Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - News & Analysis - Browser Malware, Operational Burdens Driving Enterprises To Seek Effective Technology for Secure Web Access
News & Analysis

Browser Malware, Operational Burdens Driving Enterprises To Seek Effective Technology for Secure Web Access

ISBuzz TeamBy ISBuzz TeamMay 11, 2015Updated:July 4, 20245 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
SECURE WEB ACCESS
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

In New ESG Study, IT Professionals Cite Escalating Security Vulnerabilities and Operational Issues; Say Securing the Browser is an Administrative Nightmare

SECURE WEB ACCESSSpikes Security [1], the isolation security company, today announced findings of a new survey of IT and information security professionals, commissioned by Spikes Security and conducted by The Enterprise Strategy Group, Inc. (ESG) to assess cybersecurity risks related to web browsers, and organizational strategies to address them. “The State of Browser Security” examines the cybersecurity risks and the impact of breaches associated with commonly-used web browsers, which are compounded by ineffective policies that put too much freedom and control in the hands of end users.

The study surveyed 200 IT and information security professionals responsible for/familiar with their organization’s security requirements for browsers deployed on endpoint devices. All respondents were either employed with midmarket companies (defined as organizations with 100 to 999 employees, 31 percent of respondents) or enterprise organizations (defined as organizations with 1,000+ employees, 69 percent).

Seventy-five percent of respondents stated that breach prevention and detection is more difficult today compared to two years ago. Of those respondents, fifty-nine percent report that malware has grown more sophisticated over the last two years, despite the fact that 87 percent of all organizations surveyed have increased endpoint protection spending in the last two years. The problem is further complicated by the fact that 84 percent of organizations commonly allow multiple browsers to be deployed on endpoints, which are primary vectors for targeted cyber attacks. IT departments try to minimize the risks of these attacks: 85 percent report that their departments work to keep browsers and patches updated, and 84 percent monitor browser configurations for vulnerabilities. Unsurprisingly, 82 percent of respondents are also concerned about files containing malicious content downloaded via browsers.

“One key finding here is that there appears to be too much time and effort focused on securing a product that is inherently insecure – the browser,” notes Jon Oltsik, senior principal analyst with the Enterprise Strategy Group, Inc. “Despite efforts to stay on top of patches and updates – and spending more on endpoint security products that should detect malware – it is obvious that IT organizations are becoming frustrated in their attempts to stay ahead of cyber criminals.”

OPEN TO A NEW APPROACH:  An overwhelming 92 percent of IT and information security professionals surveyed would characterize their organization as being “very aggressive” or “somewhat aggressive” in terms of their willingness to test and adopt new types of cybersecurity technologies, and 90 percent of respondents are familiar with next-generation technologies that isolate web sessions – and malware – outside the network. They indicated strong interest in testing and deploying solutions that can prevent browser-based attacks.

“The common web browser is a malware distribution system for advanced persistent threats,” said Branden Spikes, CEO, CTO, and Founder, Spikes Security. “It’s simultaneously the most ubiquitous and strategically important application in the enterprise, so naturally it has become the focus for hackers. Every click can potentially place the network and the organization at risk.”

OTHER KEY FINDINGS:

  1. CONSEQUENCES OF ORGANIZATIONAL SECURITY BREACHES:  Browser-based security breaches had a number of costly ramifications. For example, 81 percent of organizations that experienced a security breach within the past 24 months related to an attack that was introduced into the network via an endpoint browser, say that the time required to remediate these security breaches was “very significant” or “significant,” 72 percent state that security breaches led to “very significant” or “significant” regulatory fines, and 38 percent report that browser-based security breaches led to a “very significant” public relations impact.
  2. IT DEPARTMENTS STRUGGLE TO MAINTAIN SECURITY: Although browser security and management was a priority, ESG’s findings revealed that a majority of organizations are not keeping up with many critical security maintenance activities. While this is certainly understandable given the large population of endpoint devices with multiple browsers, security operations lapses leave organizations open to attack. Of particular concern are statements such as:
  • 57 percent of IT and information security professionals agree that: “_It’s impossible to control user browsing behavior, despite our attempts to enforce policies_.”
  • 54 percent of IT and information security professionals agree that: “_We have so many endpoint devices, it’s too expensive and time-consuming to ensure they are all properly protected.”_
  • 54 percent of IT and information security professionals confirm: “_We get so many alerts of possible endpoint security threats and breaches, it’s impossible to keep up with all of them.”_

Spikes-Security-ESG-Report-Infographic

Complete findings and analysis of the research will be presented by ESG analyst, Jon Oltsik, in a live webcast on Wednesday, May 20 at 10am PDT. To register, click here.

About Enterprise Strategy Group (ESG)

Enterprise Strategy Group (ESG) is an integrated IT research, analysis, and strategy firm that is world-renowned for providing actionable insight and intelligence to the global IT community. Recognized for its unique blend of capabilities—including market research, hands-on technical product and economic validation, and expert consulting methodologies—ESG is relied upon by IT professionals, technology vendors, investors, and the media to clarify the complex.For more information visit here www.esg-global.com

About Spikes Security

Spikes Security is a venture-backed Silicon Valley start-up founded in 2012. The company is focused on delivering secure, scalable, high performance appliance and software solutions that empower businesses with the freedom to safely leverage the web without fear of cyber attacks. Its initial offering is AirGap™, a powerful browser security solution that prevents all browser-borne malware from entering corporate networks and infecting endpoints. For more information visit here www.spikes.com
ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

The Real Cost of Inconsistent Third-Party Access

December 18, 20255 Mins Read

What Happens When Devices Cross Borders? The Role of Geofencing in Global IT

August 7, 20256 Mins Read

The Evolving Importance of Identity Governance in FinTech

July 10, 20258 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}