Navigating the Browser Security Stack: Models, Considerations, Vendors
In this blog
The average company runs 118 different SaaS apps, with nearly all of them in a browser tab, and a recent review of major incidents found nearly 48% involved browser-based activity. There are many threats facing browsers today, but autonomous AI agents have added a new kind of risk. AI tools can take actions inside a browser on a user's behalf, like logging into accounts and uploading files, so a hijacked agent could cause far more damage than a typical breach. Late last year, researchers hacked a widely used AI browser with a disguised link and did the same to a popular AI assistant months later with a malicious calendar invite.
This is why browser security has become such a fast-growing technology. These solutions control what data moves through the browser, what code runs inside it and how threats get stopped before they become breaches.
Approaches to browser security
Browser security isn't just one product. Protecting this surface can take several different forms, each with its own unique benefits and considerations.
Enterprise browser
This is a complete browser replacement with security built into the browser itself. It offers the most customization and control as well as a low-latency user experience. It's worth noting that deploying this solution does mean rolling out a new browser across the organization. Island and Palo Alto currently have two of the strongest enterprise browsers on the market, and Google's Chrome Enterprise is a capable option as well.
Secure browser extension
Instead of replacing the browser entirely, this solution adds protection onto the existing browser. It's the easiest option to deploy and offers strong visibility. However, a secure extension's effectiveness somewhat depends on what browser it's being applied to; a user could also potentially turn off or bypass the extension. LayerX is the most popular player in this space.
Remote browser isolation
Remote browser isolation (RBI) isolates your browser session and runs it in the cloud so malicious content can't execute on your device. This model offers an extremely high level of security because it's impossible for anything risky to reach the user. And since RBI isn't a browser replacement but an add-on, there's no new browser to install. Several considerations with RBI are that running everything through the cloud adds a level of latency and cost, and there is limited visibility into certain user actions. Zscaler, Netskope and Fortinet offer RBI within their broader platforms, and Menlo Security is a strong option as well.
Browser runtime security
This approach inspects browser activity at the deepest level. It watches what happens during the browsing session itself instead of comparing everything to a list of known malicious activity or bad sites. Because of this, it can catch attacks that don't match anything seen before, such as a new malicious site or a script built for a specific target. It's important to note that this is the newest and least tested browser security approach. Zscaler and Push Security are the most well-known vendors who operate this model.
These are just a few of the leading approaches to browser security, not a complete list. New vendors and models continue to emerge as the space evolves.
Use cases for browser security
These approaches solve problems organizations face every day. Here's where browser security shows up in practice:
Secure AI web app access. Employees using Large Language Models (LLMs) in a browser tab can unintentionally expose sensitive data by including it in a prompt. Browser security prevents this by blocking sensitive information from being entered and stopping risky file uploads before they go out.
Contractors and third-party access. Companies often need to give short-term workers access to internal apps, which brings up many security concerns. Browser security solutions can provide quick onboarding and access to private applications in both client-based and clientless models.
BYOD. When employees use personal phones or laptops for work, IT can have a hard time gaining visibility and securing these devices from threats. Browser security technologies provide in-depth protection while allowing someone to continue using their personal device.
Regulated industries and data loss prevention (DLP). Healthcare, financial services and government all have strict rules about protecting sensitive data. Browser security solutions can provide last-mile controls such as blocking downloads, copy and paste and printing based on the specific app and user.
Where browser security shows up in a broader security architecture
Browser security can be a standalone add-on but is often included as part of a Secure Access Service Edge (SASE) or Security Service Edge (SSE) model. SASE focuses on cloud-delivered security solutions that protect users and systems wherever they are and whatever device they're on. Browser security works at the presentation layer of the OSI model, whereas SASE/SSE enforces policy at the network layer. This makes them very complementary as together they create a defense-in-depth strategy for securing user access. Many vendors are including browser security technologies as part of their SASE platforms.
A key aspect of SASE is that it offers a single control plane and significantly eases the burden on management. This is a great benefit of adopting browser security as part of a SASE solution. One way WWT sees this evolution is by providing administrators the ability to leverage their DLP policies across both SASE and browser security tools. SASE controls DLP at the network layer while browser security enforces the same DLP policies across last-mile controls.
If your organization already uses a SASE platform, it may be most convenient to add that vendor's browser security option. However, some organizations may prefer to buy browser security separately as it offers more flexibility to choose based on specific needs.
Matching browser security to your business
Browser security is an important architecture decision, one that requires the same attention as the rest of your security stack. The best fit for your organization depends on a variety of factors, like the types of devices being used, existing security tooling and company priorities.
WWT works with organizations across every industry on this issue, tailoring the approach to each one's environment and priorities. Schedule a briefing with one of our experts to determine the best browser security fit for your organization.