
Incydr
Email security has protected against phishing and impersonation while improving threat response
What is our primary use case?
I am using Mimecast Insider Risk Management and Data Protection, and I used it in my previous company for around two to three years.
We are leveraging Mimecast Insider Risk Management and Data Protection for email security, and it is acting as our primary email gateway, through which all our emails are entered. We have all the policies and security configuration implemented on Mimecast Insider Risk Management and Data Protection as our main gateway.
Mimecast Insider Risk Management and Data Protection is an email gateway, so all our email passes through our primary security device. It is used for all the security checks, policy checks, all the block checks, and URL rewriting. Our work mainly revolves around email work such as tracing emails and applying some blocking or remediation configurations.
We are leveraging Mimecast Insider Risk Management and Data Protection for email security, which includes URL sandboxing, URL shorteners, URL sand details, and headers.
What is most valuable?
Mimecast Insider Risk Management and Data Protection is a very robust and highly reliable gateway. We are very satisfied with its excellency with the anti-spam and URL rewriting feature. We are also leveraging it to stop phishing and malware attempts that our company receives. It has a good capability to deal with day-to-day trends and also has a good interface.
Regarding the best features Mimecast Insider Risk Management and Data Protection offers, it has highly customizable policies. It also has reliable, dynamic rewriting and blocking of URLs. Additionally, it provides instant threat remediation and is very good in identifying impersonation and BEC attacks. We have good admin visibility.
Mimecast Insider Risk Management and Data Protection has impacted our organization positively in several ways. It has good threat remediation and good attachment protection. It also has good impersonation and BEC protection. For our organization, these three are the most critical threat vectors that an attacker can leverage to enter the company. Mimecast Insider Risk Management and Data Protection has good control over these threat vectors. Apart from that, it has a good interface and good integration with other tools.
What needs improvement?
Regarding improvement for Mimecast Insider Risk Management and Data Protection, I believe there is one area that needs attention: QR code phishing. I can see it is still allowing some emails that have phishing QR codes inside them or some phishing attachments. It needs to slightly improve on the QR-ishing side.
For how long have I used the solution?
I have been in this field for around six years and am working as a SOC incident responder.
What do I think about the stability of the solution?
Mimecast Insider Risk Management and Data Protection is stable.
What do I think about the scalability of the solution?
Regarding Mimecast Insider Risk Management and Data Protection's scalability, as we have a public cloud, there should not be an issue with scalability.
How are customer service and support?
Customer support for Mimecast Insider Risk Management and Data Protection is good. I have interacted with them multiple times regarding any kind of ongoing issues, and I can confirm that customer support is good.
Which solution did I use previously and why did I switch?
I am using only Mimecast Insider Risk Management and Data Protection because I am working in an incident response team where we need to work for different clients. The choice of devices totally depends on what the client is using.
How was the initial setup?
I am not the implementer; Mimecast Insider Risk Management and Data Protection was already there at the customer premises. We learned it, applied it, and used it.
What about the implementation team?
The accuracy of Mimecast Insider Risk Management and Data Protection is good. We do not see any kind of mis-data or misinterpretation. From the accuracy side, I can confirm that it is reliable and there are no issues.
What was our ROI?
Mimecast Insider Risk Management and Data Protection is time-saving. From the employee perspective, it is neutral. From the security perspective, Mimecast Insider Risk Management and Data Protection is helping in reducing the ongoing threats for the organization.
What's my experience with pricing, setup cost, and licensing?
I am from the incident response team, and regarding pricing and cost, I am not very familiar with this. I cannot comment on the pricing part.
Which other solutions did I evaluate?
We do not have a business relationship with this vendor other than being a customer.
What other advice do I have?
I will give one piece of advice regarding Mimecast Insider Risk Management and Data Protection: be sure about zero-day attacks because it might be missing in applying any remediation or security controls on any kind of zero-days. This is applicable for all the security equipment we are using on a daily basis. Just be assured if there is a zero-day. I gave this review a rating of 8.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Automated monitoring has protected sensitive data and detects insider and compromised account risks
What is our primary use case?
I use Mimecast Insider Risk Management and Data Protection primarily to identify and investigate risky user behavior involving sensitive information, whether the action is malicious, negligent, or compromised. The goal is to detect situations where employees, contractors, or privileged users may be exposing company data before it becomes a breach.
A typical use case would include email forwarding by an employee containing confidential information to their personal accounts. Another example is a large or unusual amount of downloads of sensitive data just before a user is either terminated or they resign. Additionally, I monitor sharing of any company IP data, customer data, or financial information such as PII or PCI information, which is regulated data not supposed to be outside the organization.
I also use it to detect compromised accounts that are behaving differently from normal user accounts. We also use it to support HR with security investigations based on support tickets that come up when they feel that something appears malicious or they report something that seems malicious.
There was one example where an employee who had recently submitted their resignation began forwarding documents they created with the company to their personal email ID so that they could use those as templates with the new organization they would join. The problem was that they did not realize that all of our documents have the company's digital signature and the company's logo on them. They were trying to exfiltrate data which they had created while they were employed with us, which got flagged.
Another instance occurred when we had a compromised mailbox where an attacker gained access through credential theft. Mimecast Insider Risk Management and Data Protection identified unusual outbound email activity and anomalous user behavior that did not match the employee's normal patterns of how they would send emails. This helped us contain that account and prevent sensitive information from being shared externally.
