Browser security for mid-market: the new endpoint nobody is watching

by
Dawid Winiarski
Last update:
July 17, 2026

A decade ago, work happened in installed applications on managed devices behind a corporate network. Security was built for that world: endpoint agents on the laptop, controls at the network perimeter, the directory governing access.

Work moved into the browser, and the controls did not follow. SaaS, AI tools, internal apps, customer data: nearly all of it now flows through a browser tab. The directory sees the login but not what happens after it. The network tools see less every year as people work remotely. Endpoint agents see the device, not what is happening inside the page. That leaves the place where work actually happens as the place security sees least.

  • The browser is the new endpoint. SaaS, AI tools, internal apps, and customer data nearly all flow through a browser tab, and for most mid-market companies it is unmonitored.
  • 82% of interactive intrusions are now malware-free (CrowdStrike, 2026): the attacker works through valid logins and the browser, not a file an endpoint tool would catch.
  • The browser exposes five things the other layers miss: data leaving through the page, personal accounts running alongside work ones, malicious or over-permissioned extensions, shadow SaaS and shadow AI, and credential and session theft.
  • Adversary-in-the-middle phishing surged 146% year over year (Microsoft, 2025), and credential theft, session hijacking, or token abuse appear in roughly 70% of analysed incidents (Castellum Labs, 2025). The session, not just the password, is the thing to protect.
  • The controls that close the gap: enforce single sign-on and conditional access, govern browser extensions, add data-loss prevention at the browser layer, separate work from personal, bring discovery to the browser, and cover unmanaged and personal devices.
  • Browser security is not a replacement for identity, SaaS, or endpoint security. It is the layer that covers what they cannot reach: what people actually do once they are in a page.

why the browser became the risk

The shift from installed applications to the browser was gradual, and the security model did not move with it. The directory governs who can log in but goes blind once the session starts. Network tools that once watched all traffic see a shrinking slice as people work off the corporate network. Endpoint agents inspect the device and the files on it, not the content of the web page open in front of the user. It is why 82% of interactive intrusions are now malware-free: the attacker works through valid logins and the browser, not a file an endpoint tool would catch (CrowdStrike, 2026). The browser is the new endpoint, and for most mid-market companies it is unmonitored.

what the browser exposes

Data leaving through the page. Sensitive data pasted into a personal AI account, uploaded to a personal cloud drive, or copied into a tool nobody approved. Traditional data-loss prevention built for email and network traffic does not see a paste into a web app.

Personal accounts alongside work ones. People run personal and work accounts in the same browser. Company data ends up in personal AI tools and personal storage, often without any intent to do harm, and entirely outside the directory's view.

Malicious and over-permissioned extensions. Browser extensions can read everything on the pages you visit, including what you type. A risky extension is effectively a keylogger and screen-reader with the user's own permissions. Most companies have no idea which extensions are installed across their people.

Shadow SaaS and shadow AI. The browser is how shadow tools get adopted: a quick sign-up, no install, no procurement. Tools that never touch single sign-on are invisible to the directory but plainly visible in the browser.

Credential and session theft. Phishing pages, malicious sites, and session-token theft happen in the browser, and increasingly bypass multi-factor authentication by stealing the session after login rather than the password before it. Adversary-in-the-middle phishing surged 146% year over year, with tooling now generating tens of thousands of attempts a day (Microsoft, 2025), and credential theft, session hijacking, or token abuse appear in roughly 70% of analysed incidents (Castellum Labs, 2025). The session, not just the password, is the thing to protect.

the controls that close it

Enforce single sign-on and conditional access. Push as many apps as possible behind your identity provider, and use conditional access so company apps are reachable only from acceptable contexts. This shrinks the surface before you add anything browser-specific.

Govern browser extensions. Get visibility of which extensions are installed, and control which ones are allowed, especially those requesting broad read access to page content. This is one of the highest-value, least-done controls.

Add data-loss prevention at the browser layer. To stop sensitive data going into personal AI accounts or unapproved tools, you need a control that sees the page, because that is where the action happens. Browser-layer DLP can warn or block on uploads and pastes that network and email DLP never see.

Separate work from personal. Keep work activity in a managed browser or a managed profile, distinct from personal browsing, so company data and personal accounts do not share the same space.

Bring discovery to the browser. Because the browser sees shadow SaaS and personal-account AI that the directory misses, it is also one of the best places to discover them.

Cover unmanaged and personal devices. Much browser risk lives on devices you do not manage: contractors, personal laptops, BYOD. A browser-layer control can extend protection to these without managing the whole device, which is often the only practical option.

where this fits with your other controls

Browser security is not a replacement for identity, SaaS, or endpoint security; it is the layer that covers what they cannot reach. Identity governs who can log in. SaaS governance covers the apps connected to your directory. The browser layer covers what people actually do once they are in a page, including the personal accounts and shadow tools the other layers never see. Together they close the gap between what is connected and what is happening.

It also does real compliance work: controlling where personal data can be pasted or uploaded supports GDPR, and controlling AI data egress supports the EU AI Act and your own AI policy.

Subscribe to unshadowed.

Subscribe to receive the latest blog posts to your inbox and stay up to date with

By subscribing you agree to with our Privacy Policy.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

let's start with a conversation

Most first conversations start with not quite knowing what you have or where to begin. That's normal, and it's exactly where we're useful.

Tell us what prompted this. An upcoming audit, an incident, a client's security questionnaire, or just a sense that things have gotten messy.

We'll take it from there

Julian Machowski
Head of Technical Sales
+48 783 762 997
julian@unshadowit.com
Let's connect on LinkedIn
Message received. We'll be in touch soon.
Something failed. Try again or call us directly.