Mimecast Incydr · Insider risk

Mimecast Incydr: see and stop data leaving with your own people

Most organisations have strong perimeter security and almost no idea how their own people handle sensitive data. Incydr gives you continuous visibility of how files move across endpoints and cloud, scores the risk by what the data is and who moved it, and automates the response, so a leaver, a careless upload and a genuine insider are told apart and dealt with in proportion. C4C Group is an accredited UK Mimecast partner and reseller. We supply, implement and support Incydr, and we have the case study to show what it does.

What it does

Six things legacy data loss prevention gets wrong

Sees how data actually moves

Continuous visibility of file activity across endpoints and cloud, including Microsoft 365, Google Drive and Box, personal cloud apps, browsers, email and removable media. Not a policy you had to write in advance, a record of what happened.

Scores risk by data and by person

Weighs what the file is, where it went and who moved it, against a baseline of normal activity for that role, so a contractor uploading source code to a personal drive ranks above an analyst saving a deck to OneDrive.

Catches the leaver and the mistake alike

Departing employees, disgruntled staff and people who are simply careless look the same to legacy tools. Incydr tells them apart, so the response fits the intent.

Responds without a war room

Automated triage and escalation, with the option to contain or block a risky action in the moment, and a workflow that hands genuine cases to security or HR with the evidence already attached.

Runs without getting in the way

Lightweight on the endpoint and silent to the user. It does not slow devices, interrupt legitimate work or need the rule writing that makes traditional data loss prevention brittle.

Leaves an audit trail a regulator will accept

Auditable incident records and an ongoing view of risk posture, which is what turns insider risk from an anxiety into evidence of data governance.

Proof

A UK financial services organisation, ninety days in

80%fewer unmonitored file transfers
90 daysto measurable results
Fullendpoint and cloud visibility

The client had strong perimeter security and little insight into how its own people were moving sensitive data through personal cloud apps and USB devices, with a regulator expecting evidence of governance. C4C deployed Incydr with baselining, custom risk scoring by data sensitivity and role, and automated triage, and within ninety days everyday employee activity had become a managed, visible risk surface. Read the Incydr case study.

Honest fit

Where Incydr is the right buy, and where it is not

Right for

Organisations with strong perimeter security and little idea how their own people handle sensitive data. Regulated sectors that must evidence data governance, firms with intellectual property to protect through hiring, leavers and mergers, and anyone whose existing data loss prevention generates rules and noise rather than answers.

Think twice if

Your exposure is mainly inbound, phishing and impersonation, in which case email security is the priority and Incydr is the second step, not the first. Or if there is no process to act on what it finds. Detection without an owner in security and HR is a dashboard, and we will say so rather than sell you one.

The head to head with Microsoft is in Incydr vs Microsoft Purview. The problem side is in our guides to insider risk management and human risk as the real security perimeter. For the collaboration compliance side, Teams, Slack and Zoom records, see Mimecast Aware.

How C4C delivers it

Supplied, implemented and supported by an accredited partner

Our independence is in the recommendation, our partnership is in the delivery and support. See the wider Mimecast partnership and the security practice it sits in.

Questions

Frequently asked questions

What is Mimecast Incydr?

Mimecast Incydr is an insider risk management platform. It gives continuous visibility of how files move across endpoints, cloud services, browsers, email and removable media, scores that activity by the sensitivity of the data and the role of the person, and automates the response, from alerting a security team to containing the action. It is built to catch data walking out of the door, whether through malice, a leaver or a mistake.

How is Incydr different from traditional data loss prevention?

Traditional data loss prevention depends on rules written in advance, which are hard to get right and generate noise. Incydr starts from visibility of what actually moved and a baseline of what is normal for each role, then prioritises the exceptions. It runs quietly on the endpoint without blocking legitimate work, so security teams see fewer alerts and more genuine cases.

Does Incydr slow down laptops or interrupt users?

No. The agent is lightweight and silent to the user. It records file activity and applies risk scoring without interrupting the work being done, and containment or blocking is applied only where a policy calls for it.

What results has C4C seen with Incydr?

For a leading UK financial services organisation, C4C deployed Incydr with custom risk scoring and automated triage. Within 90 days the organisation had full visibility of data movement across endpoints and cloud and an 80 percent reduction in unmonitored file transfers, with auditable incident records for its regulator. The full case study is on this site.

Can C4C supply and implement Mimecast Incydr?

Yes. C4C Group is an accredited UK Mimecast partner and reseller, so we can source, implement and support Incydr as well as advise on it. Our independence is in the recommendation, our partnership is in the delivery and support. Where email security or a process fix is the right first move, we say so.

How is Mimecast Incydr priced?

Incydr is licensed per user and priced on quote, depending on the user count, the modules and the term. C4C will give you a like for like quote and tell you what is negotiable. Send us your user count and we will come back with a figure.

Do you know how your data actually leaves?

Start with the free human risk assessment for an honest read on your exposure, or send us your user count for a like for like Incydr quote and a demo against your own estate.