What is most valuable?
The best features of Mimecast Insider Risk Management and Data Protection are, first, the ability to catch anomalous behavior. We did not know we had a compromised account until the user behavior was tracked, especially because the user in question was on leave and themselves were not actively looking at their email accounts to realize that their account had been compromised. This was one of the best features where it caught onto pattern recognition.
Secondly, it is heavily useful for creating DLP-aided rules where it ensures that our data protection policies kick in by scanning documents and figuring out what documents should actually leave the company and what should not. It added a second guard rail layer other than our Purview DLP, which enabled us with a second form factor for checking that no sensitive information is going outside the company.
It has been an enabling tool where it has enabled us to not be actively involved with going through emails and understanding user behavior to sit and determine what kind of user behavioral metrics we should be looking at to catch threat vectors. This has been really valuable where it is able to automate that entire process. The AI layers ensure that we have an end-to-end clarity on what is happening, and the way they enrich our data set in terms of the classifications they provide for why they have flagged it for DLP add value to what they actually do.
What needs improvement?
Improvement-wise, just because I have other clients who use Abnormal and Material Security, I can say Mimecast Insider Risk Management and Data Protection's dashboard is not that user-appealing, where someone would actually go through their dashboard and figure out metrics. Additionally, navigating their platform is not the top product. These are things they could improve on and that would add really value.
For how long have I used the solution?
I have been using Mimecast Insider Risk Management and Data Protection for around four and a half years. It started with CWG, but I am currently using it as a client.
What do I think about the scalability of the solution?
Mimecast Insider Risk Management and Data Protection is pretty scalable, especially the way it is deployed.
How are customer service and support?
They have a really good response time. The mean time to detect to mean time to respond from their end is somewhere between 15 minutes to 20 minutes. I would rate the customer support a 10.
Which solution did I use previously and why did I switch?
We were using Trend Micro and the client wanted us to move away from it.
What was our ROI?
Two things stand out: money saved and time saved. We were always a smaller team, but time saved and money saved is where I can provide ROI. I would say somewhere around 5% ROI. In terms of the time complexity saved, probably around a day of an analyst looking at data has turned into only 15 minutes of the analyst looking at data.
What other advice do I have?
It is not caught something per se that Purview DLP missed, but because Purview DLP is set in a way where we go into the portal and we look at alerts as compared to getting actively notified for it, we tend to not get to it until a certain point of the day when we open and go through those tickets, which leads us to look at DLP related emails. That said, Mimecast Insider Risk Management and Data Protection did catch onto that in parallel to Purview, and it immediately notified us of it. That is where I would say it had the edge over Purview, just because we have not configured Purview in a way where we have active notification set up.
Fewer incidents in terms of actual exploits going through as compared to detections stand out. We still get a lot of detections, but that is the best feature, where it is making sure those do not come through. It is keeping domain knowledge of which domain should be blocked because they are carrying malicious payloads. Another thing that got us was that it has the ability to check that even if some vendor has been marked safe, it still goes through vendor behavior as well. It has an understanding of how a vendor communicates with us. Because of that, it is able to catch onto some alerts which would have gotten missed otherwise.
I would rate Mimecast Insider Risk Management and Data Protection around an eight. The dashboard is the only piece that would take it to a 10. I would recommend people to take the product based on what their needs are and what their budget requirements are, because that is what finally comes down to getting this product. My overall review rating for this product is 8.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Email protection has reduced phishing incidents and provides clear visibility into mail flow
What is our primary use case?
I have been using Mimecast Insider Risk Management and Data Protection for five years.
My main use case for Mimecast Insider Risk Management and Data Protection is to trace phishing emails, block users, and create policies when necessary. We use Mimecast Insider Risk Management and Data Protection to manage our mail flow.
In a specific example of how I traced a phishing email using Mimecast Insider Risk Management and Data Protection, we have a sender address, and through that address, we enter it to see how many users received those emails. We check records including SPF, DKIM, and DMARC, along with the sender's IP address. If we find the IP address indicates that the sender is suspicious, we block the sender address to prevent future emails.
All aspects of my main use case with Mimecast Insider Risk Management and Data Protection function properly.
What is most valuable?
Mimecast Insider Risk Management and Data Protection offers several best features, including being a very user-friendly tool where we can easily create policies, add or remove users, and block sender addresses or links, making it very useful for email protection.
Integration is also easy with Mimecast Insider Risk Management and Data Protection, as we can easily implement this in our Outlook client to scan emails and protect our environment from phishing threats.
Mimecast Insider Risk Management and Data Protection has positively impacted my organization because we are using it in its full version. We receive notifications and reports if we encounter any issues. When users report emails, we can check whether they are legitimate or blocked and advise them not to accept suspicious emails, making it very useful for data protection.
What needs improvement?
Mimecast Insider Risk Management and Data Protection can be improved by enhancing policies and rules.
One improvement I would suggest is to create a dashboard where we can view all data, such as how many emails we receive and how many get blocked, rather than having to go through subfolders. A dashboard would allow us to easily check everything on one screen.
For how long have I used the solution?
I have been working in my current field for nine years.
How are customer service and support?
