Submind YouTube summaries
Thumbnail for Ranjan Singh, Mimecast | CrowdStrike Fal.Con 2026

Ranjan Singh, Mimecast | CrowdStrike Fal.Con 2026

Watch on YouTube

Video summary

Ranjan Singh, CEO of Mimecast, discusses the evolution of his company from a specialist in email security to a comprehensive platform addressing human, AI, and data risks. He emphasizes that modern security must operate at the intersection of these three vectors rather than treating them as isolated concerns. The core philosophy behind this approach is to first discover, identify, and quantify risk before implementing governance or protection measures. By quantifying risk on a scale from one to ten based on various signals like user behavior, phishing simulation results, and endpoint data loss potential, organizations can move beyond generic rules to make informed decisions about what actions are sanctioned versus prohibited. The conversation highlights how AI agents have introduced new layers of complexity, particularly regarding "agentic risk" where users might inadvertently grant excessive permissions by clicking "always allow," or employees might unknowingly exfiltrate sensitive data while testing new AI models. Mimecast's strategy involves analyzing user behavior to distinguish between legitimate actions and risky ones, even when those actions are performed by autonomous agents that may attempt to hide their tracks. The platform aims to resolve issues directly rather than just generating alerts, thereby reducing noise for security teams. This is achieved through deep integrations with partners like CrowdStrike, allowing the ecosystem to share indicators of compromise and behavioral data to create a more robust defense against sophisticated threats like business email compromise attacks that rely on invisible character manipulation. Regarding the definition of a true security platform, Singh argues that it must deliver measurable outcomes such as improved efficiency and ROI, rather than simply bundling point solutions. A genuine platform offers deep first-party integrations across email, data loss prevention, and security awareness training within a single user interface, eliminating the need for security professionals to switch between multiple tools. While pricing models are evolving toward outcome-based structures where customers pay for specific results like false positive reduction or autonomous remediation, Mimecast currently employs a hybrid model that combines traditional licensing with value derived from advanced outcomes. The ultimate goal is to empower organizations to manage their security posture effectively in an era where human error and AI-driven threats converge, ensuring that the right actions are taken autonomously while maintaining necessary human oversight for high-risk scenarios.
Read the full video transcript
Welcome back to the Mandalay Bay. My name is Dave Volante. I'm here with Chris Case and you're watching the Cub's coverage of Falcon 2026. Crowd Strikes Crowd Strike's big customer event. We're up to gosh well over 10,000 people. This is our fifth year at Crowdstrike. We started when the ecosystem was pretty tiny. We kind of predicted accurately that it was going to explode and it sure has. We're going to have a really interesting conversation right now about securing human data and AI risk all in one system in a platform. Rajan Singh is here. He's the chief executive officer of Mcast. Ranjan, thanks for coming on. >> Uh Dave Christa, thank you so much for having me. It's a great opportunity and what an event. It's an unbelievable event. >> It's really great keynote this morning by George. >> Amazing keynote and uh you know it's the first time me watching Jensen in action in in live. >> He's a he's a cool dude. >> He is a cool dude. Seeing the banter was always fun. >> It was funny. [laughter] I was I was having a conversation. I had dinner the other night with uh one of my colleagues who was he was in in our business analyst business. He was actually a president of IDC at one time after I left well after I left. He said you know back back in the day you used to be able to just go into Jensen's office say hi and [laughter] now it's like you know getting getting to the president's easier than getting to Jensen. But any rate let's talk about Mcast. You guys built your reputation in in email security, but obviously the risk has expanded beyond the inbox, right? You've got sensitive data, you've got human behavior. Where are you taking the company? >> Yeah, we have evolved uh, you know, from a 20 plus year history in ML security to now focusing on human risk, AR risk and data risk. Sounds like big statement, sounds like things what most people talk about. But we are very acutely focused on number one measuring the risk, quantifying the risk. So it's not just about all the risk vectors but quantify the risk. And we started with human risk and then we looked we look at AI risk as an extension of that human risk as opposed to just a standalone risk. And then the ultimate goal with whether it's human risk or AI risk is data excfiltration. So we as a company are operating at the intersection of human AI and data risk. And