Episode Transcript
Bradon Rogers [00:00:00]:
there's so many blind spots. And this is the thing people don't want to talk about. You start thinking about if you're dependent on breaking open SSL traffic to get visibility, you're not breaking all the traffic. You can't see inside of all of it. It's not possible.
KB [00:00:12]:
From KBI Media, I'm Karissa Breen, and this is KBKast. My guest today is Bradon Rogers, Chief Customer Officer at Island, the company that created the enterprise browser category back in 2020. We talk about whether 20 years of security spending solved complexity, Or just moved it somewhere more expensive. Why zero trust tends to stop at the login, right where the real risk starts. And the question nobody can answer yet is, what happens to all of this when the agents start working without us?
VO: Before we get into it, do me a favor and hit follow wherever you're listening. It genuinely helps the show reach more people who need to hear these conversations.
KB [00:01:03]:
Alrighty, let's get into it. Okay, so Bradon, I really wanna start with, are organizations solving complexity or just moving complexity into another control layer? And I know that's a very broad question, but I ask that because given the time that we're in, there's a lot of stuff going on and it seems, and the people I'm interviewing like yourself each week, that the complexity, the threat landscape's obviously growing and there's a lot of stuff going on here, but I really wanna get your view, bit of a lay of the land to start there first.
Bradon Rogers [00:01:30]:
Well, thank you for having me, first of all. Appreciate it. Nice to be with you, KB. I do think people are trying to solve for complexity. They've introduced for years just layers of technology around each one of the use cases they've introduced into their environment. So you can think of it, let's pick an org that's solving BYOD, for example. They'll evaluate a stack of technologies. They will evaluate processes that fit around a BYOD program that is quote unquote viable for them.
Bradon Rogers [00:01:55]:
And they'll stand that up and it's months and months of work for that. And another initiative comes along, like a merger and acquisition or a call center, standing up a third-party call center potentially. They may stand up a different stack of technology, may stand up some VDI infrastructure for that. Totally different evaluation of the stack of technologies for that. The prior set of technologies didn't really apply, and they wind up building complexity through the environment. So they wind up with 4, 5, 6 different architectures for different parts of their organization. So a lot of organizations are trying to find a way to reduce that. And I see in a lot of different technology spaces where It was yesterday's approach to solving a problem, and it introduced a lot of complexity because it wasn't woven into the fabric of the user experience itself.
Bradon Rogers [00:02:35]:
In fact, a lot of times it didn't consider the user themselves. So that complexity thing is certainly a burden for the IT practitioners, for folks in cybersecurity simultaneously, and then on, you know, the kind of forgotten third party here is their end users in the process. So everybody kind of feels the pain, takes a bite of that sandwich.
KB [00:02:53]:
And do you also think, given your role, like what's happening, like each week things seem to change, like in the news, in the media, when I'm interviewing someone like yourself, that there's a big topic that everyone's focused on, then they're not focused on it. And I've seen that in terms of the volatility and just the velocity of how things change in terms of priorities, what's important day to day, week to week. It's— I just see it changing quite considerably. And then I guess as a result of that, it means that it is increasing the complexity of how things are because people are sort of ditching one thing to then start something else because they've got to, of course, chase what's happening in the space. But these things don't necessarily just go away if you close your eyes, for example.
Bradon Rogers [00:03:32]:
Yeah, I do, I do see some of that. I think certainly the universe of AI, that's introduced kind of that problem on steroids, maybe to some extent, you know, it's the fastest changing landscape that we've ever encountered. You look at a lot of the providers that we're frontier labs, they introduce new capabilities literally almost on a daily basis. And sometimes those capabilities they introduce affect an entire stack of technologies that the org has in place today. They attack a whole space of vendors that organizations invest in. Now, orgs have to question, do I solve that with my AI provider over here, or do the stack of technologies actually hold up under the duress of people actually using AI in the process? I do believe that's creating a lot of complexity for organizations trying to wrap their hands around it. Every org's in a different part of their journey in that as well. So some orgs are just trying to lasso the basics of it, like to put their hands around how are users using it, like what are they wanting to use, what's the most effective use of that in our organization.
Bradon Rogers [00:04:25]:
So some orgs have AI steering committees where they brought a bunch of different personalities to the table from different parts of the org. Some orgs have gotten really mature in the process and they've created chief AI officers in the process as well. But I do believe that traditional problem that you're calling out is now put on steroids with regard to the movement of AI in the organizations and how organizations are trying to find a way to to get positive benefit from that without, you know, absolutely blowing the budget out of the water that we're kind of constantly hearing about right now, as well as concern around spend.
