Video summary
Ranjan Singh, CEO of Mimecast, discusses the evolution of his company from a specialist in email security to a comprehensive platform addressing human, AI, and data risks. He emphasizes that modern security must operate at the intersection of these three vectors rather than treating them as isolated concerns. The core philosophy behind this approach is to first discover, identify, and quantify risk before implementing governance or protection measures. By quantifying risk on a scale from one to ten based on various signals like user behavior, phishing simulation results, and endpoint data loss potential, organizations can move beyond generic rules to make informed decisions about what actions are sanctioned versus prohibited.
The conversation highlights how AI agents have introduced new layers of complexity, particularly regarding "agentic risk" where users might inadvertently grant excessive permissions by clicking "always allow," or employees might unknowingly exfiltrate sensitive data while testing new AI models. Mimecast's strategy involves analyzing user behavior to distinguish between legitimate actions and risky ones, even when those actions are performed by autonomous agents that may attempt to hide their tracks. The platform aims to resolve issues directly rather than just generating alerts, thereby reducing noise for security teams. This is achieved through deep integrations with partners like CrowdStrike, allowing the ecosystem to share indicators of compromise and behavioral data to create a more robust defense against sophisticated threats like business email compromise attacks that rely on invisible character manipulation.
Regarding the definition of a true security platform, Singh argues that it must deliver measurable outcomes such as improved efficiency and ROI, rather than simply bundling point solutions. A genuine platform offers deep first-party integrations across email, data loss prevention, and security awareness training within a single user interface, eliminating the need for security professionals to switch between multiple tools. While pricing models are evolving toward outcome-based structures where customers pay for specific results like false positive reduction or autonomous remediation, Mimecast currently employs a hybrid model that combines traditional licensing with value derived from advanced outcomes. The ultimate goal is to empower organizations to manage their security posture effectively in an era where human error and AI-driven threats converge, ensuring that the right actions are taken autonomously while maintaining necessary human oversight for high-risk scenarios.
Read the full video transcript
Welcome back to the Mandalay Bay. My
name is Dave Volante. I'm here with
Chris Case and you're watching the Cub's
coverage of Falcon 2026. Crowd Strikes
Crowd Strike's big customer event. We're
up to gosh well over 10,000 people. This
is our fifth year at Crowdstrike. We
started when the ecosystem was pretty
tiny. We kind of predicted accurately
that it was going to explode and it sure
has. We're going to have a really
interesting conversation right now about
securing human data and AI risk all in
one system in a platform. Rajan Singh is
here. He's the chief executive officer
of Mcast. Ranjan, thanks for coming on.
>> Uh Dave Christa, thank you so much for
having me. It's a great opportunity and
what an event. It's an unbelievable
event.
>> It's really great keynote this morning
by George.
>> Amazing keynote and uh you know it's the
first time me watching Jensen in action
in in live.
>> He's a he's a cool dude.
>> He is a cool dude. Seeing the banter was
always fun.
>> It was funny. [laughter] I was I was
having a conversation. I had dinner the
other night with uh one of my colleagues
who was he was in in our business
analyst business. He was actually a
president of IDC at one time after I
left well after I left. He said you know
back back in the day you used to be able
to just go into Jensen's office say hi
and [laughter] now it's like you know
getting getting to the president's
easier than getting to Jensen. But any
rate let's talk about Mcast. You guys
built your reputation in in email
security, but obviously the risk has
expanded beyond the inbox, right? You've
got sensitive data, you've got human
behavior. Where are you taking the
company?
>> Yeah, we have evolved uh, you know, from
a 20 plus year history in ML security to
now focusing on human risk, AR risk and
data risk. Sounds like big statement,
sounds like things what most people talk
about. But we are very acutely focused
on number one measuring the risk,
quantifying the risk. So it's not just
about all the risk vectors but quantify
the risk. And we started with human risk
and then we looked we look at AI risk as
an extension of that human risk as
opposed to just a standalone risk. And
then the ultimate goal with whether it's
human risk or AI risk is data
excfiltration. So we as a company are
operating at the intersection of human
AI and data risk. And then the core
element there is quantifying the risk.
And as you know if you can quantify
something you can usually solve for it
improve it. So our philosophy and
framework is discover identify and
quantify the risk. From there we make it
really easy for customers to govern
those risks. Tell us this is allowed,
this is sanctioned, this is not
sanctioned as opposed to building rules
etc. We make it really easy. Once we
have the governance in place, we can
build protection around that across all
three vectors.
