TL;DR: Browser-based attacks now account for 95% of incidents reported by organisations, while 85% of the modern workday happens in the browser and 65% of organisations say they have zero control over GenAI data feeding, according to LayerX Security. The browser has become the control gap where identity, data, and user actions converge, and existing stacks stop short of the point where exposure starts.
Editorial analysis by NHI Mgmt Group, based on content published by LayerX Security: “Francis Odum on the One Layer Your Security Stack Still Misses”.
By the numbers:
- 95% of organisations report browser-based attacks.
- 85% of the modern workday now takes place inside a browser.
- 65% of organisations say they have zero control over what data is being fed into GenAI tools.
Key questions
Q: What breaks when web security controls stay outside the browser?
A: When controls stay outside the browser, policy decisions are separated from the moment the user requests a URL, uploads a file, or receives content back from a site.
Q: Why do browser-based attacks create risk even when endpoint and DLP tools are in place?
A: Because those tools are usually built to inspect files, traffic or apps, not the in-browser behaviour where users interact with data.
Q: What are the signs that browser-layer protection is missing or failing?
A: Common warning signs include repeated session hijacking, successful credential theft despite MFA, risky browser extensions, and limited visibility into browser activity.
Practitioner guidance
- Inventory browser-layer exposure Map which browsers, extensions, SaaS destinations and GenAI tools users actually touch, including unmanaged devices and contractor sessions.
- Capture in-session telemetry Collect browser events for copy, paste, uploads and extension activity so policy decisions are based on what users do inside the session.
- Enforce identity-aware browser policy Apply rules that block personal account use, risky uploads and unsanctioned extension behaviour in corporate browser contexts.
Bottom line: Browser-layer risk is a control gap because the browser now hosts the work, the data movement and the GenAI interactions that conventional stacks fail to inspect.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Browser-layer security is a governance gap, not just a tooling gap. Endpoint, CASB, DLP and SWG controls all assume that the decisive risk is visible outside the browser session. That assumption fails when the action that matters is copy, paste, prompt or upload inside the session. The implication is that security teams need to reframe browser telemetry as part of identity governance, not just endpoint monitoring.
A question worth separating out:
Q: What do teams get wrong about browser controls and identity governance?
A: Teams often assume that strong login controls are enough, but the risk usually appears after authentication, inside the session. If browser activity is not governed, users can still copy, export, or move data outside approved workflows, even when access decisions were correctly made at sign-in.
👉 Read our full editorial: Browser-layer security maturity is the last-mile control gap