Threat Detection & DefensePress Release

Mimecast Introduces Runtime Data Security for Visibility, Control of Growing AI Risk

Detects, Governs, Blocks, and Remediates Data Exposure Caused by Employees, AI Tools, and Autonomous Agents

Mimecast, the global cybersecuarity leader in securing human and Artificial Intelligence (AI) risk, recently announced a major expansion of its Incydr™ offering with data security capabilities for the AI era, alongside a preview of its new Agent Risk Center at RSAC Conference 2026 in San Francisco. These new capabilities help deliver runtime data security—a unified approach to detect, govern, and remediate data exposure, in real-time, whether the action comes from an employee or an agent acting on their behalf.

Eighty percent of Fortune 500 companies now run active AI agents, yet only 14% have received full security approval. Enterprise data loss is no longer just a people problem — AI agents have created an entirely new attack surface. They are accessing and sharing sensitive data through pathways traditional security tools were never designed to monitor, including MCP-connected workflows, commercial agents, user-built automations, and shadow AI tools.

“Intent-based detection treats all agents equally. We don’t, because the human behind the agent is the signal that changes everything,” said Rob Juncker, Chief Product Officer at Mimecast. “Who deployed the agent? What do we already know about them? How is data moving across email, collaboration tools, browsers, SaaS apps, endpoints, and AI-driven workflows—and what intervention is required right now? That’s a runtime data security problem, not a model problem.”

Adaptive Data Security for the Human and AI Agent Era

Mimecast’s Incydr technology has long helped organisations prevent insider-driven data loss through out-of-the-box visibility, intelligent detection via its PRISM risk engine (250+ risk indicators), and adaptive response ranging from in-context education to real-time blocking. The new capabilities extend Incydr technology from insider-led data security into broader runtime data security for both human and AI-driven risk.

This Mimecast expansion takes a new approach, combining Incydr endpoint and browser intelligence with Mimecast’s email and collaboration security, delivering complete ingress-to-egress data visibility—covering the full path of enterprise data movement across endpoints, browsers, SaaS applications, AI tools, MCP connections, and email.

New and expanded capabilities are engineered to include:

  • Unified Human and Agent Visibility: A single view into data loss risk across employees and autonomous agents, spanning endpoints, cloud and SaaS applications, email, browser activity, commercial AI tools, MCP server connections, and user-developed agents.
  • Shadow AI and Unsanctioned Agent Detection: Purpose-built detection for unsanctioned AI usage, out-of-policy commercial agents, unauthorised MCP connections to production databases and critical SaaS platforms, and user-built agents operating on unapproved LLM providers or accessing production environments without security review.
  • Adaptive Risk Scoring for People and AI Agents: The Incydr risk engine now continuously scores both human users and AI agents based on behavioural anomalies, policy violations, high-risk data access, unsanctioned application usage, agent compliance posture, and exposure to critical systems and data sources (e.g., Snowflake, Stripe, PostgreSQL, AWS, Salesforce, GitHub).
  • Granular Data-to-Agent Access Mapping: A clear view of which agents and tools access which categories of sensitive data—including customer PII, source code, financial records, internal communications, HR data, and infrastructure configurations—enabling security teams to understand and control the agent-to-data blast radius.
  • Policy-Driven Governance: A comprehensive governance framework for classifying and enforcing policy across all AI tools, commercial agents, MCP servers, and user-developed agents—with sanctioned, unsanctioned, and uncategorised classifications, department-level enforcement, and AI acceptable use policy management.

Mimecast

Introducing the Mimecast Agent Risk Center

Today, a single data loss incident might involve an employee sharing a file through an unsanctioned tool—such as DeepSeek, OpenClaw, Ollama, or ChatGPT—a commercial AI agent summarising confidential records, and a user-built agent pulling from a production database it was never meant to access. These activities span multiple systems, operate under different detection logic, and require separate response playbooks—if they are detected at all.

The Mimecast Agent Risk Center is designed to consolidate that fragmented picture into one experience. Critically, the Agent Risk Center is built to connect every finding directly to action. Built-in agentic workflows automate the response chain—notifying users, escalating to managers, enforcing controls, and generating compliance reports—so teams act at machine speed, not human speed.

As engineered, the new Mimecast capabilities will include:

  • Anomaly Detection Engine for Risky Agent Behaviour: Can automatically surface high-risk patterns— unsanctioned tools with production database access, finance users connected to payment MCP servers, user-developed agents using non-sanctioned LLM providers, and executives with overly broad MCP configurations.
  • Governance Scorecards: A continuous assessment of organisational posture across four dimensions: policy coverage, review currency, human-in-the-loop enforcement, and LLM compliance—giving CISOs a clear measure of their agentic governance maturity.
  • Department-Level Risk Heatmaps: Visual analytics showing risk distribution, department-level exposure, risk factor breakdowns, and trend patterns—enabling targeted intervention rather than blanket policy.
  • Integrated Remediation Workflows: Every risk finding connects directly to action—block access, notify users, escalate to managers, create tickets, classify uncategorised tools, schedule agent reviews, and generate compliance reports—all without leaving the unified interface.

For more information on Agentic AI risk, please visit the Mimecast blog: ‘Agentic AI security: five things your strategy is probably missing.’

CSA Editorial

Launched in Jan 2018, in partnership with Cyber Security Malaysia (an agency under MOSTI). CSA is a news and content platform focusing on key issues in cybersecurity in the region. CSA is targeted to serve the needs of cybersecurity professionals, IT professionals, Risk professionals and C-Levels who have an obligation to understand the impact of cyber threats.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *