Mimecast extends data protection to the agentic enterprise
Almost overnight, AI agents have become the newest actors touching your most sensitive data. Here is how Mimecast is extending the same data protection program that secures your people to the agents now working alongside them: Starting with the Agent Risk Center, now in beta.
Key Points
- Agent Risk Center ties every AI agent to the person who deployed it, weighing identical agent actions against each individual's behavioral profile—so a risky user's activity surfaces while a trusted employee's identical action doesn't.
- Using the endpoint agent and browser extension already in place, Agent Risk Center discovers AI apps, MCP connections, and generative AI activity across the business, then enforces policy via the AI Rulebook – sanctioning or blocking tools org-wide or by department, or nudging users toward approved options.
- Launching in beta July 31, 2026, with Mihra Investigation Agent enhancements following in late August, the platform triages alerts, summarizes events with context, recommends next steps, and explains its reasoning – while an Incydr MCP Server lets teams bring their own agents into investigation work.
The agentic era arrived faster than most security programs planned for, and it lands directly on the data those programs exist to protect.
Protecting your data now means protecting the AI agents your people rely on, not just the people themselves. In a matter of months, the average employee has adopted a suite of AI helpers that operate for them: Desktop assistants, generative AI models, and MCP-connected agents that plug straight into GitHub, Salesforce, and live production systems, all moving at machine speed. Most security teams have a limited view of this new frontier. Meanwhile the price of data protection keeps rising, with insider risk now costing the average organization on the order of $19.5 million a year.
That is the shift behind what we are launching: the Agent Risk Center, in beta July 31, and new Mihra Investigation Agent capabilities on August 18, both extending the Incydr program you already run to cover agentic and human risk as one.
Data protection grew up around people: The employees who create, move, and sometimes accidentally mishandle sensitive information. That premise is breaking. The agents your workforce spins up now handle a large and growing share of that same activity for them. A program that cannot see or govern those agents is, by definition, covering a shrinking slice of what actually endangers your data.
The human-agent system is the real measure of risk
Most human risk has always concentrated in a small group. Year after year, 8% of people account for roughly 80% of incidents. What has changed is the leverage: those same people now act through machines, and the machine population is exploding. Analysts from IDC expect more than one billion active agents by 2029, taking hundreds of billions of actions every day. The lesson is that the unit of risk is not the agent on its own. It is the human-agent system: the agent plus the person who deployed it.
Picture two employees whose agents pull the same large dataset from your CRM. Maya is a tenured finance leader with a clean history. David is a sales director who has been quietly moving files to personal accounts and devices. Same agent, same action, very different risk. From day one, Agent Risk Center ties every agent to the human behind it and Mimecast will tie those two agentic actions against each person's behavioral profile and surface the sales director's activity as the one that matters.
Unified data protection: Agent Risk Center now in beta
Here is the core idea: agentic risk does not require a separate product bolted onto the side of your stack. Mimecast takes the data protection program you already operate and stretches it to cover the agents now acting for your employees – giving you full visibility across endpoint, browser, cloud, email, and agentic AI with Incydr.
Agent Risk Center opens in Beta on July 31, 2026, giving Mimecast customers a comprehensive data protection program for agentic and human risk. Because Agent Risk Center uses the Incydr endpoint agent and browser extension already in place, there is nothing extra to install. Enable it and the inventory populates instantly.
To understand your agentic risk, start with discovery. Agent Risk Center builds an inventory of the AI desktop applications in use across the business, exposes the MCP connections quietly stitching agents into systems like GitHub, Salesforce, and Slack, and captures the copy, paste, and upload activity headed for generative AI tools. Each of those is mapped to the people driving it. From there, a heatmap view slices the activity by department so you can concentrate on the pockets where unsanctioned use clusters instead of painting the whole company with one brush. Our teams have seen this pattern consistently with shadow AI: A tool one person picks up on Monday is frequently running across half the department by Friday.
Discovery earns its keep only when you can act on it. That is the job of the AI Rulebook, which converts your acceptable use policy into a control that actually enforces it. Mark a tool or connection sanctioned or unsanctioned, apply that call to the entire environment or narrow it to a single department, group, or individual, and shut down what does not belong. Where the situation is lower risk, drop in a nudge that steers people toward approved tools in the moment instead of hard-blocking them.
Our adaptive controls are built to scale with the human-agent risk to your data, carrying you from broad blocks toward precise, targeted enforcement across all channels. The flexibility in controls ensures AI adoption isn’t slowed down or driven to the shadows by broad blocks.
Put agentic to work: Mihra Investigation Agent enhancements
Agent Risk Center brings the full human-agent risk into view, but we’re also doubling down on agentic AI as a tool your security teams can use to speed investigations and alerts. The Mihra Investigation Agent puts agentic AI to work for the analysts defending your data.
In late August, the Mihra Investigation Agent will be automatically available in Incydr. These dedicated agents are fine-tuned for specific insider risk workflows, making them a powerful partner in security operations. Analysts investigate hundreds and sometimes thousands of alerts a month, and the hardest parts are knowing which ones matter, pulling together the context to understand them, and deciding what to do next.
The Mihra Investigation Agent works alongside analysts, tackling alerts individually or in-bulk. It triages alerts so teams start with the ones that need a human and close out the noise. It summarizes each event and adds the surrounding context directly in the interface, so an analyst doesn’t have to assemble it by hand. It recommends the next step, including which controls to apply. And it explains the reasoning behind every recommendation, so the decision is transparent and auditable. For teams carrying a heavy alert load or working with limited resources, that is the difference between reacting to a queue and running a program.
For customers who prefer to bring their own AI agents into investigation work, the Incydr MCP Server is available for exactly that. Whether you use the agents we build or one of your own, the goal is the same: Agentic AI that makes your data protection program faster without giving up control or explainability.
Why extend the program you already run
Covering your people, your data, and your AI should not mean juggling separate consoles, multi-week rollouts, or a patchwork of tools that barely talk to each other. The agentic surface is only going to expand as agents push toward billions of actions a day, and the programs that keep up are the ones already holding the behavioral and organizational context from your workforce, then extending it outward to the agents working beside them.
That is what lets you keep pace without hiring for it. More than half of Incydr teams run their insider risk program in under four hours a week and hit ROI inside six months, and that same efficiency now extends to the AI agents in the mix. Just as important, it hands your CISO and your board a single, coherent risk story.
If you already run Incydr, reach out to your Mimecast account team or email incydr-product@mimecast.com to try Agent Risk Center or request a 30-day Proof of Value to start protecting your humans, data, and AI with Mimecast.
Si abboni a Cyber Resilience Insights per altri articoli come questi.
Riceva tutte le ultime notizie e le analisi del settore della cybersecurity direttamente nella sua casella di posta elettronica.
Iscriviti con successo
Grazie per essersi iscritto per ricevere gli aggiornamenti del nostro blog
Ci terremo in contatto!