then the core element there is quantifying the risk. And as you know if you can quantify something you can usually solve for it improve it. So our philosophy and framework is discover identify and quantify the risk. From there we make it really easy for customers to govern those risks. Tell us this is allowed, this is sanctioned, this is not sanctioned as opposed to building rules etc. We make it really easy. Once we have the governance in place, we can build protection around that across all three vectors. >> And then lastly is resolution and our philosophy is resolve first, alert second. Um, so this is the platform that we are building. And the idea is very simple. Instead of having customers focus on point solutions of human risk, AI risk and data risk, we believe that you have to operate at the intersection of all three risks. And then they're really merging together and we're building on platform and delivering those outcomes. >> Is the quantification of the risk I think you know in terms of expected loss or is it t-shirt sizes high, medium, low? >> Uh no, it's actually literally numbers on a scale of 1 to 10. So Dave is low risk at let's say at Mcast or at Cube you're low risk, you're two out of 10. Runen is seven out of 10. How do we determine that? We take inputs from parts of our platform. Email, are you highly attacked? Are you clicking on links? Are you passing your fishing simulation test and security awareness training? What is the risk of data loss on your endpoint? And then we have deep integrations with the ecosystem, MFA fatigue attacks from the identity providers, uh indicators of compromise from endpoint like Crowdstrike. We have huge integrations with Crowdstrike or the Sassy providers. We take all of these signals, we weight them, and we calculate the risk score. >> So it's like you basically calculate a risk signature for each human and AI. Okay. And then I presume so you weight them. If I'm if I'm getting attacked a lot and I'm a high risk in that sense, but I don't have access to anything. You weight that accordingly. So there's a value component dimension correct of this as well. >> Correct. Yeah. And then the key thing about measuring that risk is we don't do it just to say hey here's where your risk is because we in our data that we see 8% of your users are responsible for 80% of your risk right it sounds like a marketing pitch because we match the numbers but I encourage anybody to go look into their environment and see who refuses to take the security awareness training or the or who fails the fishing simulation test. That alone will reveal that metric for you. Okay. >> So, Ranjad, I've had a number of c uh conversations with CISOs and other practitioners both here at Crowdstrike and a few weeks ago at Black Hat >> and they talked to the role of the CISO as evolving into one of being an arbiter of these decisions around risk and what sort of trade-offs that the enterprise needs to make. So can you talk to, you know, how these risk metrics are changing as humans start perhaps engaging with AI agents because I really think that's central to again how the CISO really thinks about executing on their job and starts to you know converse with the line of business and have these these discussions. Um, we talk about the blurring lines of human risk, AI risk, and data risk. And I'll walk you through a few examples, which is impacting how CESOS think about it, and then how should they potentially respond to it. So, human risk was all about, hey, you can click on a link. Well, now you have really sophisticated fishing attacks, right? One that we just uncovered about a week ago. Looks like a plain email. It's a BEC business email compromise attempt. But when we flagged it as malicious, what we saw inside it is between every character there were nonvisible 100 characters between every character in the word. The idea being if you are relying on text scanning based BC detection of any kind, you're not going to pick this up. But we were able to pick it up because we are studying user behavior. What is common communication pattern? what is it, you know, is it a first-time sender, for example, is this a common domain we interact with? So, we're able to pick that up. Now, you talk about AI risk. A lot of a lot of your audience will resonate with this concept. Everybody's using chat, GPT, etc. Or claude for example, which is what we use. You get asked that question. Do you want to allow once, allow always? Guess what? People click all the time. Always allow. I'm a once guy. [laughter] I am a once guy. >> You will be unique. >> Now I'm paranoid. >> After [laughter] you get to ask that question 10 times, it's always >> interesting. Wow. >> Right. So if you do >> wake up people, >> right? [laughter] >> By the way, we see this in our data. We have a gent risk center, we are able to visualize this. So if you click always allow, guess what you've just done? You've given that agent freedom to operate on your endpoint browser, take whatever actions. That's the second level of risk. And the last thing is data excfiltration. It may be non-malicious. Employees are curious. New DeepSeek model came out. Some other model