your Organisation
Most organisations have made significant investment in email security and relatively little in collaboration platform security, despite the fact that employees now share enormous volumes of sensitive data through Teams, Slack and SharePoint every day. Attackers know this and are increasingly targeting these channels. Mimecast extends the same human-centric protection that makes its email security effective into these environments, closing a blind spot that most security architectures currently ignore entirely.
Data Loss Prevention and Insider Risk
What Is It?
Mimecast’s data loss prevention capability, significantly enhanced through the 2024 acquisition of Code42’s Incydr product, addresses one of the most underestimated risks in enterprise security: the insider. Not necessarily a malicious insider, though those exist too, but the much more common category of the departing employee taking files with them, the contractor sharing sensitive documents through a personal account, or the employee innocently pasting confidential data into a public AI tool.
Incydr provides deep visibility into how data moves across endpoints, cloud storage and collaboration platforms, with detection capabilities specifically designed to identify the exfiltration patterns associated with these real-world risks. It goes beyond traditional DLP, which typically focuses on content matching at the gateway, to understand the context and intent behind data movement.
Key Capabilities
- Continuous monitoring of file activity across endpoints, Microsoft OneDrive, SharePoint, Google Drive and Box, detecting unusual access, download and sharing behaviour
- Exfiltration detection tuned to real insider risk scenarios including departing employees taking files before leaving, contractors sharing sensitive data outside approved channels, and users uploading data to personal cloud storage
- AI tool monitoring, detecting and preventing employees from pasting confidential data into unauthorised generative AI tools, ChatGPT, Copilot and similar platforms
- Incydr Instructor, a contextual education tool that automatically delivers short, targeted video lessons to employees at the moment a risky data behaviour is detected, combining correction with education
- Outbound email DLP scanning every outbound message in its entirety, including body, headers, attachments and HTML content, for content that violates data handling policies
- Lightweight endpoint agent deployable via standard desktop management tools across Windows, Mac and Linux, with VDI support and minimal performance impact
- 30+ integrations with identity, endpoint, SOAR and SIEM tools for automated workflow responses including revoking access, quarantining endpoints and alerting security teams
Why It Matters for Your Organisation
Data loss through insiders, whether malicious or accidental, is responsible for a significant proportion of breach notifications under GDPR. The regulatory consequence of a data breach involving personal data is serious: fines, reputational damage and mandatory notification obligations. The operational consequence is potentially worse. Mimecast’s DLP and insider risk capability is built around the real-world scenarios that cause these breaches, not theoretical threat models, and it combines detection with the just-in-time education that actually changes the behaviour causing the risk in the first place.
Archiving and Compliance
What Is It?
Mimecast’s cloud archiving platform provides tamper-proof, searchable retention of email and collaboration data for compliance, legal and business continuity purposes. It is available with retention periods from one day to 99 years, depending on the organisation’s regulatory and operational requirements, and delivers archive search results in under seven seconds regardless of the size of the archive.
For organisations subject to GDPR, legal hold requirements, financial sector record-keeping obligations, or e-discovery demands, the ability to locate, retrieve and produce communications records quickly and reliably is not optional. Mimecast archiving provides this capability as part of the same platform that delivers email security and human risk management, removing the cost and complexity of maintaining a separate archiving solution.
Key Capabilities
- Cloud-based tamper-proof archiving of all inbound, outbound and internal email, with configurable retention periods from one day to 99 years
- Archive search delivering results in under seven seconds across any volume of archived data, with powerful filtering by sender, recipient, date, keyword and content
- Legal hold capability, allowing specific communications to be frozen and preserved for legal proceedings without affecting normal archive operations
- E-discovery tools that enable legal and compliance teams to conduct targeted searches and produce evidence packages without requiring IT involvement
- Email continuity, providing a backup email service that allows employees to send and receive email during primary mail server outages, with automatic synchronisation when service is restored
- European data residency with data hosted in Frankfurt across two replicated sites, supporting GDPR data sovereignty requirements for Irish and EU organisations
- Compliance certifications including ISO 27001, ISO 27018, SOC 1 and SOC 2 Type II, with HIPAA/HITECH support for healthcare organisations
- Named a Leader in the 2025 Gartner Magic Quadrant for Digital Communications Governance and Archiving Solutions
Why It Matters for Your Organisation
GDPR places explicit obligations on organisations to be able to locate, retrieve and produce personal data on request, and to demonstrate that data has been handled in accordance with retention policies. Legal proceedings and regulatory investigations create similar demands, often at short notice and under time pressure. An archiving solution that is slow, unreliable or incomplete creates both compliance risk and operational risk. Mimecast’s archiving platform is specifically designed to make these obligations manageable, with search performance and legal hold capabilities that allow even the largest organisations to respond to data requests quickly and confidently.
DMARC and Brand Protection
What Is It?
DMARC (Domain-based Message Authentication, Reporting and Conformance) is the email authentication standard that prevents attackers from sending emails that impersonate your organisation’s domain. When properly configured and enforced, DMARC ensures that only authorised email systems can send email purporting to come from your domain, protecting your customers, partners and employees from phishing attacks that use your brand identity as a lure.
Mimecast acquired DMARC Analyzer in 2019, and its DMARC capability is now one of the most mature in the market. The platform provides full visibility into all email being sent using your domain, guided implementation support to move from monitoring to full enforcement without disrupting legitimate mail flows, and ongoing management to ensure protection remains effective as your email infrastructure evolves.
Key Capabilities
- Automated DMARC record creation and management, removing the technical complexity that causes many organisations to stall at the monitoring stage and never reach full enforcement
- Complete visibility into all email sources sending on behalf of your domain, including authorised services, shadow IT and unauthorised sources that may indicate active abuse
- Guided implementation path from initial monitoring through SPF and DKIM alignment to full DMARC enforcement, with clear reporting at each stage to give security teams confidence before moving to the next step
- Real-time alerts for suspicious domain activity, providing early warning of brand abuse and domain spoofing campaigns targeting your customers or partners
- Reporting and evidence for regulators and auditors demonstrating that appropriate controls are in place to prevent domain spoofing
- Integration with the Mimecast platform’s broader email security and human risk capabilities, contributing to the unified view of email-based risk across the organisation
Why It Matters for Your Organisation
Domain spoofing attacks, where an attacker sends phishing emails appearing to come from your organisation, damage your brand, harm your customers and create regulatory exposure. DMARC is the technical standard that prevents this, but in practice the majority of organisations have not reached full DMARC enforcement because the implementation process is complex and the risk of disrupting legitimate email flows deters progress. Mimecast DMARC Analyzer removes this barrier, providing the visibility and guided implementation support needed to reach full enforcement without risk. For organisations whose customers receive communications by email, proper DMARC implementation is both a security control and a customer protection obligation.