Mimecast Insider Risk Management and Data Protection's customer support was good overall, but sometimes we did not receive timely responses, needing to wait two to three days for updates.
Which solution did I use previously and why did I switch?
We did not use a different solution before Mimecast Insider Risk Management and Data Protection. We started with the default Microsoft setup and then implemented Mimecast Insider Risk Management and Data Protection.
Which other solutions did I evaluate?
I did not evaluate other options before choosing Mimecast Insider Risk Management and Data Protection.
What other advice do I have?
I recommend considering Mimecast Insider Risk Management and Data Protection, as it is a very useful and user-friendly tool to protect our Exchange environment.
I can share specific outcomes where we have noticed a reduction in phishing incidents. Many times, we receive phishing emails in our environment. If emails reach user mailboxes, users can report any suspicious emails they encounter. When they report, we get the notification, and as admins, we scan those emails and check all relevant details.
I would rate this product an 8 out of 10.
Advanced protection has secured email, stopped phishing, and prevented data leakage
What is our primary use case?
I have been using Mimecast Insider Risk Management and Data Protection for around two years for data protection and risk management. It is used for email security protection against phishing attacks, malware, ransomware, and data leakage to protect the organization's email security.
What is most valuable?
Mimecast Insider Risk Management and Data Protection filters malicious emails, protects attachments and URLs, maintains email continuity during outages, and archives email for compliance. It protects from malicious URLs, credential theft, phishing websites, and newly created malicious URLs while preventing harmful attachments. The solution scans attachments before delivery and detects ransomware, trojans, and zero-day malware. Additionally, it protects from impersonation attempts; if someone impersonates a business email, it stops CEO fraud and business email compromise. It effectively prevents sensitive information from leaving the organization.
The best features Mimecast Insider Risk Management and Data Protection offers are URL protection, attachment management, impersonation attempts protection, and blocking senders. As I work in email security, URL protection and blocking senders are the most valuable features, and we use them day-to-day in our business.
Mimecast Insider Risk Management and Data Protection stops phishing by combining SPF, DKIM, and DMARC validation with anti-spam, impersonation protection, URL protection, attachment sandboxing, and machine learning-based threat protection to identify and block phishing attempts.
I track messages, release quarantined emails, manage policies, and investigate phishing incidents through Mimecast Insider Risk Management and Data Protection, which protects our organization positively.
What needs improvement?
Mimecast Insider Risk Management and Data Protection already provides data loss prevention through content examination and email encryption; however, the insider risk management and data protection could be enhanced by adding more intelligent, behavior-based detection and integration with enterprise security tools.
I wish for better integration with SIEM and XDR, specifically improved integration with platforms such as Splunk, Microsoft Defender, and Sentinel.
Mimecast Insider Risk Management and Data Protection is already providing strong email security and data loss prevention capabilities, but the insider risk management could be enhanced by adding advanced user behavior and analytics, including AI-based risk scoring and more context-aware data loss prevention policies. Deeper integration with SIEM and XDR platforms would improve visibility across the security system, and with better data classification and adaptive security policies, it would help reduce false positives and prevent sensitive data from leaving the organization.
For how long have I used the solution?
I have been working in the cybersecurity domain for almost four years.
What do I think about the stability of the solution?
Mimecast Insider Risk Management and Data Protection is stable for our organization.
What do I think about the scalability of the solution?
Mimecast Insider Risk Management and Data Protection is delivered as a cloud-native SaaS architecture, so customers do not need to buy or maintain email security servers. As the organization grows, Mimecast scales its cloud resources to handle increased demand, providing easy user expansion and high email processing capacity.
How are customer service and support?
Mimecast Insider Risk Management and Data Protection provides technical support to help customers deploy, manage, and troubleshoot its email security services. Mimecast Insider Risk Management and Data Protection provides enterprise technical support through its support portal, phone, email, and an extensive knowledge base, so their support team assists with mail flow issues, email delivery, and policy management threat protection as well. Since it is a SaaS platform, software updates and security enhancements are managed by Mimecast, and I highly recommend Mimecast Insider Risk Management and Data Protection for email security.
Which solution did I use previously and why did I switch?
I did not previously use a different solution before Mimecast Insider Risk Management and Data Protection.
What was our ROI?
The main benefit is time saved; I am not sure about money saved, but it is definitely time saved.
Which other solutions did I evaluate?
Our client has chosen Proofpoint over Mimecast Insider Risk Management and Data Protection because they are highly recommended to the Proofpoint solution rather than Mimecast Insider Risk Management and Data Protection.
What other advice do I have?
Mimecast Insider Risk Management and Data Protection is using artificial intelligence and machine learning to improve email security by analyzing and identifying threats; for example, a new phishing email pretending to be from Microsoft 365 may be blocked because AI identified suspicious language and sender characteristics.
It can help detect phishing, business email compromise, spam, malicious URLs, and suspicious attachments by analyzing email content.
In the future, AI could further enhance Mimecast Insider Risk Management and Data Protection through advanced user behavior analytics and AI-assisted incident investigations. I provide this review with a rating of 8 out of 10.
Behavior correlation has improved insider risk detection and simplifies daily threat monitoring
What is our primary use case?
