{"id":370264,"date":"2026-06-16T07:04:10","date_gmt":"2026-06-16T14:04:10","guid":{"rendered":"https:\/\/cms-articles.softonic.io\/en\/?p=370264"},"modified":"2026-06-17T00:11:29","modified_gmt":"2026-06-17T07:11:29","slug":"82-of-it-teams-already-lived-through-a-web-based-incident","status":"publish","type":"post","link":"https:\/\/cms-articles.softonic.io\/en\/82-of-it-teams-already-lived-through-a-web-based-incident\/","title":{"rendered":"82% of IT teams already lived through a web-based incident"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Eight in ten. That&#8217;s the share of surveyed IT professionals whose organization handled a browser-related security incident in the past twelve months. Half describe the damage as moderate or severe, which in IT speak usually translates to someone calling their boss on a Sunday.<\/p>\n\n\n<div class=\"sc-card-program\">\r\n  <div class=\"sc-card-program__body\">\r\n    <div class=\"sc-card-program__row clearfix\">\r\n      <div class=\"sc-card-program__col-logo\">\r\n        <img decoding=\"async\" class=\"sc-card-program__img\" src=\"https:\/\/images.sftcdn.net\/images\/t_app-icon-s\/p\/c45ba2cd-a2cc-4681-97ab-fc1e67030541\/1463014841\/nordlayer-logo\" alt=\"Nordlayer\" width=\"100px\" height=\"100px\">\r\n      <\/div>\r\n      <div class=\"sc-card-program__col-title\">\r\n        <span class=\"sc-card-program__title\">Nordlayer<\/span>\r\n        <a class=\"sc-card-program__button sc-card-program-internal\" href=\"https:\/\/go.nordlayer.net\/aff_c?offer_id=1019&aff_id=29822\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">Download<\/a>\r\n      <\/div>\r\n      <div class=\"sc-card-program__col-rating\">\r\n        <svg class=\"rating-score__content\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" version=\"1.1\" x=\"0\" y=\"0\" viewbox=\"0 0 50 50\" enable-background=\"new 0 0 50 50\" xml:space=\"preserve\"><path class=\"rating-score__background rating-score--good\" fill=\"none\" stroke-width=\"6\" stroke-miterlimit=\"10\" d=\"M40 40c8.3-8.3 8.3-21.7 0-30s-21.7-8.3-30 0 -8.3 21.7 0 30\"><\/path><path class=\"rating-score__value rating-score__value--0\" fill=\"none\" stroke-width=\"6\" stroke-dashoffset=\"0\" stroke-miterlimit=\"10\" d=\"M40 40c8.3-8.3 8.3-21.7 0-30s-21.7-8.3-30 0 -8.3 21.7 0 30\"><\/path><text class=\"rating-score__number\" content=\"\" text-anchor=\"middle\" transform=\"matrix(1 0 0 1 25 31.0837)\" data-auto=\"app-user-score\"><\/text><\/svg>\r\n      <\/div>\r\n    <\/div>\r\n    <div class=\"sc-card-program__row\">\r\n      <span class=\"sc-card-program__description\"><\/span>\r\n    <\/div>\r\n    <div class=\"sc-card-program__row\">\r\n      <img decoding=\"async\" class=\"sc-card-program__bigpic\" src=\"\" onerror=\"this.style.display='none'\">\r\n    <\/div>\r\n    <a class=\"sc-card-program__link track-link sc-card-program-sponsored\" href=\"https:\/\/go.nordlayer.net\/aff_c?offer_id=1019&aff_id=29822\" target=\"_blank\" rel=\"noopener noreferrer nofollow\"><\/a>\r\n  <\/div>\r\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">The interesting part isn&#8217;t the headline percentage. It&#8217;s the profile of the companies hit hardest: BYOD policies, heavy SaaS use, remote-first teams. In other words, a normal 2026 company.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">&#8220;Hackers don&#8217;t hack anymore. They just log in.&#8221;<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">That&#8217;s the line from <a href=\"https:\/\/go.nordlayer.net\/aff_c?offer_id=1019&amp;aff_id=29822\" target=\"_blank\" rel=\"noopener nofollow\" title=\"\">NordLayer&#8217;s<\/a> Andrius Buinovskis, and it does most of the work this report needs to do. Infostealer malware harvested around 1.8 million credentials and a staggering 68.8 billion cookies across 2025 alone. Once those are out, a login looks like any other login. Nothing trips. Nothing alarms.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">You don&#8217;t need a Hollywood breach. You need a stolen cookie.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Your work is in the browser. Almost all of it.<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/go.nordlayer.net\/aff_c?offer_id=1019&amp;aff_id=29822\" target=\"_blank\" rel=\"noopener nofollow\" title=\"\">NordLayer&#8217;s<\/a> team analyzed 504 of the highest-rated work applications across 51 categories on Gartner Peer Insights. Every one of them was reachable from a browser. Nearly 79% were browser only: no installable client, no desktop fallback. Open a tab, you&#8217;re in.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">That&#8217;s the new perimeter. It&#8217;s also why a single endpoint antivirus, by itself, isn&#8217;t really enough anymore.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Confidence is high. Coverage is patchier than people think.<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Here&#8217;s the contradiction the report keeps circling back to. 73% of IT pros say their organization is well prepared. Yet when you ask which specific browser controls they&#8217;ve actually deployed, the picture changes. DLP tools lead at just 53%. Everything else trails below that.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The concern is genuine. 98% of respondents say their org is worried about web-based threats. 81% expect attacks to grow more elaborate. 73% expect more of them. The will is there. The tooling hasn&#8217;t caught up.