Opens in a new tab
vmblog logo 2024 wht (updated)

Mimecast at RSA 2026: Closing the API Security Gap and Tackling Human Risk at Machine Speed – VMblog QA

Share: 

David Marshall | Published: March 16, 2026
RSAC 2026 Q&A

As the RSA Conference 2026 approaches, Mimecast is arriving with more than booth swag and marketing messaging — the company is bringing two major product announcements that directly address two of the most pressing pain points in enterprise security today. In this exclusive pre-show Q&A, Giulian Garruba, Sr. Director of Product Marketing at Mimecast, pulls back the curtain on what attendees can expect at Booth N-5245 in the North Hall, from hands-on demos with live security engineers to a human risk assessment kiosk and a packed theater schedule featuring sessions on AI-powered social engineering, generative AI governance, and compliance in the age of distributed workforces. The headline news? Mimecast has fully closed the long-standing protection gap in API-based email security deployments — a gap that, until now, quietly left organizations dependent on Microsoft and Google’s native controls to pick up the slack.

But the bigger strategic story coming out of RSA 2026 may be Mimecast’s vision for security in the AI agent era. With the majority of today’s workforce already using generative AI as a productivity accelerator, Garruba makes clear that the attack surface has fundamentally shifted — and the human layer is now the critical control plane. Mimecast is responding with adaptive, real-time security controls tied to individual user risk signals, the expansion of its Mihra AI agent family including a new investigation agent, and the launch of the Mihra MCP Gateway, which integrates Mimecast workflows directly into existing AI environments. Add to that a Tuesday morning session from Chief Product Officer Rob Juncker on agentic AI and insider threats, plus partner theater appearances from CrowdStrike, AWS, Zscaler, SentinelOne, and Arctic Wolf, and it’s clear Mimecast is positioning RSA 2026 as a coming-out moment for its next-generation platform. Read on for the full conversation.

++

VMblog: Where can attendees find you at RSA 2026? What’s your booth number, and what kind of experience can visitors expect when they stop by?

Giulian Garruba: You can find us at Booth N-5245 in the North Hall, and we’ve put a lot of thought into making it worth the stop. We have demo stations staffed by our security engineers, a human risk assessment kiosk where you can get a personalized read on your organization’s exposure, and a theater with sessions running all week on topics that are top of mind for security leaders. We’re covering everything from how AI is supercharging social engineering attacks and what to do about them, to practical frameworks for governing generative AI usage in the workplace, to how security leaders can rethink traditional governance and compliance as valuable intelligence in a world of distributed workforces and blurred data boundaries. We know everyone’s time at RSAC is limited, so we made sure everything we’re presenting is practical, relevant, and worth carving out time for: focused sessions, hands-on demos, and conversations that connect directly to the challenges security teams are facing today.

VMblog: What is your message to RSA attendees this year?

Garruba: It comes down to this: AI is changing everything – not just the way you work, but the threats your organization faces and the tools you use to defend against them. At Mimecast, we’ve been investing heavily in AI-powered innovation to make sure our customers are protected where they need it most. We arrive at RSAC with two major announcements that we think tell that story well.

  • The first is that our complete email security stack is now available through API deployment, and the significance of that is worth unpacking. For years, organizations choosing API architecture had to accept a protection gap. The API-native vendors made deployment easy, but quietly relied on Microsoft and Google’s native controls to fill what they couldn’t catch, and customers are starting to notice. We’ve now closed that gap entirely. We’ve taken the best of our gateway product (comprehensive detection engines) and added into the API deployment, and taken the best of API deployments (behavioral AI to catch the most evasive threats) and added it into our gateway product. The same detection engines, the same AI, available via the deployment you choose. That means we can deliver on our goal to meet organizations where they are with confidence.
  • The second announcement is about where we are taking the platform for the AI agent era. AI agents and automated workflows are proliferating across the enterprise, and that creates new attack surfaces, new data risks, and new compliance challenges. Our latest platform enhancements are designed to meet that reality head-on, with adaptive controls that adjust in real time based on user risk, AI-powered investigation capabilities, and an open ecosystem approach that lets security teams work the way they already work, rather than forcing them into another siloed tool. The theme across all of it is that security needs to be as dynamic and connected as the environment it is protecting.

VMblog: You mentioned the second announcement was about the AI agent era. Can you share a bit more about the security challenges of AI, and how Mimecast addresses them?

