In our most recent Maximizing Mimecast session, Dave Capuano, VP of Product Management for Insider Risk and Data Protection, walked us through how the insider risk landscape has shifted over the past 18 months and what that means for security teams trying to govern both human behavior and the AI tools acting on their behalf. Dave covered the current state of shadow AI, walked through live demos of the Insider product, previewed the upcoming Agent Risk Center capability, and shared what is coming for email data loss prevention (DLP) for Gateway customers.
The Expanding Insider Risk Challenge
Dave opened by framing a challenge that has fundamentally changed over the past 18 months. Insider risk has never been simple to address, but AI has introduced a new dimension that most organizations are not yet equipped to handle. The challenge is no longer limited to employees. AI agents operating on behalf of your workforce are now part of the attack surface. Many of these agents are connecting to applications through MCP, processing sensitive data, and making decisions, often without adequate governance, audit trails, or controls.
To put the scale of this in context, Dave shared data pulled from across the Insider customer base:
- More than 1,400 unique AI tools detected in active use across the customer base
- 94% of those tools were completely unrecognized by the organizations using them
- Nearly 3 million AI interactions observed across the customer base in a single 28-day period
- Close to 1 million files uploaded directly to AI tools in that same period
- Approximately 8,300 data movement events per business hour, or roughly 2.3 per second
These are not market projections. As Dave noted, this is what we are seeing in production environments today. The scale of the problem makes periodic audits insufficient. Continuous visibility is now a requirement.
What Insider Provides Today
During the session, Dave walked through live demos of the Insider product to show how customers are currently using it to address shadow AI, departing employee risk, and source code protection. Three capabilities stood out in the discussion.
Visibility across endpoints and cloud applications. A lightweight sensor on Windows, Mac, or Linux endpoints tracks data movement in real time, including uploads to browsers, applications, Git push and pull, and sync tools. On the cloud side, Insider integrates with G-Drive, OneDrive, Box, O365, Gmail, and Salesforce to provide full coverage across the most common data sharing environments. Source, destination, file type, content sensitivity, and classification labels are all captured.
Controls tied to context. Insider uses over 400 risk indicators to categorize data movement and drive responses that are proportional to the risk level. Low-risk events might trigger a coaching pop-up or micro-training video. Higher-risk events can automatically revoke public shares, restrict application use, block uploads to unsanctioned destinations, or prevent removable media from being mounted. Watch lists can be auto-populated from Active Directory groups, allowing focused monitoring on specific user populations like contractors or employees in offboarding.
AI-assisted investigation. An investigation agent runs in the background to assess triggered alerts, differentiate true positives from false positives, surface historical context and related user sessions, and generate a recommendation. This is available in limited early access today and will move to general availability later this year. The session also included a live demo of connecting a sanctioned LLM to Insider via MCP, pulling PII-related alerts from the last 7 days and generating a structured incident summary report with top offenders, exposure breakdown, and exfiltration destinations.
One of the most discussed parts of the session was Dave's preview of Agent Risk Center, an upcoming capability extension for Insider. Agent Risk Center is specifically designed to address agentic risk: the AI tools, agents, and MCP connections operating in your environment on behalf of your employees.
The capability will provide a full inventory of AI tools and MCP servers detected in the environment, an AI rulebook where organizations can define what is sanctioned and what is not, department-level visibility into sanctioned versus unsanctioned usage, and access to all existing Insider response controls applied to agentic activity.
For customers who already have Insider deployed, this will not require redeployment. It builds on the existing telemetry and infrastructure. Agent Risk Center is planned for beta in July, with early access following in September. If you are an existing Insider customer and want to be considered for beta, reach out to your Customer Success Manager.
Learn more from the press release.
Coming Soon: Email DLP for Gateway Customers
Dave also previewed an upcoming capability specifically for Mimecast Gateway customers: agentless email DLP built on the Insider infrastructure. This requires no changes to existing mail flow and will inspect every outbound email for sensitive content, including PII, credentials, confidential data, and MIP-labeled files.
Because it is built on Insider, customers get the same risk indicators, watch lists, forensic search, and investigation agent capabilities across email events as they do across endpoint and cloud activity. For organizations starting their insider risk journey, this creates a single place to investigate activity across gateway email, endpoint, and cloud collaboration tools.
Email DLP for Gateway customers is planned for early access in Q3 and general availability in Q4. If you are interested in early access, contact your account manager.
Key Takeaways from the Session
- The insider risk attack surface now extends to AI agents and MCP-connected tools, not just employees. Most organizations have limited or no visibility into what those agents are doing.
- Continuous visibility is required. Across the Insider customer base, data is moving to AI tools at a rate of 2.3 events per second. Quarterly audits cannot keep pace with that volume.
- Insider supports MCP connections to sanctioned LLMs, allowing security analysts to query alert data conversationally and generate structured reports for leadership.
- Agent Risk Center is coming in beta in July for existing Insider customers, with early access in September. It uses existing Insider telemetry, no redeployment required.
- Email DLP for Gateway customers arrives in early access in Q3, giving organizations a unified view of data risk across email, endpoint, and cloud from within the Insider platform.
Watch the Recording
If you were not able to attend the live session, the on-demand recording is available in the Mimecast Knowledge Base. Login is required to access recordings.
Join the Next Session
The Maximizing Mimecast series continues throughout the year. Register to stay informed on upcoming sessions and receive reminders automatically.
Have questions or thoughts on what was covered? We would love to hear from you in the comments below.
Log in to the Mimecast Community to leave a comment and connect with other customers.