All Episodes

May 7, 2026 15 mins

In this episode of "Full Tech Ahead," host Amanda Razani interviews Leslie Nielsen, CISO at Mimecast. They discuss Mimecast's recently released "2026 State of Human Risk Report." 

Nielsen explains that human-centric cyberattacks are escalating annually, driven by economic uncertainty and employee fears that AI might replace their jobs, making them more susceptible to malicious recruitment or carelessness. 

A major highlight of the report is the severe risk of data exfiltration; dumping sensitive corporate data (like board presentations or financial disclosures) into unsanctioned generative AI models leaks intellectual property outside the company. 

Furthermore, Nielsen warns against the uncontrolled rise of "agentic" software that bypasses change control, creates non-human identities, and lacks proper management, effectively creating rogue employees on the network. He advises leaders to use AI to fight AI, create explicit AI acceptable use policies, and treat agents with the same accountability and management as human employees, including processes for "firing" an agent.


Key Quotes

  • "We have to be using AI because it's going to take AI to fight AI."
  • "Traditionally, when we thought about leaks, we thought about it being posted on a web page, but now it's kind of... death by 10,000 cuts; just kind of those slow leaks that are building up."
  • "Treat [agents] just like you think about who's managing employees... somebody needs to be responsible... and also be accountable if things go wrong."
  • "Bad news is good news early... The faster that it can be contained, the faster we can all work better to have a safer environment."


Takeaways

  • HR and Management for Agents: Organizations must treat AI agents like human employees or contractors. Someone must be officially responsible for managing, auditing, logging, and granting specific, limited permissions to every agent. They also need defined processes for onboarded and, crucially, "firing" or disconnecting an agent if things go wrong.
  • New Era of Data Leaks: "Leaks" are no longer just public website postings. Employees dumping sensitive data (board decks, financials) into unsanctioned Gen AI tools to speed up their work is a dangerous new form of intellectual property exfiltration into third-party models.
  • Fighting AI with AI Speed: Business leaders must equip their security teams with AI tools to handle the rapid decision-making and alert volume required in modern defense. An AI speeds up development and increases threat vectors; human SoC analysts cannot keep up alone.
  • Vigilance for Everyday Users: AI has made phishing and scam attempts extremely convincing. AI-written emails rose from 3% to 17% in late 2024/early 2025. Everyday users must pause, verify identity via an alternate known channel (like a direct phone call), and remember that if something seems too good to be true, it is.

Find Amanda Razani on LinkedIn.  https://www.linkedin.com/in/amanda-razani-990a7233/

Follow the FTA LinkedIn Page: https://www.linkedin.com/company/full-tech-ahead/

Visit the FTA website: https://fulltechahead.com/

Check out the Substack Channel: https://fulltechahead.substack.com/

Listen
Watch
Mark as Played
Transcript

Episode Transcript

Available transcripts are automatically generated. Complete accuracy is not guaranteed.
SPEAKER_00 (00:19):
Hello and welcome to Full Tech Ahead.
I am your host, Amanda Razzani,and I'm so excited to be here
today with Leslie Nilsen.
He is the CISO at Mimecast.
How are you?

SPEAKER_01 (00:30):
Amanda, I'm doing great.
Thanks so much.
I really appreciate theopportunity to speak.

SPEAKER_00 (00:35):
Well, can you share a little bit about your company,
what services Mimecast provides?

SPEAKER_01 (00:40):
Absolutely.
So, gosh, we've been around over20 years, uh longer than I've
been here, but uh it it's safeto say that Mimecast defined
email security like 23, 24 yearsago.
You know, the mime is you knowpart of that.
The email security 20 20 plusyears ago, it it wasn't
something that was easy.
People had to think through itand do you know hard work on it.