Mimecast Insider Risk Management and Data Protection serves as a risk management solution that monitors user activity signals across M365 services including email, SharePoint, OneDrive, Teams, and endpoint activity.
On a daily basis, I use Mimecast Insider Risk Management and Data Protection to monitor new risk threats, high severity cases, user flags, and level scores by checking the risk management dashboard. Currently, there are no primary use cases within my organization beyond this monitoring function.
What is most valuable?
Mimecast Insider Risk Management and Data Protection offers behavior correlation as one of its best features, which provides risk-based user profiling and rule-based triggers.
This functionality helps my team because it compiles signals from emails, Teams, SharePoint, and OneDrive endpoints more quickly. The solution connects multiple actions over time and builds a comprehensive risk picture of each user.
Mimecast Insider Risk Management and Data Protection has positively impacted my organization by enabling investigation of risk behavior and user behavior, reducing potential data leakages, improving awareness of sensitive data handling across users, strengthening compliance with internal policies and regulatory requirements, and streamlining incident investigation through centralized case management. Overall, it has enhanced my organization's ability to proactively identify insider threats while minimizing manual effort for the security and compliance team.
What needs improvement?
Improvements could be made through AI-based risk explanations to provide better guidance on necessary enhancements to the platform.
What other advice do I have?
I cannot provide specific metrics regarding the reduction of manual effort. Regarding Mimecast Insider Risk Management and Data Protection's AI capabilities, its governance capabilities are not as deep or unified as purpose-built insider risk platforms such as Microsoft Purview.
I have observed false positives because the solution is rule-based. My review rating for this solution is 9.
Email protection has reduced phishing and spam by enabling precise domain and user controls
What is our primary use case?
My main use case for Mimecast Insider Risk Management and Data Protection includes blacklisting the domain, privacy suppression, creating new groups, creating new rules, checking the domain, checking the conflict of the mails, and managing spam mails.
In my current organization, we receive a lot of spam mails and phishing mails, so we blacklist the domain name by going into Mimecast Insider Risk Management and Data Protection, accessing the privacy suppression feature, and adding that domain. Once we add that domain, it is blacklisted, and we will not receive any mails from that particular domain in our tenant.
Whenever unwanted mail is sent to our tenant, we receive a ticket to action, which involves going into Mimecast Insider Risk Management and Data Protection to blacklist the domain or add it to privacy suppression.
What is most valuable?
The best feature of Mimecast Insider Risk Management and Data Protection is that once I add the domains to be blacklisted or create an exclusion list or add domains in the privacy suppression, I never receive mails from similar domains, which safeguards our tenant effectively. Additionally, we can whitelist specific users from blacklisted domains, which is a great and helpful feature.
The flexibility of Mimecast Insider Risk Management and Data Protection helps my organization by ensuring we do not receive mails from unwanted domains that often carry fraudulent offers or phishing attempts, like those with fake domain names. If we have blacklisted a domain but need to receive mail from a particular user, we add that user's email ID to the allowed user list.
Mimecast Insider Risk Management and Data Protection handles incident response effectively by integrating with our ticketing system, allowing for timely action when unwanted mails are received. It integrates well with other security tools like CrowdStrike, SentinelOne, and Microsoft Defender, providing in-depth insights while safeguarding against unwanted and suspicious mails.
What needs improvement?
Everything in Mimecast Insider Risk Management and Data Protection is good, and nothing requires improvement. However, I would suggest adding features like AI and automation, as this application is used by various teams, and automating processes like blacklisting unwanted email domains could greatly benefit users and customers.
Mimecast Insider Risk Management and Data Protection should provide the flexibility to customize the application features based on the company's needs.
For how long have I used the solution?
I have been using Mimecast Insider Risk Management and Data Protection for four years.
What do I think about the stability of the solution?
Mimecast Insider Risk Management and Data Protection is stable.
What do I think about the scalability of the solution?
I would rate the scalability of Mimecast Insider Risk Management and Data Protection around 9.5, as it is highly scalable and widely used by many organizations, including large enterprises.
How are customer service and support?
The customer support for Mimecast Insider Risk Management and Data Protection is really good. I would rate the customer support a perfect 10.
Which solution did I use previously and why did I switch?
I have never used a different solution; we have always been with Mimecast Insider Risk Management and Data Protection. Before choosing Mimecast Insider Risk Management and Data Protection, we evaluated options such as Defender and Sophos, but found Mimecast Insider Risk Management and Data Protection to be the best.
How was the initial setup?
Integrating Mimecast Insider Risk Management and Data Protection with our existing systems was really easy and not difficult at all.
What was our ROI?
While I cannot quantify savings in money, Mimecast Insider Risk Management and Data Protection has significantly saved time and enhanced our environment's security from attacks and threats.
What's my experience with pricing, setup cost, and licensing?
I find the pricing, setup cost, and licensing of Mimecast Insider Risk Management and Data Protection to be reasonable; it is not overly high or low, given the quality of service and customer support provided.
What other advice do I have?
Mimecast Insider Risk Management and Data Protection is useful and beneficial for securing the environment and matching compliance policies, making it worth buying the license.
I find Mimecast Insider Risk Management and Data Protection to be a great application that safeguards the complete tenant and manages mail flow smoothly. Over the past four years of using this application, I have never encountered any conflicts between the mailing services and Mimecast Insider Risk Management and Data Protection, making it an excellent choice for security and threat intelligence.
