New Mimecast CEO Ranjan Singh: Combating Shadow AI Is ‘No. 1 Opportunity’ For Partners
In his first interview since being promoted to Mimecast CEO, Singh tells CRN that the company is accelerating its expansion beyond email security with the launch of new AI agent discovery capabilities.
Mimecast is looking to extend its longtime strength in email security into the rapidly emerging challenge of securing AI agents, while giving channel partners a larger role in helping customers uncover and control shadow AI usage, recently appointed Mimecast CEO Ranjan Singh told CRN.
In his first interview since being promoted to CEO in late June, Singh said Mimecast is accelerating its expansion from a top email security vendor into a broader platform focused on human, AI and data risk.
[Related: The 20 Coolest Web, Email and Application Security Companies Of 2026]
The latest move in this evolution was the Monday launch of Mimecast Agent Risk Center, a new capability for discovery, monitoring and governance of AI agents. Agent Risk Center is initially being offered in beta to customers of Mimecast’s Incydr data protection platform, with early access expected to begin in September and general availability targeted for January 2027.
While enabling secure deployments of new AI tools is certainly a key focus for many organizations, “the bigger problem is AI is already in use,” Singh said in the interview with CRN.
“Shadow AI is highly prevalent. And I think that’s the No. 1 opportunity [for partners],” he said. “It’s [an opportunity] for our channel partners, and ourselves, to just go to our customers and say, ‘Do you know what shadow AI use is taking place? Do you know what intellectual property is leaving your environment? Let’s work together on that. Let’s do a simple discovery process.’”
Prior to being named CEO of Mimecast in June, succeeding Marc van Zadelhoff in the role, Singh had served as chief product and technology officer at Mimecast since April 2025. Previously, he had spent more than three years as chief product officer at Kaseya and, before that, as a product and engineering leader in a number of industry segments including financial services.
That background has given Singh a strong focus on thinking about competition and potential disruption as technologies evolve. That is something “I’m constantly thinking about—where is the next disruption going to come from? And [how do we] stay ahead of those disruptions?” he said.
At the same time, “there will always be competition. There’ll always be disruption,” Singh said. “But if we have conviction in our strategy and vision, and we’ve thought it through, then it’s a matter of execution.”
At Mimecast, there’s no question that executing on growth going forward will depend on doubling down on channel partners, according to Singh.
Ultimately, “we want to be the most customer-centric company in this industry, bar none, and we want to do that with the channel,” he said.
What follows is more of CRN’s interview with Singh.
In this kind of environment, having someone who not only knows product but has been developing the product for that company for several years, how is that advantageous?
One of the benefits of being a product engineering leader is if you think about all the industries AI is disrupting, coding is in front of it. I see it more as an opportunity than a threat. We have a core group of 42,000 customers. [With AI] we are just able to serve them better. So yes, security has been democratized. Small startups can develop new security tools, as the case may be. But our advantage is we get better at execution, can deliver more value faster to our customers—and, most importantly, we can enrich the platform. We focus on three core things. We want to help customers lower their risk score. We want to deliver operational efficiency to the customers. And we want to deliver better ROI. We can leverage the tools to do all three things at an accelerated pace. So I’m less concerned about disruption. I’m more concerned about making sure in this age that we are able to deliver those outcomes at an accelerated pace.
In terms of the product strategy for the company, is there anything that could be changing that you might want people to know about?
For the last two years, Mimecast has been focused on human risk. Over the last year or so, with the advent of AI, we have evolved our strategy and road map—and actually our platform—to focus on human, AI and data risk. What does that mean? Well, human risk is really 8 percent of your users are 80 percent of your risk in any enterprise. And Mimecast has uniquely established the concept of a human risk score—where we are identifying the risk due to individual users, groups, organizations. But we quantify that risk. Not only do we quantify that risk, we are able to provide easy governance around this risk—‘Tell us what actions are sanctioned. Tell us what actions aren’t sanctioned.’ From there, we are able to protect against that governance. And then the last piece is really bringing resolution to anybody attempting to go outside the governance. So instead of flagging alerts, we are delivering operational efficiency by making sure we are just taking care of the problem. That’s what we’ve been doing on the human risk front. … Our platform—human, AI and data risk—has four strong suites—which are email and collaboration threat protection, security behavior management, governance compliance and insider threat and data loss. And then a fifth pillar that we’ll be launching is around AI security.
How are you approaching AI security as a company?
Our opinion is that AI risks are really the same set of risks that are tied to humans—because 90 percent of the workflows that are taking place are really humans driving AI. I have about 20-plus agents running on my laptop. The non-human identity is tied to my human identity. So the way we think about AI risk is really AI risk associated with the users. And so, we are surfacing all the agentic risk that may exist on your endpoint, on your browser, and all the actions that are tied to the user. We can apply the same four things: Discover and identify the risk, put a risk score on it, simple governance policy, protect against those and then resolve any alerts and any violations of that policy. And ultimately, the goal of any AI or human risk threat is data exfiltration. And the Mimecast platform excels at [protecting against] that. So you take the human and the AI risk, you combine it into a singular score, you do the discovery, the protection and all of those things—and ultimately, there are tools in place to prevent the data exfiltration. So our focus is really solving for these three core risk areas while delivering those three outcomes that I talked about: Lower the risk score, increase operational efficiency, deliver better ROI through our platform—as compared to a set of point products that an enterprise may attempt to solve those same problems by integrating.
