Tekspace Research

Browser Security

A Cyber SaaS Analysis 2026
New domain assessments as they publish. Unsubscribe any time, and we never share or sell your data.

Work moved to the browser. Most security controls didn't follow it there.

Tekspace has spent years inside the systems that keep Australian businesses secure. As work shifted to SaaS and GenAI, data began flowing through tools organisations never provisioned. Exposed sessions, sensitive prompts, credentials leaving on unmanaged extensions, all in the one place endpoint and network controls cannot see. We know the outcomes that matter.

This report changes that. We map the visibility problem at the browser layer, study what businesses actually need to enable AI without adding exposure, and evaluate the leading vendors in the space, finding an architecture that delivers enablement and protection at once.

Thank you to Stacy Gurrie at Byte and Mathew Jose at CodeBlue New Zealand and the team behind the scenes (see Addendum for credits). Together, this work helps us deliver on our focus to protect people and data with simple, impactful cybersecurity.

Portrait photo of Frank De Pasquale
Frank De Pasquale
CEO at Tekspace

Threat Context

Insights from Parabellum Logo

CREST Pen Test certification badge. OffSec OSCE3 certification badge OffSec OSCE certification badge OffSec OSCP certification badge OffSec OSEP certification badge OffSec OSWE certification badge OffSec OSED certification badge OffSec OSWP certification badge OffSec OSAI certification badge

The browser is the primary work surface for Australian organisations, yet most security controls have zero visibility.

The average Okta customer now runs 101 apps1 and staff access those apps through the browser, in sessions outside the view of security.

That increased exposure has made businesses vulnerable.

In FY2024-25, ASD responded to 11% more cyber incidents, and the average self-reported cost of a business cybercrime report rose 50% to $80,850, with compromised accounts or credentials a factor in 42% of the incidents ASD rated C3 or higher.2

Credential theft pays threat actors who sell the data on the dark web to large syndicates.

What today's controls miss

The browser is now the front door

  1. Of detections were malware free

    In 2025, 82% of the detections CrowdStrike observed were malware free, as attackers log in and use legitimate tools instead.9

    82%
  2. Personal AI app use in Australia and New Zealand

    Personal AI app use still sits at 55%, down from 76% a year earlier.6

    55%
  3. Of infostealer-infected systems with corporate logins were unmanaged

    Among infostealer-infected systems holding corporate logins, 46% were unmanaged devices, outside the reach of endpoint agents.10

    46%
  4. Of incidents ASD rated C3 or higher involved compromised credentials

    Compromised accounts or credentials featured in 42% of the incidents ASD rated C3 or higher in 2024 to 2025.2

    42%

Bars are drawn to scale, on a 0 to 100% axis.

From session data to sold on the dark web

The browser is where attackers steal credentials and active session tokens. The dark web is where they profit. IBM X-Force’s 2025 Threat Intelligence Index describes a thriving dark web trade in stolen credentials.3

Session hijacking kits are also sold to exploit the browser. Attackers buy adversary-in-the-middle phishing kits4 to steal valid tokens. Once an attacker holds a valid session token, they inherit all that user's access without triggering any further authentication challenge.

What "stolen browser data" looks like in practice: In April 2026, Vercel disclosed a breach that began at Context.ai, a third party AI tool one of its staff had trialled. A Context.ai employee’s computer was infected with the Lumma infostealer after they downloaded Roblox cheat scripts, which took Google Workspace, Supabase, Datadog and AuthKit credentials. Context.ai says an attacker then reached its AWS environment and likely took OAuth tokens. One belonged to a Vercel employee who had signed up with a corporate Google account and granted “Allow All” access. The attacker used it to take over the account and move into Vercel’s systems. Nobody broke through Vercel’s perimeter. The same weekend, a seller offered the data for about USD $2 million.5

The browser data commodity

A supply chain you don't control

Australian cookies for sale 308M

Stolen browser cookies linked to Australia, listed for sale on dark web forums and Telegram channels.11

Still active when listed 25M

Nearly 25 million of those Australian cookies were still active when listed for sale.11

