
Bradon Rogers, Chief Customer Officer at Island, the company that created the enterprise browser category in 2020, joins KB to unpack why the industry spent two decades bolting security around the browser instead of building it in. They dig into whether organisations are solving complexity or just relocating it, why VPNs and VDI survived so long when everybody hated them, and Bradon’s blunt read on SASE: legacy on-prem architecture shoved into the cloud. He explains why SSL inspection leaves blind spots the laws of physics won’t let you close, what zero trust misses after access is granted, and how data boundaries keep company information out of personal AI tenants without turning security into the say no police. Bradon closes with his prediction for the next two years: non-human identities, agents working without human hands on the wheel, and agentic engineers who won’t just be developers but lawyers and doctors shepherding agents through their work. About Bradon: Bradon Rogers is...
Loading summary
A
There's so many blind spots and this is the thing people don't want to talk about. You start thinking about if you're dependent on breaking open SSL traffic to get visibility, you're not breaking all the traffic. You can't see inside of all of it. It's not possible.
B
From KBI Media, I'm Carissa Breen and this is KBCast. My guest today is Braden Rogers, chief customer officer at island, the company that created the enterprise browser category back in 2020. We talk about whether 20 years of security spending, solve comple or just moved it somewhere more expensive. Yzero Trust tends to stop at the login right where the real risk starts. And the question nobody can answer yet is what happens to all of this when the agents start working without us? Before we get into it, do me a favor and hit follow wherever you're listening. It genuinely helps the show reach more people who need to hear these conversations. Alrighty, let's get into it.
C
Okay, so, Brayden, I really want to start with our organization. Solving complexity or just moving complexity into another control layer. And I know that's a very broad question, but I asked that because given the time that we're in, there's a lot of stuff going on and it seems, and the people I'm interviewing, like yourself each week, that the complexity, the threat landscape's obviously growing and there's a lot of stuff going on here. But I really want to get your view, bit of a lay of the land to start there first.
A
Well, thank you for having me, first of all. Appreciate it. Nice to be with you, kb. I do think people are trying to solve for complexity. They've introduced for years just layers of technology around each one of the use cases they've introduced in their environment. So you can think of it, let's pick an org solving byod, for example. They'll evaluate a stack of technologies. They will evaluate processes that fit around a BYO program that is quote unquote viable for them and they'll stand that up. And it's months and months of work for that. And another initiative comes along like a merger and acquisition or call center standing up a third party call center potentially. They may stand up a different stack of technology, may stand up some VDI infrastructure for that. Totally different evaluation of the stack of technologies for that the prior set of technologies didn't really apply. And they wind up building complexity through the environment. So they wind up with 4, 5, 6 different architectures for different parts of their organization. So a lot of organizations are trying to find a way to reduce that. And I see in a lot of different technology spaces where it was yesterday's approach to solving a problem, and it introduced a lot of complexity because it wasn't woven into the fabric of the user experience itself. In fact, a lot of times it didn't consider the user themselves. So that complexity thing is certainly a burden for the IT practitioners, for folks in cybersecurity simultaneously and then on, you know, the kind of forgotten third party here is their end users in the process. So everybody kind of feels the pain, takes a bite of that sandwich.
C
And do you also think, given your role, like, what's happening, like each week things seem to change, like in the news, in the media, when I'm interviewing someone like yourself, that there's a big topic that everyone's focused on, then they're not focused on it. And I've seen that in terms of the volatility and just the velocity of how things change in terms of priorities, what's important day to day, week to week, it's. I just see it changing quite considerably. And then I guess as a result of that, it means that it is increasing the complexity of how things are, because people are sort of ditching one thing to then start something else because they've got to, of course, chase what's happening in the space. But these things don't necessarily just go away. If you close your eyes, for example.
A
Yeah, I, I do, I do see some of that. I think certainly the universe of AI that's introduced kind of that problem on steroids maybe to some extent. You know, it's the fastest changing landscape that we've ever encountered. You look at a lot of the providers, the core Frontier labs, they introduce new capabilities literally almost on a daily basis. And sometimes those capabilities introduce, affect an entire stack of technologies that the org has in place today. They attack, you know, attack a whole space of vendors that organizations invest in. Now orgs have to question, do I solve that with my AI provider over here, or do the stack of technologies actually hold up under the duress of people actually using AI in the process? I do believe that's creating a lot of complexity for organizations, try to wrap their hands around it. Every org's in a different part of their journey in that as well. So some orgs are just trying to lasso the basics of it, like, put the hands around how are users using it? Like, what are they wanting to use? What's the most effective use of that in our organization? So some orgs have AI steering committees where they Brought a bunch of different personalities to the table from different parts of the org. Some orgs have gotten really mature in the process, and they've created chief AI officers in the process as well. But I do believe that traditional problem that you're calling out is now put on steroids with regard to the movement of AI in the organizations and how organizations are trying to find a way to. To get positive benefit from that without, you know, absolutely blowing the budget out of the water that we're kind of constantly hearing about right now, as well as concern around spend. So.
