Secure the front door. Email is where most attacks arrive — Mimecast Incydr catches data leaving via employees — USB, personal cloud, webmail, Git — risk-ranked with full context, without rigid DLP policies.
Buy through TechBag
Same software. Better outcome — at no extra cost.
Free, vendor-neutral, 30 minutes
How it’s rated
Full scoreboard ↓Quick answer
Mimecast Incydr is insider-risk management and data protection — the technology Mimecast acquired with Code42 in 2024. It focuses on a threat traditional DLP handles badly: the data that leaves your organisation via employees, whether accidental, negligent or malicious. Rather than relying on rigid, pre-defined DLP policies that block and frustrate, Incydr watches how data actually moves — to USB drives, personal cloud accounts, personal email, unmanaged devices, Git and more — and surfaces the risky exfiltration that matters, ranked by risk, with the full context of who, what, where and how. It is engineered to detect data exposure, loss, leak and theft fast, without lengthy deployments or complex policy management, and it offers a graduated response: automated micro-learning for accidental low-risk events, case management for investigations, and blocking for the highest-risk cases. As part of Mimecast's Human Risk Management platform, insider-risk signals connect to the same view of human risk as email, collaboration and awareness training — so the departing employee emailing files to a personal account is one connected picture. TechBag scopes, PoCs and quotes it in INR/GST.
This page covers Incydr — the insider-risk layer (Code42). The rest of the platform:
Most product pages skip this. We start here — so you buy a capability, not a buzzword.
Protection against data leaving via employees — accidental, negligent or malicious — by watching how data actually moves, not rigid content rules.
The Code42 Incydr technology, now in Mimecast’s platform.
What consolidation actually replaces, dimension by dimension.
| Dimension | Unprotected / signature email | Incydr (Mimecast) |
|---|---|---|
| The model | Pre-defined content policies | Watch how data actually moves |
| False positives | Floods that bury analysts | Risk-ranked, few real events |
| Exfiltration vectors | One channel, or missed | USB, cloud, email, Git, devices |
| Departing employees | Slip through | Flagged with context |
| Response | Block everything, frustrate all | Micro-learn, investigate, block |
| Deployment | Multi-quarter policy project | Fast, no policy marathon |
| Productivity | Ground to a halt | Non-disruptive by design |
| The context | Siloed data tool | Connected human-risk view |
No content-policy project — watch how data moves, respond to fit the risk. Connects to email in one human-risk platform.
Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.
Watches file movement across the exfiltration vectors employees use — USB, personal cloud, personal email, browser uploads, Git, unmanaged devices — rather than relying on pre-defined content policies.
Surfaces the exfiltration that matters, ranked by risk and enriched with context (who, what, where, how, when) — so analysts see the few real risks, not thousands of policy alerts.
Automated micro-learning for accidental low-risk events, case management for investigations, and blocking for the highest-risk cases — response proportional to risk.
Engineered to deploy fast without lengthy rollouts or complex policy management — value in days, not the multi-quarter DLP project buyers dread.
Part of the Human Risk Management platform — insider-risk connects to email, collaboration and awareness training in one human-risk view.
One agent on every machine, one console over all of them — modules attach without a second operational world.
Mimecast Incydr catches the data that walks out via employees — risk-ranked, fast to deploy, part of the portfolio, and paired with the human firewall.
Detects data leaving via USB, personal cloud, personal email, browser upload, Git and unmanaged devices — the real ways data walks out.
Every event enriched with who, what, where, when and how — the context to judge whether it is accidental, negligent or malicious.
Surfaces the exfiltration that matters, ranked by risk — the few real risks, not thousands of DLP policy alerts.
Flags the classic insider risk — a departing employee taking files to a personal account or drive before they leave.
Watches how data moves rather than requiring pre-defined content policies to block — avoiding the false positives and friction of legacy DLP.
Accidental, non-malicious risk triggers automated micro-learning — coaching the user in the moment, not a security ticket.
