
The typical implementation process for Mimecast software involves several stages, each designed to ensure a smooth and efficient setup:
Information Gathering & Account Setup:
Collect necessary information about the customer’s environment.
Set up the Mimecast account.
Outbound Email Routing Configuration:
Configure outbound email routing through Mimecast.
Ensure firewall settings allow access to Mimecast data centers.
Advanced Integration & Journaling:
Integrate with existing email systems (e.g., Exchange, Office 365).
Set up email journaling if required.
Policy Setup & Testing:
Configure security policies, such as Targeted Threat Protection.
Conduct testing to ensure policies are correctly applied.
Inbound Email Routing Configuration:
Configure inbound email routing.
Ensure DNS records (MX, TXT) are correctly updated.
Firewall Lockdown:
Finalize firewall configurations to ensure secure communication.
Ongoing Training & Knowledge Transfer:
Provide training sessions for administrators.
Conduct mid-point and final review calls to optimize service.
Guided Implementation: Typically completed within 30 days of the kickoff call.
Managed Implementation: Typically completed within 45 days of the service start date.
This structured approach ensures that Mimecast’s email security solutions are implemented efficiently, allowing organizations to quickly benefit from enhanced email protection and management capabilities.
Mimecast can be customized to fit specific business needs:
Flexible Plans: Mimecast offers various plans such as protect, Protect Plus, and Custom, which can be tailored to meet specific organizational requirements.
Customizable Policies: Administrators can create and manage custom policies through the Mimecast Administration Console. This includes setting up web security policies and email security configurations to match the organization's security posture.
Advanced Integrations: Mimecast integrates seamlessly with existing email systems like Microsoft 365 and Google Workspace, allowing for custom configurations that enhance security and continuity.
Add-Ons: Mimecast provides several add-ons like Cybergraph AI, DMARC Analyzer, and Email Incident Response, which can be included to extend the functionality and customization of the core email security services.
User Interface: The modern and intuitive user interface allows administrators to easily set up and modify specific filters and policies, making it adaptable to various business needs.
Customer Success Stories: Case studies, such as the one from Rotana Hotel Management, demonstrate that Mimecast engineers assist in customizing the platform to fit operational needs, making it easier to configure and manage.
Industry-Specific Solutions: Mimecast services a wide range of industries including healthcare, financial services, manufacturing, and education, providing tailored solutions that address sector-specific challenges.
Security Awareness Training Program: Mimecast provides a security awareness training program that includes short, engaging video modules. These are designed to educate users on security best practices, such as handling phishing attempts, ransomware, and other cyber threats. The training is humorous and engaging, making it more effective and enjoyable for employees.
Personalized Training: The program includes personalized risk scores based on testing data, which helps tailor the training to address specific employee needs and improve their security awareness.
Phishing Tests: Mimecast offers phishing simulation modules to test and improve employees' ability to recognize and respond to phishing attempts.
Managed/Guided Onboarding: Mimecast provides managed and guided onboarding services, which include step-by-step guidance and support to ensure a smooth implementation of their services.
Access to Resources: Users have access to a variety of resources, including how-to articles, videos, and support documentation, to assist them in navigating and utilizing Mimecast's features effectively.
Secure Email Gateway: Mimecast provides a secure email gateway that offers 100% anti-malware protection and 99% anti-spam protection. It scans all inbound, outbound, and internal emails in real-time to detect and block malicious links, weaponized attachments, and social engineering attempts.
Targeted Threat Protection: This includes defenses against advanced threats such as spear-phishing, ransomware, and impersonation fraud. Mimecast uses sophisticated detection engines and threat intelligence to identify and neutralize these threats before they reach the network.
Content Control and Data Leak Prevention (DLP): Mimecast scans outbound emails to prevent the inadvertent or deliberate leakage of sensitive information. Depending on the policies set by administrators, emails containing sensitive data can be blocked, quarantined, or encrypted.
Secure Messaging: This feature allows users to send encrypted emails directly from their email client, ensuring secure communication without requiring knowledge of encryption methods.
Secure File Transfer: Mimecast enables secure sending and receiving of large files (up to 2 GB) directly from the inbox, avoiding the use of insecure third-party file-sharing services.
Information Security Management System (ISMS): Mimecast has deployed an ISMS that is regularly assessed by independent auditors. This system forms the foundation of their information security practices and includes various industry certifications.
Dedicated Security Personnel: Mimecast employs full-time, trained, and certified security personnel responsible for information security. These personnel report directly to senior leadership and are bound by confidentiality agreements.
Physical Security: Mimecast operates from industry-certified third-party data centers with strong physical controls, including access control mechanisms, surveillance, and security guards. These data centers are protected against natural disasters, unauthorized entry, and other potential threats.
Regular Audits: Mimecast's data centers and security practices are regularly audited for compliance with their security controls. Customers can request copies of these assessments through their Customer Experience contact.
Regular Updates: Mimecast frequently releases updates to various components such as detection engines, threat intelligence, and remediation tools. For example, updates were noted on July 22, 2024, for spam/phishing, and on July 18, 2024, for detection engines.
Product Life Cycle Notifications: Mimecast provides notifications 6-12 months before the End of Life for versions, ensuring customers have ample time to prepare for transitions.
Service Updates: Mimecast maintains a dedicated page for service updates, where users can track the latest changes and improvements across different services.
Release Notes: Detailed release notes are provided for new capabilities, enhancements, breaking changes, and bug fixes, particularly for their API and other services.
Customer Communication: Mimecast communicates updates through their customer care channels and community forums, ensuring that users are informed about upcoming changes and how to manage them.