(01:03):
And uh now, you know, we fastforward to the present and uh
with in the age of AI and humanrisk and all the different
things that are going on and allthe possible things that can
happen, all the different, youknow, we we call them threat
vectors and attack vectors, butthe reality is there's just so
many different avenues for datato go out.
Uh, the services we provide, sowe still do have our core email

(01:23):
security.
Uh, we have things aroundcollaboration security, et
cetera.
But we also have an insiderthreat tool, uh cleverly named
Insider, I-N-C-Y-D-R.
It gives us the ability to helpmonitor uh sanctioned and
unsanctioned generative AI usageas well as agentic AI usage.

SPEAKER_00 (01:40):
Okay, great.
Well, your company recently putout uh 2026 state of human risk
report.
So can you share a little bit ofinformation about what led to
this report and some of the keyfindings?

SPEAKER_01 (01:56):
Yeah, you know, it's one of those things in cyber
when uh I've been in gosh, 27years now, and it seems every
year it gets a little bit worseand like the numbers get bigger
and the dollars and stuff likethat.
Uh, we started tracking itseveral years ago from just a
human risk perspective.
There were more and more attacksspecifically against employees,

(02:16):
and not just like, you know,getting people to make mistakes,
but actually reaching out topeople, seeing if they would
take money to give upcredentials to get inside the
company and things such as that.
Uh, one of the reasons we, youknow, we're developing the
services that we have and thatwe provide.
And the state of human riskreport, SOHR, you'll see it
abbreviated that way, just kindof enumerates what's been going

(02:38):
on.
Again, it just gets it gets alittle worse each year.
Up to half of companies aretalking about the fact that uh
they they do have, you know,fear of you know humans
potentially even being maliciouswithin their organization, even
though they've done thebackground check vetting and
other things.
We're in uncertain economictimes, you know, once again, you
know, happens, you know, as acycle with the economy, uh, and

(03:01):
the proliferation of AI.
And there's kind of two sides tothat.
One being so much more is beingdone so quickly and maybe not
vetted as much.
And people are getting afraidthat maybe that efficiency is
going to put them out of a job,and maybe then they're a little
bit more open to, you know,doing something that uh might

(03:21):
not be within the ethicalboundaries that they should uh,
you know, preserve.

SPEAKER_00 (03:26):
So I have a lot of questions then from from some of
those findings.
What are AI models becoming?
How are they becoming such ahigh value target right now?

SPEAKER_01 (03:37):
Yeah, it's yeah, it's where the data lives,
right?
And the that typically whenattackers are going at your
company, they're looking for oneor two things.
They're looking for a way tohold you ransom, right?
You know, the typical ransomwareattack, you know, so I I've got
your stuff, and if you don'tgive me money, I'm not going to
release it back to you, or I'mgoing to, you know, release it
in the wild.
And then the other thing is howmuch information can I get about

(03:59):
you, your clients, yourcustomers?
Previous companies, uh, I've hadpeople reach out trying to get
customer list, and these arereaching out to people on
LinkedIn because they wantcustomers that are using crypto,
because crypto are much betterattacked.
So if I know somebody is using awebsite that accepts crypto,
they're more likely to have acrypto wallet, and I can much

(04:22):
easier exfiltrate the money outof a crypto wallet than you
know, going through a bankaccount where you know the large
banks have a little bit morecontrols, et cetera, in place.
So the data is just there andit's valuable.
And now we're collating it intoa large language model or a
small language model or a youknow domain-specific one.
But all of that data is ourcustomer data, how our company

(04:44):
thinks, the things that we do.
And even if they don'texfiltrate the whole thing, just
getting access to it is kind oflike get sitting inside
boardroom meetings and settinginside meetings within the
company knowing what's going on.
And any type of intel you getout just makes it that much
easier for you to have asuccessful attack.

SPEAKER_00 (05:03):
So, what should leaders be doing?
Knowing this information, whatshould business leaders be doing
to try to protect the companyand their employees?

