Full-Time
Cloud-based email security, archiving, continuity
$144k - $216k/yr
Chicago, IL, USA
Remote
Remote within Illinois; territory includes Chicago North Central.
See people who can refer or advise you
Mimecast provides cloud-based cybersecurity services focused on email. It blocks phishing, malware, and spam, archives and indexes emails for compliance, and offers continuity to keep email access during outages. Revenue comes from subscription plans and it integrates with other cybersecurity tools to form a broader security stack for SMEs to large enterprises. Its goal is to reduce email-based risk, protect data integrity, and ensure uninterrupted communications across client organizations.
Company Size
1,001-5,000
Company Stage
IPO
Headquarters
London, United Kingdom
Founded
2003
See people who can refer or advise you
Help us improve and share your feedback! Did you find this helpful?
Health Insurance
Hybrid Work Options
Performance Bonus
blueAPACHE launches world-first Human Risk Management as a Service, powered by Mimecast. New managed capability addresses the growing human side of cyber risk for mid-market organisations, with Mimecast as the technology platform partner SYDNEY, 26 June 2026 blueAPACHE, Australia's most awarded mid-market IT services provider, has announced it is launching a Human Risk Management as a Service powered by Mimecast, the human, data, and AI security platform. Believed to be a world-first managed capability that brings together awareness training, policy visibility, behavioural controls, and incident remediation into a single, repeatable outcome-based service for mid-market organisations, blueAPACHE is the first Mimecast channel partner globally to bring this model to market. The service is designed for organisations with between 50 and 1,500 seats that are managing the competing pressures of regulatory compliance, security framework alignment, and the rapid adoption of AI and cloud-based tools. For these businesses, human risk has historically been addressed in fragmented ways across multiple service lines. Human Risk Management as a Service consolidates that into a clear, per-user monthly model that sits alongside blueAPACHE's managed services and managed detection and response bundles, giving customers a structured blueprint across the three core pillars of modern managed security. "In the mid-market, customers are buying an outcome, not a product," said Michael Zuppa, CEO of blueAPACHE. "What they need is a managed service that takes responsibility for awareness, cultural uplift, visibility, and remediation as a continuous, consistent capability. We have been delivering parts of this for years across our vCISO, email security, and awareness training services, but the structure was not clear enough for customers to engage with it as a whole. Human Risk Management as a Service changes that." The need for a dedicated human risk service reflects a persistent and growing reality in Australian organisations. The biggest security incidents continue to originate from email-based threats, phishing campaigns, and human error, including employees unintentionally breaking policy or moving sensitive data without realising the risk. The rapid adoption of AI tools has compounded this exposure, with individuals already using public AI services while data classification and DLP policies are still being developed. For mid-market organisations, the gap between current maturity and adequate protection is a live and immediate risk. "Human risk has always been the hardest part of the security equation to operationalise at scale," said Mimecast ANZ Partner Leader Lizelle Hughes. "blueAPACHE has developed something that will make meaningful change for Australian organisations. The reality is that 8% of employees generate 80% of risk, and AI agents now operate with the same access and none of the judgment that a human brings. Mimecast was built to detect and respond to that exposure across every channel where humans and AI agents work. This is the kind of outcome-focused thinking that moves the whole industry forward, and Australian organisations stand to benefit directly." As organisations progress through data classification and AI governance maturity programmes, blueAPACHE's Human Risk Management capability provides visibility, enforcement, and protection from day one, covering how data is being accessed, moved, and used across corporate and public AI environments while formal policy based frameworks and rules are in place. "Time is the risk," Zuppa said. "Organisations are already on an AI journey whether they are ready or not. We need to ensure the visibility and controls we have in place are protecting the customer while they are still working through their maturity. That is what this service is designed to do." Mimecast was selected as the platform technology partner underpinning the service following a structured assessment of MSP-aligned security platforms. blueAPACHE identified Mimecast as the leader in the category based on its human risk command centre capability, the breadth of its visibility layer, the strength of its structured training and reporting tools, and its demonstrated commitment to MSP operational requirements including flexible subscription models, licence management, and service delivery at scale. The Human Risk Management as a Service offering is now live with customers. The partnership also reflects blueAPACHE's broader relationship with Mimecast as both a managed service delivery partner and a credible resell and implementation partner across its enterprise customer base, drawing on deep operational experience with the Mimecast platform built over many years. About blueAPACHE blueAPACHE is Australia's most awarded mid-market IT services provider. Founded in 1998, it is an Australian owned organisation specialising in Managed Services, cloud, security, and modern workplace solutions for mid-market and enterprise customers. blueAPACHE delivers outcome-driven services underpinned by strong security standards and operational discipline, supporting highly regulated and rapidly scaling organisations across multiple industries. About Mimecast Mimecast protects the work of every person in the organization, across every channel, from every actor, human and AI. Founded in 2003 and headquartered in London, Mimecast serves more than 42,000 organizations and 27 million users worldwide. Mimecast analyses 24 trillion behavioural signals annually across email, collaboration, and AI agent workflows, drawing on a 20+ year behavioural baseline that no competitor matches. blueAPACHE secure humans, data & AI.