C
So the main sort of theme we're going to talk about today is browser security. But before we get into some of the nuanced pieces around that, do you think browsers is something that people don't. It just gets a little bit relegated. What I mean is like, even to connect it on the interview, it says, okay, we're going to go in the browser. We're not thinking really about the security then around it, because the thing just seems to work. But we've got other things that we should be focusing on, like applications, et cetera. Would you say where you sit and what you've seen in your career, it is this something that people seem to forget about and then becomes a problem now, but then also down the line and it grows because the thing just kind of works.
A
A great question. I do believe that the browser is kind of the forgotten entity in the organization. I don't think people see the browser as a problem. I just don't think they see it as an assistive vehicle for them. They think that it, like you said, it does what it does. If you think about the browser that we all use every single day, you know, as end users, the browser's job is to, you know, reach out, grab content, and then put content in front of my eyes as an end user, and in many cases pour content down to the desktop. So this is why we put a bunch of things around that experience. A lot of times we'll put, you know, an agent on the host, a DLP agent, the data, or we'll steer the traffic of that browser back through some cloud entity, some SASE provider, and we'll have to break open ssl, introduce all kinds of other complexity, we'll backhaul, et cetera. But the core of that is not that the browser is. The problem is that the browser wasn't a cooperative member of the real estate in the first place. But what if we could take the browser and actually make it be a functionally cooperative part of Our policy and our governance could that change how we approach many of the common problems? And that's what we found when we do rollouts in our world at island with the enterprise browser is once you have the mechanics and the instrumentation in the browser itself starts causing you to question do I need to deliver the solutions of the past to solve these problems in the same way anymore? Do I need to break and inspect SSL? Like that's a problem from 20 years ago and we continued propagating that problem and we get more and more blind spots when we try to do that. Do I need to backhaul traffic? Do I need to shift that back through cloud proxy somewhere? And you know, for SaaS based applications, users are going to so but when you, once you make it a cooperative member of the real estate, you start reimagining the fundamental architectures with how you support the Org. And then back to the original question you asked about complexity. You start eliminating the complexity because the same architecture using to solve problem A turn around and it actually solves problem B2 and problem C and problem D and it gets, it gets to be an exceptionally powerful part of the overall environment for the organ and does become the ultimate architecture at the end of a much simpler architecture with a lot, without a lot of the burdens of the past, like no streaming pixels, no breaking in spec, no backhaul. All that stuff that we've seen from VDI SASE providers and things like that.
C
And on that note, would you also say just like browser or browser security, the browser it's just, it's just become less obvious of a risk perhaps as well like other things seem to take precedent, we hear more about it, etc. Like, you know, I've conducted so many interviews on this podcast. I've only think maybe once I've spoken to someone else about browser security in that duration. So it's just not something that we often hear about. So I'm just curious really to understand is it because it doesn't seem obvious for people? I mean there's things that are obvious, we don't pay attention to it and so forth.
A
Well, I don't think many organizations have a, an initiative that is a secure browser project now. And the reason is they don't see the browser as the weak spot in the organization. They just see it as not a cooperative member of the real estate as we talked about a moment ago. So they go evaluate the things I got to put around that experience. But you know, very few organizations are looking at it and going, you know, What I got to fix this weak browser that's been produced by all these consumer companies and wrap some terrible experience around that. Nobody's looking at that as the problem. They're looking at the problem and going, I've got to protect data, you know, make sure data doesn't leak in my organization. I got to keep my users safe from wandering in different places. So that's why they do the bolt on things we talked about a moment ago. You know, we believe that there's just an immense amount of potential that has been corked up in that browser interface for many years, one which the users already know very well. The users have a lot of experience using browsers. They've been trained on them for years, just inherently trained. And the result is, if we can unpack that kinetic potential in the existing browser, it does let us start reducing all the complexity and a lot of the pain. But I think to the point you're making is it's, you know, I wouldn't say the browser's been an oversight, but everybody sees the browsers doing what it was designed to do, which was to fetch content for me and let me interact with content. But do we see the browser as a part of my security surface, to be a part of that? Real estate can be helpful for me? No, Nobody ever viewed it that way. And that's why the enterprise browser has been such an amazing thing for the orgs that have adopted it.
