The browser is the new enterprise endpoint. Why can’t your security tools see inside?

Work has moved into the browser, but security is stuck at the network layer: these are the major findings from Forrester's recently released Digital Workplace And Employee Technology Survey.
Forrester's 2026 research among enterprise organizations (including Google, Microsoft, and Palo Alto Networks) establishes the browser as the new enterprise endpoint. The data also, however, exposes a disconnect between the modern workspace and security tools currently used to defend it:
.png)
In other words, applications, data, and now AI live in the browser, which makes it the de facto enterprise endpoint. But network-based tools like secure web gateways (SWGs) and secure access service edge (SASE) are blind to everything that happens inside the browser.
The Forrester survey reveals an interesting double standard: companies run unified endpoint management (UEM) and endpoint detection and response (EDR) solutions on the desktop, locking down local admin and enforcing least privilege. These same companies also let users pick any browser and install whatever they want.
As defenders harden traditional endpoints, threat actors use the soft target of the browser as the entry point. Firewalls, SASE, and proxies can block known malicious sites, but they have no insight into the browser session itself. Communication to SaaS apps and internet sites is generally encrypted, so these tools can only assess a site's safety using general information. They can't see when a trusted site has been compromised and is sending malformed scripts that launch an attack inside the browser. The only way to look inside the stream is deep packet inspection (DPI), which means decrypting the entire session and introducing latency that damages the user experience.
.png)
The end result is that, for many companies, the place where most work now happens runs without the controls and visibility applied everywhere else. Forrester’s survey details three particular ways this creates risk exposure for the enterprise organization.
The browser's invisibility to traditional network security approaches means that data can move or access can leak with zero control or insight. Here's where the exposure concentrates.
If the browser is the endpoint, extensions are the local applications running on it. Some increase productivity, like spelling and grammar checkers; others offer security services like password management. But because of how they function inside the browser they can read the page you're on, extract that information, and send it to third parties. They can reach cookies, passwords, and even access tokens, then hand that access to attackers to use against an org’s business apps and infrastructure.
The risk isn't limited to extensions that were malicious from the start; safe, highly-rated browser tools can become a trojan with a single update. On the traditional endpoint, you limit which apps users install and what those apps can access. Unrestricted extension policies and extensive permission skip that discipline entirely, leaving business data and app access exposed.
A core principle of Zero Trust is least privileged access: users and devices get only the minimum rights needed to do their work. That discipline, however, tends to disappear when it comes to the browser. IT leaders commonly define one standard browser but leave an OS-installed browser unmanaged, or let users run whatever browser they choose for whatever purpose.
Activities inside the browser session are commonly unsupervised, as well. Employees syncing between work and personal browser instances leak login information, cookies, and extensions. Users copy and paste data between controlled and uncontrolled apps; they share business files to personal cloud storage or download them to their personal device. Each of those moves carries business data across a boundary that no policy is watching.
Enterprise AI use has exploded, and the browser has become the common access point for it. Through the browser, users reach for unsanctioned AI to handle business tasks. AI is also increasingly baked into SaaS apps, another data access and sharing point that is invisible to security tools outside the browser.
Blocking access isn't the answer, though. As fast as IT and security operations restrict public AI sites, the long history of shadow IT shows that users will route around most safeguards rather than respect them. The more durable approach is to govern AI in the browser, not around it.
Taken together, these three blind spots share the same solution: visibility and control applied inside the browser rather than around it. The tools to do that exist today, and they don't require the latency or user friction of decrypting every session.
This report does more than uncover a significant gap between where work happens and how it's protected: It also includes the full set of guidelines for defending enterprise data in the browser, plus a downloadable "Browser Security Policy Recommendations" template to start tightening control today.
Read the full report to learn how native browser controls, UEM, GPO, enterprise browsers, and security extensions give you management and telemetry you don't have today. You’ll also learn modern browser security best practices such as layering protections into the endpoint itself, feeding browser telemetry to the SOC, and how to govern browser-based AI before it governs you.

Can network-layer tools like SWGs and SASE see what happens inside a browser session? No. These tools sit on either side of the browser and are blind to activity within the session itself. Because traffic to SaaS apps and websites is generally encrypted, they can only judge a site's safety from general signals and cannot detect when a trusted site has been compromised and is launching an attack inside the browser.
Are most companies that adopt browser security actually securing the browser itself? No. While 81% of security leaders say they're adopting browser security solutions, most still rely on network-layer tools positioned outside the browser rather than controls operating within it.
Can a safe, highly-rated browser extension become a security risk? Yes. Extensions can read the page, extract data, and reach cookies, passwords, and access tokens. Even a trusted, well-rated extension can turn malicious through a single update, handing that access to attackers.
Does syncing between work and personal browser instances create risk? Yes. Syncing leaks login information, cookies, and extensions across the work-personal boundary. Copying data between controlled and uncontrolled apps, sharing files to personal cloud storage, or downloading them to personal devices all move business data past a boundary no policy is watching.
Is blocking access to public AI tools an effective way to control AI use in the browser? No. The history of shadow IT shows users will route around restrictions rather than respect them. The more durable approach is to govern AI inside the browser rather than trying to block it from the outside.
Information in Forrester publications is based on Forrester’s efforts to compile and analyze the best resources reasonably available to Forrester at any given time. Opinions reflect judgment at the time and are subject to change. This report is part of a broader collection of Forrester resources, including interactive models, frameworks, tools, data, and access to analyst guidance.