News
82% of IT teams already lived through a web-based incident

- June 16, 2026
- Updated: June 17, 2026 at 7:11 AM

Eight in ten. That’s the share of surveyed IT professionals whose organization handled a browser-related security incident in the past twelve months. Half describe the damage as moderate or severe, which in IT speak usually translates to someone calling their boss on a Sunday.
The interesting part isn’t the headline percentage. It’s the profile of the companies hit hardest: BYOD policies, heavy SaaS use, remote-first teams. In other words, a normal 2026 company.
“Hackers don’t hack anymore. They just log in.”
That’s the line from NordLayer’s Andrius Buinovskis, and it does most of the work this report needs to do. Infostealer malware harvested around 1.8 million credentials and a staggering 68.8 billion cookies across 2025 alone. Once those are out, a login looks like any other login. Nothing trips. Nothing alarms.
You don’t need a Hollywood breach. You need a stolen cookie.
Your work is in the browser. Almost all of it.
NordLayer’s team analyzed 504 of the highest-rated work applications across 51 categories on Gartner Peer Insights. Every one of them was reachable from a browser. Nearly 79% were browser only: no installable client, no desktop fallback. Open a tab, you’re in.
That’s the new perimeter. It’s also why a single endpoint antivirus, by itself, isn’t really enough anymore.
Confidence is high. Coverage is patchier than people think.
Here’s the contradiction the report keeps circling back to. 73% of IT pros say their organization is well prepared. Yet when you ask which specific browser controls they’ve actually deployed, the picture changes. DLP tools lead at just 53%. Everything else trails below that.
The concern is genuine. 98% of respondents say their org is worried about web-based threats. 81% expect attacks to grow more elaborate. 73% expect more of them. The will is there. The tooling hasn’t caught up.
Three things the report tells you to actually do
Buinovskis groups his advice into three priorities, and they read more like guardrails than silver bullets:
- See what’s running. Get visibility into the SaaS in use, the extensions installed, and the sites people visit. Without that, shadow IT does whatever it wants.
- Block at the source. DNS filtering and DLP take a lot of weight off the user. Especially useful for teams handling financial or personal data.
- Stop assuming trust. Zero trust at the browser level means employees only reach the resources they actually need, and an attacker with a valid cookie still hits a wall.
Read the whole report
We’ve barely scratched the surface here. The full Why Browser Security Can’t Wait: Web-based Threats Report 2026, methodology and all, lives at: https://nordlayer.com/browser-research-report/
If browser security sits anywhere on your roadmap for the next two quarters, you’ll save yourself the trouble of doing the math.
Latest from Softonic
- The Solo Leveling video game will receive a new expansion while there are no news about a third season of the anime
- Kenneth Branagh would like to direct another movie of the superhero that catapulted him to success
- Spike Lee defends Michael as a great movie about the king of pop
- In 2025, 550 million hours of Star Wars were watched in the US alone
You may also like
NewsJurassic World: Evolution arrives on Nintendo Switch 2 with its most complete edition yet
Read more
NewsRobert Pattinson, about Matt Damon: “He’s a psychopath”
Read more
NewsFinal Fantasy Resonance confirmed for Switch 2: it launches October 22, 2026
Read more
NewsNetflix’s I Will Find You hits 85 million views: top 10 in sight
Read more
- News
xAI open-sources Grok-Build after reports of 5.1GB uploads
Read more
NewsResident Evil Requiem resurfaces: Leon actor reveals cut spider one-liner
Read more