Vercel listing · April 2026 $2M

What a seller asked for the Vercel data, the same weekend Vercel disclosed a breach that began one vendor away, at Context.ai.5

ASD ACSC · FY2024-25 42%

Of the incidents ASD rated C3 or higher in 2024 to 2025 featured compromised accounts or credentials.2

AI is reshaping what "trust the browser" means

Enabling staff with AI is now urgent, and most organisations are already behind it: three in four workers in Australia and New Zealand now actively use AI apps, up from 53% a year earlier.6

Attackers exploit that gap by cloning popular AI assistant extensions: in January 2026, two fake AI sidebar extensions, one carrying Google’s Featured badge, were found stealing ChatGPT and DeepSeek chats from about 900,000 users. Some legitimate extensions have added similar collection as a product feature: Secure Annex found the Similarweb extension, used by over a million people, began capturing AI prompts and responses after a May 2025 update, disclosed in its privacy policy.7 Detection means watching extension behaviour over time, not just at install.

Agentic browsers, the kind that take actions on a user's behalf, read untrusted webpage content as if it were a user instruction. A staff member asks the agent to summarise a Reddit thread. Hidden text in a comment tells it to collect the user’s email address and a one-time login code from Gmail and post them back to Reddit, handing the attacker the account. There is no phishing click and no malware, just the user’s own signed-in session doing the attacker’s work.8

Traditional security models assume a clean separation between user instructions and untrusted content. Agentic browsers collapse it, turning any AI tool with session access into a privileged insider whose decisions are shaped by the content the user is viewing.

Agentic AI · Aug 2025 to Mar 2026

No clean technical fix

  1. Aug 2025 Brave Security

    Shows Perplexity Comet can be hijacked by hidden instructions in a web page, and finds Perplexity’s first fix incomplete.

  2. Oct 2025 LayerX: CometJacking

    A single crafted link can make Comet’s assistant send a user’s connected Gmail and Calendar data to an attacker.

  3. Oct 2025 Brave Security

    Near-invisible instructions in screenshots and web pages can hijack Comet, Fellou and other AI browsers.

  4. Oct 2025 OpenAI: ChatGPT Atlas

    Launches with a logged-out mode to limit the agent’s access. By December, says prompt injection is unlikely ever to be fully solved.

  5. Mar 2026 Zenity Labs: PleaseFix

    Attacker content such as a calendar invite can silently hijack Comet to steal local files and take over a user’s 1Password account.

Four research teams published agentic browser hijacks between August 2025 and March 2026, and Brave found Perplexity’s first fix incomplete. OpenAI says prompt injection is unlikely ever to be fully solved. Events are evenly spaced, not to scale.8

Blocking creates an internal risk

Many businesses don't consider the additional risk they create by blocking AI tools.

When the IT team locks down AI tools or restricts SaaS access overnight without guidance, staff route around it, moving to personal devices, personal accounts, or personal subscriptions.

When a user moves from a managed device to an unmanaged personal computer control is lost. It's no surprise attackers are engineering attacks that take advantage of this tension.9 Among infostealer-infected systems holding corporate logins, 46% were unmanaged devices, outside the reach of corporate endpoint tools.10

Browser security stays in the session, the reliable control for the productivity vs exposure uncertainty. It's the layer that enables staff productivity, while giving leadership the confidence that staff are using those tools correctly.

Security Outcomes

With the threat context as a backdrop, what do information technology professionals prioritise when considering a browser security solution?

  • Frank De Pasquale, Chief Executive Officer at Tekspace
  • Stacy Gurrie, Chief Executive Officer at Byte
  • Mathew Jose, Chief Information Security Officer at CodeBlue NZ

What matters in your assessment? Whatever the domain, a security product earns its place against the same four outcomes. Expand each to see how we assess the browser security category.