KB [00:04:55]:
So the main sort of theme we're going to talk about today is browser security. But before we get into some of the nuanced pieces around that, do you think browsers is something that people don't— it just gets a little bit relegated. What I mean is like even to connect today on the interview, it says, okay, we're going to go in the browser. We're not thinking really about the security then around it because the thing just seems to work, but we've got other things that we should be focusing on, like applications, et cetera. Would you say where you sit and what you've seen in your career, is this something that people seem to forget about and then becomes a problem now, but then also down the line and it grows because the thing just kind of works?
Bradon Rogers [00:05:34]:
A great question. I do believe that the browser is kind of the forgotten entity in the organization. I don't think people see the browser as a problem. I just don't think they see it as an assistive vehicle for them. They think that it, like you said, it does what it does. If you think about the browser that we all use every single day, you know, as end users, the browser's job is to, you know, reach out, grab content, and then put content in front of my eyes as an end user. And in many cases, pour content down to the desktop. So this is why we put a bunch of things around that experience.
Bradon Rogers [00:06:01]:
A lot of times we'll put, you know, an agent on the host, a DLP agent, protect the data, or we'll steer the traffic of that browser back through some cloud entity, some SASE provider, and we'll have to break open SSL, introduce all kinds of other complexity with backhaul, et cetera. But the core of that is not that the browser's the problem, it's that the browser wasn't a cooperative member of the real estate in the first place. But what if we could take the browser and actually make it be a functionally cooperative part of our policy and our governance? Could that change how we approach many of the common problems? And that's what we found when we do rollouts in our world at Island, with the enterprise browser is once you have the mechanics and the instrumentation in the browser itself, it starts causing you the question, do I need to deliver the solutions of the past to solve these problems in the same way anymore? Do I need to break and inspect SSL? Like, that's a problem from 20 years ago, and we continued propagating that problem, and we get more and more blind spots when we try to do that. Do I need to backhaul traffic? Do I need to shift that back through cloud proxies somewhere, and, you know, for SaaS-based applications users are going to? So, But once you make it a cooperative member of the real estate, you start reimagining the fundamental architectures with how you support the org. And then back to the original question you asked about complexity, you start eliminating the complexity because the same architecture you're using to solve problem A, turn around and it actually solves problem B too, and problem C and problem D. And it gets to be an exceptionally powerful part of the overall environment for the org and does become the ultimate architecture at the end of the day, a much simpler architecture. without a lot of the burdens of the past, like no streaming pixels, no breaking in spec, no backhaul, all that stuff that we've seen from VDI, SASE providers, and things like that.
KB [00:07:36]:
And on that note, would you also say just like browser or browser security, the browser, it's just become less obvious of a risk perhaps as well? Like other things seem to take precedent, we hear more about it, et cetera. Like, you know, I've conducted so many interviews on this podcast, I don't even think maybe once I've spoken to someone else about browser security in that duration. So it's just not something that we often hear about. So I'm just curious really to understand, is it because it doesn't seem obvious for people? I mean, there's some things that are obvious, we don't pay attention to it and so forth.
Bradon Rogers [00:08:08]:
Well, I don't think many organizations have an initiative that is a secure browser project now. And the reason is, is they don't see the browser as the weak spot in the organization. They just see it as not a cooperative member of the real estate, as we talked about a moment ago. So they go evaluate the things I got to put around that experience. But, you know, very few organizations are looking at it and going, you know what, I got to fix this weak browser that's been produced by all these consumer companies and wrap some terrible experience around that. Nobody's looking at that as the problem. They're looking at the problem and going, I've got to protect data, you know, make sure data doesn't leak in my organization. I got to keep my users safe from wandering in different places.
Bradon Rogers [00:08:43]:
So that's why they do the bolt-on things we talked about a moment ago. You know, we believe that there's just an immense amount of potential that has been corked up in that browser interface for many years, one which the users already know very well. The users have a lot of experience using browsers. They've been trained on them for years, just inherently trained. And the result is, if we can unpack that kinetic potential in the existing browser, it does let us start reducing all the complexity and a lot of the pain. But I think to the point you're making is, it's, you know, I wouldn't say the browser's been an oversight, but everybody sees the browser as doing what it was designed to do. which was to fetch content for me and let me interact with content. But did we see the browser as a part of my security surface, to be a part of that real estate can be helpful for me? No, nobody ever viewed it that way.
Bradon Rogers [00:09:27]:
And that's why the enterprise browser's been such an amazing thing for the orgs that have adopted it.
KB [00:09:30]:
You mentioned before, like, users, as we know, like, users hate friction. And then as soon as there's friction, even more so nowadays, because everyone wants to do things faster, cheaper, better, whatever, you know, so they can put their feet up on Friday and watch beer, have beers with their buddies and do whatever. So do you think as well, perhaps companies have thought, look, the browser's doing what we kind of want it to do, but we don't wanna introduce too much friction, 'cause when there's friction, there's workarounds, all sorts of problems start happening elsewhere. You're trying to solve one problem, another one opens up. So do you think there is a lot of that based on, like you said, it's doing what it says it's doing on the packet and that's it. We don't need to explore more into it.