came out. Let me see how good of a PowerPoint it can do. They're not thinking, hey, I don't have an enterprise agreement. Maybe I'm just re uh revealing my crown jewels here. This is what CISOs are thinking about, right? And so the the framework that we are suggesting is always start with the user. It's the risk due to the user and then the AI risks are just accelerating extens extending the risk due to the user and those are the things you need to focus on. >> So you are you you are building a platform to solve for this. What are the salient aspects of that platform? um first and foremost is quantify the risk and surface it right so across all of these vectors whether it's users whether it's data whether it's sentiment analysis across all the collaboration channels whether it's data excfiltration or your AI and governance risk we are quantifying that risk second is really make it easy to govern third is protection detection and protection there we are leveraging all of these sensors that we have to understand the behavior of the user and AI acting on the on behalf of the user and so we are able to leverage that and improve the quality of detection right fewer false positives fewer false negatives and then ultimately it's about resolving as opposed to alerting whether it's a really sensitive file or a simple file you don't want to keep alerting all the time so we focus a lot on separating or you know filtering the signal from noise as I like to talk about it, right? You can alert on everything, but you really only want to alert the sock that's already very busy on the key things that matter. So, very focused on all four aspects across all these threat vectors. >> What's your recommendation, best practice on Okay, so you've identified these risks, you've helped prioritize them, how do I then act on them? So I think the first thing really Dave what we are seeing is when it comes to shadow AI and agentic risk customers don't even understand what's going on in their environment and there's sees there's good reason by the way look around the show floor how many different vendors are there claiming that we can solve the agentic risk problem so what's the natural reaction let me pause and see what's happening but thankfully they're going to their key providers crowdstrike mime Mimcast and a few others and saying hey what can you do for me so step one is really understanding the risk I'll give you a data point in the last 7 days we looked at about 65 customers that are triing our agentic risk center in a particular region we uncovered 125 AI native applications that they didn't know about we uncovered 1,300 AI enabled applications that they didn't know This is where you have Excel or Word etc. and you enable the goo you know the cloud plugin etc. So long before we can even talk about how to action it just starting with the discovery and doing simple governance this is allowed this isn't allowed would be a huge step forward from there are plenty of options available including mcast and partnership with crowd strike to go and resolve those to block take blocking actions >> but the one thing is user freedom is key in this day and age so that's where the quantification of risk comes in. If Ranjan is a high-risisk user, you can take blocking actions. If Dave is a low-risk user, you can take notification. Hey Dave, did you really mean to take this action? Can you please confirm? And then you're off and running on your way. >> Yeah. So much more sophisticated than you would get out of your your Gmail, which you know is very kind of brute force. Every time you send an external email, it's like, hey, this is an external email. Like, yeah, no kidding, >> right? >> And what? So you're really doing much more much deeper inspection and you can you had a little a knob that I can turn. >> Exactly. >> You know, just allow it. >> And building on that, Surjan, I'm really curious when we think about AI agents in particular. They're the big sort of insider risk factor. Yeah. >> These days and it's much more difficult to understand what actions are potentially legitimate versus not. Can you talk to how you're thinking about maybe kind of solving not solving that problem but kind of understanding what is potentially legitimate? >> Yeah, so it it again goes back to understanding user behavior >> and then agents acting on behalf of those users, right? The same controls in the hands of one user Dave a low risk lot of safe options. Ranjan the high-risk user who likes to autoallow every action that agent is highly risky. >> So what we the way we think about it is okay you have all these agentic controls first and foremost we can look across our 42,000 customers and understand really what is some of the malicious activity what are the unsanctioned agents etc. So we have a lot of built-in rules to identify, but the second thing is really tying it back to user behavior and the behavioral analytics to truly uncover what is risky behavior. >> So somebody years ago said to me that um bad human behavior will beat good security every time. Now you've got um this AI risk which is novel. You see the hugging face attack, a hack, not a not an attack, it's a it's