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Three things the report tells you to actually do<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Buinovskis groups his advice into three priorities, and they read more like guardrails than silver bullets:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>See what&#8217;s running.<\/strong> Get visibility into the SaaS in use, the extensions installed, and the sites people visit. Without that, shadow IT does whatever it wants.<\/li>\n\n\n\n<li><strong>Block at the source.<\/strong> DNS filtering and DLP take a lot of weight off the user. Especially useful for teams handling financial or personal data.<\/li>\n\n\n\n<li><strong>Stop assuming trust.<\/strong> Zero trust at the browser level means employees only reach the resources they actually need, and an attacker with a valid cookie still hits a wall.<\/li>\n<\/ul>\n\n\n<div class=\"sc-card-program\">\r\n  <div class=\"sc-card-program__body\">\r\n    <div class=\"sc-card-program__row clearfix\">\r\n      <div class=\"sc-card-program__col-logo\">\r\n        <img decoding=\"async\" class=\"sc-card-program__img\" src=\"https:\/\/images.sftcdn.net\/images\/t_app-icon-s\/p\/c45ba2cd-a2cc-4681-97ab-fc1e67030541\/1463014841\/nordlayer-logo\" alt=\"Nordlayer\" width=\"100px\" height=\"100px\">\r\n      <\/div>\r\n      <div class=\"sc-card-program__col-title\">\r\n        <span class=\"sc-card-program__title\">Nordlayer<\/span>\r\n        <a class=\"sc-card-program__button sc-card-program-internal\" href=\"https:\/\/go.nordlayer.net\/aff_c?offer_id=1019&amp;aff_id=29822\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">Download<\/a>\r\n      <\/div>\r\n      <div class=\"sc-card-program__col-rating\">\r\n        <svg class=\"rating-score__content\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" version=\"1.1\" x=\"0\" y=\"0\" viewbox=\"0 0 50 50\" enable-background=\"new 0 0 50 50\" xml:space=\"preserve\"><path class=\"rating-score__background rating-score--good\" fill=\"none\" stroke-width=\"6\" stroke-miterlimit=\"10\" d=\"M40 40c8.3-8.3 8.3-21.7 0-30s-21.7-8.3-30 0 -8.3 21.7 0 30\"><\/path><path class=\"rating-score__value rating-score__value--0\" fill=\"none\" stroke-width=\"6\" stroke-dashoffset=\"0\" stroke-miterlimit=\"10\" d=\"M40 40c8.3-8.3 8.3-21.7 0-30s-21.7-8.3-30 0 -8.3 21.7 0 30\"><\/path><text class=\"rating-score__number\" content=\"\" text-anchor=\"middle\" transform=\"matrix(1 0 0 1 25 31.0837)\" data-auto=\"app-user-score\"><\/text><\/svg>\r\n      <\/div>\r\n    <\/div>\r\n    <div class=\"sc-card-program__row\">\r\n      <span class=\"sc-card-program__description\"><\/span>\r\n    <\/div>\r\n    <div class=\"sc-card-program__row\">\r\n      <img decoding=\"async\" class=\"sc-card-program__bigpic\" src=\"\" onerror=\"this.style.display='none'\">\r\n    <\/div>\r\n    <a class=\"sc-card-program__link track-link sc-card-program-sponsored\" href=\"https:\/\/go.nordlayer.net\/aff_c?offer_id=1019&amp;aff_id=29822\" target=\"_blank\" rel=\"noopener noreferrer nofollow\"><\/a>\r\n  <\/div>\r\n<\/div>\n\n\n\n<h2 class=\"wp-block-heading\">Read the whole report<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">We&#8217;ve barely scratched the surface here. The full <em>Why Browser Security Can&#8217;t Wait: Web-based Threats Report 2026<\/em>, methodology and all, lives at: <a href=\"https:\/\/nordlayer.com\/browser-research-report\/\">https:\/\/nordlayer.com\/browser-research-report\/<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If browser security sits anywhere on your roadmap for the next two quarters, you&#8217;ll save yourself the trouble of doing the math.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Eight in ten. That&#8217;s the share of surveyed IT professionals whose organization handled a browser-related security incident in the past twelve months. Half describe the damage as moderate or severe, which in IT speak usually translates to someone calling their boss on a Sunday. The interesting part isn&#8217;t the headline percentage. It&#8217;s the profile of &hellip; <a href=\"https:\/\/cms-articles.softonic.io\/en\/82-of-it-teams-already-lived-through-a-web-based-incident\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;82% of IT teams already lived through a web-based incident&#8221;<\/span><\/a><\/p>\n","protected":false},"author":9318,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","wpcf-pageviews":0},"categories":[1015],"tags":[],"usertag":[],"vertical":[],"content-category":[],"class_list":["post-370264","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/370264","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/users\/9318"}],"replies":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/comments?post=370264"}],"version-history":[{"count":1,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/370264\/revisions"}],"predecessor-version":[{"id":370284,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/370264\/revisions\/370284"}],"wp:attachment":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/media?parent=370264"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/categories?post=370264"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/tags?post=370264"},{"taxonomy":"usertag","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/usertag?post=370264"},{"taxonomy":"vertical","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/vertical?post=370264"},{"taxonomy":"content-category","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/content-category?post=370264"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}