Back to main siteBack Contact us
Solution Brief

Mimecast

Email Security

Email security, archiving and human risk, treated as one problem

Most organizations buy email protection to stop phishing, then discover over the following years that they also need a defensible archive, control over who can impersonate their domain, and some way of improving the judgement of the people clicking the links. Mimecast's position is that these are aspects of a single risk rather than four separate purchases, and the platform is organised accordingly.

VendorMimecast
CategoryEmail security and human risk
Reading timeAbout four minutes
I

Executive summary

Email remains the primary route into most organizations, not because the technical controls are weak but because the attack targets a person rather than a system. A well-constructed message asking an employee to change bank details does not contain malware, does not carry a malicious link, and therefore gives a filter almost nothing to act on.

Mimecast approaches that by combining four capabilities: detection at the gateway or via direct integration with the mail platform, a tamper-resistant archive, DMARC management to stop the organization's own domain being used against it, and training tied to how individual employees actually behave.

Takeaway: the buying decision is whether these belong together, because purchased separately they cost more and share nothing.

II

Why current controls miss what matters

The filtering included with a mail platform is competent against volume. Known malicious attachments, recognised phishing infrastructure and bulk spam are handled well, and for many organizations that covers the overwhelming majority of unwanted mail by count.

It covers much less of the risk by value. Business email compromise, where an attacker uses a legitimate but compromised account or a convincing lookalike domain to request a payment, arrives as an ordinary message. There is no payload to detonate and no reputation signal to fail.

Mimecast states that its detection engines are trained on twenty four trillion data points and identify three times more business email compromise and credential phishing than traditional methods. That is a vendor claim rather than an independent benchmark, and it should be tested during evaluation against your own mail flow.

The second gap is impersonation of your domain outbound. Without DMARC enforcement, anybody can send mail claiming to be from your organization, and your customers absorb the consequences of an attack you never see.

Takeaway: the residual risk after basic filtering is concentrated in messages that look entirely legitimate.

III

The approach

Detection can be deployed as a gateway ahead of the mail platform or through direct integration with it, which matters operationally: the integrated route avoids changing mail routing, while the gateway route inspects before delivery.

DMARC Analyzer addresses the outbound half. It reports who is sending mail as your domain, which is invariably more parties than anyone expects, and guides the policy from monitoring to enforcement without severing legitimate senders.

The archive captures inbound, outbound and internal mail in tamper-resistant storage with configurable retention, supporting regimes including HIPAA, GDPR and SEC 17a-4, with e-discovery search and litigation hold.

Training closes the loop by delivering short modules and simulated phishing, so the people who repeatedly click are the people who receive the instruction.

MAIL FLOW INBOUND detection OUTBOUND DMARC enforcement TRAINING AND SIMULATION RETAINED ARCHIVE
Exhibit A. Four capabilities arranged around one mail flow, rather than four products with four consoles.

Takeaway: the integration is the argument; evaluate it as a platform or not at all.

IV

What each capability answers

Business questionCapability that answers it
Did a convincing fake invoice reach anyoneInbound detection
Can outsiders send mail as our domainDMARC enforcement
Produce every message about this matterArchive and e-discovery
Which employees keep clickingSimulation and training
Prove retention to a regulatorRetention policy and hold

Key findings

  • The residual risk after standard filtering sits in messages with no malicious payload.
  • Outbound domain impersonation is a liability to customers, and invisible without DMARC reporting.
  • An archive is a compliance and litigation instrument, not a backup, and the distinction matters when a request arrives.
  • Vendor detection claims should be tested against your own mail during evaluation rather than accepted.

Takeaway: value concentrates in the questions a mail platform alone cannot answer.

V

Recommendation

For organizations with a regulatory retention duty, or any real exposure to payment fraud, the combined platform is worth costing against the separate products it replaces. Archive alone frequently justifies the difference where e-discovery has ever been required.

For a small organization with no retention obligation and modest payment exposure, the full platform may exceed the requirement, and a focused anti-phishing product plus DMARC management will cover most of the risk for less.

In either case, run a trial against live mail flow. Detection efficacy varies with the traffic an organization actually receives, and the only representative sample is your own.

Takeaway: decide the retention requirement first, because it is what makes the platform case.

Next steps

Schedule the readout

A short session covering what currently filters your mail, whether anyone has looked at who sends as your domain, and what would happen if a regulator asked for two years of correspondence.

Schedule the readout

Get in touch with Your Company

Questions about this solution? Reach us directly.