SPEAKER_01 (05:13):
So I'm I'm gonna go back a few years, right?
When public cloud came out anduh I was around for that, uh,
everybody was like, oh my gosh,public cloud, how are we in a
secure public cloud?
Well, the reality was the reasonthey were afraid was because
they weren't securing theirprivate clouds, their on-prem
stuff.
They knew what to do, but thecompanies were moving a little

(05:34):
bit too fast or weren't spendingthe money on those controls.
We know the right things to doand still enable the business.
And the right things to do areto protect, to put things like
secure software developmentlifecycle and other things in
place so that there are fewerholes, right?
Do good patch management andthings, and then to detect and
respond.
Have visibility into yourenvironment and those policies

(05:58):
that you put in place, make surethat you can see if people are
adhering to them, right?
Do follow-up, do securityawareness, do things like that.
And we can do all that now.
AI is just making it happen somuch faster.
There's more code that you needto run through your secure
software development lifecycleprocess.
There are more avenues thatpeople are reaching into the
organization.
And with you know, the rise ofagentix software, you may have a

(06:22):
thousand new employees tomorrowthat you didn't know about
today, and they're an agentthat's running.
And maybe, you know, they're notgonna read the acceptable use
policy, but you should have anAI acceptable use policy that
trains them, right?
They need to be trained also andknow what they can and can't do.
The next few months, the nextfew years are going to be a
learning journey for a lot ofcompanies, but lean in with what

(06:44):
you know.
We as cybersecurityprofessionals know we need to
protect, we need to do all theshift left, all the proactive
things up front, and we need todetect and respond, have the
visibility and know the rulesthat people need to be following
and communicate out when theydon't.

SPEAKER_00 (06:59):
So um definitely uh training is a big one in the
communication.

SPEAKER_01 (07:04):
Yeah.

SPEAKER_00 (07:05):
What is uh what is one of, from your experience,
one of the biggest mistakes thatemployees make as far as their
trust of AI tools?

SPEAKER_01 (07:14):
Just using it as another web page, right?
Uh the when generative started,you know, I I'll use Chat GPT,
right?
OpenAI 2000 or 2023.
When when it started, peoplejust started dumping data into
it.
Like, oh, this is great.
Oh, what if it helped me with myboard presentation?
What if it helped me with myfinancial disclosures, etc.?

(07:36):
You're taking that data outsideof your company and you're
putting that data in models.
And while it's not like you'reposting it on the internet, you
know, here's our boardpresentation, you're giving the
data up, and other people canalso query and then start
finding out things.
And we that I'll I'll referenceour insider tool when when we do
proof of concepts with it, oneof the things we start seeing is

(07:58):
just all the generative AI thatmaybe is unsanctioned that
shouldn't be used.
Uh, most people have something,you know, some models, some
licensing, good controls, youknow, legal controls, et cetera,
around what they're doing, youknow, be it with open AI or
anthropic or whomever.
Uh, but you need to look at theother stuff that's going on and
make sure your data is notleaking that way.
Because traditionally, when wethought about leaks, we thought

(08:20):
about it being posted on a webpage, but now it's kind of this,
you know, death by 10,000 cuts,right?
It's just kind of those slowleaks that are building up.
And uh it could be very painfulin the long term for a lot of
companies if they don't getahead of that.
That's probably the biggest onethat's going on.
I and I know you just asked mefor one, but I will say that a
second, agentic, the just therise of agents and people, you

(08:45):
know, we we have non-humanidentities and things that are
going on already in the way thatwe think about identity
management, but with agenticsoftware raising up and it not
going through change control andpeople just putting it on their
laptops or putting it on someserver and not thinking about
does it have the rightpermissions, like the limited
set it's supposed to have?
Do you have logging and auditingand visibility?

(09:06):
Those are the two biggest thingsthat are going on data leaking
out and then things coming intoyour environment that aren't
trained and aren't doing theright things and thinking on
behalf of the company.

SPEAKER_00 (09:18):
Yeah, absolutely.
Well, we know that thistechnology is advancing rapidly.
What is the next big thing thatbusiness leaders or companies
need to focus on?