>> And then lastly is resolution and our
philosophy is resolve first, alert
second. Um, so this is the platform that
we are building. And the idea is very
simple. Instead of having customers
focus on point solutions of human risk,
AI risk and data risk, we believe that
you have to operate at the intersection
of all three risks. And then they're
really merging together and we're
building on platform and delivering
those outcomes.
>> Is the quantification of the risk I
think you know in terms of expected loss
or is it t-shirt sizes high, medium,
low?
>> Uh no, it's actually literally numbers
on a scale of 1 to 10. So Dave is low
risk at let's say at Mcast or at Cube
you're low risk, you're two out of 10.
Runen is seven out of 10. How do we
determine that? We take inputs from
parts of our platform. Email, are you
highly attacked? Are you clicking on
links? Are you passing your fishing
simulation test and security awareness
training? What is the risk of data loss
on your endpoint? And then we have deep
integrations with the ecosystem, MFA
fatigue attacks from the identity
providers, uh indicators of compromise
from endpoint like Crowdstrike. We have
huge integrations with Crowdstrike or
the Sassy providers. We take all of
these signals, we weight them, and we
calculate the risk score.
>> So it's like you basically calculate a
risk signature for each human and AI.
Okay. And then I presume so you weight
them. If I'm if I'm getting attacked a
lot and I'm a high risk in that sense,
but I don't have access to anything. You
weight that accordingly. So there's a
value component dimension correct of
this as well.
>> Correct. Yeah. And then the key thing
about measuring that risk is we don't do
it just to say hey here's where your
risk is because we in our data that we
see 8% of your users are responsible for
80% of your risk right it sounds like a
marketing pitch because we match the
numbers but I encourage anybody to go
look into their environment and see who
refuses to take the security awareness
training or the or who fails the fishing
simulation test. That alone will reveal
that metric for you. Okay.
>> So, Ranjad, I've had a number of c uh
conversations with CISOs and other
practitioners both here at Crowdstrike
and a few weeks ago at Black Hat
>> and they talked to the role of the CISO
as evolving into one of being an arbiter
of these decisions around risk and what
sort of trade-offs that the enterprise
needs to make. So can you talk to, you
know, how these risk metrics are
changing as humans start perhaps
engaging with AI agents because I really
think that's central to again how the
CISO really thinks about executing on
their job and starts to you know
converse with the line of business and
have these these discussions. Um, we
talk about the blurring lines of human
risk, AI risk, and data risk. And I'll
walk you through a few examples, which
is impacting how CESOS think about it,
and then how should they potentially
respond to it. So, human risk was all
about, hey, you can click on a link.
Well, now you have really sophisticated
fishing attacks, right? One that we just
uncovered about a week ago.
Looks like a plain email. It's a BEC
business email compromise attempt. But
when we flagged it as malicious, what we
saw inside it is between every character
there were nonvisible 100 characters
between every character in the word. The
idea being if you are relying on text
scanning based BC detection of any kind,
you're not going to pick this up. But we
were able to pick it up because we are
studying user behavior. What is common
communication pattern? what is it, you
know, is it a first-time sender, for
example, is this a common domain we
interact with? So, we're able to pick
that up. Now, you talk about AI risk.
A lot of a lot of your audience will
resonate with this concept. Everybody's
using chat, GPT, etc. Or claude for
example, which is what we use. You get
asked that question. Do you want to
allow once, allow always? Guess what?
People click all the time. Always allow.
I'm a once guy. [laughter]
I am a once guy.
>> You will be unique.
>> Now I'm paranoid.
>> After [laughter] you get to ask that
question 10 times, it's always
>> interesting. Wow.
>> Right. So if you do
>> wake up people,
>> right? [laughter]
>> By the way, we see this in our data. We
have a gent risk center, we are able to
visualize this. So if you click always
allow, guess what you've just done?
You've given that agent freedom to
operate on your endpoint browser, take
whatever actions. That's the second
level of risk. And the last thing is
data excfiltration. It may be
non-malicious. Employees are curious.
