Firewalls, endpoint agents, cloud security platforms — Australian organisations have invested heavily in all of them. The browser has been left largely ungoverned. No audit trail. No data loss prevention. No way to distinguish a managed corporate device from a contractor’s personal laptop. No visibility into what staff are submitting to public AI tools.
Work happens in a browser. So do most breaches. Most organisations are not securing it.
Why the browser is your biggest security gap
Most enterprise work now happens in a browser. Employees access payroll systems, customer records, financial platforms, healthcare applications, and collaboration tools through a browser tab. Contractors and third parties connect to internal systems through a browser. Remote and hybrid staff use personal or unmanaged devices, and the browser is the only consistent interface connecting them to corporate data.
Consumer browsers — Chrome, Edge, Safari, Firefox — were not designed for this. They have no native data loss prevention. They cannot enforce access policy at the application level. They generate no audit trail. They treat copy, paste, download, screenshot, and print as unrestricted user actions. And they cannot distinguish between a managed corporate device and a personal laptop.
This is where breaches increasingly start. Not through a network perimeter, but through a browser tab left open on a personal device. A contractor who copies customer data to a personal cloud drive. A phishing link that harvests credentials through a fake login page.
AI has made this problem significantly worse
The Microsoft and LinkedIn 2024 Work Trend Index found that 78% of AI users are bringing their own AI tools to work without corporate oversight — a practice Microsoft itself described as putting company data at risk. (Microsoft & LinkedIn, 2024 Work Trend Index) Customer records entered into a public AI tool. Financial data submitted to a personal ChatGPT account. Internal strategy discussed with an AI assistant that retains and trains on the conversation.
In most organisations, that data is leaving through a browser tab, with no policy, no visibility, and no way to stop it.
Why conventional security tools don’t solve it
Network-layer security controls — firewalls, secure web gateways, VPNs — operate between the user and the internet. They cannot see or govern what happens inside a browser session once a connection is established. They cannot restrict copy-paste between a corporate app and a personal one. They cannot prevent a file download to an unmanaged device. They cannot block a user from submitting sensitive data to a public AI platform.
Endpoint agents can help, but they require device enrolment — which excludes BYOD users, contractors, and casual or scaling workforces by design. The gap between what conventional tools secure and where work actually happens is real, and it is widening.