Mimecast Insider Risk Management and Data Protection has positively impacted my organization by protecting us from a lot of unwanted spam and phishing mails, as users are often unaware of what to click on in emails. It has helped safeguard our complete tenant from these types of threats.
Since using Mimecast Insider Risk Management and Data Protection, the unwanted mails for our tenant have decreased by 95% compared to before we migrated to this application.
Currently, I work in a production company, and it is very useful in day-to-day life, such as blacklisting domains and safeguarding our tenant and users from spam mails, phishing mails, and vulnerability management. It quarantines unwanted mails quickly and easily, providing safety and protection from threat attacks.
Mimecast Insider Risk Management and Data Protection integrates well with other security tools like CrowdStrike, SentinelOne, and Microsoft Defender, providing in-depth insights while safeguarding against unwanted and suspicious mails.
I would rate Mimecast Insider Risk Management and Data Protection a nine out of ten.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Email protection has eliminated incidents and now secures sensitive data and insider risks
What is our primary use case?
I use it for email threat protection or DLP in my day-to-day work by enabling the impersonation protection, attachment protection, URL protection, and also enabling the DKIM, DMARC, and SPF record. I also enable all the spam filters, create the proper policies, profile group policies, and other things.
How has it helped my organization?
Since implementing Mimecast Insider Risk Management and Data Protection, I have seen specific outcomes such as achieving zero incidents over the last five years.
What is most valuable?
Out of all those features, I find preventing sensitive data leaks as well as inside threat detection and DLP the most valuable and essential.
What needs improvement?
Regarding Mimecast Insider Risk Management and Data Protection's AI capabilities, I think its governance and security are effective because it has reduced false positives in data protection as well as inside risk alerts, improved real-time detection of data exfiltration attempts, expanded monitoring to email, M365 teams, SharePoint, increased automation for incident response and remediations, and improved integration with SIEM and SOAR.
I find Mimecast Insider Risk Management and Data Protection's AI accuracy and reliability of its output to be consistent and trustworthy for my organization.
For how long have I used the solution?
What do I think about the stability of the solution?
What do I think about the scalability of the solution?
How are customer service and support?
Which solution did I use previously and why did I switch?
I switched from Proofpoint to Mimecast Insider Risk Management and Data Protection because Proofpoint is not accurate, not user-friendly, and has more false positives compared to Mimecast Insider Risk Management and Data Protection.
How was the initial setup?
What about the implementation team?
What was our ROI?
What's my experience with pricing, setup cost, and licensing?
Which other solutions did I evaluate?
What other advice do I have?
I observed that the AI-powered risk score has improved, with automation in place using AML, so that most threats are detected and there are fewer false positives. I gave this product a 10 out of 10 rating because of these capabilities.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Email defenses have stopped outsider threats and protect sensitive data with clear user guidance
What is our primary use case?
Mimecast Insider Risk Management and Data Protection is used to identify all risks that have been identified in my current client's environment. The solution is applicable at the gateway level and serves to stop outsider threats from invading our environment. Regarding data protection, we have implemented the DLP part so that insider employees do not share sensitive information with outsiders.
We have various DLP rules implemented into Mimecast Insider Risk Management and Data Protection. One such rule involves setting the email content to trigger on specific words. When any sensitive word from our defined set is detected, the DLP rule triggers and notifies our team. We have also implemented Mimecast secure email messaging, where any documents sent to external parties must be shared via the Mimecast secure email gateway only so that documents do not get leaked. Through Mimecast, we are working to secure our environment.
What is most valuable?
The best features Mimecast Insider Risk Management and Data Protection offers are the banner, which is the CyberGraph feature, and the DLP rules.
Regarding the CyberGraph feature, we recently implemented it. For a company with thousands of employees, it is quite difficult to make every user understand phishing emails, not to click on links, or open attachments, even with user awareness sessions. In that case, CyberGraph helped because it comes with a banner. When a user receives an email, a banner appears in different color codes before the email body. This makes the user aware and forces them to read what is written on the banner. This is what helps us rely on Mimecast Insider Risk Management and Data Protection, as we do not need to personally conduct user awareness. It has helped a lot. Regarding the DLP rules, they are quite efficient and very easy to understand from a Mimecast perspective. That is what I liked.
Mimecast Insider Risk Management and Data Protection has had a great impact. It has helped us to manage outsider threats from invading our environment in a very effective way.
What needs improvement?
Mimecast Insider Risk Management and Data Protection is good, user-friendly, and has a nice UI. I do not think there should be any improvement at this time. Everything I have used has been user-friendly, so I do not think there is any improvement I need to suggest.
For how long have I used the solution?
I have been using Mimecast Insider Risk Management and Data Protection for almost one year.
How are customer service and support?
The customer support is amazing.
Which solution did I use previously and why did I switch?
We were using Mimecast Insider Risk Management and Data Protection from the beginning.
What was our ROI?
I have not seen a return on investment.
Which other solutions did I evaluate?
We did not evaluate other options. We were going with Mimecast only.
What other advice do I have?
