Frequently Asked Questions
How does Mimecast stop ransomware delivered via email?
Mimecast stops email-borne ransomware by running suspicious files and links in full CPU-level emulation, a deeper inspection than the virtual-machine sandboxes used by built-in security features from the leading email platforms, which ransomware has been designed to detect and evade. It follows the complete attack chain from attachment to final payload, scanning links and QR codes and potential drive-by downloads, to deliver a verdict.
How does Mimecast contain ransomware that enters through a compromised account?
Internal Email Protect scans employee-to-employee email to catch threats spreading from a compromised account. Behavioral analysis flags anomalous activity and quarantines messages, containing lateral movement before it escalates.
Can Mimecast help us recover without paying a ransom?
Yes. Enterprise Information Archiving provides a tamper-proof, immutable copy of all emails and attachments. If data is encrypted or deleted during an attack, organizations can restore from the archive without engaging the attacker.
Will email work during a ransomware attack?
Mimecast’s Mailbox Continuity service routes email through the cloud if primary servers are encrypted or taken offline, allowing employees to send, receive, and access historical email throughout the incident.
How does Mimecast address the human element of ransomware attacks?
Mimecast includes interactive security behavior training and phishing simulations designed to help employees recognize social engineering attempts. Reducing click rates on malicious links directly lowers the probability of a successful ransomware infection.
Does Mimecast’s ransomware protection support regulatory compliance?
Yes. Mimecast’s archiving, policy enforcement, and detailed audit logs help organizations demonstrate compliance with GDPR, HIPAA, and PCI-DSS, providing the evidence regulators require and reducing liability in the event of an incident.