Top product launches at RSAC 2026. RSAC 2026 showcased a wave of innovation, with vendors unveiling technologies poised to redefine cybersecurity. From AI-powered defense to breakthroughs in identity protection, this year's conference delivered a glimpse into the future. Here are the most interesting products that caught its attention, and could shape what's next. Astrix Security has revealed a major expansion of its AI agent security platform, covering every layer where AI agents operate in the enterprise: from managed AI platforms to shadow deployments running on managed devices, detecting both agent existence and unauthorized access to enterprise resources, and enforcing policy over what agents are allowed to do. Bonfy.AI announced Bonfy Adaptive Content Security (Bonfy ACS) 2.0, a platform built to secure enterprise content across all systems, applications, and AI agents - anywhere data moves, resides, or is processed. Bonfy delivers real-time, contextual protection across email, SaaS apps, collaboration tools, browsers, cloud and on-prem file stores, AI systems, and agent frameworks, so enterprises can safely accelerate AI adoption without flying blind. The Vellox suite showcases how AI-native cyber defense can counter growing threats to U.S. national security and critical infrastructure. The product suite is fueled by more than 30 years of technology, tradecraft, and adversarial insights. Booz Allen's cyber operators are engaged at the center of nearly all major commercial and federal cyber missions, enabling singular insight when developing and deploying military-grade offensive and defensive products for U.S. federal, defense, and intelligence customers as well as Fortune 500 and Forbes Global 2000 companies. Black Duck has announced the general availability of Black Duck Signal, an agentic AI application security solution purpose-built to secure AI-generated code in autonomous development workflows. Signal introduces a new model for application security: agentic AI augmented by decades of human-curated security context. Delivered as an agentic AI solution, Signal enlists a coordinated system of specialized AI security agents that draw on ContextAI, Black Duck's application security model, to analyze code, assess impact and guide remediation actions in real time. Cisco has introduced solutions to address AI security issues and remove a top barrier to agent adoption. By establishing trusted identities, enforcing strict zero trust Access controls, hardening agents before deployment, enforcing guardrails at runtime, and giving SOC teams the tools to stop threats at machine speed, Cisco is building security into the foundation of the emerging AI economy. Mimecast has announced a major expansion of its Incydr offering with new data security capabilities and a preview of the Agent Risk Center. These enhancements deliver runtime data security through a unified approach to detect, govern, and remediate data exposure in real time, whether driven by employees or agents acting on their behalf. Novee introduced AI Red Teaming for LLM Applications for its AI penetration testing platform, designed to uncover security vulnerabilities in LLM-powered applications before attackers can exploit them. Unlike conventional application security tools built for web and infrastructure testing, Novee's AI pentesting agent is specifically designed to continuously probe AI-enabled applications. The agent autonomously simulates real-world, sophisticated attack scenarios and chaining techniques together to identify vulnerabilities that manual testing or static scanners often miss. Dashlane has unveiled Omnix AI Advisor, a natural-language AI security assistant embedded into the Dashlane Omnix platform. Built upon Omnix's advanced credential protection and visibility capabilities, Omnix AI Advisor accelerates enterprises' transition to a proactive security posture by turning real-time credential risk data, such as dark web exposure and phishing logs, into contextual, actionable intelligence. Palo Alto Networks has advanced its AI security platform with Prisma AIRS 3.0, securing the agentic AI lifecycle and enabling enterprises to move from observation to safe autonomous execution. Prisma AIRS replaces fragmented point solutions with a single platform to manage the primary threats and risks of AI apps and autonomous agents. The new capabilities allow teams to future-proof their operations as agent ecosystems evolve. Stellar Cyber has introduced agentic AI to cut alert noise and speed investigations, changing how SOC teams operate. The enhancements advance its autonomous SOC platform, shifting teams from reactive alert handling to outcome-driven security operations. Straiker has launched Discover AI and expanded Defend AI to secure coding agents, productivity agents, and custom-built agent platforms. Agents are operating across enterprise systems with broad access, growing autonomy, and zero security oversight. That's why Straiker built Discover AI and Defend AI: to give security teams visibility into what agents are running and protection against what they might do. Teleport announced Beams, a trusted runtime designed to solve the security and IAM challenges blocking teams from designing and running AI agents in production infrastructure. Beams runs each agent in an isolated Firecracker VM with built-in identity. Each Beam is connected to infrastructure and inference services without secrets, with audit and access control. More about