Garruba: AI agents are moving fast, and they’re being deployed by employees across organizations who are under pressure to move faster and do more. Today, the majority of the workforce is using generative AI as an accelerator – to work faster and smarter. The challenge is that every one of those AI interactions ultimately depends on a human to direct it, approve its actions, and govern its behavior. When those humans are stressed, distracted, or making poor judgments, they can leave the door open to sensitive data being exfiltrated and put critical systems at risk, at a scale and speed that wasn’t possible before. We like to call this human risk at machine speed.

The risks come from two distinct sources. On one hand, human error remains a leading cause of security incidents, and AI amplifies this risk by enabling small mistakes—like sharing sensitive data with unsanctioned AI tools—to escalate rapidly. On the other hand, malicious actors exploit AI to act faster and with greater precision, increasing the scale and impact of attacks. AI means these actions can have a bigger impact, much faster than ever before. This means your security team has to be equipped with the tools to not only catalog sensitive data and untrusted AI destinations, but also to identify these data movements and block them before that data leaves the organizational boundary.

Our approach is centered on the human layer as the control plane for AI. Our latest platform updates include adaptive, automated security controls that adjust in real time based on individual user risk signals, and Incydr Data Protection to prevent sensitive data from reaching unsanctioned AI tools. We’re expanding our family of Mihra AI agents with an investigation agent that automates tasks, enhances context, and provides actionable recommendations. We also just launched the Mihra MCP Gateway, which lets security teams connect Mimecast investigation workflows directly into their existing AI environments, so they’re not forced onto another siloed interface. The goal is to usher organizations into a new era in human risk protection, one defined by effective, responsible use of AI, both for productivity and security.

VMblog: Are you participating in any speaking sessions or panel discussions at RSA 2026?

Garruba: Yes. Our Chief Product Officer, Rob Juncker, is presenting on Tuesday, March 24th at 8:30am in the Moscone South Esplanade. The session is called ‘AI in the Shadows, Trouble on the Surface: Inside the New Insider Threat’ and it gets into something that doesn’t get enough attention in the broader AI conversation: what happens when the people deploying and directing AI tools are themselves the risk. Rob will explore how the explosion of agentic AI is amplifying insider threats in ways that traditional security models weren’t built to handle, and what security leaders can actually do about it. Rob is a fantastic and engaging speaker, and it’s hard to find a more relevant topic for IT leaders navigating this landscape today. Definitely worth the early start.

VMblog: What exciting demos or interactive experiences can attendees expect at your booth?

Garruba: Plenty! We have hands-on demo stations staffed by Mimecast security engineers all week. These are real conversations with real practitioners, not canned slide shows. You can see our Human Risk Command Center in action, explore the new API email security capabilities, and get a feel for how Incydr monitors and responds to shadow AI data movement. We also have a human risk assessment kiosk that gives you a personalized read on where your organization might be exposed.

One thing we’re particularly excited about is our partner theater sessions on Tuesday and Wednesday. We’ll be joined on stage by CrowdStrike, AWS, Zscaler, SentinelOne and Arctic Wolf. These sessions are a great reflection of how Mimecast operates in the real world: delivering for organizations as part of a connected ecosystem. If you want the full agenda, check out info.mimecast.com/rsac2026.

We’re also featuring a customer led session with CISO Giles Ashton-Roberts from Swissport to talk through how security leaders can rethink insider risk in today’s distributed workforce. The session, which will run twice, Tuesday at 3:00 p.m. PT and Wednesday at 12:30 p.m. PT, explores how context-rich visibility and risk-based prioritization with Mimecast Incydr can help organizations act before an incident occurs.

VMblog: As an experienced RSA participant, what advice would you give to attendees to make the most of their conference experience in 2026?

Garruba: Go in with a point of view, not just an open schedule. RSAC is enormous, and if you don’t prioritize, you’ll spend the week bouncing between keynotes and expo floor noise without coming away with anything actionable. Pick two or three themes you really want to stress-test (AI security, insider risk, whatever’s keeping you up at night) and then seek out the sessions and vendors who can challenge your thinking on those specifically. Don’t just collect swag. Ask hard questions. And the one-on-one conversations are often more valuable than the presentations. Don’t be afraid to grab someone at a booth and ask them what’s on your mind. Show up early, stay curious, and don’t be afraid to disagree with what you’re hearing on stage.

##