Sponsored by NordLayer
How to secure a hybrid workforce against everyday browsing threats
Here are six safe browsing tips that will keep the remote workspace secure
Ah, the joys of hybrid work. But for all the good it did for work-life balance, hybrid work has wreaked havoc on the IT security perimeter. Virtually every enterprise tool now resides in cloud-based web apps, which makes the browser the new workspace.
It’s also what makes it a big, juicy target for cybercriminals who wait for remote workers to make a careless click or two in an unmanaged browser. So, here are six safe browsing tips (in no particular order) that will keep the remote workspace secure no matter where you open the laptop.
Secure browser access for hybrid and distributed teams
NordLayer Browser helps teams secure access to work apps from any location or device. Give employees and contractors access to the resources they need while keeping browser activity and access policies under IT control.
1. Cut down on session cookie theft
Multi-factor authentication (MFA) is a no-brainer at this point, but it’s not nearly enough. Infostealer malware now focuses heavily on stealing active session cookies, which are the small digital tokens stored in your browser’s memory that keep you logged into various apps without requiring a password every so often.
The situation is bad: about 80% of all MFA bypasses are now executed using stolen session tokens rather than cracked passwords. And if that wasn’t enough, there’s an entire malware-as-a-service (MaaS) scene where developers rent out such software like Lumma Stealer and Vidar to criminals for a fee.
The info-stealing process starts with an infected endpoint, usually when a user is tricked into downloading Trojan software or opening a malicious/weaponized email attachment as the two old-fashioned ways, or by executing a fake browser update prompt in more recent times.
Once an attacker steals a live session cookie, they paste it into their own browser and walk right past your MFA protections. Meanwhile, a technique called tab nabbing silently alters an inactive background tab to mimic a fake login screen while you aren't looking, tricking you into re-entering credentials.
So what can you do? For starters, log out of high-privilege portals when you finish your work. Then, use browsers that automatically isolate session storage, and make it a habit to never leave sensitive admin portals open in the background tabs overnight.
2. Audit and restrict your browser extensions
It’s not a stretch to say that browser extensions are dark horses of endpoint security. From a seemingly benign PDF converter to a deal-finder add-on (and everything in between), there are plenty of permissions you grant with each installation.
Mind you, these are serious privileges we’re talking about - the “read and change all data” variety.
Say a threat actor simply buys an existing extension or goes the roundabout way of compromising its GitHub repository. Overnight, what used to be a quiet little add-on to your workflow transforms into a keylogger or a session-stealing tool that collects your credentials in the background.
This happens far more than most employees think. Just a few months ago, Microsoft took down 119 malicious browser extensions from the Edge Add-ons store that had been downloaded 2.6 million times. And that’s just one recent example.
Hence, it’s vital to take stock of your installed extensions every month or so. A good rule of thumb is to delete anything you haven’t used for more than a couple of months.
Additionally, be vigilant and/or suspicious of the permissions you grant (one of the most underrated safe browsing tips). Some extensions request broad access to read website data across all domains, so be sure to have the IT team vet and approve them before use.
3. Separate browsers and profiles
Hybrid work tends to create a hybrid of its own: mixing personal browsing with work tasks. The core issue here is that personal activity can introduce data that transitions (and ultimately, survives) into the work context.
When you use the same browser profile for everything, your personal web extensions and passwords sit in the same space as your company’s single sign-on (SSO) credentials. Blending shopping and social media with corporate SaaS means that autofill data, cookies, saved tokens, and device fingerprints become harder to see and control.
In case a malicious website or compromised add-on steals your browser data, your corporate access goes down with it.
As much as you need an online break every once in a while, try to maintain strict digital boundaries. For instance, create dedicated browser profiles with separate Google or Microsoft accounts. If you have multiple browsers installed, use a private session (since it erases the browsing history upon closure) on the browser you don’t rely on for work.