Mimecast has expanded its Incydr technology with runtime data security capabilities designed to address AI-related risks. The new features detect, govern and remediate data exposure caused by employees, AI tools and autonomous agents in real time. The enhancement comes as 80% of Fortune 500 companies now run active AI agents, though only 14% have full security approval for them. The expanded platform combines endpoint and browser intelligence with email and collaboration security to provide visibility across the entire data movement pathway. Key capabilities include unified visibility across human and AI agent activity, shadow AI detection, adaptive risk scoring for both users and agents, and policy-driven governance frameworks. The technology monitors data movement across endpoints, browsers, SaaS applications, AI tools and email systems. Mimecast also previewed its Agent Risk Center at RSAC 2026 Conference.
Mimecast introduces runtime Data Security for visibility and control of growing AI risk. Expanded Mimecast Incydr(TM) technology and new Agent Risk Center detects, governs, blocks, and remediates data exposure caused by employees, AI tools, and autonomous agents. LEXINGTON, Mass., March 24, 2026 (GLOBE NEWSWIRE) - Mimecast, the global cybersecurity leader in securing human and AI risk, today announced a major expansion of its Incydr(TM) offering with data security capabilities for the AI era and also previewed the new Agent Risk Center at RSAC 2026 Conference. These new capabilities help deliver runtime data security - a unified approach to detect, govern, and remediate data exposure, in real-time, whether the action comes from an employee or an agent acting on their behalf. Eighty percent of Fortune 500 companies now run active AI agents, yet only 14% have full security approval for them[1]. Enterprise data loss is no longer just a people problem - AI agents have introduced an entirely new attack surface. Agents are accessing and sharing sensitive data through pathways which traditional security tools were never designed to monitor - MCP-connected workflows, commercial agents, user-built automations, and shadow AI tools. "Intent-based detection treats all agents equally. We don't, because the human behind the agent is the signal that changes everything," said Rob Juncker, Chief Product Officer, Mimecast. "Who deployed the agent? What do we already know about them? How is data moving across email, collaboration tools, browsers, SaaS apps, endpoints, and AI-driven workflows - and what intervention is required right now? That's a runtime data security problem, not a model problem." Adaptive Data Security for the Human and AI Agent Era Mimecast's Incydr technology has long helped organizations prevent insider-driven data loss through out-of-the-box visibility, intelligent detection via its PRISM risk engine (250+ risk indicators), and adaptive response ranging from in-context education to real-time blocking. The new capabilities extend Incydr technology from insider-led data security into broader runtime data security for both human and AI-driven risk. This expansion takes a new approach, combining Incydr endpoint and browser intelligence with Mimecast's email and collaboration security, delivering complete ingress-to-egress data visibility - covering the full path of enterprise data movement across endpoints, browsers, SaaS applications, AI tools, MCP connections, and email. New and expanded capabilities are engineered to include: * Unified Human and Agent Visibility - A single view into data loss risk across employees and autonomous agents, spanning endpoints, cloud and SaaS applications, email, browser activity, commercial AI tools, MCP server connections, and user-developed agents. * Shadow AI and Unsanctioned Agent Detection - Purpose-built detection for unsanctioned AI usage, out-of-policy commercial agents, unauthorized MCP connections to production databases and critical SaaS platforms, and user-built agents operating on unapproved LLM providers or accessing production environments without security review. * Adaptive Risk Scoring for People and AI Agents - The Incydr risk engine now continuously scores both human users and AI agents based on behavioral anomalies, policy violations, high-risk data access, unsanctioned application usage, agent compliance posture, and exposure to critical systems and data sources (e.g., Snowflake, Stripe, PostgreSQL, AWS, Salesforce, GitHub). * Granular Data-to-Agent Access Mapping - A clear view of which agents and tools access which categories of sensitive data - including customer