TL;DR: Browser-level controls can enforce MFA, password policy, credential handling, and zero-trust telemetry at the application layer, while citing CISA’s seven-goal pledge framework as the benchmark, according to Island. The practical signal is that browser policy is becoming part of identity control enforcement, not just a user-experience layer.
NHIMG editorial — based on content published by Island: Built for Security: Island’s Commitment to CISA’s Secure by Design Pledge
By the numbers:
- Island says its Enterprise Browser uses only about 40 percent of the Chromium source code.
Questions worth separating out
Q: How should security teams decide where to enforce MFA in browser-based access flows?
A: Teams should enforce MFA as close to the application entry point as possible, then verify that the same requirement holds for unmanaged devices, contractors, and legacy apps.
Q: Why do browser-based identity controls matter for unmanaged devices?
A: Unmanaged devices often sit outside standard endpoint trust assumptions, so browser-enforced controls can restore a degree of policy consistency at the access boundary.
Q: What do security teams get wrong about risk assessment in identity programmes?
A: They often treat assessment output as the goal rather than the start of remediation.
Practitioner guidance
- Define where browser policy ends and IAM begins Map MFA, password, and conditional access responsibilities across browser, application, IdP, and endpoint controls so no team assumes another layer is enforcing the same rule.
- Inventory applications that depend on browser-side enforcement Prioritise legacy, SaaS, and contractor access paths where the browser is compensating for missing native MFA or password policy support.
- Treat browser telemetry as security evidence Route browser-generated logs and anomaly signals into SIEM and incident response playbooks with clear retention, access, and integrity controls.
What's in the full article
Island's full blog post covers the operational detail this post intentionally leaves for the source:
- How Island maps its browser controls to the seven Secure by Design goals across product lifecycle and deployment.
- Specific examples of MFA enforcement in application flows, idle-machine access, and unmanaged-device scenarios.
- The browser telemetry and logging detail behind its zero trust claims, including how evidence is captured and retained.
- The Chromium fork and patching model that Island says reduces attack surface and speeds remediation.
👉 Read Island's post on how its enterprise browser aligns with CISA Secure by Design →
Enterprise browser security: what it means for IAM teams?
Explore further
Secure by design is becoming an identity governance issue, not just a software assurance issue. When a browser becomes the policy enforcement point for MFA, password rules, and telemetry, it is participating in identity control rather than merely consuming it. That shifts accountability for authentication outcomes across product, security, and IAM teams. Practitioners should treat browser policy as part of the control surface, not a cosmetic layer.
A few things that frame the scale:
- 1 in 4 organisations are already investing in dedicated NHI security capabilities, with an additional 60% planning to do so within the next twelve months, according to The State of Non-Human Identity Security.
- Another 85% of organisations lack full visibility into third-party vendors connected via OAuth apps, which shows how quickly identity control can disappear outside core IAM.
A question worth separating out:
Q: Who should own browser-based identity risk in an enterprise?
A: Ownership should sit across IAM, security operations, and endpoint teams, because the risk spans authentication, session handling, and device posture. If browser-based attacks are only treated as endpoint issues, identity abuse will be missed. If they are only treated as IAM issues, device and browser context will be ignored. Shared ownership is the only workable model.
👉 Read our full editorial: Secure by design for enterprise browsers and identity controls