TL;DR: Browser-based identity attacks now account for major enterprise entry points, and Push Security says browser telemetry exposes more of the attack surface needed for quantitative risk modelling than network or endpoint data alone. That shift makes risk estimates more defensible, but it also reveals shadow AI, OAuth sprawl, extension abuse, and ghost logins that many programmes still do not measure.
Editorial analysis by NHI Mgmt Group, based on content published by Push Security: “The CISO's data problem (and how browser telemetry can help)”.
Key questions
Q: How should teams measure identity risk when browser telemetry is available?
A: Teams should measure identity risk from observed attack frequency and observed control failure, not from generic benchmarks or risk matrix scores.
Q: Why do IdP-only metrics understate account takeover risk?
A: IdP-only metrics miss browser-mediated behaviour such as direct SaaS logins, OAuth consent abuse, device code phishing and extension-driven access.
A: Browser telemetry captures activity at the point where users authenticate, reuse passwords, encounter phishing tools, and access SaaS apps.
Practitioner guidance
- Instrument browser-layer identity telemetry Capture authentication flows, OAuth grants, SaaS access patterns and extension activity so your risk model reflects what users actually do in the browser.
- Rebuild identity risk inputs from observed behaviour Use observed attack frequency and observed control failure rates instead of relying on benchmarks, whiteboard estimates or broad risk matrices.
- Reconcile IdP reports with ghost login evidence Compare browser-level login telemetry with central IdP data to identify access paths that bypass your normal authentication visibility.
Bottom line: Browser telemetry exposes identity attacks at the point where they execute, which makes quantitative risk modelling more defensible than models built on indirect proxies.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Browser telemetry creates a different category of risk evidence: Identity risk has usually been measured with inferred probabilities, not directly observed attacker behaviour. When the browser becomes the execution environment, frequency, control weakness, and user interaction are all visible in-session. That makes browser telemetry one of the few places where quantitative security teams can replace broad assumption with environment-specific evidence.
A few things that frame the scale:
- 92% of organisations expose NHIs to third parties, raising concerns about supply chain security, according to Ultimate Guide to NHIs.
- 71% of NHIs are not rotated within recommended time frames, increasing the risk of compromise over time.
A question worth separating out:
Q: What should teams do when browser telemetry shows frequent non-email phishing?
A: They should expand threat models beyond email and align detection with the channels attackers actually use. Search ads, messaging apps, social platforms, and clipboard-based lures can all drive identity compromise, so email-only controls understate exposure and misdirect investment.
👉 Read our full editorial: Browser telemetry is changing how teams quantify identity risk
Browser telemetry creates a different category of risk evidence: Identity risk has usually been measured with inferred probabilities, not directly observed attacker behaviour. When the browser becomes the execution environment, frequency, control weakness, and user interaction are all visible in-session. That makes browser telemetry one of the few places where quantitative security teams can replace broad assumption with environment-specific evidence.
A few things that frame the scale:
- 92% of organisations expose NHIs to third parties, raising concerns about supply chain security, according to Ultimate Guide to NHIs.
- 71% of NHIs are not rotated within recommended time frames, increasing the risk of compromise over time.
A question worth separating out:
Q: What should teams do when browser telemetry shows frequent non-email phishing?
A: They should expand threat models beyond email and align detection with the channels attackers actually use. Search ads, messaging apps, social platforms, and clipboard-based lures can all drive identity compromise, so email-only controls understate exposure and misdirect investment.
👉 Read our full editorial: Browser telemetry is changing how teams quantify identity risk
Browser telemetry is now a governance input, not just a detection source: identity risk models built on benchmarks and analyst estimates are weaker than models built on observed user behaviour. Browser data shows when attacks actually reach users, how often they succeed, and where controls fail in practice. That makes quantitative identity risk more defensible to finance and board stakeholders, and it should become part of the core identity evidence set.
A question worth separating out:
Q: How should security teams use browser telemetry in identity risk management?
A: Security teams should use browser telemetry as an identity signal source, not as standalone activity logging. The goal is to connect events like logins, downloads, profile changes, and session starts to an account’s privileges and downstream access. That makes browser data useful for spotting compromised credentials, shadow IT, and identity blast radius early.
👉 Read our full editorial: Browser telemetry is changing how teams quantify identity risk