a it's a hack. Um, not a malicious attack. Very interesting. Okay, so humans aren't going to try to cover their tracks. They they're not paying attention. They're just clicking, right? But these AIs, they are they're they have omera. They don't rat on each other, right? They they're just trying to not get caught. >> They're working collectively, right? >> Working collectively. They have civilizations. They do kamic. I mean, they're doing crazy things. And one of the things they do is they they scrub over the their their tracks. They they hide their tracks. They rewrite the log files. So how do you interpret that? How does that mess with your algorithms? How do you deal with that? >> I like to say security is a team sport. So under no circumstance will I came my past will solve all of these problems. Um I think the answer is really we have to work as an ecosystem just as you heard in the keynote today really the keys are okay is the agent acting autonomously is the agent acting on behalf of users we operate at the intersection of users AI acting on behalf of users and data excfiltration there'll be other platforms that are looking as autonomous agent activity crowdstrike talked a lot about that today we have to converge all of these signals really to understand what is the threats we pose and you know the solution has to come out of working together with the ecosystem a lot of what you heard today behind the scenes there's a lot of work going on in this ecosystem uh a lot of us are working together trying to figure out how to solve these problems I won't claim that we have it all figured out but at least we have a starting point and the starting point is really do you know what's going on in your environment right and if 90% of the risk is associated with users. I think that's a good starting point if you can at least discover all of those agentic risks. >> I think it's a fair answer. Um it was interesting seeing Jensen up on the stage today. Jensen's the alpha of the industry. I feel like CrowdStrike is becoming the >> sort of co-alpha with Nikesh, you know, at PaloAlto. But they're you're kind of you're seeing the ecosystem evolve here and coalesce around Crowdstrike. What is it about Crowdstrike that makes them an attractive partner and and unique in your view? >> Uh, you know, first of all, their belief in a very open ecosystem. Uh, George talked about it today. Uh, second is really Mcast and CrowdStrike have been working together for a long long time exchanging indicators of compromise with the same intention. Let's solve the problem we we can't solve alone, right? Mcast looks at two billion emails daily. We block a lot of threats. We have a lot of indicators of compromise from malware to malicious files to URLs to domains. We're feeding all of that information to CrowdStrike. We can leverage CrowdStrike to isolate all the endpoints, all the users that are tied to those endpoints. And in return, Crowd Strike sees a lot of malicious activity. We can take a lot of that information and feed it and try to understand user behavior and the risk metrics. Um, so really it's just an open ecosystem, an open approach with a common goal of solving this problem together. Uh, you know, I've been at Mcast for 15, 20 months. I've watched CrowdStrike from afar in other companies that I've worked in. It's always been about an open ecosystem getting together to solve problems and and that's really what's exciting about working with CrowdStrike. >> Well, I appreciate that. And we've seen this ecosystem grow. You have a final thought or >> Yeah. So before the cameras rolled, we were talking a little bit about platforms and I think it's relevant to the ecosystem discussion >> and my opinion part of what makes a platform is having those inter you know those integration points. >> We were also talking a little bit about will customers be more incentivized to try to consolidate down some of their security stack especially as they're trying to move more quickly to respond to these AIdriven adversarial threats and the enterprise adoption of AI. So can you share some thoughts on what your how you define a platform and what you're maybe what you're seeing from customers. >> Yeah, absolutely. Um I have a very s we have a very simple philosophy around platforms which is number one it must deliver outcomes. If you have a platform, what are you promising the customer? Better security posture, better operational efficiency, better ROI. And you should be able to quantify that, right? It's not just we deliver better efficiency. We deliver 40% better efficiency if you use our platform as opposed to using point tools or or end, you know, single tools, right? So there is an advantage and an outcome that we're delivering. Number two, the platform must be deeply integrated. I talk about firstparty integrations and thirdparty integrations. Firstparty integrations is okay, we have email, we have DLP, we have uh fishing simulation, security awareness training. The three need to come together to deliver an experience. If a security professional works in one tool in one environment, an integrated platform shouldn't force them to go into three different user