IT Brief Asia - Technology news for CIOs & IT decision-makers
Asia
Mimecast CEO: Agentic AI threat novel but not entirely new

Mimecast CEO: Agentic AI threat novel but not entirely new

Fri, 28th Aug 2026 (Today)
Donovan Jackson
DONOVAN JACKSON Interview Editor

Well known for its strength in security which grew out of an email-centric view of the world, Mimecast is expanding its core mission from pure human risk management to a combined human-and-AI risk platform. That comes as autonomous agentic AI systems steadily enter the workforce, adding value but also sometimes attacking components of corporate environments at growing scale.

It might be AI and even agentic, but behind every and any bit of technology is a person, and that's what Mimecast CEO Ranjan Singh instantly zeroes in on. "Fundamentally, that's what we see; 90% of risk is still tied to users. Before AI, a user was responsible for giving up their credentials. They got hacked. They got phished. They were malicious. They exfiltrated data. So, that 90% problem is still the majority of the risk."

This, added Singh, should come as some comfort. After all, one of the realities of a changing environment where, unlike employees, agents can multiply at a virtually uncapped rate, the looming overload can be pulled back to a more manageable circumstance. "Rather than being overwhelmed with 'can I solve every agentic AI risk', let's focus on the actual problem. Uncover your risky users, and you uncover all the agentic AI used by those users."

Suddenly, the mountain reverts if not to a molehill, then certainly nothing that would trouble even the most modest alpinist. Or, as Singh pointed out, AI is no longer a new category of threat but an extension of the existing user threat.

Which is spot on. Security professionals again and again stress the necessity for good, solid basics as the Pareto baseline of reasonable measures.

There's more comfort from Mimecast's boss: "You can think about just about every AI dimension in this way; for those concerned about deep fakes, think about what a deepfake is doing, study the places where it's used. It's simply an extension of a problem that already existed [identity and access management].  So in the world of deepfakes, just do that [IAM] more proficiently, more rigidly. These are all simply an extensions of existing threats, and not necessarily new threat categories."

From human to human + AI risk score

Noting that people are bringing generative and agentic tools into the workplace as a further extension of the 'BYOD' trend, Singh said this generally happens ahead of security and governance teams. The consequences can be hidden.

Mimecast's counter rests on a four-pillar approach to risk management that starts with visibility. "We focus on whether it's user or AI risk. Number one, identify and quantify with a human and AI risk score. Number two, make it easy to govern the risk, building guardrails which we make easy to build. With guardrails, you know what you're protecting against, and not throwing the kitchen sink at the problem. And then, if somebody is attempting to violate the guardrails, whether it's a human or an agent, instead of alerting, solve the problem."

This third component, which Mimecast also describes as 'block and contain'  is the meat and potatoes and as Singh went on to explain, it is here that a good deal of the 'overwhelm' is eliminated by combining detection with resolution. "We are the sensor, and closest to the endpoint, cloud, browser, email. So instead of just finding, why not also resolve the problem? Why not block the threat instead of sending an alert to an overburdened SOC team to take action, which is too late? So that is how we are helping customers approach this problem."

Of course, false positives are still a thing, and therefore complete autonomy comes with its own risks. And if people are where the problem starts, they're also where the problem is solved in the fourth pillar: Close the loop. "So there is always a human involved [and] the way you do this is with thresholds. You drive automation, and you say what is your confidence level? You get customer reinforcements, and when false positives are fed back to us, we adjust our engines and refine over time."

With this approach, said Singh, Mimecast's Managed Threat Response automatically resolves somewhere around 98% of threats within a minute. "If we get it wrong, we adjust it. And for the remaining one or 2% we have a human in the loop."

The shadow AI explosion - driven by users

Singh's point is that users are where the focus should continue to fall, as they are directly responsible for the introduction and proliferation of agents.

"For 90% of the companies we work with, when we first deploy our tools, we uncover lots and lots of shadow AI. They're really shocked."

He said an examination of around 80 Australian and New Zealand Mimecast customers showed roughly 125 AI-native applications at each one. More striking still was the 1,250+ AI-enabled services (such as Microsoft 365 with Copilot or Claude agents, or third-party Excel add-ins). Customers, he said, typically had little to no awareness that this is how pervasive AI has already become.

That's not a bad thing in itself. "You have to be permissive, you have to have user freedom. But the key is to be able to identify and discover what's happening in your environment and dynamically build those guard rails."

And, he added, AI agents shouldn't have more autonomy than humans. "That's a good guardrail exercise in terms of thinking about managing agents, controlling agents and managing access to agents. Put scores around it, then you have something to work with. And your governance policies must be dynamic. What may be okay yesterday may not be okay tomorrow, so our philosophy is 'permissive, with discovery, identification and dynamic management'."

In short, as agentic AI entrenches itself as business as usual, Mimecast's point aligns with the (sometimes obscured) basic premise underlining any technology development. It is done for people and it is used by people.