Ask where a company's work happens and the honest answer is a browser tab. The applications are hosted elsewhere, the files live in someone else's storage, and the interface to nearly all of it is the same piece of software the employee also uses to read the news. This has been true for years and the security architecture never caught up, because the architecture was built around a network and a device, and the work stopped depending on either.

What is changing is the recognition that the tab itself is the control point. Not the laptop, which may be personal. Not the network, which may be a hotel. The browser, which is the one component present in every session regardless of where the person is or whose hardware they are holding.

The gap is between logging in and doing anything

Identity solved the front door and stopped there. Strong authentication establishes who someone is at the moment of sign-in, and after that the session is largely unobserved — which is exactly where the interesting risk lives. Nothing in a login prevents a legitimately authenticated user from pasting a customer list into a consumer chatbot, downloading a database export to an unmanaged machine, or working inside a convincing replica of a site they use daily.

That last case is why credential strength alone was never sufficient. Passkeys removed the password as a stealable object, which is a genuine advance and does nothing about a session that is real. The attacker with a valid session does not need a credential.

The controls now moving into the browser follow from that. Copy and paste can be governed per destination, downloads can be restricted by application rather than by file type, screenshots can be blocked in defined contexts, and extensions — long the least examined software in the enterprise — can be inventoried and controlled centrally. None of this is conceptually new. What is new is applying it where the work is rather than where the network used to be.

It is also becoming a purchasing question rather than an architectural preference. Cyber insurers have turned into the de facto regulators of corporate security, and their questionnaires increasingly ask about data movement into unmanaged destinations, which is a browser question with no network answer. When the renewal depends on it, the budget appears.

The unglamorous driver underneath is sprawl. A company that owns more software than it can account for cannot instrument each application individually, and would not want to. The browser is the one place every one of those tools is used, which makes it the only practical vantage point — the same logic that once put controls at the network edge, arriving at a different edge.

Two things are slowing adoption, both predictable. Replacing the browser is a change employees notice immediately, and the alternative — an extension on the browser they already have — is less capable and easier to disable. And the visibility that makes this useful is also the visibility that makes it uncomfortable: a tool that can see what an employee pastes can see a great deal more than that. The deployments that have gone well have been narrow and explicit about scope, which is a harder sell internally than a control nobody has to be told about.

Topics technologysecurity

Technology Correspondent

Priya Natarajan

Priya Natarajan reports on artificial intelligence, enterprise software and the infrastructure behind the modern internet. Her work focuses on how technical decisions become business decisions.