My experience using Mimecast Insider Risk Management and Data Protection has been great. Before, I did not have any experience with Mimecast or any email security tools. When I first saw the interface and the UI of Mimecast, it was so user-friendly and simple to understand. A person with no background in email security can still learn and use Mimecast Insider Risk Management and Data Protection and practice on it within a few weeks. That is what makes Mimecast Insider Risk Management and Data Protection user-friendly.
Mimecast Insider Risk Management and Data Protection is amazing. I have found it very trustworthy. I would simply tell others to go with Mimecast Insider Risk Management and Data Protection because it is user-friendly and amazing. I rate this product nine out of ten.
Targeted phishing attacks have been managed efficiently and email threats are analyzed faster
What is our primary use case?
The main usage of Mimecast Insider Risk Management and Data Protection for me, coming from a security background, involves handling the daily phishing emails we receive. I use Mimecast message tracking and email preview features to determine whether emails are phishing and to take relevant actions accordingly.
A week ago, we received a phishing email in Defender, and Mimecast Insider Risk Management and Data Protection helped us handle it. I took the data to Mimecast and applied relevant filters in message tracking. I discovered that the framework values for SPF and DKIM were not matching, and the spam value was high. After pulling the header from Mimecast and analyzing it, I observed some delays that led me to conclude the email was likely phishing.
This is the primary function I perform with Mimecast Insider Risk Management and Data Protection.
What is most valuable?
The best features offered by Mimecast Insider Risk Management and Data Protection include message tracking and attachment information. If an email contains any attachment, the system displays it and allows me to download it for review. The email preview feature enables me to view incoming emails.
Message tracking is the game changer for me in Mimecast Insider Risk Management and Data Protection. I can filter any email information based on sender address, subject, and attachment information, and I can gather relevant data such as frameworks, whether they are passing or not, and the header.
Mimecast Insider Risk Management and Data Protection has positively impacted our organization because before implementing this tool, when we received phishing emails, we did not have an appropriate tool to check the framework. We only analyzed emails from a grammar perspective, and many phishing emails reached user inboxes. Since Mimecast has been introduced into our system, we have been very effective at tackling phishing emails and helping our organization remain secure.
What needs improvement?
Mimecast Insider Risk Management and Data Protection can be improved in the user interface. The UI is still very outdated and not functional, and there is no AI chatbot that would help us navigate through the interface.
I believe that Mimecast Insider Risk Management and Data Protection could improve the attachment info option. Sometimes it is glitchy, and occasionally the format is not proper, making it difficult to download the attachment and review it.
Regarding the AI capabilities of Mimecast Insider Risk Management and Data Protection, the governance and security features are very strong, but it is still lacking in AI features.
What do I think about the stability of the solution?
Mimecast Insider Risk Management and Data Protection has been very stable in my experience. The logs have been flowing through Sentinel without any log shortage, and all features are working very well.
What do I think about the scalability of the solution?
The scalability of Mimecast Insider Risk Management and Data Protection depends on the organization. If you purchase more features, it will be more scalable at that point.
How are customer service and support?
Customer support for Mimecast Insider Risk Management and Data Protection is adequate, but I would not say it is excellent. We raised a vendor ticket for one of the features, and the response was within 28 to 48 hours. While not quick, we do eventually receive a resolution.
Which solution did I use previously and why did I switch?
There was no solution before Mimecast Insider Risk Management and Data Protection. It was the first solution we used regarding email security.
What was our ROI?
I have seen a return on investment since using Mimecast Insider Risk Management and Data Protection. It has definitely saved us considerable time. Previously, everything had to be done manually, and we were still unable to achieve our goals of catching phishing emails. Since Mimecast has been introduced, it has been saving us significant time. Money has also been saved, as our stakeholders made an investment in the tool. If we properly secure the environment through this tool, it indirectly helps save money.
What's my experience with pricing, setup cost, and licensing?
Regarding pricing, setup cost, and licensing for Mimecast Insider Risk Management and Data Protection, these are decisions that stakeholders make, and I am the one actually using the tool, so I am not fully aware of these details. However, regarding licensing, in our team, everyone has separate roles we are working with, leading to limited access.
Which other solutions did I evaluate?
Before choosing Mimecast Insider Risk Management and Data Protection, I believe we evaluated Proofpoint as a comparison. However, because Mimecast has a strong reputation, we chose it instead.
What other advice do I have?
The advice I would give to others looking into using Mimecast Insider Risk Management and Data Protection is that there are many features in this tool. Make sure when you purchase this tool that you go through the catalog, and after buying, explore every field because not everything is in the dashboard itself. You need to go into depth to understand how those features can help you in your day-to-day security work. I would rate this product an 8 overall.
Email security has improved and real-time insights simplify managing complex mail flows
What is our primary use case?
I manage an organization with more than five thousand employees who are all in either on-site or hybrid environments and receive multiple emails every day. The email flow on a daily basis is too much to handle manually. Emails can be sent from approved domains, or they can be spam or other unwanted messages. I cannot reveal my customer's name, but I can say that they are in the shopping business. Since they are in the shopping business, they receive multiple mail flows from the sales team and regular communications, and it becomes very crucial to differentiate which emails are useful and which are not.