1

Efficacy

  • Intervention inside the browser session itself, not at the network edge
  • Credential theft, malicious extensions and zero-day web content stopped in place
  • Generative AI and unsanctioned SaaS use governed at the point of interaction
2

Operational Efficiency

  • Agentless deployment across managed, unmanaged and BYOD devices
  • Policy enforcement accurate enough to avoid a parallel exceptions process
  • Automated response and SIEM or SOAR handoff for confirmed events
3

Reporting and Analytics

  • Session telemetry beyond connection logs, including prompts submitted to AI tools
  • Shadow SaaS and extension inventory maintained as a standing view
  • Dashboards showing where enforcement is holding and where it is bypassed
4

User Experience

  • No measurable impact on browsing performance
  • Existing browsers and workflows preserved rather than replaced
  • Friction introduced only when a user's own action meets a policy

Product Landscape

Comparing browser security products is complex. Solutions overlap and differ in approach; browser extensions, enterprise browsers and cloud-hosted isolation platforms. Tekspace's Cyber Continuum™ ranks 13 of the best browser security products in one transparent, measurable spectrum.

Focused

  • Check Point Harmony Icon
    Check PointHarmony
  • ManageEngine Icon
    ManageEngine
  • SquareX Icon
    SquareX

Features

  • Phishing Detection & Prevention
  • Web Filtering & Application Control
  • Credential Theft Protection
  • Agentless Deployment
  • Data Loss Prevention
  • Multi-Browser Support
  • Shadow AI Usage Detection
  • File Upload/Download Control
  • BYOD/Unmanaged Device Access
  • Browser Session Telemetry
  • Extension Risk Management
  • Malware & Zero-Day Protection
  • Remote Browser Isolation

Broad

  • Akamai LayerX Icon
    AkamaiLayerX
  • Apozy Icon
    Apozy
  • Conceal Icon
    Conceal
  • Acium Icon
    Acium
  • KeepAware Icon
    KeepAware
  • Red Access Icon
    Red Access

Features

  • Zero Trust Browser Security
  • SIEM/SOAR Integration
  • VPN Replacement via ZTNA
  • Shadow IT Detection & Control
  • Human Risk Management
  • Vendor Deployment Integrations
  • Advanced DNS Protection
  • Prompt Recording & Capturing
  • AI-Powered Threat Detection
  • Reporting & Dashboard
  • Content Disarm & Reconstruction
  • Identity & SSO Management
  • Policy Enforcement & Governance
  • Threat Intelligence Integration
  • MSP Multi-Tenancy
  • Zero Trust Files
  • Zero Trust Credentials

Comprehensive

See Vendors and Features
Push Security Icon
CrowdStrike Seraphic Icon
Menlo Security Icon
DefensX Icon

Comprehensive

  • CrowdStrike Seraphic Icon
    CrowdStrikeSeraphic
  • Push Security Icon
    Push Security
  • Menlo Security Icon
    Menlo Security
  • DefensX Icon
    DefensX

Features

  • Browser Detection & Response
  • SaaS Security Posture Management
  • Password Hygiene & Enforcement
  • Adware & Ad Blocking
  • Screen & Print DLP
  • Automated Threat Response
  • One-Click LLM Security Hardening
  • Sensitive Data Protection via Regex Pattern Matching
  • OAuth & Token Security
  • Compliance Certification

We understood 400+ disparate features across the thirteen vendors, normalising them down to 40 scored features in 12 capability groups, each group sitting under one of the four outcomes above and each feature ranked by its technical depth.

Want to know which of these fits your environment? We help with that.

A logo on a chart does not tell you whether the tool covers the unmanaged devices your contractors are on, or the AI tools your people have already adopted.

Book your session

Conclusion

Browser security is an architectural shift, and your last line of defence when every other control has failed.

It can replace VPN and VDI with a single, faster enforced path, but its real value is what no other layer offers: visibility inside the session. That is what tells an approved tool apart from sensitive data being pasted into a personal account, letting teams unlock productivity without adding exposure.

Match the architecture to your risk; you may not need every capability on day one. We hope this research helps you make a deliberate, not reactive, choice.

We're hearing this exact question from IT leaders right now, as GenAI rollouts move from pilot to policy this quarter. When you're ready to pressure-test that choice against your own environment, you can book time with Tekspace directly.

