Back to top

Zero trust starts where work happens: inside the browser

Two engineers
Over the last decade, the enterprise browser evolved from a simple access tool into a critical component of modern zero trust architecture.
Three points to remember
  1. Modern work happens in the browser, so zero trust must operate there as well
  2. Browser-based activities, including AI interactions, create security risks traditional controls often cannot see
  3. The most effective security controls are seamless – embedded in how people work, not layered on top of it

The workplace moved into the browser

Most people still think of the browser as a window to the internet. A mere tool for opening websites, checking email or joining a meeting. However, over the last decade, the enterprise browser evolved from a simple access tool into a critical component of modern zero trust architecture.

Today, much of modern work happens inside authenticated enterprise browser sessions. Employees collaborate in cloud platforms, manage infrastructure through web consoles, access internal applications through portals, and increasingly rely on AI copilots embedded directly into those workflows. The “office” doesn’t need to be a building or even a network anymore. It can be a collection of browser tabs.

That shift changes more than where people work. It changes where organizations need to enforce trust.

For years, enterprise security strategies focused heavily on protecting networks and devices. Firewalls guarded the perimeter. VPNs extended trusted access. Endpoint tools monitored laptops and servers for malicious software. Those controls still matter, but the nature of risk has changed. Increasingly, the most consequential security events happen after a user successfully logs in.

The browser didn't just become where work happens. It became one of the enterprise's most important security boundaries. 

The biggest risks often look like normal work

Attackers no longer need to breach hardened infrastructure when they can simply exploit trusted browser sessions. Instead of trying to breach hardened systems directly, many adversaries now focus on stealing credentials, hijacking sessions or exploiting routine user behavior. In modern environments, sensitive data often moves through ordinary actions: copying text between applications, uploading files to cloud services, downloading reports or pasting information into AI assistants. 

If exploited, none of those behaviors necessarily look malicious in isolation. In fact, they often look like productive work.

As attackers continue to adopt and adapt tactics that appear to be routine work, many organizations are beginning to rethink the role of the enterprise browser in cybersecurity architecture. Rather than treating browsers As simply another application to protect, organizations are increasingly treating it as a zero trust enforcement layer. Security policies can be applied where users actually work, and at the very moment they access data, interact with cloud applications or engage AI assistants. As work continues shifting into browser-based environments, protecting the browser is becoming synonymous with protecting the enterprise itself.
 

Kevin Hiltpold

[For] federal environments, the path forward is not to bolt more controls onto unmanaged browsers. The path forward is to make the browser itself the control plane.

Kevin Hiltpold
Senior Director Cyber Architecture and Technology Strategy, Leidos Defensive Cyber

When AI becomes part of the workflow, the security perimeter moves with it

Generative AI has made this problem harder to ignore. AI assistants are now embedded in everyday work summarizing reports, drafting content, automating tasks that used to take hours. That is genuinely useful. It’s also a new way for sensitive data to walk out the door.

Most users don’t think of pasting information into a chatbot as a security decision. But from a security standpoint, that data may have just crossed a boundary that no firewall was watching.

Traditional security tools weren’t designed for this. They monitor networks and devices, not what happens inside a trusted browser session. Enterprise browser controls work differently: they sit inside the workflow itself, able to restrict how data moves between sensitive systems and unapproved AI tools. They can flag or block actions in real time, based on who the user is and what they’re doing.

That’s a meaningful shift from older access models like virtual desktop infrastructure (VDI), which controlled environments by walling them off. Browser-based enforcement aims to do that same job with less friction, without forcing users to jump between desktops or reconnect to VPNs every time the work changes. 

Modern work doesn’t stay in one place, and neither should security

The challenge is especially acute for organizations operating across multiple cloud environments at once, juggling internal applications, external partners and AI-enabled tools inside the same workflows. Security controls that slow that work down, or force users to context-switch between disconnected systems, create their own kind of operational risk. 

Enterprise browser approaches address this risk by applying zero trust policies consistently regardless of where the application lives or who owns that platform. The enforcement travels with the user, not the network.

Leidos brings zero trust capabilities to some of the most demanding operational environments in the federal government, helping agencies apply zero trust enforcement consistently across multicloud architectures, AI-enabled workflows and coalition platforms. The work isn’t theoretical. It’s built around the reality that mission success increasingly depends on secure, frictionless access to the right information at the right moment.

Security is moving closer to the interaction

A browser may not look like a security boundary, but modern work has made it one. As cloud services, AI assistants and mission applications converge inside the browser, trust must be enforced at the point where users interact with data, not only where they connect to the network. The organizations that recognize this shift will be better positioned to protect information while supporting the speed and agility modern missions demand.
 

Author
Headshot of Katie Hovanec
Katie Hovanec Marketing Communications Writer

Katie Hovanec is a marketing communications writer at Leidos specializing in cybersecurity. She covers topics including zero trust, RMF, cATO, ICAM, cyber threat intelligence, security analytics, and emerging cyber technologies for mission-critical organizations.

Posted

July 24, 2026

ESTIMATED READ TIME

Author