New DeepSeek model came out. Some other
model came out. Let me see how good of a
PowerPoint it can do. They're not
thinking, hey, I don't have an
enterprise agreement. Maybe I'm just re
uh revealing my crown jewels here. This
is what CISOs are thinking about, right?
And so
the the framework that we are suggesting
is always start with the user. It's the
risk due to the user and then the AI
risks are just accelerating extens
extending the risk due to the user and
those are the things you need to focus
on.
>> So you are you you are building a
platform to solve for this. What are the
salient aspects of that platform?
um first and foremost is quantify the
risk and surface it right so across all
of these vectors whether it's users
whether it's data whether it's sentiment
analysis across all the collaboration
channels whether it's data excfiltration
or your AI and governance risk we are
quantifying that risk second is really
make it easy to govern third is
protection detection and protection
there we are leveraging all of these
sensors that we have to understand the
behavior of the user and AI acting on
the on behalf of the user and so we are
able to leverage that and improve the
quality of detection right fewer false
positives fewer false negatives and then
ultimately it's about resolving as
opposed to alerting whether it's a
really sensitive file or a simple file
you don't want to keep alerting all the
time so we focus a lot on separating or
you know filtering the signal from noise
as I like to talk about it, right? You
can alert on everything, but you really
only want to alert the sock that's
already very busy on the key things that
matter. So, very focused on all four
aspects across all these threat vectors.
>> What's your recommendation, best
practice on Okay, so you've identified
these risks, you've helped prioritize
them, how do I then act on them?
So I think the first thing really Dave
what we are seeing is when it comes to
shadow AI and agentic risk customers
don't even understand what's going on in
their environment and there's sees
there's good reason by the way look
around the show floor how many different
vendors are there claiming that we can
solve the agentic risk problem so what's
the natural reaction let me pause and
see what's happening but thankfully
they're going to their key providers
crowdstrike mime Mimcast and a few
others and saying hey what can you do
for me so step one is really
understanding the risk I'll give you a
data point
in the last 7 days we looked at about 65
customers that are triing our agentic
risk center in a particular region
we uncovered 125 AI native applications
that they didn't know about
we uncovered 1,300
AI enabled applications that they didn't
know
This is where you have Excel or Word
etc. and you enable the goo you know the
cloud plugin etc. So long before we can
even talk about how to action it just
starting with the discovery and doing
simple governance this is allowed this
isn't allowed would be a huge step
forward from there are plenty of options
available including mcast and
partnership with crowd strike to go and
resolve those to block take blocking
actions
>> but the one thing is user freedom is key
in this day and age so that's where the
quantification of risk comes in. If
Ranjan is a high-risisk user, you can
take blocking actions. If Dave is a
low-risk user, you can take
notification. Hey Dave, did you really
mean to take this action? Can you please
confirm? And then you're off and running
on your way.
>> Yeah. So much more sophisticated than
you would get out of your your Gmail,
which you know is very kind of brute
force. Every time you send an external
email, it's like, hey, this is an
external email. Like, yeah, no kidding,
>> right?
>> And what? So you're really doing much
more much deeper inspection and you can
you had a little a knob that I can turn.
>> Exactly.
>> You know, just allow it.
>> And building on that, Surjan, I'm really
curious when we think about AI agents in
particular. They're the big sort of
insider risk factor. Yeah.
>> These days and it's much more difficult
to understand what actions are
potentially legitimate versus not. Can
you talk to how you're thinking about
maybe kind of solving not solving that
problem but kind of understanding what
is potentially legitimate?
>> Yeah, so it it again goes back to
understanding user behavior
>> and then agents acting on behalf of
those users, right? The same controls in
the hands of one user Dave a low risk
lot of safe options. Ranjan the
high-risk user who likes to autoallow
every action that agent is highly risky.
>> So
what we the way we think about it is
okay you have all these agentic controls
first and foremost we can look across
our 42,000 customers and understand
really what is some of the malicious
activity what are the unsanctioned
agents etc. So we have a lot of built-in
rules to identify, but the second thing
is really tying it back to user behavior
and the behavioral analytics to truly
uncover what is risky behavior.
>> So somebody years ago said to me that um
bad human behavior will beat good
security every time. Now you've got um
this AI risk which is novel. You see the
hugging face attack, a hack, not a not
an attack, it's a it's a it's a hack.