What are the key things to know about your AI security announcement that is being launched?
With AI security, we’ll be able to surface all of the agentic risk in a customer’s environment—on their desktop, in their browser—and associate it with the user risk. So that’s combining your AI and your user risk into a single score, visualizing all the agentic activity that’s taking place in your environment. Today, we uncover on a regular basis that 90 percent of the users are using shadow AI in lots and lots of environments. So we are surfacing that risk and, of course, we are protecting against it. We are protecting against prompt injection. We are protecting against all of the agentic workflows in a number of ways.
What are you seeing in terms of the concerns about shadow AI?
Shadow AI [is] the No. 1 thing on top of CISOs’ and IT leaders’ minds at various firms. There are different schools of thought. Some openly admit, ‘Hey, we are trying to figure out how to bring AI safely and responsibly into our environment.’ Mimecast has done a pretty amazing job of doing that over the last two years, so we are happy to have the conversation with chief digital officers and such. But really, the bigger problem is, AI is already in use. Even the ones that are trying to figure it out, users are already starting to use it. Shadow AI is highly prevalent. And I think that’s the No. 1 opportunity. It’s [an opportunity] for our channel partners, and ourselves, to just go to our customers and say, ‘Do you know what shadow AI use is taking place? Do you know what intellectual property is leaving your environment? Let’s work together on that. Let’s do a simple discovery process.’ It takes 30 seconds to get going. That’s a simple discovery, and that alone is valuable for the customer. It’s valuable for our channel partners.
Overall, what is your message to partners and what the big opportunities are with Mimecast?
First of all, we are a 100 percent channel-first company. And that has been Mimecast’s history for nearly 20 years of its existence. So obviously, I’m doubling down on that strategy and making sure that our channel partners have all of the insights on who Mimecast is today. So that’s job No. 1. Job No. 2—in no particular order—is ensuring that Mimecast is easy to do business with. We have made a lot of investments already, and I continue to plan to make a lot more investments to make it easy to do business with us. Billing, ordering, processing, partner relationship management, enablement—all of those things we do reasonably well. I think we can do a lot better with that notion of customer centricity. And third, it is our partnering with the channel and with the ecosystem—because the goal is, in this era, we have to deliver value to the customers. We have to provide the best security posture. We can’t do it alone. We must work with the channel. They understand the customer base best, and they have an ecosystem to go along with it. So advancing in all of these dimensions is what I’m looking forward to.
How differentiated are you with the size of the customer base and the number of partners that you have? How big of an advantage is that in this environment?
Really, the advantage starts with a large enough channel partner base, a large enough ecosystem that we deeply integrate with. But the customer base starts with about 42,000 end customers, 1.8 billion emails processed daily. And the key asset and differentiation there really is we understand their communications patterns—not only through email, but collaboration as well. If you understand the communication patterns, you really don’t have to focus on what I would call specific types of threats because you’re just looking for anomalies. You’re looking for that day-zero threat. And you’re only going to uncover that by having an understanding of the communications patterns. So we are able to do a lot of threat detection and protection simply on the basis of that communications history that we have and the data that we process. Another dimension is, among that large customer base, we already have our sensors deployed on endpoint and in the browser. A lot of our customers use our insider threat and data loss protection solutions. So we already have agents and browser plugins deployed, which gives us deep visibility. It’s very lightweight sensors that give us deep visibility into data movement. And when I say data, it’s all-encapsulating. We could take a screenshot from here, move it to Google Drive—that’s a data movement. We could see something on the USB drive—that’s data movement. So we really have sensors where the activity is happening. And once again, the users are the highest risk in any enterprise. Users are operating on endpoints. Users are operating in the browser. Our differentiation is we have the communications history; we have the visibility into all the actions that they are taking on their daily work. And the combination of the two is really unparalleled compared to anybody else in the market.
Are there any areas where you believe Mimecast is underappreciated or where you see misconceptions in the market?
What I would say is Mimecast is more than an email security company. We are focused on human, AI and data risk. We cover that through our comprehensively integrated platform that has five core elements to it: email and collaboration security, security behavior management, insider threat and data loss protection, AI security. And really the combination of all of those things is how we are able to deliver the outcomes that I talked about—lower the risk score as it pertains to humans and AI acting on behalf of the humans, delivering much higher operational efficiency and delivering a higher ROI, as compared to putting together a smorgasbord of point products and attempting to orchestrate the same outcomes. I think Mimecast has a channel-first mindset, a customer-centric mindset. We want to be the most customer-centric company in this industry, bar none, and we want to do that with the channel. We want to do that with our customers. I’m really excited at the opportunity of being able to do that in the era of AI.