Bradon Rogers [00:10:07]:
Well, if you think about all the things we bolted around it, We made the user's life hard. We put the user through unnecessary hurdles, and we didn't put natural interfaces in front of them to make their life easy. When they want to access an internal application, well, historically speaking, we would force them to launch a VPN client. Well, your average user isn't a network expert, you know, and that's another client they got to deal with. And that's an example. Sometimes then we force them to launch a VDI client in that process, and they get yet one more unfamiliar experience. And then sometimes we'll put a browser inside of that VDI infrastructure and they'll launch a browser through all those mechanics. We believe that there's a lot of those things that can be reduced and eliminate end-user friction, make the end user's job easier.
Bradon Rogers [00:10:49]:
It's really important as well is you think about the world of cyber for years, the cyber folks have gotten a lot of bad press from being the say-no police. They get in the way, the friction that cyber causes. That doesn't need to be the case. What if cyber could be an assistive part of giving people what they need to be able to do their jobs and more? What if we could let users use any AI of choice in the environment without the risk of company data being exposed or let into financial services that users access personal Gmail? Or in this new agentic universe, start unleashing the world of the agentic workflows for my workforce without having to worry about what happens in that flow and make sure we create the appropriate productivity and protective nature of how we want agents to be adopted, so we can get a good understanding of how they're being used in the first place in the environment. So, that, you know, it's a really perfect journey for making the user's life easier and giving them access and reducing friction for the user. But it's also a good vehicle for starting to reduce the friction as orgs start moving to this whole agentic universe in and outside of the browser. And that's a really important part of this conversation, because the work that needs to be done around the agentic workspace It's not just a browser-centric workspace. It's stuff that lives locally on the desktop, stuff that lives inside of your applications that are in your SaaS-based apps and your private apps.
Bradon Rogers [00:12:05]:
And so the workspace for the end user extends many of those core capabilities over to the agent, which is a big foundational part of what we've been delivering for many years at Eilon. It's not just in the browser. It's things outside of the browser to empower that agentic world.
KB [00:12:18]:
You're raising a point around VPN VDIs. So even, let's look at that for a moment. People would then say, complain, like it's slower. I can't even connect to it. And therefore, We use a VPN when we're outside of our work perimeter, but it doesn't even work anyway. So therefore I have to go all the way back into the office to do the work I was supposed to do. So we've sort of, again, created the friction of trying to do, like you said, these bolt-on, trying to do the right thing. But then as a result, it's made things slower.
KB [00:12:43]:
People can't do their job as efficiently. And then as a result, they just don't do it or then run things on their personal laptop because it's faster.
Bradon Rogers [00:12:49]:
Mm-hmm.
KB [00:12:50]:
Talk to me a little bit more about that journey because there's still a lot of companies out there, as you would know, that are still running VPNs.
Bradon Rogers [00:12:55]:
1,000%. We see them all over the place. And some orgs, these massive global orgs, they have multiple VPN providers. And, you know, the good thing is they already know the pains of those. I'd say a lot of organizations with VPNs are moving down the path of trying to find alternate vehicles, zero trust network access vehicles that give seamless access to internal apps without the need to launch a VPN client. And a big part of that's functionally part of the world that we built within the enterprise browser is just, that's, it's foundational, seamless access to private applications being built in without the need for a VPN client. And then, you know, you've got the obvious risks once you've got VPN ports exposed. You know, there's obviously the concerns that people take stolen credentials, you know, they leverage stolen credentials and use the VPN as one of the conduits because it doesn't take much to scan the front end of an organization to find open VPN ports and bang away on those.
Bradon Rogers [00:13:47]:
You know, when you leverage a zero trust network access approach, you're using context to drive the access with no exposed ports in the process. So, and then again, one of the key things is you're not steering all the traffic for the internal resources back on-prem. You're steering it for the things that need to go on-prem to the resource that's necessary. And that'll be really important. Again, I go back to the AI conversation because AI doesn't just exist locally on the host or just in your SaaS apps. Your internal universes need to be a part of your AI framework, needs to be a part of the foundation. of how you empower the agentic universe and giving seamless access to the agents based on context is a really, really important part of this. So, so it serves a nice spectrum from the end user all the way to the agents in that process for the internal needs.
Bradon Rogers [00:14:30]:
And again, getting rid of that VPN stuff in the process is always a big plus.
KB [00:14:34]:
So I want to know if the major browser and platform vendors, for example, build more of native enterprise controls. Does this become like a standalone category now, or was it more like a feature set considering just what we're sort of talking about again, even with people running agents locally on their machines, et cetera? It's getting away now from the browser, et cetera.