C
You mentioned before, like users, as we know, like users hate friction. And then as soon as there's friction, even more so nowadays, because everyone wants to do things faster, cheaper, better, whatever, you know, so they can put their feet up on Friday and watch beer, have beers with their buddies and do whatever. So do you think as well, perhaps companies have thought, look, the browser is doing what we kind of want it to do, but we don't want to introduce too much friction. Because there's friction, there's workarounds, all sorts of problems start happening elsewhere. You're trying to solve one problem, another one opens up. So do you think there is a lot of that based on, like you said, it's doing what it says it's doing on the packet and that's it. We don't need to explore more into it.
A
Well, if you think about all the things we bolted around it, we made the user's life hard. We put the user through unnecessary hurdles, and we didn't put natural interfaces in front of them to make their life easy when they want to access an internal application. Well, historically speaking, we would Force them to launch a VPN client. Well, your average user isn't a network expert, you know, and that's another client they got to deal with. And that's an example sometimes then we force them to launch a VDI client in that process and they get yet one more unfamiliar experience. And then sometimes we'll put a browser inside of that VDI infrastructure and they'll launch a browser through all those mechanics. We believe that there's a lot of those things that can be reduced and eliminate end user friction, make the end user's job easier. It's really important as well, is you think about the world of cyber. For years the cyber folks have gotten a lot of, lot of bad press from being the say no police. They get in the way the friction that cyber causes. That doesn't need to be the case. What if, you know, cyber could an assistive part of giving people what they need to be able to do their jobs and more. What if we could let users use any AI of choice in the environment without the risk of company data being exposed or you know, let into financial services that users access personal Gmail or you know, in this new agentic universe, start unleashing the world of the agentic workflows for my workforce without having to worry about what happens in that flow. Make sure we create the appropriate productivity and protective nature of how we want agents to be adopted so we can get a good understanding of how they're being used in the first place in the environment. So that, you know, it's a really perfect journey for making the user's life easier and giving them access and reducing friction for the user. But it's also a good vehicle for starting to reduce the friction as org start moving to this whole agentic universe in and outside of the browser. That's a really important part of this conversation because the work that needs to be done around the the agentic workspace is not just a browser centric workspace. It's stuff that lives locally on the desktop, stuff that lives inside of your applications that are in your SaaS based apps and your private apps. And so the workspace for the end user extends many of those core capabilities over to the agent, which is a big foundational part of what we've been delivering for many years at Iowan. It's not just in the browser, it's things outside of the browser to empower that agentic world.
C
You're raising a point around VPN vdis. So even let's look at that for a moment. People would then Say complain, they get slower. I can't even connect to it. And therefore we use a VPN when we're outside of our work perimeter, but it doesn't even work anyway, so therefore I have to go all the way back into the office to do the work I was supposed to do. So we've sort of again created the friction of trying to do, like you said, these bolt on trying to do the right thing, but then as a result it's made things slower. People can't do their job as efficiently and as a result they just don't do it or then run things on their personal laptop because it's faster. Talk to me a little bit more about that journey because there's still a lot of companies out there, as you would know, that are still run in
A
VPNs a thousand percent. We see them all over the place. And some orgs, these massive global orgs, they have multiple VPN providers and you know, the good thing is they already know the pains of those. I'd say a lot of organizations with VPNs are moving down the path of trying to find alternate vehicles. Zero trust network access vehicles that give seamless access to internal apps without the need to launch a VPN client. And a big part of that's functionally part of the world that we built within the enterprise browser is just that's it's foundational, seamless access to private applications being built in without the need for a VPN client. And then, you know, you've got the obvious risks once you've got VPN ports exposed. You know, there's obviously the concerns that people take stolen credentials. You know, they leverage stolen credentials and use the VPN as one of the conduits because it doesn't take much to scan the front end of an organization to find open VPN ports and bang away on those. You know, when you leverage a zero trust network access approach, you're using contacts to drive the access with no exposed ports in the process. So. And then again, one of the key things is you're not steering all the traffic for the internal resources back on prem, you're steering it for the things that need to go on prem to the resource that's necessary and that'll be really important. Again, I go back to the AI conversation, because AI doesn't just exist locally on the host or just in your SaaS apps. Your internal universe needs to be a part of your AI framework, needs to be part of the foundation of how you empower the agentic universe and giving seamless access to the agents based on context is a really, really important part of this. So. So it serves a nice spectrum from the end user all the way to the agents in that process for the internal needs. And again, getting rid of that VPN stuff in the process is always a big plus.
C
So I want to know if the major browser and platform vendors, for example, build more of a native enterprise controls, does this become like a standalone category now or was it more like a feature set? Considering just what we're sort of talking about again, even with people running agents locally on their machines, et cetera, it's getting away now from the browser, et cetera.
