Incydr  logo

Incydr

by Mimecast (Code42) · Since 2003
No reviews yet
Active3+ countriesCloud
Quick facts
VendorMimecast (Code42)
Year launched2003
StatusActive
Location1 Finsbury Avenue, London, England EC2M 2PF, GB
Countries served3+
Languages10
Integrations30+
Free tier
Free trial
Contact sales

About Incydr

Incydr is a data security software from Mimecast (Code42) that focuses on data loss prevention. It provides visibility, monitoring, and alerting to help organizations manage sensitive information effectively. Incydr helps detect potential data breaches and ensures compliance with data protection regulations. The platform allows users to identify and safeguard critical data, track data movement, and respond to incidents in real time. Key capabilities: data visibility incident monitoring data classification compliance reporting threat detection Best for: organizations that need to protect sensitive data and maintain regulatory compliance.

Incydr by Mimecast is a robust Insider Threat Management (ITM) software solution designed to detect, assess, and respond to data exfiltration risks originating from within an organization. Originally developed by Code42 and now integrated into Mimecast’s cybersecurity portfolio, Incydr focuses on protecting intellectual property and sensitive data from unauthorized sharing, whether intentional or accidental. Its key features include real-time risk detection, automated response workflows, endpoint monitoring, and visibility into cloud and browser activity. The user interface of Incydr is sleek and purpose-built for security teams. It offers intuitive dashboards that highlight high-risk behaviors, file movements, and user activity across endpoints. Navigation is straightforward, with customizable views and filters that allow analysts to prioritize threats efficiently. The design emphasizes clarity, making it easy to interpret risk scores and initiate response actions without unnecessary complexity. Functionally, Incydr excels in its ability to monitor file activity across sanctioned and unsanctioned applications, detect shadow IT usage, and provide detailed audit trails. Its automated response engine can trigger alerts, revoke access, or escalate incidents based on predefined policies.

Pros & Cons

What users like
  • +Prioritization of Risk (PRISM) reduces alert fatigue by scoring and ranking incidents, helping teams focus only on the most critical threats.
  • +Context-driven incident response monitors user intent and data context, distinguishing normal file sharing from malicious or negligent actions.
  • +Non-disruptive security design uses a lightweight, policy-free agent that maintains full visibility without slowing user productivity.
  • +Behavioral correction delivers automated micro-training to educate users in real time, turning mistakes into learning moments.
  • +Fast deployment enables setup within minutes and actionable insights within hours, offering quicker ROI than traditional DLP tools.
What users flag
  • Lacks some deep DLP capabilities such as content inspection, OCR, and detailed audit trails.
  • Real-time blocking remains limited compared to competitors that use proactive behavioral analytics.
  • Pricing transparency is low, with no publicly available plans, making budgeting harder for smaller teams.
  • Requires dedicated security expertise to manage alerts effectively, which may be complex for small organizations.
  • Download tracking is less comprehensive than upload monitoring, potentially leaving minor visibility gaps.

Features

Key features

PRISM Risk Prioritization System
An intelligent system that uses over 250 contextual Incydr Risk Indicators (IRIs) across Data, User, and Destination dimensions to score events from 0-10. This filters out "noise" and allows security teams to focus on critical alerts (score 9-10).
Comprehensive Data Exfiltration Monitoring
Tracks file movement across all vectors, including Endpoints (Windows, Mac, Linux), Web Browsers, Cloud Apps (OneDrive, Google Drive, Box), Email (O365, Gmail), USB, Airdrop, and GenAI tools (copy/paste and file upload detection).
Native Response Controls
Provides a full spectrum of response options: automated micro-training (Instructor lessons), real-time blocking of file uploads/sharing, revoking external file links, and quarantining endpoints.
Departing Employee Watchlists
Automates monitoring for high-risk user groups, such as employees on notice or contractors, to detect and contain IP theft before separation.
Minimal User Disruption (Lightweight Agent)
Uses a cross-platform endpoint agent designed to be lightweight (0-4% CPU usage) and non-disruptive, ensuring user productivity is not compromised.

Additional features

Risk Exposure Dashboard
Provides tailored views to monitor file exposure, compliance, and program performance.
Risk Indicator Analysis (IRIs)
Utilizes over 250 indicators to differentiate between harmless file activity and true data loss risk.
Cloud App Monitoring (API-Based)
Connects directly via APIs (no proxies needed) to monitor sharing events in corporate cloud storage and email.
Forensic Search
Logs and indexes all file activity, allowing security teams to quickly investigate events, recover files (including deleted ones), and verify file contents.
Shadow AI Detection
Monitors data movement (copy/paste and file uploads) to unapproved Generative AI tools and websites.
User Behavior Correction
The Incydr Instructor delivers automated, situational micro-trainings to correct employee mistakes in real time.
Cross-Browser Compatibility
Lightweight browser extension monitors web interactions across managed and unmanaged web applications.

Pricing

Free trial
Free version
Request a quote
Promo Offer

Countries & Languages

3
Countries served
10
Interface languages
12
Billing currencies

Available in

Globally (North AmericaEuropeAsia-Pacific)

Interface languages

EnglishSpanishFrenchGermanItalianJapaneseKoreanPortugueseRussianChinese

Billing currencies

🇺🇸USD🇪🇺EUR🇬🇧GBP🇯🇵JPY🇦🇺AUD🇨🇦CAD🇨🇳CNY🇮🇳INR🇷🇺RUB🇧🇷BRL🇰🇷KRW🇲🇽MXN

No reviews yet

Be the first to drop a review