Bradon Rogers [00:14:56]:
I would argue that it's a category now. And I'd say that because not only is there the universe of what we're doing at Island, but there's players across the space that are doing things with browsers and with alternate form factors of extensions. We have both. So we have a browser and an extension form factor so that it can live in your existing browser. But this whole category that we created back in 2020 has given rise to a whole series of different players taking different problems and solving them from different angles. Some are taking the angle that you talked about earlier is let's harden that browser. Let's make it a safer browser to operate in. We believe that's important, by the way, making the environment safe.
Bradon Rogers [00:15:31]:
So my language earlier is not misinterpreted that we don't think it should be important to operate in a safe place. That's why we deliver a full browser for this really ultra-sensitive environments that need a hardened way of working. But we do believe there's a category that's in existence today. Your existing browsers, again, there's a little bit of tear on those things because they're torn between the consumer revenue that drives their viability. They're making money on targeted advertising and search, and there's billions of dollars behind that. A heavy pivot to the enterprise is probably not in some folks' best interest. So, So, but there are some, some things that you can do in your existing browsers, but again, bolt it on with an extension on top of that. Like our extension is a good example, is a great starting point for that.
Bradon Rogers [00:16:09]:
But yeah, I firmly believe there's a very thriving category simply just based on the massive organizations that are now doing this at scale.
KB [00:16:16]:
And do you also, just going back to the VPN stuff for a moment, do you, are we going to start to see like massive migration? Because this is just the way of the world now. And what I'm hearing a lot in interviews is people saying, hey, companies, big enterprises that are so entrenched of 50, 100 years they are, moving faster now because they know that they don't do something, the competitors are obviously going to beat them, but then also they have major risks that they're carrying. So we go, are we going to start to see people like effectively not just lift and shift, but also their mindset towards this? Because my question is, this has been a problem then for a while, but then people sort of just weren't doing anything or moving. But is it just, there's that catalyst there, companies know they need to evolve, they need to be a little bit more modern, and their back's up against the wall a little bit on this?
Bradon Rogers [00:17:00]:
1,000%. There's the thought process that recognizes these are legacy approaches. And in many cases, they were stuck because there wasn't a better alternative. So I'll use a perfect example, VDI. What was your better answer? You had to put an app in the hand of an end user, call center worker, one of your own employees, et cetera. And you had to do that in a way where you could contain things. And what was the best option? Well, string the pixels, make sure that data stays where it needs to stay behind that VDI universe. And in the process, yeah, everybody's going to suffer a little bit.
Bradon Rogers [00:17:31]:
The budget holders suffer. The people architecturally that are having to deliver it have to suffer through a lot of pain. And the end users, like we mentioned earlier, they really suffer. But that's a good example of something that just wasn't a better alternative in a lot of cases. You think about the SASE universe. That's a modern approach in some people's eyes, but we took the legacy on-prem architecture and we just shoved that up into the cloud. And then we started backhauling traffic for users through that pinch point. Again, there wasn't a better alternative in a lot of ways.
Bradon Rogers [00:17:58]:
And we view the world of what we've done with the enterprise browser and again, this whole category as being something that transforms many of those things where all those things from the past are gone. So now there is an option. And I think that's the key for this, back to your question, is it gives people optionality in a lot of different areas. If you want to reduce that VPN footprint, it gives you an option on that front where you can reduce or eliminate it. You want to get rid of that VDI infrastructure?
KB [00:18:20]:
Great.
Bradon Rogers [00:18:21]:
There's an option where you can run the apps locally outside the browser and have them be a cooperative part of the fabric of protecting the applications and giving network connectivity where necessary. If you need an alternate path for, you know, how we manage passwords and password management, privileged access management, there's alternatives in that. So it just provides a lot of different doorways for things that people didn't have in the past as starting points for the problems they have. And that's why the starting point sometimes is quite diverse with customers that we begin to work with as well.
KB [00:18:47]:
So you said there were just no other options, which makes sense. So then what was coming to my mind as you were speaking, Bradon, would be, do you think companies have just spent all this time on like cloud and network and all this sort of stuff? But it's like, actually, if we look back to a user in our company, what are the— where's the place of work? It's in the browser. I know for myself, I run Gmail, it's in a browser. I'm running— I'm talking to you, it's in a browser. Social media stuff, it's in a browser. Canva's in a browser. So.
Bradon Rogers [00:19:12]:
Yeah.
KB [00:19:13]:
It just feels as if like it's very obvious that's where people are conducting their work each day in a browser. Why have there been so much emphasis? And I know it's hard because each person I talk to, you know, cloud security, we're going to talk about all these things and I understand that, but it just seems that when we look at how people in our company are performing the work, that's a very good starting point in terms of, hey, we should be very focused on this because this is where Chris and Sabrina is doing our work each day.