Built-in case management for efficient investigation collaboration — the workflow to run an insider-risk case to conclusion.
For the highest-risk use cases, automated blocking stops the exfiltration — response proportional to the risk.
No lengthy rollouts or complex policy management — engineered for fast time-to-value, unlike the classic DLP project.
Feeds the Human Risk Management platform — the risky data-mover connected to their email, collaboration and training profile.
Connects to Mimecast email security — data leaving by personal email seen alongside the email threat picture.
Detects and responds without disrupting employee productivity — security that does not grind the business to a halt.
The overview, getting started, and protecting M365 email.
How Incydr detects insider risk and data exfiltration.
Detecting the data that leaves via employees.
The platform insider-risk signals connect into.
Want a live, India-context walkthrough on your own fleet?
Book a guided demo →Here’s what genuinely sets Incydr apart from traditional DLP.
Legacy data-loss prevention relies on pre-defined content policies — rules that try to describe every kind of sensitive data and block it. In practice that produces two failures at once: floods of false positives that bury analysts and frustrate employees, and blind spots for anything the rules did not anticipate. Insider risk — a departing employee taking files, a negligent share to personal cloud — routinely slips through. Incydr takes a different approach: instead of trying to classify all content up front, it watches how data actually moves and surfaces the risky exfiltration that matters, which is far better suited to catching what employees actually do with data.
Data does not walk out only one way. Incydr monitors the full range of exfiltration vectors employees use: USB drives, personal cloud accounts (Dropbox, Google Drive), personal webmail, browser uploads, Git repositories, Airdrop, and unmanaged devices. Because it watches movement across all of these rather than one channel, it catches the departing engineer pushing source code to a personal GitHub, or the salesperson emailing the customer list to a personal address — the real-world exfiltration patterns that single-channel or content-rule tools miss.
Not every file movement is a threat — employees legitimately move data constantly. Incydr's value is triage: it surfaces the exfiltration that matters, ranked by risk and enriched with the full context of who moved what, to where, how and when. Analysts see the handful of genuinely risky events with the story attached, rather than drowning in thousands of undifferentiated policy alerts. That signal-over-noise focus is what makes insider-risk management actually workable for a real security team.
Incydr's response is graduated, matched to intent. For accidental, non-malicious events, automated micro-learning coaches the employee in the moment — turning a mistake into a teachable moment without a security ticket. For events that need investigation, built-in case management runs the case. For the highest-risk use cases, automated blocking stops the exfiltration outright. This graduated model — educate, investigate, block — is far more practical than legacy DLP's blunt block-everything stance, which frustrates the many to stop the few.
Buyers dread DLP because classic deployments are multi-quarter projects: classify all the data, write and tune endless policies, fight false positives for months. Incydr is engineered for fast time-to-value — it watches data movement without requiring you to pre-define exhaustive content policies, so it deploys quickly and starts surfacing real risk in days, not after a lengthy rollout. That speed-to-value, without disrupting employee productivity, is a core reason organisations choose it over traditional DLP.
Since the Code42 acquisition, Incydr is part of Mimecast's Human Risk Management platform — so insider risk is not a siloed data-security tool. The employee moving data risky-ly connects to the same human-risk view as their email behaviour, their awareness-training status and their collaboration activity. A departing employee emailing files to a personal account, for instance, is one connected story across email and insider-risk signals. That connected view of the human across every channel is Mimecast's differentiator over a standalone insider-risk or DLP point product.
Your crown-jewel data, your exfiltration vectors (USB, cloud, webmail, Git), and your departing-employee process. TechBag scopes it free.
Deployed fast — no content-policy project; watching data movement across vectors, surfacing risk-ranked exfiltration with full context.
Micro-learning for accidental events, case management for investigations, blocking for highest-risk; connected to email in the platform.
Real exfiltration caught with context, response proportional to risk, one human-risk view. TechBag models the mix in INR/GST.
Trusted across regulated industries in 100+ countries
Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.
