Brand Exploit Protect - Key Rotation​ - Jun 2024

Service Update

Availability June 18th, 2024
Product(s) Email Security Cloud Gateway (CG), Brand Exploit Protect
Who's affected Email Security Cloud Gateway (CG), Administrators

Overview

We are committed to ensuring the utmost security for Brand Exploit Protect (BEP). As part of our ongoing efforts, we will be rotating your Mimecast integration Secret and Access keys.
  • These integrations allow you to create a policy to block emails from fraudulent sites, and clicks to these sites from anywhere, with a single action from within Brand Exploit Protect's URL details screen.
  • It also allows you to automatically apply block policies created in Brand Exploit Protect to existing rules within your Mimecast email and web security policies.
  • This practice is essential for maintaining the integrity of your data and safeguarding it against potential threats. 

This does not impact Brand Exploit Protect from detecting malicious sites and takedowns, and is only related to Mimecast email and web security policies.

What's changing

Your Mimecast integration Secret and Access keys will be rotated. This is important, because of:

  • Enhanced Security: Regularly rotating keys helps strengthen security measures and aligns with industry regulations.
  • Risk Mitigation: In case a customer-managed key is compromised, rotation ensures that your data remains secure.

Recommended actions 

You must replace the old keys with the new ones, by using the following steps:

In the Mimecast Administration Console

  1. Log on to the Mimecast Administration Console.
  2. Navigate to Services | API and Platform Integrations | Mimecast API 1.0.
  3. Enter application name, category, and description,  check Enable Extended Session.
  4. Enter notification settings.
  5. Copy the Application ID and Application key to a safe place, e.g. Notepad.
  6. Click on Create Keys and enter a valid email address.
  7. Enter Type and Password.
  8. Copy the Access and Secret keys to a safe place, e.g. Notepad.

In Brand Exploit Protect

  1. Log on to Brand Exploit Protect.
  2. Navigate to Settings | General | Mimecast Integration.
  3. Enter the Application ID, Application Key, Secret key and Access key, which were saved via Notepad
    Depending on your region (and your Mimecast Account Code), enter the Base URL from the dropdown list. See Global Base URLs

    Mimecast Integration  

If you have multiple domains, you will need to enter the same Application ID, Application Key, Secret Key, and Access key which were saved via Notepad.


If you have any questions or need further assistance, please contact the BEP Security Operation Center team at: bep-soc@mimecast.com

See Also...

Was this article helpful?
0 out of 0 found this helpful

Comments

0 comments

Please sign in to leave a comment.