Bradon Rogers [00:19:38]:
Yeah, 1,000%. So the majority of a user's work does happen in the browser. And a lot of the beginning points of AI, the AI journey for organizations starts in the browser. It doesn't finish in the browser, just like the user's work doesn't all happen in the browser. We still use Microsoft clients outside the browser. We use things like ChatGPT inside the browser and outside the browser. And obviously the cloud universe is in a variety of different places. But yeah, I think that part of this was the art of the possible hadn't been uncorked.
Bradon Rogers [00:20:04]:
Uh, there was no motivation for a lot of the browser creators to take a path like this. And it just, it took a spark. And I think the reality is that, you know, we believe at Island we created that spark and then a lot of others have joined suit in the process as well. And, uh, you know, there's certainly the, uh, the concern about, you know, the organizational change management and the, we're gonna pull our users' browsers outta their hands. And no, you don't have to do that. You know, when you think about this journey, the, it's a crawl, walk, run kind of strategy. So you may put an extension in the existing browser for a while and gain control that way. On your managed devices or get visibility.
Bradon Rogers [00:20:34]:
There may be situations where a full browser may be called for in a given situation, but you have those optionalities in that process. And there may be certain audiences that need this for certain applications, but not other apps. They can keep using their browser of choice for personal and non-critical work. So there's a lot of different ways to go about adopting this, but in much the same way, let's say 20+ years ago when VDI came along, a lot of organizations today have massive, I mean, huge VDI footprints. It didn't start that way. It started with a subtle few areas of the problems they faced, and it began to creep across the organization into areas that it turned into something that was much larger than originally either was intended or originally started. So, we believe that, again, the enterprise browser can start that way for a lot of organizations and solve a specific use case. Doesn't have to tackle everything for all users.
Bradon Rogers [00:21:19]:
And there's some great resources and strategies for change management that doesn't freak your end users out. And by the way, One little side note, once the end users wind up seeing it, they realize it looks just like the browser they already know, and the user, user panic goes away about change management in that process anyway. We see that over and over again.
KB [00:21:34]:
We'll come back to that after a quick word from our sponsor. For remote-first companies, maintaining a strong security posture across distributed teams can be a challenge. That's why thousands of modern, remote-friendly firms turn to Vanta. Vanta automates the heavy lifting for ISO 27001, SOC 2, GDPR, and more, keeping you compliant and audit-ready wherever your team logs in from. Visit Vanta.com/KBKast, Vanta.com/KBKast, to learn more. So after we heard about all the VPN stuff, then came the zero trust. I remember even maybe 6 years ago, that's all I heard about. I'm then curious, would you say, let's talk about zero trust, it just sort of ends too early though.
KB [00:22:24]:
What happens after the access is granted? Like, what's the user doing then? How do, there's no way of governing it then. So would you say that perhaps it's not obsolete, but it's sort of what happens after that then? Like, if I've copied something and then what am I doing as a user? Am I a rogue user? What's happening there? So does that whole function about zero trust become Not as secure then?
Bradon Rogers [00:22:46]:
A great question. So if you think about a zero trust philosophy, I'm not going to get too deep into this, but the whole philosophical approach to zero trust is not a point in time type thing. It's not an authentication, you have access and then nothing else gets assessed. It is continuous. It is contextually driven. So context, things like identity and device awareness and geolocation and network that you're on and all these contextual clues come together to form the basis of continually assessing engagement so that the appropriate policy gets applied. And that's exactly what you do in an enterprise browser. You know, the first thing you do is you log in.
Bradon Rogers [00:23:19]:
You log in using your single sign-on provider, you know, multifactor in that process. And based on all those contextual clues I mentioned a moment ago, the appropriate access is granted. But that doesn't mean it stops there. You get access and now it's all done. You know, woven into the fabric are all the vehicles to protect the data in the applications continuously. If context changes, if a user tampers with the device or someone tampers with the device and it no longer meets our posture, it instantly adapts to that and says, all right, you know what? We just deprecated some access in this process because it's not living up to the standard we expect. So for us, access is just the starting point. Once you get access to the applications, obviously that's got to be easy for the end users.
Bradon Rogers [00:23:57]:
It's natural in our world because they already know how to use a browser. But once they now have access to the key applications to do their job, the continuous process of using mechanics inside of the browser itself with policy and audit in that process to keep the experience safe and drive dynamic adaptation around the given environment that it's operating in. That's fundamental. That's just foundational to the concepts of zero trust as a general philosophy.