A
I would argue that it's a category now and I'd say that because not only is there the universe of what we're doing at island, but there's players across the space that are doing things with browsers and with alternate form factors of extensions. We have both, so we have a browser and an extension form factor so that can live in your existing browser. But this whole category, as you know, that we created back in 2020, has given rise to a whole series of different players taking this, taking different problems and solving from different angles. Some are taking the angle that you talked about earlier is let's harden that browser, let's make it a safer browser to operate in. We believe that's important by the way, making the environment safe. So my language earlier is not misinterpreted that we don't think it should be important to operate in a safe place. That's why we deliver a full browser for this really ultra sensitive environments that need a hardened way of working. But we do believe there's a category that's in existence today, your existing browsers. Again there's a little bit of tear on those things because they're torn between the consumer revenue that drives their, their viability. They're making money on targeted advertising and search and there's billions of dollars behind that. A heavy pivot to the enterprise is probably not in some folks best interest. So, so, but there are some, some things that you can do in your existing browsers, but again bolted on with an extension on top of that. Like our extension is a good example, is a great starting point for that. But yeah, I firmly believe there's a very thriving category simply just based on the massive organizations that are now doing this at scale.
C
And you also just go back to the VPN stuff for a moment, do you? Are we going to start seeing massive migration? Because this is just the way of the world now and What I'm hearing a lot in interviews is people saying, hey, companies, big enterprises that are so entrenched of 50, 100 years, they are moving faster now because they know that they don't do something, the competitors are obviously going to beat them. But then also they have major risks that they're carrying. So we go, are we going to start to see people like, effectively not this lift and shift, but also their mindset towards this? Because my question is this has been a problem then for a while, but then people sort of just weren't doing anything or moving. But is it just. There's the catalyst there. Companies know they need to evolve, they need to be a little bit more modern and their backs up against the wall a little bit on this, a thousand percent.
A
There's the thought process that recognizes these are legacy approaches. And in many cases they were stuck because there wasn't a better alternative. So I'll use perfect example vdi. What was your better, what was your better answer? You had to put an app in the hand of an end user, call center worker, one of your own employees, et cetera. And you had to do that in a way where you could contain things. And what was the best option? Well, string the pixels, make sure that data stays where it needs to stay behind in that VDI universe. And in the process, yeah, everybody's going to suffer a little bit. The budget holders suffer, the people architecturally that are having to deliver it have to suffer through a lot of pain. And the end users, like we mentioned earlier, they really suffer. But that's a good example of something that just wasn't a better alternative in a lot of cases. You think about the SASE universe, that's a modern approach in some people's eyes, but we took the legacy on PREM architecture and we just shoved that up into the cloud and then we started back hauling traffic for users through that pinch point. Again, there wasn't a better alternative in a lot of ways. And we view the world of what we've done with the enterprise browser and again, this whole category as being something that transforms many of those things, where all those things from the past are gone. So now there is an option. And I think that's the key for this. Back to your question is it gives people optionality in a lot of different areas. If you want to reduce that VPN footprint, gives you an option in that front where you can reduce or eliminate it. You want to get rid of that VDI infrastructure, great. There's an option where you can run the apps locally outside the browser and have them be a cooperative part of the fabric of protecting the applications and giving network connectivity where necessary. If you need an alternate path for, you know, how we manage passwords and password management, privileged access management, there's alternatives in that. So it just provides a lot of different doorways for things that people didn't have in the past as starting points for the problems they have. And that's why the starting point sometimes is quite diverse with customers that we begin to work with as well.
C
So you said there were just no other options, which makes sense. So then what was coming to my mind as you were speaking, Brayden, would be, do you think companies have just spent all this time on, like, cloud and network, all this sort of stuff?
B
But it's like, actually, if we look
C
back to a user in our company, what are. Where's the place of work? It's in the browser. I know for myself, I run Gmail. It's in a browser. I'm running. I'm talking to you. It's in a browser. Social media stuff's in a browser. Canvas in a browser. So it just feels as if, like, it's very obvious that's where people are conducting their work each day in a browser. Why have there's been so much emphasis? And I know it's hard because each person I talk to, you know, cloud security, we talk about all these things and I understand that, but it just seems that when we look at how people in our company are performing the work, that's a very good starting point in terms of, hey, we should be very focused on this because this is where Chris Verina is doing our work each day.