Addendum

Credits

In launching this report, the Tekspace would like to acknowledge contributions from the following teams and individuals.

Contributors

  • Lead Analysts — Frank De Pasquale, CEO at Tekspace.
  • Threat Context — Martin Dybalski, Director; Stuart Shanahan, Director of Technical Services; and Kris Bowen, Senior Offensive Security Consultant, all at Parabellum.
  • Security Outcomes — Mathew Jose, Chief Information Security Officer at CodeBlue New Zealand; and Stacy Gurrie, Chief Executive Officer at Byte.
  • Research and analysis by the Tekspace Research team.

References

  1. Okta, Businesses at Work 2025, March 2025. Okta customers deployed an average of 101 apps each in 2024, up 9% year on year and above 100 for the first time.
  2. ASD, ACSC Annual Cyber Threat Report 2024-25, October 2025. 1,253 incidents (11% increase); compromised accounts or credentials in 42% of incidents rated C3 or higher; average self-reported cost of a business cybercrime report $80,850, up 50%; $202,700 average cost per report for large businesses, up 219%.
  3. IBM, X-Force Threat Intelligence Index 2025, April 2025. 84% increase in emails delivering infostealers in 2024 compared with 2023; early 2025 data showed a 180% increase over 2023.
  4. Microsoft, Digital Defense Report 2025, 16 October 2025. Token theft listed as a key user impersonation tactic; adversary-in-the-middle (AiTM) phishing named among methods used to bypass MFA.
  5. Vercel, security bulletin, 19 April 2026 (updated 24 April); Hudson Rock, 20 April 2026; BleepingComputer, April 2026. Breach via Context.ai: Lumma infostealer on a Context.ai employee’s computer, OAuth token for a Vercel employee’s corporate Google account, data offered for about USD $2 million the same weekend Vercel disclosed.
  6. Netskope, Threat Labs Report: Australia & New Zealand 2026, September 2026. Users actively using AI apps rose from 53% to 75%; personal AI app use fell from 76% to 55%.
  7. OX Security via Dark Reading, 8 January 2026; Secure Annex (John Tuckner), 29 December 2025.
  8. Brave, 20 August 2025 and 21 October 2025; LayerX, 4 October 2025; OpenAI, 21 October 2025 and 22 December 2025; Zenity Labs, 3 March 2026. Agentic browser prompt injection disclosures (Perplexity Comet, Fellou, ChatGPT Atlas), including Brave’s Reddit one-time code account takeover demonstration.
  9. CrowdStrike, Global Threat Report 2026. 82% of detections in 2025 were malware free.
  10. Verizon, Data Breach Investigations Report 2025, April 2025. Among infostealer-infected systems holding corporate logins, 46% were unmanaged devices; edge devices and VPNs were the target in 22% of vulnerability exploitation breaches, up from 3%; about 54% of those edge vulnerabilities were fully remediated, taking a median of 32 days.
  11. NordVPN with NordStellar, Sticky fingers in the cookie jar, 27 May 2025. 307,941,945 cookies linked to Australia listed for sale; 24,800,956 (8.05%) active.

Browser Security category

What this report does and doesn’t claim to cover, how we compare products fairly, and what to do if you still have questions.

Scope

This report evaluates browser-native edge security platforms delivering web threat prevention, browser-based data loss protection, SaaS access governance, and GenAI usage controls. It does not cover traditional network security products (SASE, SD-WAN, secure web gateways operating at the network layer), standalone endpoint detection and response platforms, or broader governance/risk/compliance tools.

Feature Granularity Model

We compare products at what we call Level 2: The Functional Group: specific enough to be meaningful, broad enough to compare very different products fairly, without losing sight of how they’re meaningfully different.

Further questions

Why isn't a secure web gateway, CASB, or the browser's own built-in protection enough on its own?