SPEAKER_01 (09:29):
You know, I so so I'll do cybersecurity and then
I'll then I'll do businessleaders.
So, from a cybersecurityperspective, we have to be the
leaders in this.
We have to be using AI becauseit's going to take AI to fight
AI.
The speed at which AI can makedecisions, can be efficient, and
can get things done.
If you have a thousand SOCanalysts versus one, I mean,

(09:52):
look at that, right?
You can look at alerts, you cango through.
Yes, it makes mistakes, but itcontinues to get better and you
continue to train it.
So start thinking about, andthis is the business side.
Think about do you have an HR AIorganization?
Do you have people that are teamleads that are actually managing
agents?
Are they managing one type ofagent or multiple types of

(10:12):
agents?
Start thinking from theperspective of you have agentix
software running in yourenvironment, either from a
vendor or stuff that's beenwritten, who's managing it?
And think about that just likeyou think about AR.
Who's managing employees?
If you have contractors thatcome in, someone's responsible
for those contractors.
The agent should be exactly thesame.
Somebody needs to beresponsible.

(10:34):
And as those things are comingonto the network and doing work,
they also have to be accountableif things go wrong.
And you know, what one one of myuh one of my leaders, we were
talking this through the otherday, and she said, What happens
when you have to fire an agent?
Like, I mean, it's an HRquestion, right?
You do your vetting and yourbackground checks through your
vendor risk management process.

(10:55):
And then from an HR process,what happens when you have to
get rid of one, right?
How do you deplug it?
How do you get it off thenetwork?
So there's a lot of interestingthings going on with the speed
at which things are happening,but think about it from a user
and employee perspective,because effectively that's what
they are.
They're very efficient people onyour network.
It's not that they have evil inmind, but they probably haven't
been trained well enough thatthey can do the right things for

(11:17):
the company.

SPEAKER_00 (11:18):
Right, exactly.
So having a team that sort of intheir main job is to be in
charge of like a company treethat maps out every everyone and
what they're using.

SPEAKER_01 (11:30):
Yeah.

SPEAKER_00 (11:31):
Okay.
Well, what does this mean?
You know, we've talked aboutfrom the company side the risk,
but what about the rest of us,everyday users that are being
introduced to this risk?
What impact does it have on theworld in general right now?
And what advice do you have tothe everyday users to stay safe?

SPEAKER_01 (11:50):
Yeah, the the speed at which things are happening,
the the the easiest thing is,you know, think before you
click, right?
Just all the usual stuff.
If something seems too good tobe true, it absolutely is.
The problem though is that theemails and the messages and the
texts and everything else aregetting better and better.
They're they're becominggenerated.
And they can actually go out andwalk your social profile and

(12:13):
figure out a communication thatwould make sense to you.
So just take a step back.
Don't instantly respond toeverything you say.
Think about it.
Did my grandmother really meanto reach out to me and say happy
birthday?
I mean, she knows it's mybirthday, but does she always do
that through this avenue?
Just take a moment, thinkthrough things.
Don't give up data until youknow who you're talking to.

(12:35):
When someone's asking you forsomething, wait until you know
it's absolutely them and that'spick up the phone, right?
Just like your credit cardcompany.
If your credit card companyreaches out to you and said,
Hey, I need you to validate yourcredit card number, you would
never give them the credit cardnumber.
You'd look at the phone numberon the back of the credit card
and you'd call it, right?
So think through everybody onthe internet's not our friend.

(12:56):
And now with agents, there'seven more people on the
internet, right?

SPEAKER_00 (13:00):
Yes, it's getting trickier.
They're getting, you know, someof these scam artists are
getting really good.