A
Yeah, a thousand percent. So the majority of a user's work does happen in the browser. And a lot of the beginning points of AI, the AI journey for organizations, starts in the browser. It doesn't finish in the browser. Just like the user's work doesn't all happen in the browser. We still use Microsoft clients outside the browser. We use things like ChatGPT inside the browser and outside the browser. And obviously the Claude universe is in a variety of different places. But, yeah, I think that, you know, part of this was, you know, the art of the possible hadn't been uncorked. Uh, there was no motivation for a lot of the browser creators to take a path like this. And it just, it took a spark. And I think the reality is that, you know, we believe at island, we created that spark. And then a lot of others have joined suit in the process as well. And, you know, there's certainly the, the concern about, you know, the organizational change management and the we're going to pull our users browsers out of their hands and no, you don't have to do that. You know, when you think about this journey, it's a crawl, walk, run, cut strategy. So you may put an extension in the existing browser for a while and gain control that way on your managed devices or get visibility. There may be situations where a full browser may be called for in a given situation, but you have those optionalities in that process. And there may be certain audiences that need this for certain applications, but not other apps. They keep using their browser of choice for personal and non critical work. So there's a lot of different ways to go about adopting this, but in much the same way, you know, let's say 20 plus years ago when VDI came along, a lot of organizations today have mass, I mean huge VDI footprints. It didn't start that way. It started with a subtle few areas of the problems they faced and it began to creep across the organization into areas that turned into something that was much larger than originally either was intended or originally started. So we believe that again, the enterprise browser can start that way for a lot of organizations and solve a specific use case, doesn't have to tackle everything for all users and there's some great resources and strategies for change management that doesn't freak your end users out. And by the way, one little side note, once the end users wind up seeing it, they realize it looks just like the browser they already know and the user panic goes away about change management in that process. Anyway, we see that over and over again.
B
We'll come back to that after a quick word from our sponsor. For remote first, companies, maintaining a strong security posture across distributed teams can be a challenge. That's why thousands of modern remote friendly firms turn to Vanta. Vanta automates the heavy lifting for ISO 27001 SoC2GDPR and more, keeping you compliant and audit ready wherever your team logs in from. Visit vanta.comkbcast v-a n t a.com kbcast to learn more.
C
So after we heard about all the VPN stuff, then came the Zero Trust. Remember, even maybe six years ago, that's all I heard about. I'm then curious, would you say let's talk about zero Trust. It just sort of ends too early though. What happens after the access is granted? Like what's the user doing then? How to. There's no way of governing it then. So would you say that perhaps it's not obsolete, but it's sort of what happens after that. Then like am I copied something and then what I'm, what am I doing as a user? Am I a rogue user? What's happening there? So does that whole function about zero trust become not as secure then?
A
A great question. So if you think about a zero trust philosophy, I'm not going to get too deep into this, but the whole philosophical approach to zero trust is not a point in time type thing. It's not an authentication. You have access and then nothing else gets assessed. It is continuous. There's contextually driven. So context things like identity and device awareness and geolocation and network that you're on and all these contextual clues come together to form the basis of continually assessing engagement so that the appropriate policy gets applied. And that's exactly what you do in an enterprise browser. You know, the first thing you do is you log in. You log in using your single sign on provider. You'll multi factor in that process. And based on all this contextual clues I mentioned a moment ago, the appropriate access is granted, but that doesn't mean it stops there. You get access and now it's all done. You know, woven into the fabric are all the vehicles to protect the data in the applications continuously. If context changes, if a user, you know, tampers with the device or someone tampers with the device and it no longer meets our posture, you know, it instantly adapts to that and says all right, you know what, we just deprecated some access in this process because it's not living up to the standard we expect. So for us access is just the starting point. You know, once you get access to the applications, obviously that's got to be easy for the end users. It's natural in our world because they already know how to use a browser. But once they now have access to the key applications to do their job, you know, the continuous process of using mechanics inside of the browser itself with policy and audit in that process to keep the experience safe and drive dynamic adaptation around the given environment that is operating in. That's fundamental, that's just foundational to the concepts of zero trust as a general philosophy.
C
And I definitely know it's continuous, it's just more like what was maybe an example would be I've authenticated, everything looks fine. I work in finance. I need to get a high level summary of the report my boss sent me. I'm just going to feed it in now to chat GBT and see what it spits out. There's no way like from a zero trust perspective, that of governing that and then that gets leads to your earlier point around like dlp. Well that would be a problem then because I've just now put into, you know, OpenAI system, well, sensitive information about my company earnings for the year that no one knows about. And I've just fed it through there because I need to summarize it. So it's more like that is the part that I find really interesting because Zero trust may ask me in like an hour, hey, you're sort of doing something that's unusual, but it still doesn't prevent the issue that I've just fed something through to get an answer because it was the easiest option.