KB [00:24:20]:
And I definitely know it's continuous. It's just more like what was maybe an example would be, I've authenticated, everything looks fine. I work in finance. I need to get a high-level summary of the report my boss sent me. I'm just going to feed it in now to ChatGPT and see what it spits out. There's no way, like, from a zero trust perspective of governing that. And then that gets to lead to your earlier point around like DLP. Well, that would be a problem then because I've just now put into, you know, OpenAI's system, well, sensitive information about my company earnings for the year that no one knows about.
KB [00:24:52]:
And I've just fed it through there because I need to summarize it. So it's more like that is the part that I find really interesting because zero trust may ask me in like an hour, hey, you're sort of doing something that's unusual, but it still doesn't prevent the issue that I've just fed something through to get an answer because it was the easiest option.
Bradon Rogers [00:25:11]:
Yeah, 1,000%. So one of the most important things is organizations have sanctioned environments, and especially in today's AI universe, using your example before, most orgs have some level of sanctioned AI usage, whether it's Copilot, it's part of their Microsoft agreements, whether they've done explicit agreements with Anthropic or with OpenAI or others in the process, they've put their foot into the water with AI in some way or another. A big foundational part of zero trust, but also into the world of what we do in the enterprise browser, is recognizing tenancy, recognizing the applications, recognizing this is our corporate application or a personal app. So being able to identify, is this the corporate cloud environment we're engaging, or is this someone's personal cloud environment? Well, if they decide to engage cloud, we can steer them to the corporate environment, and that way they can do those movements that you're talking about. But if all of a sudden they're in the personal universe, they switched over to the personal tenant, all the markers on the screen and a lot of the markers that would be seen in a network would tell you that that's the corporate environment and can't distinguish corporate versus personal. And a really important part of our universe is a concept around this creation of what we call an application or data boundary. Just lets the user have the freedom of movement within the boundary of the corporate apps and tenants so that the company data doesn't spill to places like you're talking about in your example there, the things that are outside of our control. It doesn't mean we want to inspect content in the boundary.
Bradon Rogers [00:26:29]:
So if you pull data that's sensitive data over into a sanctioned AI universe, I may not want it ingesting certain data. For example, if I'm on a merger and acquisition team, I may not want my AI, my agents, or my chat universe ingesting data from deal rooms we're doing due diligence on inside of merger and acquisition deal rooms because it's too soon. We're not ready to ingest that data yet. So You can have the ability to make the boundaries exclude certain applications, even though the user has access to those things. But you can also say, I don't want this content bleeding over into those worlds as well. So we get perfect control, perfect fidelity. The most important part of this is, and this is one of the most dangerous parts of cyber right now, is there's so many blind spots. And this is the thing people don't want to talk about.
Bradon Rogers [00:27:11]:
You start thinking about if you're dependent on breaking open SSL traffic to get visibility, you're not breaking all the traffic. You can't see inside of all of it. It's not possible. There are laws of physics that make that not possible. Things like certificate pinning and advanced cipher suites and the whole world of post-quantum ciphers. The good thing about what I was talking about a moment ago is if data's going beyond the boundary to personal or to something sanctioned, we get complete fidelity because we're not having to fight SSL traffic in that process. So there are no blind spots. So for us, I think that's a really wonderful answer for organizations that are worried about this future of AI, the things that it's consuming, and making sure that AI is consuming the things that we want to consume.
Bradon Rogers [00:27:48]:
And still, while, by the way, In that example I gave a moment ago, I may give the user access to the deal room, but I don't want the agent having access to the deal room that the user may employ. So it gives me the ability to win on both sides of the fence in that question.
KB [00:28:00]:
And would you say, I know you said before that companies have got like these sanctioned environments, but would you say this is something that organizations that you are talking to out in the market that they're starting to then think about? Because like some of these use cases have changed. Like even before 2022, we didn't have that capability to be like, oh, I'm just gonna open up OpenAI and ask it a question and it's gonna give me summaries. 'Cause I was a reporting analyst, so I kind of wish I had that back in the day. And I know it's hard to answer because there's no real blueprint. We're discovering things as we go and new things pop up. But when we're talking about an everyday user and what they're probably likely to do or not do and the result of that, what was that guy in the US government earlier this year that accidentally, you know, uploaded something to OpenAI and he got pinged for it, of course. But I mean, that's a government person that's doing it. So imagine the everyday person in a big enterprise that may not be aware of what they're doing.
KB [00:28:47]:
It's just more looking at that then from a use case point of view, but then also the ramifications then of that. Like you said, if there's M&A stuff going on and all of a sudden the whole deal falls through because information's been leaked.
