
Presented by CloudMosa
Hey there, enterprise professionals! Did you know that work is increasingly happening inside the browser? It’s true! And with this shift comes a rise in browser-based cyberattacks. According to industry reports, attacks through browsers have been on the rise in recent years. In fact, Gartner predicts that by 2027, more than 85% of enterprise workloads will be accessed through the browser.
However, most enterprise security systems are still focused on protecting the device rather than the browser session where these attacks actually occur. According to Shioupyn Shen, founder and CEO of CloudMosa, the company behind Puffin Cloud Security, this approach needs to change.
CloudMosa originally developed its cloud architecture to enhance browser performance and accessibility, anticipating that enterprise work would transition to the browser. Today, this architecture is proving to be strong in modern enterprise security, especially with the rise of AI-assisted hacking.
The browser: the new operating environment for enterprises
The browser has become the primary entry point for SaaS platforms, CRM systems, and collaboration tools in the enterprise. As workflows and AI agents increasingly operate within the browser environment, the definition of a threat has evolved.
In the past, security teams could focus on monitoring and patching endpoints and networks. But now, as web code executes locally on user devices, every open browser tab poses a potential risk for malicious scripts, credential theft, and other exploits.
“The browser has transformed into the central operating environment for modern enterprise work,” Shen explains. “Traditional browsers were not designed to handle this level of responsibility.”
The limitations of detection-first security against browser-based attacks
Detection-first security often starts after risky code has already reached the device and begun executing in the browser. With modern browsers running dynamic JavaScript and WebAssembly locally, attacks can take place before security tools can respond.
Instead of focusing solely on detection, Shen suggests preventing risky code from reaching the device in the first place.
AI-driven malware challenges signature-based detection
AI enables attackers to create and deploy malware at a scale that traditional tools cannot handle. Polymorphic malware can change its code from one instance to the next, making signatures less reliable. Fileless attacks and browser-delivered techniques further complicate detection.
With an increase in attacks by AI-enabled adversaries, enterprises need to adapt to the evolving threat landscape.
Creating architecture to reduce the attack surface
Rather than solely relying on detection, it’s crucial to change where web code executes. CloudMosa’s Puffin Cloud Security shifts browser execution to isolated cloud environments, enhancing both performance and security.
The platform runs web sessions in disposable cloud environments and streams a pixel view to the device, preventing malicious code from running on the endpoint.
Integrating browser isolation into existing security stacks
Puffin complements existing security infrastructure by routing high-risk sessions through isolated cloud environments. This approach enhances browser-level policy enforcement without disrupting existing tools.
Choosing between faster detection and endpoint isolation
While detection remains essential, preventing attackers from reaching the endpoint is paramount. CloudMosa’s architecture focuses on worst-case scenarios, emphasizing security in the cloud rather than on the device.
By isolating browser activity in cloud sandboxes, Puffin Cloud Security provides a secure browsing experience for enterprises.
Security leaders face a choice: redesign for foresight now or wait until hindsight reveals the necessity for change.
Sponsored articles are content produced by a company with a business relationship with VentureBeat, and they’re always clearly marked. For more information, contact sales@venturebeat.com.
