# Overview
Most IT programs focus on endpoints, networks, and EDR, while browsers—where employees spend much of their workday—get less operational attention. That gap produces five specific risks that routinely go unnoticed because organizations lack visibility and control over what runs inside users' browsers.
# The five risks
1) No inventory of installed extensions
Many organizations have no centralized record of what extensions are installed across their fleet, who installed them, or what permissions they require. Without a baseline inventory, IT cannot reliably detect changes, audit compliance, or enforce policies. Shadow IT frequently hides inside extension libraries.
2) Unreviewed extension access to sensitive data
3) AI tools ingesting sensitive business data
Browser-based AI usage creates ungoverned data flows when employees paste or submit business information into public or unmanaged AI services. Unlike managed SaaS applications, these browser interactions often leave no footprint in existing monitoring systems, making it hard to detect or control sensitive-data exposure.
4) Browser settings drifting out of policy
When browser configurations are not centrally enforced, settings vary by user and device. Security controls such as saved-password policies and download permissions can drift over time. A single misconfigured setting can create continuing exposure across every session the user runs.
5) Browsing activity blind spots in incident response
# Practical next steps
- Establish visibility first: create a centralized inventory of installed browser extensions, their publishers, and permissions.
- Govern AI usage: specify which AI services are permitted, what data can be submitted, and how accounts are managed and monitored.
- Monitor for changes continuously: detect new or modified extensions and react quickly when risky changes appear.
- Collect browser telemetry useful to incident response: activity logs, extension change history, and relevant session data to speed investigations.
# A simple principle
Treat the browser as a managed attack surface rather than an informal workspace. Visibility into what runs in browsers, combined with enforceable policies and telemetry for incident response, reduces the most common exposures without requiring a large new project or platform.