On a daily basis, I check whether the mail flow is within the established threshold. Unless there are end-of-season sales occurring, I do not see a high mail flow that exceeds the threshold we observe. I evaluate the detections I am seeing, and in Mimecast Insider Risk Management and Data Protection, I can see detections based on various time frames, such as twenty-four hours, forty-eight hours, or whatever custom time frame I choose. The maximum limit according to our enterprise is thirty days. Since I need to see activity in real time, I analyze whether all the respective mail flows are coming in and what category they fall under. The categories can include malware, spam, extortion campaigns, or multiple others.
I analyze that data by fetching the raw logs for my customer, checking the spam scores for their emails, and reviewing statuses such as accepted, rejected, held, deferred, and more. I analyze whether Mimecast Insider Risk Management and Data Protection's policies work properly. I cannot just rely on it being a SaaS-based product with enabled policies working correctly. There are many use cases where I have seen emails being delivered that should not have been delivered. That does not make Mimecast Insider Risk Management and Data Protection a bad product; it means that I have not fine-tuned the policy to my organization's expectations. Once I work on the tool daily, I understand the mail flow, recognize which emails fall into the spam category, and compare them not only on the Mimecast Insider Risk Management and Data Protection database but also with external comparison tools like MX Toolbox or VirusTotal to analyze things. This gives an overview of what my general scenario looks.
How has it helped my organization?
The way attachments are being read by Mimecast Insider Risk Management and Data Protection is crucial, especially concerning what data is sent outside the organization from the internal network and what kind of data is being sent from outside to inside. This can include URLs, file types, PDFs, and other content. The OEM team has blocked many widely recognized malicious file types themselves, which helps in rejecting emails that people try to send containing malicious content. For PDFs specifically, which are sent regularly, it becomes crucial that if an authorized user sends something for business purposes, it should go through; however, if Mimecast Insider Risk Management and Data Protection flags it as suspicious or the domain user is not whitelisted, that is completely fair.
Mimecast Insider Risk Management and Data Protection performs its share of detection, and I have even tested it with a very large file, such as an eight-hundred-page document where only one or two hyperlinks were malicious content. Mimecast Insider Risk Management and Data Protection detected that immediately. Comparatively, other specific technologies did not block it even when I temporarily removed the sending limit that some mail tools impose, for example, only sending up to five to twenty MB. In that testing scenario, Mimecast Insider Risk Management and Data Protection shines with how policy enforcement and data protection is implemented. Secondly, it shows the top malicious senders for the week or whatever time frame I desire, illustrating which users were targeted the most. It does not just present a list; clicking on a user reveals who exactly sent the emails, the sending mail category, and more specifically regarding the targeting of the user.
The emails can fall into categories such as ransomware, spam, or impersonation, indicating whether a legitimate email has failed DKIM or DMARC validation, which Mimecast Insider Risk Management and Data Protection detects efficiently. While other tools also identify these aspects, Mimecast Insider Risk Management and Data Protection clarifies how everything works quite well. In day-to-day work, one key point I would definitely highlight is log fetching. Many other tools make fetching logs tiresome and irritating; every log search requires so much hassle with filtering. In contrast, Mimecast Insider Risk Management and Data Protection enables me to just paste the mail ID, and it finds everything automatically, fetching all relevant logs in one place without needing to differentiate between statuses such as rejected or accepted. It offers specific groups including permitted senders, trusted senders, and blocked senders. It is all clean and sophisticated. Having worked with various tools and technologies before, I can say that tools such as this should exist; they ought not to be complex. During troubleshooting calls, I should not be figuring out why the tool does not provide the required logs; it should be quick.
The SSO integration in Mimecast Insider Risk Management and Data Protection works securely and smoothly, functioning across all browsers. However, I must mention that at times, the homepage of Mimecast Insider Risk Management and Data Protection takes too long to load, which I am personally not complaining about, but colleagues have reported slow loading on rare occasions.
What is most valuable?
Mimecast Insider Risk Management and Data Protection has a very clean interface, which makes it easy to use effectively once it is handed over to the organization. I can actually ask the Mimecast Insider Risk Management and Data Protection team how to understand the tool, and they have guidelines and documentation that provide all the necessary information. Mimecast Insider Risk Management and Data Protection offers several features beyond policies and digest notifications, such as message digest notifications that I receive. It helps in understanding trace paths very well. What I mean by trace path is that when a user is sitting inside the organization and wants to send an email to an outside domain, it will not be sent directly.
First, the email goes to the Microsoft Outlook mail server. From there, an SMTP request is initiated to Mimecast Insider Risk Management and Data Protection. Once the SMTP connection is established, the email gets forwarded from the specific sender mail server to the receiver mail gateway, which is Mimecast Insider Risk Management and Data Protection. Now, from the Mimecast Insider Risk Management and Data Protection gateway, the email gets analyzed. It runs through policy checks, checks for permitted blocks, trusted senders, and frequent sender information, analyzing whether I have received some specific emails from this user and whether any of them were flagged. It goes through the database, and post all Mimecast Insider Risk Management and Data Protection internal checks, the email is verified as acceptable and is good to go.
Once verified, the email goes out to the recipient's mail server. There may be a mail server at the recipient's mail end as well, but that is not my concern since I do not manage that. It then reaches the user's inbox. Many times, the organization's control includes complaints such as not receiving the email, or the email was rejected or the attachment was missing. Why do those things happen? Mimecast Insider Risk Management and Data Protection provides a clear idea through the message delivery option, where I input the from ID and to ID for a specific timeframe, and I can see what headers were captured in the emails in a completely raw format, policies that were hit, the spam score, detections, and the exact reason for these events.