Um, not a malicious attack. Very
interesting. Okay, so humans aren't
going to try to cover their tracks. They
they're not paying attention. They're
just clicking, right? But these AIs,
they are they're they have omera. They
don't rat on each other, right? They
they're just trying to not get caught.
>> They're working collectively, right?
>> Working collectively. They have
civilizations. They do kamic. I mean,
they're doing crazy things. And one of
the things they do is they they scrub
over the their their tracks. They they
hide their tracks. They rewrite the log
files.
So how do you interpret that? How does
that mess with your algorithms? How do
you deal with that?
>> I like to say security is a team sport.
So under no circumstance will I came my
past will solve all of these problems.
Um I think the answer is really we have
to work as an ecosystem just as you
heard in the keynote today really the
keys are okay is the agent acting
autonomously is the agent acting on
behalf of users we operate at the
intersection of users AI acting on
behalf of users and data excfiltration
there'll be other platforms that are
looking as autonomous agent activity
crowdstrike talked a lot about that
today we have to converge all of these
signals really to understand what is the
threats we pose and
you know the solution has to come out of
working together with the ecosystem a
lot of what you heard today behind the
scenes there's a lot of work going on in
this ecosystem uh a lot of us are
working together trying to figure out
how to solve these problems I won't
claim that we have it all figured out
but at least we have a starting point
and the starting point is really do you
know what's going on in your environment
right and if 90% of the risk is
associated with users. I think that's a
good starting point if you can at least
discover all of those agentic risks.
>> I think it's a fair answer. Um it was
interesting seeing Jensen up on the
stage today. Jensen's the alpha of the
industry. I feel like CrowdStrike is
becoming the
>> sort of co-alpha with Nikesh, you know,
at PaloAlto. But they're you're kind of
you're seeing the ecosystem evolve here
and coalesce around Crowdstrike. What is
it about Crowdstrike that makes them an
attractive partner and and unique in
your view?
>> Uh, you know, first of all, their belief
in a very open ecosystem. Uh, George
talked about it today. Uh, second is
really Mcast and CrowdStrike have been
working together for a long long time
exchanging indicators of compromise with
the same intention. Let's solve the
problem we we can't solve alone, right?
Mcast looks at two billion emails daily.
We block a lot of threats. We have a lot
of indicators of compromise from malware
to malicious files to URLs to domains.
We're feeding all of that information to
CrowdStrike. We can leverage CrowdStrike
to isolate all the endpoints, all the
users that are tied to those endpoints.
And in return, Crowd Strike sees a lot
of malicious activity. We can take a lot
of that information and feed it and try
to understand user behavior and the risk
metrics. Um, so really it's just an open
ecosystem, an open approach with a
common goal of solving this problem
together. Uh, you know, I've been at
Mcast for 15, 20 months. I've watched
CrowdStrike from afar in other companies
that I've worked in. It's always been
about an open ecosystem getting together
to solve problems and and that's really
what's exciting about working with
CrowdStrike.
>> Well, I appreciate that. And we've seen
this ecosystem grow. You have a final
thought or
>> Yeah. So before the cameras rolled, we
were talking a little bit about
platforms and I think it's relevant to
the ecosystem discussion
>> and my opinion part of what makes a
platform is having those inter you know
those integration points.
>> We were also talking a little bit about
will customers be more incentivized to
try to consolidate down some of their
security stack especially as they're
trying to move more quickly to respond
to these AIdriven adversarial threats
and the enterprise adoption of AI. So
can you share some thoughts on what your
how you define a platform and what
you're maybe what you're seeing from
customers.
>> Yeah, absolutely. Um I have a very s we
have a very simple philosophy around
platforms which is number one it must
deliver outcomes. If you have a
platform, what are you promising the
customer? Better security posture,
better operational efficiency, better
ROI. And you should be able to quantify
that, right? It's not just we deliver
better efficiency. We deliver 40% better
efficiency if you use our platform as
opposed to using point tools or or end,
you know, single tools, right? So there
is an advantage and an outcome that
we're delivering. Number two, the
platform must be deeply integrated. I
talk about firstparty integrations and
thirdparty integrations. Firstparty
integrations is okay, we have email, we
have DLP, we have uh fishing simulation,
security awareness training. The three
need to come together to deliver an
experience. If a security professional
works in one tool in one environment, an
integrated platform shouldn't force them
to go into three different user
interfaces and act on it. And that's
what I talk about first party
integrations. And then thirdparty
integrations is all about delivering a
better ROI. You're already invested in
all of these tools. How can we leverage
information, IoC's, etc. to deliver even
more value like that's creating value
from your existing investments. So I
think these are core tenants of a
platform as opposed to a commercial
bundle where you take four products
together, wrap it into a skew and give
give a discount. You know, to me that's
not a platform. So the other thing is
common look and feel, a common
experience. You know Microsoft is a
great example of that and plenty of
other players Adobe, Google etc. And in
this day and age instead of user
interfaces you really want the work
being done on behalf on your behalf. So
the platform that we are building as an
example think about claude cowwork.
