TL;DR: Customer feedback and migration experience show Code42 leaves blind spots across copy/paste, SaaS content, AI app visibility, and remediation workflows, according to Nightfall, while Mimecast’s acquisition adds uncertainty about product direction. The real issue is not tuning. It is whether legacy insider-risk tooling can still govern modern data exfiltration paths at all.
NHIMG editorial — based on content published by Nightfall: From Legacy to AI-Native: Your Complete Guide to Migrating from Code42 to Nightfall
By the numbers:
- 79% of organisations have experienced secrets leaks, with 77% of these incidents resulting in tangible damage.
- Only 5.7% of organisations have full visibility into their service accounts.
- 96% of organisations store secrets outside of secrets managers in vulnerable locations including code, config files, and CI/CD tools.
Questions worth separating out
Q: What breaks when insider-risk tools only inspect metadata and file names?
A: They miss sensitive data when the content is copied, pasted, uploaded into SaaS apps, rendered in screenshots, or transformed into another format.
Q: Why do insider-risk programmes need identity provider integration?
A: Because user risk and policy scope change constantly with role moves, offboarding, and group membership updates.
Q: How do security teams know if exfiltration controls are actually working?
A: Look for evidence that bulk file access, compression, and outbound staging are detected early and correlated with privileged sessions.
Practitioner guidance
- Test detection across content transformations Validate whether sensitive data is still detected after copy/paste, screenshotting, OCR conversion, and SaaS field entry.
- Map exfiltration coverage by channel Create a channel-by-channel inventory for endpoints, browsers, email, cloud sync, collaboration apps, and AI tools.
- Link insider-risk policies to IdP groups Sync policy scope, user risk scoring, and remediation actions to identity provider groups so access changes are reflected automatically.
What's in the full article
Nightfall's full blog post covers the migration detail this analysis intentionally leaves at a higher level:
- Day-by-day migration sequencing for moving from Code42-style workflows to Nightfall.
- Operational configuration details for Slack, Atlassian, Microsoft 365, Google Workspace, and AI app coverage.
- Examples of automated remediation, dynamic risk scoring, and policy tuning workflows.
- Implementation notes for SOC integration, endpoint deployment, and review of false positives.
👉 Read Nightfall's migration guide from Code42 to AI-native insider-risk controls →
Code42’s gaps in insider risk coverage: what teams should re-check?
Explore further
Metadata-centric insider-risk control is no longer enough. This article shows that file-name and location-based detection leaves organisations blind to content moving through copy/paste, screenshots, AI apps, and SaaS forms. That is a governance failure because the control model assumes sensitive data always remains in a file-like object. Practitioners should treat content inspection as a baseline requirement, not an enhancement.
A question worth separating out:
Q: Who is accountable when insider-risk coverage fails across SaaS and AI tools?
A: Accountability sits with the security and identity owners who define the control boundary, plus the platform teams that approve integrations and policy scope. If coverage stops at the browser or ignores AI tools, the programme has accepted a partial boundary. Governance should define which channels are mandatory, which are monitored, and which risks are knowingly residual.
👉 Read our full editorial: Code42 migration exposes the limits of legacy insider risk controls