The theoretical aspects are acceptable, but the best part is the clarity it provides on the connection between the sender and recipient SMTP, such as start and end time. It shows when the connection was made to Mimecast Insider Risk Management and Data Protection, when the email got delivered, the time Mimecast Insider Risk Management and Data Protection took to establish that connection to the recipient's mail server, and when Mimecast Insider Risk Management and Data Protection sent that email. It provides thorough clarity for understanding exactly where the delay lies, including how much time Mimecast Insider Risk Management and Data Protection took for internal processing before the email went out. Many times, the blame is placed on the tool that it is not functioning properly, but those logs allow me to verify the problem's exact location. The report generation is quite easy. For policy creation, I cannot create a new policy, but almost all the policies that an organization could need are present. The interface is good—I am saying this again, but it is.
Moreover, the access level, such as the access matrix, is pretty clearly defined—basic administrator, read-only access, custom IT help desk, super administrator, and one in between, based on the plan taken for Mimecast Insider Risk Management and Data Protection. Mimecast Insider Risk Management and Data Protection learning community is something I recommend; I have done certification for them and am preparing for their advanced certification. The certification is really helpful; I learned through experience mainly, but anyone can start from the original OEM certification. There are helpful documentations and multiple tests as part of the courses, which range from ten to twelve hours for basic and advanced exams.
What needs improvement?
A con to mention is that Mimecast Insider Risk Management and Data Protection, at times, may not capture everything. For instance, the time that Mimecast Insider Risk Management and Data Protection took to process something such as incoming email is normally fifteen to twenty seconds, which is completely normal. Though the email is released, delays of ten to twenty minutes may be experienced, which does not get captured in Mimecast Insider Risk Management and Data Protection. It may show delays on the recipient's mail server end, but creates a contradiction since in Mimecast Insider Risk Management and Data Protection I do not see any delay, while the recipient's mail server indicates a delay occurring at Mimecast Insider Risk Management and Data Protection.
For testing, I whitelisted the specific domain for the sender's email. After whitelisting that, the delay disappeared, yet I wonder why Mimecast Insider Risk Management and Data Protection did not capture that in this specific log. This issue has not occurred often, maybe once or twice in the past six to seven months, but understanding that aspect has led me to reach out to OEM. They provided their views, but I was not very satisfied; they could show where it is getting captured and why it is not highlighted clearly. That is a con of Mimecast Insider Risk Management and Data Protection, but overall, it is a great tool. Mimecast Insider Risk Management and Data Protection is totally recommended. The policies are solid, they work effectively, the implementation time is not very long, integrations with SIEM are quite easy, and the Glassbreak account is something I have tested, making Mimecast Insider Risk Management and Data Protection better in this regard. Overall, it is a great tool.
For how long have I used the solution?
I have been using Mimecast Insider Risk Management and Data Protection for one and a half years.
What do I think about the stability of the solution?
Mimecast Insider Risk Management and Data Protection is definitely stable without fail based on my experience.
What do I think about the scalability of the solution?
Mimecast Insider Risk Management and Data Protection scales efficiently. In the last two months, I saw a high volume of inbound email, including spam and fraudulent emails. The tool effectively detected both malware and spam, ensuring that only a few emails categorized as malware reached user mailboxes. For malicious content, Mimecast Insider Risk Management and Data Protection performs adequately, blocking suspicious formats while still validating the email's content.
How are customer service and support?
Customer support for Mimecast Insider Risk Management and Data Protection is excellent. I rarely face issues, usually resolving in two to three business days when necessary.
Which solution did I use previously and why did I switch?
I am not certain about the primary solution used before switching to Mimecast Insider Risk Management and Data Protection, as I did not oversee its initial deployment. I can tell you that switching involved considerations regarding costs, particularly with DLP vendors and mail control.
What was our ROI?
I am not certain about specific time savings with Mimecast Insider Risk Management and Data Protection as technical observations can be vague. However, time is definitely saved in practices, as the tool requires less hands-on management after fine-tuning. I can generate specific reports, including top malicious senders and domain statistics, presenting them during customer review sessions, and those analyses help justify needed blocks.
What's my experience with pricing, setup cost, and licensing?
I am unsure about Mimecast Insider Risk Management and Data Protection's pricing, setup costs, and licensing details. However, I know that licensing details are user-specific according to the license purchased. Information on current license details is easily accessible through the right-most side of the interface under support, showing information such as account manager details for the firm and expiration timelines. I can say that the OEM escalation metrics are good, and I have never faced delays in calls to support, though sometimes CSR has business day delays.
Which other solutions did I evaluate?
I did not evaluate other options before choosing Mimecast Insider Risk Management and Data Protection as I am an engineer focused on technical aspects.
What other advice do I have?
My advice for those looking at Mimecast Insider Risk Management and Data Protection is to compare your use case comprehensively. Do not just rely on reviews, as they offer communal insight; evaluate from a technical perspective and consider the stability of your infrastructure and how well it aligns with your operational needs moving forward. Be thorough in understanding the features that other users find critical and ensure they align with your specific requirements. I give this review an overall rating of eight out of ten.