Built-in browser protections, secure web gateways and CASBs are all built to catch known-bad sites and traffic in transit, not to see inside a session after a user has already authenticated. As this report's threat context shows, most initial access today arrives without malware at all, using stolen credentials and hijacked session tokens that those tools were never designed to catch, which is why a dedicated browser-layer control exists.

How is this different from a traditional secure web gateway (SWG)?

A traditional SWG sits at the network layer, routing traffic through a gateway to catch known-bad destinations, which leaves it blind to what happens inside an authenticated SaaS or GenAI session running in the tab. The platforms in this report operate at the browser and DNS layer instead, giving them visibility into that session activity a network-layer gateway cannot see, along with genuine Zero Trust Network Access rather than a bolt-on VPN replacement.

How were the 13 vendors in this report actually compared?

We normalised the market down to 40 scored features and assessed each vendor at what we call the Functional Group level: specific enough to be meaningful, broad enough to compare very different products fairly. See Feature Granularity Model above for how that scale works.

Two of these vendors have been acquired since publication. Does that change the findings?

Seraphic was acquired by CrowdStrike and is now sold as Falcon Seraphic Enterprise Browser. LayerX was acquired by Akamai and still sells under its own name. Both were assessed as standalone products and neither has been reassessed since. What changes is how you buy them, not what they were found to do. Where a product has been folded into a larger platform, check the packaging and commercial terms before comparing it against a standalone tool.

What happens if I want another vendor assessed?

Get in touch. This report focuses on solutions widely regarded as market leaders or strong emerging players, not every product on the market, and we are glad to look at ones we have not yet covered.

Disclaimers

All assessments reflect Tekspace’s independent professional judgement based on structured product research.

This report is intended as a decision-support tool and does not constitute professional advice. Organisations should conduct their own due diligence appropriate to their specific requirements, risk profile, and regulatory obligations.

If you believe any information in this report requires correction, or if you would like your product assessed for inclusion, contact Tekspace Research at hello@tekspace.com.au.

Contact our team
Close

Focused

  • Check Point Harmony Icon
    Check PointHarmony
  • ManageEngine Icon
    ManageEngine
  • SquareX Icon
    SquareX

Features

  • Phishing Detection & Prevention
  • Web Filtering & Application Control
  • Credential Theft Protection
  • Agentless Deployment
  • Data Loss Prevention
  • Multi-Browser Support
  • Shadow AI Usage Detection
  • File Upload/Download Control
  • BYOD/Unmanaged Device Access
  • Browser Session Telemetry
  • Extension Risk Management
  • Malware & Zero-Day Protection
  • Remote Browser Isolation
Close

Broad

  • Akamai LayerX Icon
    AkamaiLayerX
  • Apozy Icon
    Apozy
  • Conceal Icon
    Conceal
  • Acium Icon
    Acium
  • KeepAware Icon
    KeepAware
  • Red Access Icon
    Red Access

Features

  • Zero Trust Browser Security
  • SIEM/SOAR Integration
  • VPN Replacement via ZTNA
  • Shadow IT Detection & Control
  • Human Risk Management
  • Vendor Deployment Integrations
  • Advanced DNS Protection
  • Prompt Recording & Capturing
  • AI-Powered Threat Detection
  • Reporting & Dashboard
  • Content Disarm & Reconstruction
  • Identity & SSO Management
  • Policy Enforcement & Governance
  • Threat Intelligence Integration
  • MSP Multi-Tenancy
  • Zero Trust Files
  • Zero Trust Credentials
Close

Comprehensive

  • CrowdStrike Seraphic Icon
    CrowdStrikeSeraphic
  • Push Security Icon
    Push Security
  • Menlo Security Icon
    Menlo Security
  • DefensX Icon
    DefensX

Features

  • Browser Detection & Response
  • SaaS Security Posture Management
  • Password Hygiene & Enforcement
  • Adware & Ad Blocking
  • Screen & Print DLP
  • Automated Threat Response
  • One-Click LLM Security Hardening
  • Sensitive Data Protection via Regex Pattern Matching
  • OAuth & Token Security
  • Compliance Certification
Get the next assessment
No vendors selected yet
Make an enquiry