PII, source code, financial records, internal communications, HR data, and infrastructure configurations - enabling security teams to understand and control the agent-to-data blast radius. * Policy-Driven Governance - A comprehensive governance framework for classifying and enforcing policy across all AI tools, commercial agents, MCP servers, and user-developed agents - with sanctioned, unsanctioned, and uncategorized classifications, department-level enforcement, and AI acceptable use policy management. Introducing the Mimecast Agent Risk Center Today, a single data loss investigation might involve an employee sharing a file through an unsanctioned tool - such as DeepSeek, OpenClaw, Ollama, ChatGPT - a commercial AI agent, summarizing confidential records, and a user-built agent pulling from a production database it was never meant to access. These events show up in different systems, follow different detection logic, and require different response playbooks - if they show up at all. The Mimecast Agent Risk Center is designed to consolidate that fragmented picture into one experience. Critically, the Agent Risk Center is built to connect every finding directly to action. Built-in agentic workflows automate the response chain - notifying users, escalating to managers, enforcing controls, and generating compliance reports - so teams act at machine speed, not human speed. As engineered, the capabilities will include: * Anomaly Detection Engine for Risky Agent Behavior - Can automatically surface high-risk patterns - unsanctioned tools with production database access, finance users connected to payment MCP servers, user-developed agents using non-sanctioned LLM providers, and executives with overly broad MCP configurations. * Governance Scorecards - A continuous assessment of organizational posture across four dimensions: policy coverage, review currency, human-in-the-loop enforcement, and LLM compliance - giving CISOs a clear measure of their agentic governance maturity. * Department-Level Risk Heatmaps - Visual analytics showing risk distribution, department-level exposure, risk factor breakdowns, and trend patterns - enabling targeted intervention rather than blanket policy. * Integrated Remediation Workflows - Every risk finding connects directly to action - block access, notify users, escalate to managers, create tickets, classify uncategorized tools, schedule agent reviews, and generate compliance reports - all without leaving the unified interface. Mimecast is previewing the Agent Risk Center at RSAC 2026, with Early Access expected in September 2026. Join Chief Product Officer, Rob Juncker, for a presentation and live demo - Mimecast booth N-5245 - at 10:30 AM on Tuesday, March 24th and Thursday, March 26th. Organizations interested in early access are encouraged to contact their Mimecast representative to learn more. About Mimecast Mimecast is a global cybersecurity and data governance leader redefining how organizations secure human and AI risk. Its AI-powered, API-enabled connected human risk platform is purpose-built to protect organizations from the spectrum of cyber threats. Integrating cutting-edge technology with human-centric pathways, its platform provides enhanced visibility and strategic insight. By enabling decisive action and empowering businesses to protect their collaborative environments, its technology safeguards critical data and actively engages employees in reducing risk and enhancing productivity. More than 42,000 businesses worldwide trust Mimecast to help them keep ahead of the ever-evolving threat landscape. From insider risk to external threats, customers get more with Mimecast. More visibility. More agility. More control. More security. Mimecast, Incydr and the Mimecast logo are either registered trademarks or trademarks of Mimecast Services Limited in the United States and/or other countries. All other third-party trademarks and logos contained in this press release are the property of their respective owners. Press Contacts Tim Hamilton Director, Public Relations Management +1 603-918-6757 [email protected] General inquiries [email protected]
Mimecast, a cybersecurity firm, has unveiled new AI-powered capabilities designed to protect high-risk users and AI tools accessing sensitive data. The platform enhancements address growing concerns around AI agents and automated workflows, which are creating new pathways for data leakage and insider risk. According to Mimecast's research, 98% of organisations now use AI to defend against threats, yet 80% worry about sensitive data exposure through generative AI tools. The company reports that just 8% of employees account for 80% of security incidents. New features include automated adaptive security policies that adjust controls based on individual user risk levels, an AI-powered investigation agent called Mihra that accelerates incident response, and streamlined workflows delivering 78% faster resolution of reported messages. The platform aims to secure how employees and AI tools interact in real time.