An even better option is to use a managed enterprise browser strictly for work tasks, and leave the usual Chromes and Edges for personal recreation.
4. Reject fake browser updates
A relatively new spin on false browser warning alerts, fake browser update prompts attempt to trick users into running malicious packages on their devices. Sometimes labeled as the ClickFix attack, the impetus is typically a non-existent technical issue or other seemingly benign interaction.
The attack generally begins with a compromised website. Once the user lands, it shows a fake message urging them to perform an update. Of course, the click won’t update the browser. It will, however, execute an HTML smuggling script or download an infostealer payload.
Because the user willingly executes a native administrative tool, standard endpoint antivirus protection often fails to flag the action as malicious. To it, the action looks like genuine user behavior.
At this point, it’s worth remembering that browsers automatically update themselves in the background or through official operating system settings. A web page will never legitimately deliver a browser update via a downloadable .exe or .zip file, and especially not from a random domain. If you see a pop-up on a site telling you to update, close the tab immediately.
5. Look out for malvertising and domain spoofing
Sometimes, all it takes is a click on an ad bought by cybercriminals. Called malvertising, it’s the method of placing display advertisements on search engines and popular news sites with hidden malicious redirect scripts.
Then, there are homograph attacks, where attackers register domain names that visually seem like the real corporate portals.
A fairly common ruse is swapping Latin letters with Cyrillic ones, particularly the letter ‘a’ that looks identical in lowercase. Since domain systems recognize Latin and Cyrillic letters as completely separate characters, the switch works from the technical side. To the naked eye, the URL looks the same.
In a slight twist, typosquatting is the practice of registering web addresses that are common misspellings of real sites. As such, it relies on human error, like a user who accidentally misspells a certain URL and ends up with a deceptive hyperlink.
If you stick to pre-saved bookmarks or password manager-assisted autofills, you have an excellent chance of outsmarting attackers. You might even notice it as it happens, as some password managers (at least, the most reputable ones) will refuse to autofill your credentials based on their strict domain matching.
6. Stop storing passwords in a browser
Here’s another instance where password managers come in handy. You see, built-in browser password stores are primary targets for infostealers, which extract saved browser credentials and exfiltrate them to attacker-controlled servers in no time.
In fact, one study showed that 98.6% of infostealer logs contained active passwords, and 99.54% included specific URLs where those credentials were used.
The fix is simple: just turn off auto-save password prompts. Ideally, you should store corporate credentials exclusively in an enterprise-grade password manager that has zero-knowledge encryption and centralized administrative control.
How a managed enterprise browser fixes a lot of work-related browsing problems
Now, these safe browsing tips are all good for, but the fact remains that they rely almost entirely on the employee’s willpower. It doesn’t help that consumer browsers are built for personal convenience, not corporate defense, as they grant users unrestricted freedom that doesn’t bode well for corporate environments.
Securing the hybrid workforce calls for a different approach, and enterprise browsers answer the call. By moving security controls directly into the browser, this solves the problems of hybrid security at a fraction of the cost or deployment complexity of traditional enterprise tools.
They create a secure and isolated browsing environment dedicated to work that includes:
- In-browser data loss prevention: Admins can isolate work sessions, restrict clipboard actions like copy-pasting corporate code into public AI tools, deny sensitive file downloads, and block malicious URLs in real time.
- Peripheral protection: Administrators can also disable camera and microphone permissions on untrusted domains.
- Policy-based routing: It’s possible to route browser traffic automatically through private gateways with dedicated corporate IPs. This gives remote workers protected access to internal SaaS apps without needing a system-wide VPN.
- Session and extension governance: Prevents cookie theft with automated browser session timeouts, and eliminates add-on risks by enforcing strict extension whitelists across all teams.
- Web threat filtering: Fake URLs and malvertising are blocked at the browser level before they reach the employee’s screen.
The bottom line is that the hybrid work model is here to stay, but the security risks that come with it don't have to be.
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.
