UK asset manager, 1,800 staff
A departing fund manager copied files to a personal cloud account two days before resigning, and the firm could not prove what had left. C4C designed the insider risk programme, supplied and deployed Mimecast Incydr across 2,000 endpoints and the Microsoft 365, Google Drive and Box estate, and within ninety days the firm could see, score and stop sensitive data leaving. Twelve genuine incidents were caught in the first year, with no confirmed loss.
The perimeter was strong. Email was filtered, endpoints were protected, and the firm had passed every external test. What nobody could see was its own people. When a fund manager resigned and a laptop image showed files copied to a personal cloud account two days earlier, the security team could not say what the files were, whether client data was among them, or whether anyone else had done the same. The regulator had already asked for evidence of data governance. There was none to give.
C4C is an accredited UK Mimecast partner and reseller. We designed the programme, supplied the Incydr licences, deployed the platform and ran the first ninety days alongside the security, HR and legal teams. The first month was spent baselining, and the baseline was the moment the programme earned its place.
Delivered through our IDEAL framework, the disciplined method behind every C4C engagement.
Within ninety days everyday employee activity had become a visible, managed risk surface. In week six the platform flagged a contractor bulk downloading a client list the night before their contract ended; the transfer was blocked and HR handled the rest. What surprised the firm was how little of what it found was malicious. Most was habit, and habit changed the moment people knew it was visible.
C4C is an accredited UK Mimecast partner and reseller with a human first approach to cyber resilience. We supplied and deployed Incydr here and we support it still, and we say so. Our value was not the platform on its own. It was designing a programme that HR, legal and the security team could all stand behind, so the visibility was trusted, and the first ninety days were spent finding what mattered rather than drowning in alerts.
Key technologies
Incydr is an insider risk and data exfiltration platform. Rather than guarding the perimeter, it watches how files move inside and out of the organisation, across endpoints, cloud storage, email and removable media, scores that movement against a baseline of normal activity and the sensitivity of the data, and lets a security team see and stop the small share that is genuinely risky without policing everything else.
Sooner than most expect, provided the first month is spent baselining rather than alerting. Here the baseline itself revealed the leaver pattern, the USB traffic and a forwarding mailbox within thirty days, a live exfiltration was stopped in week six, and the firm had measurable, auditable results inside ninety days.
It is not bigger. It is blinder. Most organisations have invested heavily in the perimeter and can evidence it. Very few can say what their own people did with sensitive data last week. This firm had passed every external test and still could not tell the regulator what had left with a departing fund manager. Insider risk is the gap that the rest of the security spend does not cover.
It does not have to, and here it did not. The programme watched data movement, not people, and said so in a published policy before go live. HR and legal sat on the triage panel from the first alert. Staff were briefed on what was visible and why. The result was that most of the risky habit stopped on its own once people knew it could be seen, long before any enforcement was needed.
By baselining first. You establish what normal file activity looks like for each role, then score deviations against the sensitivity of the data involved. A fund manager exporting a client list the night before leaving scores very differently from an analyst moving a spreadsheet to a shared drive. Without the baseline every alert is noise; with it, the twelve that mattered in a year were found.
Incydr is licensed per user and priced on quote, depending on the user count, the modules and the term. Mimecast does not publish list prices and as a partner we cannot either. C4C is an accredited UK Mimecast partner and reseller, so we can source, implement and support Incydr as well as advise on it. Send us your user count and the platforms in use and we will come back with a like for like quote and an honest view of whether you need it.
Tell us what you are working through. We will give you an independent, vendor neutral view and a clear next step.
Talk to us