You've set up your workflows on a daily
basis. You've set up the frequency and
they're talking to the mimecast
platform. they're taking actions. A
common example that we implement today I
like to describe is you've already fed
us your acceptable use policy. Give me
all the alerts that have taken place in
the last 24 hours that violate that
acceptable use policy. That's a report
that lands on the CISO desk or security
professional desk. You don't have to
lift a finger. That's the kind of value
a platform should be able to deliver. So
given that your first principle you
started with outcomes, how does that
change the thinking on on pricing? I
mean I'm interested specifically how
you're thinking about it for Mcast, but
generally for the industry there's a lot
of talk about outcome pricing. You know
Palunteer sort of does it others you
know the the the the deploy codes the
FDE codes they're doing sort of
outcomebased pricing. How do you think
about pricing in this new world? Um I
think there are certain places where
there is probably maturity in outcome
based pricing when you're dealing with
service you know tickets CRM those kinds
of things I think from a cyber security
standpoint
we have to have a hybrid I feel uh you
have to have some kind of a baseline on
the classic SASbased pricing and
augmented with outcome based pricing an
area that we will be bringing outcome
based pricing is think about uh insider
threat and data loss protection. And we
have various agents. We have an
investigate agent. We have a
configuration agent where
you know when we generate an alert, you
can click on the button on an
investigate agent. That's if we deliver
an outcome, false positive, false
negative. You can price that in tokens,
however you think about it. But
customers may not want to click on an
investigate agent. They want to automate
it. We call that a tier four outcome
where you want complete autonomous
actions.
>> Okay? and you have worked with us to to
have a degree of certainty around
certain actions. You're not going to
auto autonomously allow those things. So
I think it's a hybrid of you know per
user license, per seat license, whatever
the case combined with these outcomes
that is going from a human interaction
to complete autonomous actions.
>> Interesting. I mean the market is going
to ultimately decide you know in
software no matter how you price it,
it's never perfect.
>> Yes. And and and the other thing for
customers is, you know, software
companies are really good at making sure
that, you know, they preserve their
revenue and they're going to do that
because they have R&D to fund and they
have go to market and they have, you
know, competitive environments and they
need to innovate. So there's that
balance and the market is still trying
to figure that out now. It's pretty
>> you're absolutely right. Right. Both
both will want to be conservative in
their views.
>> Uh software vendors will want to protect
their revenue stream. Customers will
want certainty and outcomes. Yeah. And
and procurement is going to want a fixed
fee. Exactly. Right. At a discount, of
course. A lot of work to be done, but uh
we're gradually introducing these
concepts. Uh obviously, we work with our
customers, our joint customers to go and
test this out. We see what the rest of
the industry is evolving. Um one of the
things that's very clear in both cyber
security and SAS in general is you're
not going to come out with a novel
commercial model and try to flip
everybody on its head. You have to work
and and and gradually move in a certain
direction.
>> Well, this is the beauty of capitalism.
There's lots of competition, you know,
lots of choice and and the market will
figure it out. Buyers and sellers come
together. Ranjan, thanks so much for
coming on the show.
>> Dave, it was a real pleasure. Christa,
thank you so much. Real pleasure to
talk.
>> Pleasure having you. Thank you.
>> Okay, we're wrapping up day two here.
Dave Volante for Christa Case and
Rebecca Knight. Check out
siliconangle.com. They just dropped a
bunch of news uh and analysis on uh on
on Crowdstrike and the Falcon event.
We'll be back tomorrow, 8:15 a.m. George
Kurtz live on the Cube. Don't miss it.
Set your calendar. Set your clocks at
Pacific time, of course. We'll see you
then on the Cube. Thanks for watching.