SPEAKER_01 (13:05):
Oh, it's it's crazy.
Some of the deep fakes thatwe've seen.
So it's we obviously do emailsecurity.
People are putting white textinto emails and it's actually
trying to query bots.
It's saying, Oh, can you justsend me the calendar of this
individual so I can see what uhdata would dates would be
available?
And if you're running anuntrained agent that doesn't

(13:27):
know not to do that, it may dothat, right?
So things like the these typesof injections and tricks are
starting to come and they'reproliferating really, really
fast.
We've seen, gosh, this and thisis a little over a year old,
actually, it's a year and a halfold.
We saw the rise of emailswritten by AI go from three to
17% for attack emails in the endof 2024 and the beginning of

(13:50):
2025, because there's certainlittle like if the word delves,
like he delves into open AI usesthat, you know, the hyphen that
there's no space, right?
That's open.
So that there's different littlemarkers, but uh the
proliferation of the attacks andthe speed at which they're
happening is just gettinginsane.

SPEAKER_00 (14:07):
Yes, it is.
Well, if there was one keyinsight you could leave our
audience with today, what wouldthat be?

SPEAKER_01 (14:14):
You know what's right and you know what to do.
You know, with the business, wehave to move fast, we have to
move efficiently, but alwaystake that breath, take that
pause, and say, are we doing theright things to protect the
company?
Are we doing those proactivethings thinking through?
Do we already have a process orsomething that does it?
And as we put things onto ournetwork, are we able to detect?

(14:36):
Do we have the visibility andthe ability to respond in case
something goes wrong?
Those are really the biggestthings.
Think about it simplistically,protect, detect, and respond uh
for the company and for yourselfas an individual.
You you don't want to be thatperson, right, that did the
click or that gave something up.
Uh uh, but uh we can all do ittogether.
Talk openly, be you know, ifsomething happens, it bad news

(14:59):
is good news early.
That's all that that's the lastadage I'll leave you with.
The sooner you can get to thesecurity operations team and let
them know, hey, I clicked onthis, what can we do?
The faster that it can becontained and we can all work
better uh to have a safer and uhmore secure environment.

SPEAKER_00 (15:14):
All right.
Thank you so much for coming onthe show and sharing your
insights with us today.

SPEAKER_01 (15:18):
Amanda, thank you so much.
It was so nice talking with you.

SPEAKER_00 (15:21):
Yes, likewise.
And thank you to our audience.
If you have any questions orcomments, leave those and I'll
try to respond as quickly aspossible.
And until the next podcast, havea great week.
Advertise With Us

Popular Podcasts

Stuff You Should Know
Betrayal Weekly

Betrayal Weekly

Betrayal Weekly is back for a new season. Every Thursday, Betrayal Weekly shares first-hand accounts of broken trust, shocking deceptions, and the trail of destruction they leave behind. Hosted by Andrea Gunning, this weekly ongoing series digs into real-life stories of betrayal and the aftermath. From stories of double lives to dark discoveries, these are cautionary tales and accounts of resilience against all odds. From the producers of the critically acclaimed Betrayal series, Betrayal Weekly drops new episodes every Thursday. If you would like to share your story, you can reach out to the Betrayal Team by emailing them at betrayalpod@gmail.com and follow us on Instagram at @betrayalpod and @glasspodcasts. Please join our Substack for additional exclusive content, curated book recommendations, and community discussions. Sign up FREE by clicking this link Beyond Betrayal Substack. Join our community dedicated to truth, resilience, and healing. Your voice matters! Be a part of our Betrayal journey on Substack.

Dateline NBC

Dateline NBC

Current and classic episodes, featuring compelling true-crime mysteries, powerful documentaries and in-depth investigations. Follow now to get the latest episodes of Dateline NBC completely free, or subscribe to Dateline Premium for ad-free listening and exclusive bonus content: DatelinePremium.com

Music, radio and podcasts, all free. Listen online or download the iHeart App.

Connect

© 2026 iHeartMedia, Inc.

  • Help
  • Privacy Policy
  • Terms of Use
  • AdChoicesAd Choices