Bradon Rogers [00:28:59]:
Yeah, that boundary thing I discussed a moment ago is incredibly important for that because the end user themselves, because by controlling the presentation of the apps, which you control in the browser, that's what you're controlling, the actual presentation. I could say, you know what, when the user goes to ChatGPT, let's make sure they're going to the company tenant. So, because the example you're using, especially several years ago before there were guardrails around a lot of this, people would take company data, like the example you used a moment ago, and spill that right into some uncontrolled AI universe. And the users are interested intellectually in AI. It's interesting. It speaks their native tongue. So in the process, it's easily accessible. Why not use it? Because it can make me more effective at my job.
Bradon Rogers [00:29:36]:
But it's incumbent upon the organization to provide outlets for the user to be able to leverage that stuff at the right time. and to have mechanics that can steer them effectively to the right things at the right time, while also, by the way, simultaneously not having a big sledgehammer to say no to all the stuff that maybe the user wants to approach. But, you know, for example, I may want a user to let them access cloud resources, but it may not be our sanctioned resource, so our company data won't spill over the boundary. In the process, the user still gets access to the cloud universe in the process, and they're not fighting my cybersecurity controls at every turn. So there are ways for both sides to win in that process where It doesn't have to be the difficult trade-offs of the past. The boundary thing is one of the most important starting points for that. I say that only because if you think about the way we had to protect data for years, we were constantly caring and feeding for DLP. And it is this nonstop washing machine.
Bradon Rogers [00:30:25]:
It's a washing machine stuck on spin cycle. You never get out of it. And in the world of the boundary, that's the top-level data protection element. And then you inspect content within it. So you're doing a lot less caring and feeding in the process as well.
KB [00:30:37]:
And what would you say, Bradon, the browser can't control even in the best-case sort of architecture? Is there any sort of, like, talk me through what does that look like in your eyes?
Bradon Rogers [00:30:48]:
Yeah, so, you know, browsers naturally don't control thick applications, the things that live outside of the browser. That's why we spent a lot of time over the past several years building a complete platform. And we don't use that word platform lightly. Like, you hear that word being misused in the industry a lot. When you literally build one policy, in our universe of management, and that policy lives in and outside the browser. We have something called Island Desktop. So Island Desktop is a persistent service that lives on the host. When you install our browser, it can install this service, and this service gives the ability for our same set of mechanics to live in the browser, to live outside of the browser for specific applications and services that are local to the device.
Bradon Rogers [00:31:24]:
Again, that's advantageous for legacy clients with the orgs trying to get off VDI and things like that, give the user a local experience. And in the modern world, the modern AI usage is very advantageous for people using things like Claude Desktop and other types of AI services locally in the machine, because those same set of resources live in and outside the browser and give the user— the user doesn't feel the borders or the boundaries in the process, and they still get access to internal resources with the thick app where necessary, or with the browser apps. So, all those same mechanics live in and outside the browser, so it's one seamless workspace that that cooperates. And as I mentioned a minute ago, it is a platform, 'cause you'll build one policy and it'll operate inside and outside the browser. You're not having to build 10 different policies. Oh, the policies for outside the browser are gonna be these, the network mechanics have to be these, the digital experience has to be this. Oh, that's different than the browser. No, it's all one set of policies, one set of capabilities in and outside.
KB [00:32:15]:
And would you say, 'cause you're right, now that if we look at the average sort of workload, people are gonna do stuff in the browser, but then also running like desktop programs with codecs, Claude, would you say that companies are now starting to get ahead of this conversation? Because it's been hard before because there's so many things that have changed and they're trying to like keep their head above the water. But if we look purely just at the how people are working each day, it would make sense that that would be the next sort of problem to solve. Would you say that companies are very focused on what does this look like for them from securing it to making sure that people are doing things safely within the guardrails, within the policies?
Bradon Rogers [00:32:51]:
Yeah, they're living in both worlds right now. So they're living in the world of the prior stuff we talked about, like eliminating VDIs and SASE universe and things like that as well. And then, you know, they're over here wrestling with this whole universe of AI and what does it mean for them, both inside and outside the browser, to your point, things like Codex and Claude desktop and things like that. And there are some new workflows that are brought forth by these technologies that your status quo tech that have been in existence for years, they have no means to address them very effectively. I'll use a perfect example. You know, if you think about engaging AI and understanding intent with AI, you're going to spin up an agent, you're going to bring up Claude Desktop, you may launch Claude Cowork, Claude Code, tell Claude Code to build an agent for you. It's going to build the agent framework and it's going to build a lot of the mechanics that live locally in the machine. You're not going to sit in the network and watch packets flying by and actually learn the intent.
