An AI Agent Leaked a Sales Team's Financials. Mimecast Built Agent Risk Center to Catch the Next One

An AI Agent Leaked a Sales Team's Financials. Mimecast Built Agent Risk Center to Catch the Next One

BackerLeader 44 235 404
calendar_today agoschedule4 min read

A CISO told Mimecast Chief Product and Technology Officer Rob Juncker a story last week at Black Hat that sums up where agentic AI security actually stands right now.

One of the company's enterprise account reps had an automation set up to read incoming emails, draft a response, and send it automatically if the email looked safe. A customer wrote in, said they were happy with the partnership, and asked for a few details on the company's financial performance for their procurement team. The agent did exactly what it was built to do. It pulled together the rep's forecast, top accounts, deal terms, and the objections they'd been running into, and emailed the whole thing back.

The customer didn't sign. They wrote back and said they were pulling out of the deal. That's how the CISO found out.

"That user had access to that spectrum of information," Juncker told me. "And this is where an agent like that is really scary. In other cases, it's also super safe." The difference isn't the agent. It's what the person behind it had access to in the first place.

That story is the plain-English version of what Mimecast's Agent Risk Center (ARC) is built to catch. ARC moved from a preview at RSAC in March to a full beta launch at Black Hat USA in August, and Juncker told me the acceleration came straight from customers. In proof-of-value scans across its customer base, Mimecast found shadow AI in 98% of organizations it looked at.

The mechanism: it's identity, not just activity

Mimecast built its reputation on human risk, tracking more than 250 signals about what employees do: files accessed, sites visited, tools used. Juncker's argument is that AI agents don't need a new model. They need the same one, pointed at a new actor.

"Your scope defines what AI has access to," Juncker said. When someone asks an AI tool a question, connects it to an MCP server, or lets it act on their behalf, that activity runs through the same identity Mimecast already has a risk profile for. ARC ties every agent action back to the human who deployed it, then applies that person's existing risk score to whatever the agent does next.

That identity link matters more than it sounds. I pushed Juncker on whether ARC was tracking the agent's identity separately from the human's. He confirmed both: the agent has its own identity, and Mimecast pairs it back to the person responsible for it, so the data flow is traceable in both directions.

The practical effect is an anomaly detection model that doesn't treat every agent the same way. "The more risky a human is, the more controls we put in place," Juncker said, citing Mimecast's own research that 8% of users generate 80% of an organization's risk. Employees with clean security track records get more room to experiment with AI tools. Employees who already show risky behavior, like auto-responding to inbound email, get tighter guardrails, and those guardrails now extend to whatever AI they're using.

How ARC finds MCP connections nobody told it about

For developers, the more interesting question is discovery. How does Mimecast see an MCP connection it was never configured to know about?

Juncker's answer: mostly the endpoint. ARC reads the configuration of AI tools installed on a machine to see what MCP servers are wired in and how the traffic is moving, backed by network-level visibility. It's a first pass, by his own admission. "That's a second-level problem we're going to get to," he said, referring to deeper inspection of autonomous, self-directed agent behavior. Right now, the priority is answering a simpler question for security teams: what's connected, and what can it touch.

That visibility also extends further down the chain than you'd expect. Mimecast tracks four categories of AI activity: commercial agents bundled into other software (like Salesforce's Agentforce), AI endpoint tools, the MCP connections tied to those tools, and agents developers build themselves. When one of those agents spins up a sub-agent, ARC treats it as its own entity while still tying it back to the parent agent's identity. Juncker described watching an agent decide mid-task to pull down an open-source package on its own, sub-agent activity most security tools never see at all.

What this means if you're the one building the agents

I asked Juncker what he'd tell developers directly, since agent sprawl doesn't only come from shadow SaaS tools. A lot of it comes from engineers wiring their own agents into production systems.

His answer wasn't a sales pitch for slowing down. He pointed to something Mimecast does internally: every agent his team spins up gets an instruction file, similar to onboarding a new employee, covering what it's allowed to do and how it should behave. He calls it security awareness training for agents. It doesn't guarantee the agent stays inside the lines. It does mean Mimecast catches drift faster and updates the training when it happens, the same cycle security teams already run for humans.

"I think right now we're enamored with the speed and the results," Juncker said. "Sometimes we forget about the security that underpins the way in which we actually deliver products to market."

Where this lands organizationally is still an open question, even to Mimecast. Juncker compared agent governance to the AppSec-versus-security split: it can't live in one team. DevOps needs runtime visibility into what agents are doing in production, while a separate governance layer needs to watch activity that reaches beyond any single application, including agents touching operational systems well outside a typical DevOps scope.

ARC is currently in beta, free for Mimecast's Incydr customers, with general availability planned for January 2027. Juncker said the company set out with a target of ten beta customers and is now just shy of 1,000.

The bigger signal isn't the beta number. It's that Mimecast built this by pointing an existing human-risk engine at a new kind of user, one that doesn't get tired, doesn't second-guess a request, and does exactly what it's told, including the parts nobody meant to authorize.

🔥 Join developers growing publicly
Share your knowledge, build in public, and grow your developer presence with a global community.

More Posts

The Sovereign Vault — A Comprehensive Guide to Protocol-Driven AI

Ken W. Algerverified - Jun 4

The Re-Soloing Risk: Preserving Craft in a Multi-Agent World

Tom Smithverified - Apr 14

MCP Is the USB-C of AI. So Why Are You Plugging Everything In?

Ken W. Algerverified - Jun 10

The Zero-Net-Loss Fleet & The Mercenary Squad: A Live AI Economy

DEVPlank - Aug 4

Helping Clients Move from Pilot to Production: The Agentic AI Governance Playbook

Tom Smithverified - Jun 8
chevron_left
16.2k Points684 Badges
207Posts
125Comments
82Connections
LLM Training & Evaluation Specialist with hands-on experience building major AI models. As one of th... Show more

Related Jobs

View all jobs →

Commenters (This Week)

1 comment
1 comment
1 comment

Contribute meaningful comments to climb the leaderboard and earn badges!