“Legacy DLP buried us in false positives and still missed the real thing. Incydr surfaced the departing engineer pushing code to personal GitHub — ranked, with full context. That is the difference.”
“It watches how data actually moves — USB, personal cloud, webmail — instead of demanding we write a thousand content rules. We got value in days, not a year-long project.”
“The graduated response is the win: accidental shares trigger micro-learning, real risk goes to a case, and the worst gets blocked. We stopped punishing everyone to catch a few.”
“Departing-employee risk was our nightmare. Incydr flags the file-taking before they leave, with the who/what/where attached. Investigations that took days take minutes.”
“Connecting insider-risk signals to the person's email and training profile in one platform changed how we think about human risk — it is one story, not separate tools.”
“For pure enterprise DLP with regulated data-type classification we still weighed the DLP leaders. For insider risk and exfiltration specifically, Incydr's approach won. Scope both.”
“It did not tank productivity — detection runs without the constant blocking that made our old DLP hated. Security the business could live with.”
“Case management built in meant our investigations stayed in one place with the evidence — no exporting to spreadsheets. Efficient.”
Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the email security market — tap any vendor to see why it sits where it does.
Execution strength vs product vision — the classic market map, minus the paywall.
Insider risk, risk-ranked, fast, in a human-risk platform — this page's product.
The grid nobody publishes — how strong the email detection is vs how integrated with the wider security portfolio.
Fast, low-noise insider risk in a human-risk platform — the corner it owns.
Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.
The native Microsoft option, classic DLP and the lineage tools — honest lanes; the edge is fast, low-noise insider risk in a human-risk platform.
| Dimension | Mimecast Incydr | Microsoft Purview IRM | Forcepoint / classic DLP | Cyberhaven | No insider-risk tool |
|---|---|---|---|---|---|
| Approach | Watch data movement, risk-rank | M365-native IRM | Content-policy DLP | Data lineage | The gap |
| Exfiltration coverage | Broad | M365-centric | Policy-bound | Broad + lineage | None |
| Signal vs noise | Risk-ranked | Improving | False-positive heavy | Context-rich | None |
| Time-to-value | Fast | Moderate | Slow | Moderate | N/A |
| Platform connection | Human Risk Management | Microsoft Purview | DLP suite | Standalone | None |
| Best fit | Insider-risk buyers wanting fast, low-noise IRM in a human-risk platform | All-Microsoft E5 estates | Regulated data-type DLP needs | Data-lineage-first buyers | Nobody with IP or regulated data |
Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.
Drag the sliders (count users; IT-hour cost as loaded incident rate). Estimates assume ~1.5 hours per user per year handling email threats that reach the inbox without AI filtering, with ~70% removed by stopping the mass at the gateway — the avoided-breach value (most attacks start here) is the larger, unpriced win. Illustrative.
Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models actual device counts and modules.
Mimecast Incydr prices per user. TechBag scopes it (and the connection to your email security) for your insider-risk needs in one GST quote.
Best for insider risk
Best for a broader rollout
Best for one human-risk view
Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.
Tell us your device counts and current tools — we’ll model it against what you spend today.
Take this into your next vendor call — including ours.
Confirm it sees YOUR exfiltration vectors — USB, personal cloud, personal webmail, browser upload, Git, unmanaged devices.
Test whether it surfaces the FEW real risks ranked with context, not a flood of policy alerts.
Run the departing-employee scenario — is the file-taking flagged with who/what/where before they leave?
Verify the three responses fit: micro-learning (accidental), case management (investigate), blocking (highest risk).
Confirm the fast-deploy claim against your environment — no multi-quarter content-policy project.
Decide whether to connect insider risk to email and the wider human-risk view now or later.
If you need heavy regulated data-type classification, compare classic DLP; for insider exfiltration, Incydr's model.
Right-size per user — TechBag scopes and quotes in INR/GST.
Scope an insider-risk PoC (catch a departing-employee exfiltration with full context), connect it to your email security, or let a TechBag advisor plan your data-protection program.
Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.