Customer Data Ownership: Mimecast acknowledges that it has no ownership rights to Customer Data. The data remains the property of the customer at all times.
Rights and Licenses: Customers grant Mimecast the necessary rights and licenses to process their data for providing services, improving threat detection, and developing the services.
Data Processing Agreement (DPA): Mimecast's DPA ensures that customers' data can be processed in compliance with applicable laws and regulations. This agreement also facilitates data portability by outlining the terms under which data can be transferred or accessed.
Compliance with Regulations: Mimecast complies with various data privacy frameworks, such as the EU-U.S. Data Privacy Framework, ensuring that data transfers meet international standards.
Customer Rights: Customers have the right to request the transfer of their data. Mimecast provides tools and support to facilitate this process, ensuring that data can be exported and migrated as needed.
Machine-Learning and Threat Data: While Mimecast processes certain data for machine learning and threat detection, this data is anonymized and does not contain identifiable customer data. The output of these processes is owned by Mimecast and is used to improve service efficacy.
Flexible Plans: Mimecast provides various plans such as Protect, Protect Plus, and Custom, which can be tailored to meet the specific needs of organizations of all sizes. These plans allow businesses to choose the level of protection and features they require and adjust as their needs evolve.
Multi-Tenant Cloud Architecture: Mimecast's cloud-based, multi-tenant architecture allows for easy scalability. This means businesses can scale their email security and management infrastructure up or down without the need to manage physical hardware or complex software installations.
Add-Ons and Enhancements: Mimecast offers several add-ons like Cybergraph AI, DMARC Analyzer, and Email Incident Response, which can be added to existing plans to extend functionality as needed. This modular approach allows organizations to scale their services based on specific requirements.
Service Optimization: Mimecast's Security Service Edge (SSE) integrates security functionalities into the network edge, enabling businesses to scale their network and security infrastructure flexibly. This ensures that organizations can adapt to increased user demand, support remote workforces, and respond to evolving security threats efficiently.
Customer Success Programs: Mimecast offers different levels of customer success programs (Bronze, Silver, Gold, Platinum) that provide varying degrees of support and engagement. These programs help organizations optimize their use of Mimecast services and scale their operations effectively.
Advance Notice: Mimecast provides notice of renewal and new pricing (if applicable) prior to the end of the current subscription term. Typically, this notice is given no less than 30 days before the start of each renewal term.
Fees Notification: For certain agreements, such as those in Germany, Mimecast provides notice of the fees payable for the upcoming renewal term at least 100 days before the renewal date.
Modification Requests: Any reduction, downgrade, or removal of services can be made effective at the start of a renewal term, but Mimecast must receive notice of such changes no less than 90 days prior to the renewal date.
Written Notice: Cancellation requires advance written notice. Typically, a 30-day advance notice is required for impending cancellation, non-renewal, or material changes to the contract.
Notice Delivery: Notices must be sent in writing to the address provided or the registered address of the receiving party and must be delivered by a major commercial delivery courier service or mailed in a manner that requires a signature by the recipient.
Professional Services: For professional services provided on a time and material basis, customers may cancel the affected portion of such services, subject to payment for services already performed. Cancellation requests must be detailed and provided within a specified acceptance period (e.g., 15 days of delivery).
End of Subscription Term: At the end of the subscription term, customers may choose to continue receiving services through Mimecast or an authorized reseller of their choice.
Entire Agreement: The agreement between Mimecast and the customer constitutes the entire agreement and supersedes all prior agreements, proposals, negotiations, and representations. Any modifications must be made in writing and signed by authorized representatives of both parties.
ISO 27001: Information Security Management System (ISMS) certification, which specifies security management best practices and comprehensive security controls.
ISO 27701: Privacy Information Management System (PIMS) certification, which extends ISO 27001 to include privacy management.
ISO 22301: Business Continuity Management System (BCMS) certification, which ensures robust business continuity practices.
SOC 2: Focuses on five Trust Service Principles: Security, Availability, Processing Integrity, Confidentiality, and Privacy. It provides a framework for managing customer data and ensuring trust in service organizations.
HIPAA: The Health Insurance Portability and Accountability Act, which sets standards for the protection of health information. Mimecast ensures HIPAA compliance through secure email management, encryption, and data protection measures.
GDPR: The General Data Protection Regulation, which governs data protection and privacy in the European Union. Mimecast helps organizations comply with GDPR through data encryption, secure archiving, and robust data management practices.
FIPS 140-2: Federal Information Processing Standard for cryptographic modules used by U.S. government agencies. Mimecast ensures FIPS compliance through approved encryption techniques for data at rest and in motion.
PCI DSS: Payment Card Industry Data Security Standard, which protects credit card information. Mimecast helps organizations meet PCI DSS requirements through secure email management and data protection.
SOX: The Sarbanes-Oxley Act, which establishes financial reporting and accounting standards for public companies. Mimecast supports SOX compliance through secure email archiving and data integrity measures.
SEC 17a-4: Securities and Exchange Commission regulation that requires the retention of business communications. Mimecast meets this requirement by providing tamper-proof, encrypted storage of emails and other communications.
NIST: National Institute of Standards and Technology guidelines for cybersecurity. Mimecast aligns with NIST standards to ensure robust security practices.
Regular Audits: Mimecast conducts regular audits to ensure compliance with various standards and to maintain the integrity of their security controls.
Data Processing Agreements: Mimecast has agreements in place to ensure compliance with data protection laws and to facilitate secure data transfers.

Mimecast
By Mimecast