05/31/2026
**Executive summary:** OWASP is the **risk language**. Mimecast, Proofpoint, and Akamai are **control platforms** that help reduce those risks in different layers of the stack.
OWASP does **not** sell security products. It defines common risk categories, testing guidance, and secure-development expectations. Mimecast and Proofpoint mainly protect the **human/email/data layer**. Akamai mainly protects the **web application/API/edge layer**. Together, they help translate OWASP risks into enforceable controls.
# # How they align
| Vendor | Primary Layer | How It “Plays” with OWASP | Best OWASP Fit |
| -------------- | ---------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------ |
| **Mimecast** | Email security, BEC, impersonation, URL/attachment defense, DMARC, continuity, DLP | Reduces phishing, credential theft, malware delivery, malicious links, spoofed domains, and outbound data leakage that often lead to OWASP-style application compromise | Identity failures, software/data integrity issues, security monitoring, social engineering around apps |
| **Proofpoint** | Email security, threat protection, user risk, DLP, post-delivery remediation | Protects the people who access applications; blocks phishing, BEC, ransomware, malicious URLs/attachments, and unauthorized data movement | Identity failures, data exposure, monitoring, software/