Join our Newsletter — 33% off our NHI Course
Home› FAQ› Cyber Security› What are the biggest browser security mistakes organisations…
Cyber Security

What are the biggest browser security mistakes organisations make?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated October 11, 2026 Domain: Cyber Security

The most common mistake is treating the browser as a commodity app while relying on VPNs, proxies, and endpoint tools to do the real governance work. Another is ignoring extensions and unmanaged devices. Both mistakes leave the session itself under-controlled, even when authentication is strong.

Browser security fails when the browser is treated like a low-value endpoint

The biggest mistake is assuming the browser is just a delivery vehicle for web apps rather than a live execution environment with its own trust boundaries. That mindset pushes governance into VPNs, proxies, and endpoint tooling, while the real session still carries tokens, cookies, permissions, and user actions. Once the browser is unmanaged, security becomes fragmented and policy loses fidelity.

That is why browser controls need to be judged on what they actually govern: web access paths, session handling, data movement, and in-browser execution. If those decisions are made elsewhere, organisations often discover too late that they secured the network path but not the interaction surface.

Extensions and unmanaged devices create hidden control paths

Extensions are a common blind spot because they can read page content, alter requests, inject scripts, or siphon data depending on their permissions. Unmanaged devices create a separate blind spot because they bypass the assumptions built into enterprise posture checks, which means the same browser session may behave very differently outside the corporate endpoint baseline.

A browser security program needs to ask whether each extension is necessary, whether its permissions are proportionate, and whether untrusted devices are allowed to reach sensitive sessions at all. The issue is not just exposure to malicious software, but also over-broad trust in software and hardware the organisation does not actually control.

Session governance is the real failure point

Strong authentication does not solve weak browser governance if the session remains long-lived, portable, or poorly scoped. Attackers do not need to break the login flow if they can hijack the active session, abuse stored credentials, or exploit an over-privileged browser context after the user is already inside.

That makes browser security less about entry and more about containment. Good control comes from limiting what the session can do, how long it can persist, where it can be reused, and which browser capabilities are permitted during sensitive activity.

Risk and Threat Considerations

The main risk is that organisations harden the perimeter and identity layer while leaving the browser as an uncontrolled execution and data-handling surface. That creates a gap where session theft, malicious extensions, data exfiltration, and unmanaged-device access can all bypass the intended control model.

Failure mechanism: Security controls are placed around the browser instead of within it, so the active session, user interaction, and extension ecosystem remain trusted even when the endpoint or access path is not.

Impact: A compromised or over-permitted browser session can expose sensitive applications, tokens, business data, and downstream actions without defeating primary authentication.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, CIS Controls v8 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AA-05 — Access Permissions and EnforcementBrowser sessions need enforced access constraints and least privilege.
PR.AA-02 — Identity Management, Authentication and Access ControlBrowser mistakes often weaken session control after authentication succeeds.
Recommendation — Restrict browser-session capabilities to the minimum required for each application. Tie browser access to authenticated identity and enforce conditional session controls.
CIS Controls v8CIS-6 — Access Control ManagementUnmanaged devices, extensions and session scope are access-control problems.
CIS-8 — Audit Log ManagementBrowser governance needs visibility into session and extension activity.
Recommendation — Inventory and restrict browser access paths, extensions and unmanaged endpoints. Log browser-relevant access and extension events for investigation and review.
NIST SP 800-53 Rev 5IA-9 — Service Identification and AuthenticationBrowser-mediated sessions often rely on authenticated service interactions and tokens.
Recommendation — Authenticate browser-facing service interactions and limit token reuse.

Practitioner Guidance

What to prioritise: Start with the browser activities that can create irreversible impact, such as access to admin portals, financial systems, customer data, and internal SaaS consoles. Those flows need tighter session limits and stricter extension policy than ordinary web use.

What to verify: Confirm which browser extensions are approved, what permissions they hold, and whether unmanaged devices can still reach sensitive apps after conditional access checks. If you cannot answer that quickly, the browser is probably more trusted than your policy assumes.

Common mistake: Teams often measure browser safety by login strength alone. In practice, the better question is whether a valid session can be abused, extended, copied, or instrumented after authentication succeeds.

Practitioner takeaway: Treat the browser as part of the control plane for access and session governance, not as a passive container. The more sensitive the workflow, the less you can afford to rely on network tools and endpoint posture alone.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 11, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org