ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Managing the security visibility gap

Michael Leland at Island argues that the browser is now the enterprise control point

Linked InXFacebook
bookmark_borderSave to Library

For years, enterprise security strategies focused on protecting the perimeter. Organisations invested heavily in securing networks, devices, and access points, building layers of tools designed to keep threats out. That approach made sense when employees worked primarily from corporate offices, using managed devices within tightly controlled environments. But the workplace has fundamentally changed.

 

Security’s visibility problem

Today, enterprise activity happens largely inside the browser. Employees spend hours moving between SaaS applications, collaborating across cloud platforms, and using AI-powered tools to improve productivity. The browser has become the primary space for enterprise productivity, making it a major attack surface for cyber-threats.

 

Yet many security models remain tied to outdated assumptions about where risk exists. While organisations can still control access to systems, they often struggle to observe or govern what users do once inside applications. That visibility gap has become even more pronounced in the era of hybrid work and BYOD.

 

Personal and unmanaged devices now routinely access sensitive business data, creating new challenges around data protection, privacy, and user activity. At the same time, many of the traditional security tools being used to manage this were never built for this browser-centric environment or the proliferation of AI tools.

 

Traditional SASE and VPNs can introduce operational complexity and performance bottlenecks by routing traffic through centralised infrastructure. MDM solutions help manage devices but provide limited visibility into activity within SaaS applications, while also raising privacy concerns for employees using personal devices. Meanwhile, VDI adds significant cost and operational overhead while delivering a poor end-user experience, particularly when most work now happens through web and cloud applications.

 

As enterprise work continues to shift into the browser, organisations need security controls that operate closer to where activity actually happens, inside the application experience itself.

 

Visibility is becoming a security risk

The real problem with today’s visibility gap is that organisations no longer have a clear view of how sensitive data is being used once employees enter applications.

 

In a browser-first workplace, risk increasingly comes from normal user behaviour rather than unauthorised access alone. Employees can accidentally upload confidential information into public AI tools, move files between personal and corporate applications, or download sensitive data onto unmanaged devices. They may also share information through unsanctioned collaboration platforms, often without security teams detecting it in real time.

 

Hybrid work and BYOD policies have made the visibility challenge even harder to manage. Employees may be fully authenticated when accessing corporate applications on personal devices, but CIOs and CISOs often lack clear visibility into how company data is handled. Sensitive information can be copied, stored locally, screenshotted, or shared elsewhere while security teams are blind to these transactions or forced to remediate the risk after the fact.

 

At the same time, attackers are increasingly targeting the browser itself. Phishing campaigns, session hijacking, credential theft, and malicious browser extensions all exploit the fact that the browser now sits at the centre of enterprise activity. Once a session is compromised, traditional perimeter-focused tools often struggle to detect suspicious behaviour within trusted applications.

 

The rapid adoption of generative AI is creating another layer of risk. Employees are adopting AI tools, often encouraged by their organisations, at a pace well ahead of governance. As sensitive business information enters external AI platforms, data exposure, regulatory compliance, and the protection of intellectual property become larger risks.

 

By embedding security into the very tools where people work, protection happens exactly when and where actions take place. Users can collaborate across trusted applications without friction, while intelligent controls continuously evaluate context to stop sensitive data from reaching unauthorised environments. Instead of relying on a single authentication event, this approach turns zero trust into a dynamic, always-on model that adapts in real time to changes in user activity, session risk and device state as work unfolds.

 

The issue is no longer simply who can access enterprise systems. It is what users and bad actors can do once inside them.

 

Legacy security models no longer work

Many security architectures were built for a time when work happened inside clearly defined corporate boundaries. 

 

As enterprise activity becomes more distributed, applying security policies consistently is getting harder without slowing users down or adding more pressure on already stretched IT teams. The issue is no longer a shortage of security tools. It is that too many of them sit too far away from where modern work takes place.

 

Most security architectures still rely on a consumer browser, treating it as an untrusted endpoint rather than as the control layer where most work happens. That creates dangerous blind spots around data movement, browser extensions, and unmanaged AI usage, leaving security teams to make decisions without real context.

 

The shift now is from static controls to adaptive enforcement, from consumer-grade tools to a workspace designed for enterprises. Instead of blocking applications and slowing users down, enterprise browser security applies policies dynamically based on live session risk, user behaviour, device posture, and data sensitivity. For example, a finance user copying customer records into an approved CRM should not trigger the same response as someone attempting to upload that data to a personal AI chatbot.

 

Modern browser security also needs to reduce operational complexity, not add to it. Point products that require separate agents, policy engines, and management consoles quickly become difficult to maintain at scale. Consolidating controls and applying them across enterprise browsers, consumer browsers, and desktops simplifies deployment, shortens response times, and provides IT teams with a consistent enforcement layer across managed and unmanaged environments.

 

At the same time, browser and desktop security cannot come at the expense of user experience. If controls interrupt workflows or introduce latency, employees will bypass them. The strongest implementations are almost invisible to the user, enforcing protection continuously in the background while allowing work to move at full speed. Security becomes embedded in the workflow itself, not layered awkwardly around it.

 

Control across the entire work environment

Security architectures that still rely on network edges and one-time authentication checks are rapidly losing visibility into how knowledge workers access, use, and share data. As AI adoption accelerates, hybrid work expands, and SaaS ecosystems grow more complex. The browser is becoming both the centre of productivity and the new frontline of enterprise risk.

 

The organisations that adapt fastest will be those that treat the browser not simply as a window to the internet but as the first critical enforcement point for modern security.

 


 

Michael Leland is VP and Field CTO at Island

 

Main image courtesy of iStockPhoto.com and patcharin innara

Linked InXFacebook
bookmark_borderSave to Library
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543