Opens in a new tab
vmblog logo 2024 wht (updated)

Mimecast's Jeff Schumann on Human Risk Management and AI-Powered Cybersecurity at Black Hat USA 2025

Share: 

David Marshall | Published: July 24, 2025

VMblog Black Hat USA QA  

As organizations grapple with an increasingly complex threat landscape, the focus is shifting from traditional infrastructure protection to securing the human element � the most targeted, unpredictable, and often least protected aspect of any organization. At Black Hat USA 2025, Mimecast will demonstrate how their connected human risk platform is transforming cybersecurity by turning employees from an organization’s biggest vulnerability into their strongest defense through precision-engineered AI and adaptive security controls.

Jeff Schumann, VP of Brand and AI Strategist at Mimecast, will be showcasing the company’s latest innovations at Booth #3846, including their Human Risk Command Center and new adaptive insights that help organizations understand, predict, and prevent risky actions before they become breaches. With AI-powered threats accelerating in both pace and precision � particularly in areas like business email compromise, which cost organizations over $6.3 billion in 2024 according to the FBI � Mimecast’s approach to leveraging AI defensively while addressing the human risk factor represents a critical evolution in cybersecurity strategy for the 42,000+ global customers they protect. 

Don’t miss this pre-show Q&A to find out more.  And make sure to add Mimecast to your MUST SEE list.

++ 

VMblog: For readers who may not be familiar, can you give us the elevator pitch on your company and what makes you stand out in today’s cybersecurity landscape?

Jeff Schumann:  Mimecast is a global cybersecurity leader transforming the way businesses manage and secure human risk through precision-engineered AI. Our connected human risk platform protects organizations from the ever-evolving threat landscape with increased visibility, control and agility.

VMblog: Black Hat attendees expect cutting-edge demonstrations and hands-on experiences. What innovative booth activities or live demos are you planning that will give visitors a real taste of your technology in action?

Schumann:  We’re bringing human risk to life at Booth #3846. Visitors can start with our rapid Human Risk Survey, a live diagnostic that instantly profiles your organization’s exposure across key attack vectors like business email compromise (BEC), Shadow IT, and AI misuse. Based on your risk score, we’ll deliver a tailored demo right there on the spot, showing how Mimecast neutralizes those threats in real time.

Visitors will also get an exclusive walkthrough of our Human Risk Command Center, a live visualization environment that shows how our platform detects, responds to, and reduces behavioral risk across the enterprise.

And throughout the expo, we’ll run fast-paced, high-impact theater sessions covering everything from advanced BEC threat chains to how to operationalize employee behavior as part of your defense posture. If you’re looking for signal in the noise, we’ll show it to you.

VMblog: If a CISO visits your booth and walks away remembering just one thing about your company, what should that key message be?

Schumann:  Human risk is the new frontline, and Mimecast is built for it.

If you remember one thing, it’s this: Mimecast turns your people from your biggest risk into your strongest defense. Our platform isn’t just adaptable; it’s engineered to evolve with your workforce and the threats targeting them. Whether it’s emerging BEC threats, insider risk, or the explosion of Shadow AI, we give security teams the visibility, context, and control to act fast and act smart.

Legacy tools chase threats. Mimecast chases outcomes.

VMblog: The “AI security arms race” is a hot topic this year. How is your company leveraging AI defensively, and what’s your take on the AI-powered threats we’re seeing emerge?

Schumann:  The threat landscape has never been more complex, and with AI, the pace and precision of attacks are only accelerating. Today’s AI-powered threats go far beyond technical exploits; they’re supercharging social engineering, making attacks feel more human and harder to detect. Defending against these risks means using AI just as aggressively on our side.

At Mimecast, we leverage AI defensively across multiple layers. Our Human Risk Command Center uses AI-driven insights to adapt protections in real time, aligning security controls to individual human risk levels. This ensures the right users get the right level of protection, without overburdening the rest of the organization.

We also apply AI to directly stop attacks. BEC remains one of the most dangerous and costly threat vectors, in 2024, according to the FBI IC3, more than $6.3 billion was transferred as part of these threats. Our Advanced BEC Protection uses AI and natural language processing (NLP) to analyze billions of signals, detect intent, and stop attacks before they reach the inbox.

In our Incydr data protection solution, AI plays a critical role in content inspection, helping identify and protect sensitive information like PII and PCI. Its NLP-enhanced PRISM system allows for smarter scoring, detection, and automated response to insider risks.

By layering AI across threat detection, human risk management, and data protection, Mimecast connects the dots between people and technology, protecting our 42,000+ global customers with an infrastructure that learns and evolves as fast as the threats do.

VMblog: What’s your company’s most compelling differentiator in a market where everyone claims to have the “next-generation” solution?

Schumann:  We secure human risk, the part of your organization that’s most targeted, most unpredictable, and least protected. While most vendors still focus on locking down infrastructure, Mimecast focuses on the employee behind the device … because that’s where modern threats are winning.

Our differentiator is simple: we offer the most advanced platform purpose-built to reduce human risk at scale. With unmatched visibility into behavior, layered with world-class threat protection, Mimecast helps organizations understand, predict, and prevent risky actions before they become breaches.

Others talk about “next-gen.” We deliver what’s actually next: a unified approach to securing people.

VMblog: Are you unveiling any major product announcements, partnerships, or technological breakthroughs at Black Hat 2025?

Schumann:  This year at Black Hat we are announcing new adaptive insights and policy controls to our Human Risk Command Center, which was unveiled in April. The new controls will enhance the command center, enabling customers to strengthen security with adaptive controls, optimize and fine-tune precision targeting, and drive behavioral change with personalized interventions.

VMblog: What should be at the top of every security leader’s priority list as we move through 2025?

Schumann:  A top priority for security leaders has to be adaptability. In a threat landscape where things are changing by the day, you never know what’ll come next. Predicting the future is next to impossible given how advanced threats are becoming, but ensuring your organization is equipped with the tools to remain agile and precise is vital to safeguarding. Without adapting to the landscape, companies risk adding blind spots and falling behind.

VMblog: Looking toward 2026 and beyond, what emerging threat or technology trend keeps you up at night, and how is your company preparing for it?

Schumann:  We are paying close attention to how threat actors are leveraging AI in attacks. These types of threats are only going to become harder to detect, so ensuring our customers have adequate protection against existing and future threats will be critical. Here at Mimecast, we’re committed to staying ahead of the threat landscape by combining AI with proven defense methods for the best results.

That’s why we’ve enhanced our Human Risk Command Center – to make sure nothing slips through the cracks. The landscape continues to evolve, and so will our platform to keep this commitment.

VMblog: If you had to predict the cybersecurity conversation we’ll all be having at Black Hat 2026, what topic or challenge do you think will dominate the discourse?

Schumann:  Given how rapidly the technology and cybersecurity landscape changes, predicting what’ll dominate a year from now is difficult. However, we anticipate the implications of advancing AI – and what this means for identity security – to be the main conversation driver. As AI continues to improve the effectiveness of tactics like brand impersonations and social engineering attacks, what does this mean for the future of identity? Conversations will make a shift from securing from the outside to focusing inward. How can we control the human element to better detect and avoid threat-actor manipulation? How can we better control users’ identities within IT environments to ensure AI bots or hackers aren’t in our systems? These are the types of conversations that’ll spark with AI’s advancement over the next year and beyond.

##