Insider Risk Management & Data Protection

    Human Risk Command Center now connects to Google Workspace for phishing and identity

    Two of the biggest threats to Google Workspace—phishing and identity abuse—now feed directly into the Human Risk Command Center, giving security teams one connected view of user exposure and the ability to act on it in real time

    by Giulian Garruba

    Key Points

    • Google Workspace now feeds two threat signals into Mimecast's Human Risk Command Center: Gmail's phishing/post-delivery reclassification alerts (raising a user's Actual Phishing score) and Google's identity risk signals like suspicious logins and leaked credentials (raising Attack Factor)—kept as separate scores rather than one blurry number.
    • This addition brings the Command Center to 21 integrated signal sources and extends coverage across both dominant email platforms, Microsoft 365 and Google Workspace, addressing two accelerating threats: phishing and OAuth consent abuse.
    • Watchlist Manager segments high-risk users in real time, which can tighten email security policy, trigger targeted Engage nudges, or feed a SIEM/SOAR via the Human Risk Public API—with no new tooling or added cost for existing customers.

    The Anti-Phishing Working Group (APWG) — the world's leading coalition of industry, law enforcement, and government organizations combating phishing and cybercrime — tracks which sectors phishing attacks target most. In its 2025 Q4 report, SaaS and webmail platforms, including Google Workspace, tied for the most-targeted sector industry-wide, each accounting for 20.3% of all phishing attacks. 

    Google's own H1 2026 Threat Horizons Report adds a second, separate data point: consent-based OAuth abuse targeting Workspace accounts spiked roughly 2,000% over a recent six-month window. Two different threats, one shared home — both live inside Google Workspace, and until now, neither had a clean path into a unified view of human risk that lives alongside other critical security signals. 

    Google Workspace seamlessly integrates with the Human Risk Command Center

    Google Workspace generates rich, native detection data across both threats: phishing messages Gmail reclassifies after delivery, users who self-report suspicious mail, logins flagged as suspicious, credentials detected as leaked. Now Google Workspace: Mail feeds Gmail's own phishing and post-delivery reclassification alerts directly into a user's Actual Phishing score. Google Workspace: Identity elevates a user's Attack Factor based on Google's own identity risk signals — suspicious logins, leaked credentials, and account suspensions. Keeping these separate isn't a technicality; it's the model working as designed. A phishing click and a leaked credential are different exposures, and the Mimecast Human Risk Command Center scores them that way rather than flattening both into one number.

    This also extends the Command Center's ecosystem coverage in a meaningful way. With these two additions, the Command Center now integrates with 21 signal sources — four first-party and seventeen third-party — spanning phishing, identity, malware, sensitive data handling, and simulated phishing. Google Workspace's addition means that coverage now spans the two dominant email and productivity platforms in the market: Microsoft 365 and Google Workspace.

    And if you're already running Mimecast alongside Google Workspace, this adds another layer rather than replacing one: native Google signal now runs right alongside Mimecast's own detection, giving your team two independent, connected vantage points on the same inbox.

    Why this matters now

    Phishing hasn't gone away, but it's no longer the only major threat channel security teams need to watch. Identity-based attacks are accelerating just as fast — arguably faster. Google's own telemetry shows attackers increasingly skipping credential theft altogether, instead tricking users into approving malicious OAuth consent requests that survive a password reset entirely. A leaked credential and a clicked link are different failure modes. Treating them as one blurry "phishing problem" misses half the picture.

    What good defense actually requires

    Regardless of vendor, closing this gap means two things working together. First, unifying detection signals — email, identity, endpoint, wherever risk shows up — into one current view of a user's exposure. Second, connecting that view to an active behavior change program, so a flagged user gets a nudge, training, or a policy response, not just another entry in a report. The best programs also resist collapsing every signal into a single number: a user who clicked a phishing link and a user whose credentials were harvested via OAuth abuse are exposed in genuinely different ways, and deserve to be scored, and acted on, differently.

    From signal to action

    Ingesting Google Workspace's phishing and identity signal is only half the story. Once that data lands in the Mimecast Human Risk Command Center, Watchlist Manager can automatically segment users into dynamic groups based on real-time risk factors — a Gmail user who clicks a phishing link, for instance, can be added to an "Attacked User" watchlist the moment the event fires, no manual review required. That same real-time risk data can tie directly into existing email security policy, tightening controls for genuinely high-risk users without a single manual step. It can also drive a targeted Engage nudge, or, via the Human Risk Public API, feed the same data into a SIEM, SOAR platform, or other tool already in your stack. The data needed to act is live today — and we're continuing to build more robust outbound integrations and workflows on top of it.

    What this means for you

    Running the Command Center today? Connect Google Workspace identity or mail signals now to strengthen your view of organizational risk — no new tooling, no additional cost. If you're layering Mimecast in front of Google Workspace, this means catching what Google's own detection flags post-delivery even when it slipped past your Mimecast gateway — a second, independent check on the same mailbox.

    Running Engage on its own, or evaluating it for a Google Workspace environment? This means real behavioral data feeding your program from day one. A user who's had three Gmail-reported phishing attempts in 90 days can now trigger a targeted Engage nudge automatically, instead of waiting for the next scheduled training module to catch up.

    Learn more about the Mimecast Human Risk Command Center.

    Subscribe to Cyber Resilience Insights for more articles like these

    Get all the latest news and cybersecurity industry analysis delivered right to your inbox

    Sign up successful

    Thank you for signing up to receive updates from our blog

    We will be in touch!

    Ready to secure the human layer? REQUEST A DEMO
    Back to Top