A
Yeah, a thousand percent. So the one of the most important things is organizations have sanctioned environments. And especially in today's AI universe, using your example before, most orgs have some level of sanctioned AI usage, whether it's co pilots, part of their Microsoft agreements, they've done explicit agreements with anthropic or with OpenAI or others. In the process they put their foot into the water with AI in some way or another big foundational part of zero trust, but also into the world of what we do in the enterprise browser is recognizing tenancy, recognizing the applications, recognizing this is our corporate application or a personal app. So being able to identify is this the corporate cloud environment we're engaging or is this someone's personal cloud environment? Well, if they're engaging, if they decide to engage Claude, we can steer them to the corporate environment and that way they can do those movements that you're talking about. But if all of a sudden they're in the personal universe, they switched over to the personal tenant. All the markers on the screen and a lot of the markers that would be seen in a network would tell you that that's the corporate environment and can't distinguish corporate versus personal. And a really important part of our universe is a concept around this creation of what we call an application or data boundary. Just lets the user have the freedom of movement within the boundary of the corporate apps and tenants so that the company data doesn't spill to places like you're talking about in your example there. The things are outside of our control. It doesn't mean we want to inspect content in the boundary. So if you pull data that sensitive data over into a a sanctioned AI universe, I may not want it ingesting certain data. For example, if I'm on a merger and acquisition team, I may not want my AI, my, my agents or my chat universe ingesting Data from deal rooms, we're doing, we're doing due diligence on inside of merger and acquisition deal rooms because it's too soon. We're not ready to ingest that data yet. So you can have the ability to make the boundaries exclude certain applications, even though the user has access to those things. But you can also say, I don't want this content bleeding over into those worlds as well. So we get perfect control, perfect fidelity. The most important part of this is, and this is one of the most dangerous parts of cyber right now is there's so many blind spots. And this the thing people don't want to talk about. You start thinking about, if you're dependent on breaking open SSL traffic to get visibility, you're not breaking all the traffic. You can't see inside of all of it. It's not possible. There are laws of physics that make that not possible. Things like certificate pinning and advanced cipher suites and the whole world of post quantum ciphers. The good thing about what I was talking about a moment ago is if data is going beyond the boundary to personal or to something sanctioned, we get complete fidelity because we're not having to fight SSL traffic in that process. So there are no blind spots. So for us, I think that's a really wonderful answer for organizations that are worried about this future of AI, the things that it's consuming and making sure that AI is consuming the things that we want to consume. And still while by the way, in that example, I gave a moment ago, I may give the user access to the deal room, but I don't want the agent having access to the deal room that the user may employ. So it gives me the ability to win on both sides of the fence in that, in that question.
C
And would you say, I know you said before that companies have got like these sanctioned environments, but would you say this is something that organizations that you're talking to out in the market that they're starting to then think about? Because some of these use cases have changed. Like even before 2022, we didn't have that capability to be like, oh, I'm just going to open up OpenAI and ask it a question and it's going to give me summaries because I was a reporting analyst, so I kind of wish had that back in the day. And I know it's hard to answer because there's no real blueprint. We're discovering things as we go and new things pop up. But when we're talking about an everyday user and what they're probably likely to do or not do. And the result of that, what was that guy in the US government earlier this year that accidentally, you know, uploaded something to open AI and he got pinged for it?
B
Of course.
C
But I mean that's a government person that's doing it. So imagine the everyday person in a big enterprise that may not be aware of what they're doing. Just more looking at that then from a use case point of view. But then also the ramifications then of that. Like you said, there's an M and A stuff going on and all of a sudden the whole deal falls through because information's been leaked.
A
Yeah, that boundary thing I discussed a moment ago is incredibly important for that because the end user themselves, because by controlling the presentation of the apps which you control in the browser, that's what you're controlling, the actual presentation. I could say, you know what, when the user goes to chat gbd, let's make sure they're going to the company tenant. So because the example you're using, especially several years ago, before there were guardrails around, a lot of this people would take company data like the example you used a moment ago and spill that right into some uncontrolled AI universe. And that, you know, the users are interested intellectually in AI. It's interesting, it speaks their native tongue. So in the process it's easily accessible. Why not use it? Because it can make me more effective at my job. But it's on. It's incumbent upon the organization to provide outlets for the user to be able to leverage that stuff at the right time and to have mechanics that can steer them effectively to the right things at the right time, while also by the way, simultaneously not having a big sledgehammer to say no to all the stuff that maybe the user wants to approach. But you know, for example, I may want a user to let them access cloud resources, but it may not be our sanctioned resource or our company data won't spill over the boundary in the process. The user still gets access to the cloud universe in the process and they're not fighting my cybersecurity controls at every turn. So there are ways for both sides to win in that process where there, there's a. It doesn't have to be the difficult trade offs of the past. The boundary thing is one of the most important starting points for that. I say that only because if you think about the way we had to protect data for years, we were constantly carrying and feeding for DLP and it is this nonstop washing machine. It's A washing machine stuck on spin cycle, you never get out of it. And in the world of the boundary, that's the top level data protection element and then you inspect content within it. So you're doing a lot less carry and feeding in the process as well.
C
And why would you say Brayden, the browser can't control even in the best case sort of architecture? Is there any sort of talk me through, what does that look like in your eyes?