Bradon Rogers [00:33:42]:
You're not going to be able to orchestrate to the appropriate model at the right time based on context. Again, status quo of technologies that might look at packets on a network, it's going to give you a limited view on that process. Status quo of technologies that look at identity, well, that's great. There's going to be agentic identities in the future where agents have agentic identities, but you're going to have, if it's not tied into an app or service, not tied into your corporate identity provider, you're not going to have visibility into the identity of it. And you're certainly not going to have access to the things that are being engaged, the types of data and stuff. That's not what identity providers do. You're going to, if you look at things like your existing CASB technologies and things like that, just again, I can go down the list over and over again. And you can answer the question of why they're not really well suited for the modern problems of a universe of AI running locally on the machine, running in the browser itself, running with MCPs, et cetera, in the process.
Bradon Rogers [00:34:32]:
So there's just a lot of different flows and mechanics that are occurring, and they're all occurring all at once. So it's not like, you know, when you do a prompt and build an agent, it just goes and does a network call. It might actually do some stuff locally in the machine too, simultaneously. It might need to engage an internal set of applications or MCP services. So it needs private access simultaneously. It may need a credential to access a key application inside the environment. So privileged access may need to be woven into that fabric. So I bring all that up because gone are the days where I can build a policy over here in this network technology and then go build a policy in my endpoint technology and they live separately from each other.
Bradon Rogers [00:35:07]:
And then I've got to build a policy over here in some other part of my environment that's separate. that has different visibility and control. They have to be one fabric that's working together. That's a whole world of the agentic platform that's super, super important for the future.
KB [00:35:18]:
So then what's your take on, would you say browser security is solving a permanent problem or a transition problem while like SaaS and AI platforms sort of mature?
Bradon Rogers [00:35:29]:
It's probably a little bit of both. I think there's certainly parts of our universe that will move further and further away from using traditional interfaces. They'll use agentic-type interfaces for engaging and building and doing things. There's certainly a world of applications and services that will still exist for our end users in the process. I think about it this way, look at the vibe coding tools. If you've done any work with Lovable or Cursor or Claude Code, they're building applications with interfaces in many cases. And, you know, those apps are being used by somebody in the process. It's going to wind up being a hybrid world.
Bradon Rogers [00:36:04]:
Where, you know, the users don't go away tomorrow. The users keep working, and the user's going to engage, you know, things in their browser. They're going to engage things outside of the browser. And you have to be equipped to live in both places simultaneously and not have to build 30 policies to handle this corner case here and this one over here. It's got to be one seamless thing for both the user and the agent in the process. And that's really, really super important that foundation exists as you start moving forward in that path.
KB [00:36:26]:
So, Brandon, final question. I know we've spoken a lot about browsers and VPNs and where it's headed. But what do you sort of think now for the rest of 2026, next year? What can we start to see given your experience in the field?
Bradon Rogers [00:36:40]:
I want to give you a very deliberate answer on that one, by the way.
KB [00:36:42]:
Sure.
Bradon Rogers [00:36:42]:
I've hammered the agentic stuff, but I think we live in a weird, interesting transitionary time where the users themselves, and again, every org's in a different part of their journey. Some users are, their usage of AI is a chat window, and that may be where they're stuck. They may not be able to go further than that or may not need to. Some users now are taking these AI resources and they're building human-assisted agents where they're spinning their own agents up to help them with their own work. Some parts of the organization are taking the agentic universe and spinning it up so they can spin up agents to help entire parts of the organization. And again, in the agentic universe we're in right now, that's generally user-generated. And a lot of times agents share user identity in that process. But over the coming year, you will start seeing now the world of agents that will have their own identity.
Bradon Rogers [00:37:28]:
So you'll see non-human identities in the process. You'll see agents wandering on machines and then network resources and other stuff accomplishing tasks. And in the future world, you'll start seeing agents figuring out things they need to go solve on their own. And they may not be assisted by a human in some cases. In some cases, they'll maybe be prompted for human intervention. So, and you know, you see this whole conversation around, you know, what a lot of the world's deeming as agentic engineers, where people that just They turn into shepherds for the agents as they engage the environment. So that's really going to be an interesting flow of the next year or 2 years. You know, this whole world of the agentic engineer, a lot of people become in their jobs and agentic engineers, by the way, won't just be people that write code.
Bradon Rogers [00:38:08]:
Agentic engineers will be people that sometimes they're developers, sometimes they're lawyers, lawyers that build agents and they just shepherd over the agents doing jobs in the universal legal. Sometimes they'll be people in the medical community. So they won't always be tech either.
KB [00:38:22]:
That was Bradon Rogers, everybody. The idea that I just keep turning over and over from that conversation is that the tools we've trusted for visibility are blind by the laws of physics, while the browser we all ignored might be the only piece left with full fidelity. If you're sitting on a board or leading a company, here's one question worth taking to your next security meeting. Where does our work actually happen? And can we see it there?
VO: I read every reply. If you've got some thoughts on this one, send me a message on LinkedIn.
KBKast - Cyber for The C-Suite.