interfaces and act on it. And that's what I talk about first party integrations. And then thirdparty integrations is all about delivering a better ROI. You're already invested in all of these tools. How can we leverage information, IoC's, etc. to deliver even more value like that's creating value from your existing investments. So I think these are core tenants of a platform as opposed to a commercial bundle where you take four products together, wrap it into a skew and give give a discount. You know, to me that's not a platform. So the other thing is common look and feel, a common experience. You know Microsoft is a great example of that and plenty of other players Adobe, Google etc. And in this day and age instead of user interfaces you really want the work being done on behalf on your behalf. So the platform that we are building as an example think about claude cowwork. You've set up your workflows on a daily basis. You've set up the frequency and they're talking to the mimecast platform. they're taking actions. A common example that we implement today I like to describe is you've already fed us your acceptable use policy. Give me all the alerts that have taken place in the last 24 hours that violate that acceptable use policy. That's a report that lands on the CISO desk or security professional desk. You don't have to lift a finger. That's the kind of value a platform should be able to deliver. So given that your first principle you started with outcomes, how does that change the thinking on on pricing? I mean I'm interested specifically how you're thinking about it for Mcast, but generally for the industry there's a lot of talk about outcome pricing. You know Palunteer sort of does it others you know the the the the deploy codes the FDE codes they're doing sort of outcomebased pricing. How do you think about pricing in this new world? Um I think there are certain places where there is probably maturity in outcome based pricing when you're dealing with service you know tickets CRM those kinds of things I think from a cyber security standpoint we have to have a hybrid I feel uh you have to have some kind of a baseline on the classic SASbased pricing and augmented with outcome based pricing an area that we will be bringing outcome based pricing is think about uh insider threat and data loss protection. And we have various agents. We have an investigate agent. We have a configuration agent where you know when we generate an alert, you can click on the button on an investigate agent. That's if we deliver an outcome, false positive, false negative. You can price that in tokens, however you think about it. But customers may not want to click on an investigate agent. They want to automate it. We call that a tier four outcome where you want complete autonomous actions. >> Okay? and you have worked with us to to have a degree of certainty around certain actions. You're not going to auto autonomously allow those things. So I think it's a hybrid of you know per user license, per seat license, whatever the case combined with these outcomes that is going from a human interaction to complete autonomous actions. >> Interesting. I mean the market is going to ultimately decide you know in software no matter how you price it, it's never perfect. >> Yes. And and and the other thing for customers is, you know, software companies are really good at making sure that, you know, they preserve their revenue and they're going to do that because they have R&D to fund and they have go to market and they have, you know, competitive environments and they need to innovate. So there's that balance and the market is still trying to figure that out now. It's pretty >> you're absolutely right. Right. Both both will want to be conservative in their views. >> Uh software vendors will want to protect their revenue stream. Customers will want certainty and outcomes. Yeah. And and procurement is going to want a fixed fee. Exactly. Right. At a discount, of course. A lot of work to be done, but uh we're gradually introducing these concepts. Uh obviously, we work with our customers, our joint customers to go and test this out. We see what the rest of the industry is evolving. Um one of the things that's very clear in both cyber security and SAS in general is you're not going to come out with a novel commercial model and try to flip everybody on its head. You have to work and and and gradually move in a certain direction. >> Well, this is the beauty of capitalism. There's lots of competition, you know, lots of choice and and the market will figure it out. Buyers and sellers come together. Ranjan, thanks so much for coming on the show. >> Dave, it was a real pleasure. Christa, thank you so much. Real pleasure to talk. >> Pleasure having you. Thank you. >> Okay, we're wrapping up day two here. Dave Volante for Christa Case and Rebecca Knight. Check out siliconangle.com. They just dropped a bunch of news uh and analysis on uh on on Crowdstrike and the Falcon event. We'll be back tomorrow, 8:15 a.m. George Kurtz live on the Cube. Don't miss it. Set your calendar. Set your clocks at Pacific time, of course. We'll see you then on the Cube. Thanks for watching.