A
Yeah. So browsers naturally don't control thick applications, the things that live outside of the browser. That's why we spent a lot of time over the past several years building a complete platform. And we don't use that word platform lightly. Like you hear that word been misused in the industry a lot. When you literally build one policy in our universe of management and that policy lives in and outside the browser, we have something called Island Desktop. So Island Desktop is a persistent service that lives on the host. When you install our browser, it can install the service. And this service gives the ability for our same set of mechanics to live in the browser, to live outside of the browser for specific applications and services that are local to the device. Again, that's advantageous for legacy clients with the orgs trying to get off VDI and things like that give the user a local experience. And in the modern world of the modern AI, usage is very advantageous for people using things like Claude Desktop and other types of AI services locally in the machine, because those same set of resources live in and outside the browser and give the user. The user doesn't feel the borders or the boundaries in the process and they still get access to internal resources with the thick app where necessary, or with the browser apps. So all those same mechanics live in and outside the browser. So it's one seamless workspace that that cooperates. And as I mentioned a minute ago, it is a platform because you'll build one policy and it'll operate in, inside and outside the browser. You're not having to build 10 different policies. Oh, the policies for outside the browser are going to be these. The network mechanics have to be these. The digital experience has to be this. Oh, that's different than the browser. No, it's all one set of policies, one set of capabilities in and outside.
C
And would you say, because you're right now, that if we look at the average sort of workload, people are going to do stuff in the browser, but then also running like desktop programs with codecs. Claude, would you say that companies are now starting to get ahead of this conversation because it's been hard before because there's so many things that have changed and they're trying to like, keep their head above the water. But if we look purely just at the how people are working each day, it would make sense that that would be the next sort of problem to solve. Would you say that companies are very focused on what does this look like for them, from securing it to making sure that people are doing things safely within the guardrails, within the policies?
A
Yeah, they're living in both worlds right now. So they're living in the world of the prior stuff we talked about, like eliminating VDIS and SASE universe and things like that as well. And then, you know, they're over here wrestling with this whole universe of AI and what does it mean for them both in inside and outside the browser? To your point, things like codecs and Claude Desktop and things like that. And there are some new workflows that are brought forth by these technologies that your status quo of tech that have been in existence for years, they have no means to address them very effectively. I'll use a perfect example. You know, if you think about engaging AI and understanding intent with AI, you're going to spin up an agent, you're going to bring up Claude desktop, you may launch Claud Cowork, Claude Code, tell Claude code to build an agent for you. It's going to build the agent framework and it's going to build a lot of the mechanics that live locally in the machine. You're not going to sit in the network and watch packets flying by and actually learn the intent. You're not going to be able to, you know, orchestrate to the appropriate model at the right time based on context. Again, status quo of technologies that might look at packets on a network and it's going to give you a limited view on that process. Status quo of technologies that look at identity. Well, that's great. There's going to be agentic identities in the futures where agents have agentic identities, but you're going to have. If it's not tied into an app or service, not tied into your, your corporate identity provider, you're not going to have visibility into the identity of it. And you're certainly not have access to the things that are being engaged, the types of data and stuff. That's not what identity providers do. You're going to. If you look at things like your existing CASB technologies and things like that just again, I can go down the list over and over again and you can answer the question of why they're not really well suited for the modern problems of a universe of AI running locally on the machine, running in the browser itself, running with mcps, et cetera, in the process. So there's just a lot of different flows and mechanics that are occurring, and they're all occurring all at once. So it's not like, you know, when you do a prompt and build an agent, it just goes and does a network call. It might actually do some stuff locally in the machine too. Simultaneously. It might. It might need to engage an internal set of applications, MCP services. So it needs private access simultaneously. It may need a credential to access a key application inside the environmental privilege. Access maybe need to be woven into that fabric. So I bring all that up because gone are the days where I can build a policy over here in this network technology and then go build a policy on my endpoint technology, and they live separately from each other, and then I've got to build a policy over here in some other part of my environment that's separate, that has different visibility and control. They have to be one fabric that's working together. That's a whole world of the agentic platform that's super, super important for the future.
C
So then, what's your take on. Would you say browser security is solving a permanent problem or a transition problem, while, like SaaS and AI platforms sort of mature?
A
It's probably a little bit of both, I think. There's certainly parts of our universe that will move further and further away from using traditional interfaces. They'll use agentic type interfaces for engaging and building and doing things. There's certainly a world of applications and services that will still exist for our end users in the process. I think about it this way. Look at the Vibe coding tools. If you've done any work with lovable or Cursor or CLAUDE code, they're building applications with interfaces in many cases, and you know those apps are being used by somebody in the process. It's going to wind up being a hybrid world where the users don't go away tomorrow, the users keep working and the user's gonna engage things in their browser, they're gonna engage things outside of the browser, and you have to be equipped to live in both places simultaneously and not have to build 30 policies to handle this corner case here and this one over here. It's gotta be one seamless thing for both the user and the agent in the process. And that's really, really super important. That foundation exists as you start moving forward in that path.
C
So, Brandon, final question. I know we've spoken a lot about browsers and VPNs and where it's headed, but what do you sort of think now for the rest of 2026 next year? What can we start to see? Given your experience in the field, I
A
want to give you a very deliberate answer on that one, by the way. Sure, I've hammered the, I've hammered the agentic stuff, but I think we live in a weird, interesting transitionary time where the users themselves and again, every org is in a different part of their journey. Some users are, their usage of AI is a chat window and that may be where they're stuck. They may not be able to go further than that or may not need to. Some users now are taking these AI resources and they're building human assisted agents where they're spinning their own agents up to help them with their own work. Some parts of the organization are taking the agentic universe and spinning it up so they can spin up agents to help entire parts of the organization. And again, in the agentic universe we're in right now, that's generally user generated. And a lot of times agents share user identity in that process. But over the coming year you will start seeing now the world of agents that will have their own identity. So you'll see non human identities in the process. You'll see agents wandering on machines and then network resources and other stuff accomplishing tasks. And in the future world you'll start seeing agents figuring out things they need to go solve on their own. And they may not be assisted by a human in some cases, in some cases they'll may be prompted for human intervention. So, and you know, you see this whole conversation around, you know, what a lot of the world's deeming as agentic engineers were people that just, they turn into shepherds for the agents as they engage the environment. So that's really going to be an interesting flow of the next year or two years. You know, this whole world of the agentic engineer a lot of people become in their jobs. And agent engineers, by the way, won't just be people that write code. Agentic engineers will be people that sometimes they're developers, sometimes they're lawyers, lawyers that build agents and they just shepherd over the agents doing jobs in the universal legal. Sometimes there'll be people in the medical community, so they won't always be tech either.
C
That was Braden Rogers, everybody.
B
The idea that I just keep turning over and over from that conversation is that the tools we've trusted for visibility are blind by the laws of physics. While the browser we all ignored might be the only place left with full fidelity. If you're sitting on a board or leading a company, is one question worth taking to your next security meeting? Where does our work actually happen and can we see it there?
C
I read every reply. If you've got some thoughts on this
B
one, send me a message on LinkedIn. Kbcast cyber for the c suite.
KBKAST – Episode 377: Deep Dive with Braden Rogers | The Forgotten Workspace – Why Nobody Ever Secured the Browser
Release Date: July 22, 2026
Host: Carissa Breen (KBI.Media)
Guest: Braden Rogers, Chief Customer Officer at Island
In this strategic-level conversation, host Carissa Breen sits down with Braden Rogers, Chief Customer Officer at Island, the enterprise browser company. Together, they examine a core blind spot in cybersecurity: browsers. While organizations have spent decades layering security around applications, endpoints, and networks, the browser—the locus for much modern work—has remained largely unaddressed. Rogers discusses how this oversight adds unnecessary complexity, sustains risk, and fails to adapt to emerging challenges like AI and agentic workflows. The episode navigates through how the “forgotten workspace” of the browser presents both risk and opportunity for optimising enterprise security and user experience.
[01:05–04:55]
[04:55–08:08]
[09:30–12:18]
[12:18–14:56]
[14:33–16:15]
[16:15–19:38]
[18:59–21:34]
[22:11–25:10]
[25:10–35:18]
[35:18–36:26]
[36:26–38:22]
On the pain of complexity:
“They wind up with 4, 5, 6 different architectures… So everybody kind of feels the pain, takes a bite of that sandwich.” —Braden, [01:30]
On existing browser security gaps:
“The browser wasn’t a cooperative member of the real estate in the first place.” —Braden, [05:34]
On user friction:
“We made the user’s life hard. We put the user through unnecessary hurdles, and we didn’t put natural interfaces in front of them to make their life easy…” —Braden, [10:07]
On Zero Trust limitations:
“The most dangerous parts of cyber right now is there’s so many blind spots. And this is the thing people don’t want to talk about…” —Braden, [25:10]
On browser-centric future:
“Where does our work actually happen and can we see it there?” —Carissa, [38:24]
On the future agentic workforce:
“You’ll see agents wandering on machines and then network resources… In the future world you’ll start seeing agents figuring out things they need to solve on their own.” —Braden, [36:40]
Throughout, the conversation remains strategic, accessible, and focused on big-picture risk and organizational dynamics rather than technical minutiae. Rogers balances urgency (“thousands of blind spots”) with optimism about the new options—especially as AI and agentic workforces become reality.
End of summary