Browser Extensions, AI Browsers and the Expanding Security Risk for Enterprises


The Security Reality Gap: Identity, Visibility and Modern Cyber Risk

At a recent cybersecurity summit hosted by the Executive Leaders Network (ELN), Peter Dorrington — Strategic Advisor, Behavioural Analytics Pioneer and trusted moderator for ELN — led a discussion with Andres Andreu, CEO at Constella.

Andreu brings more than 33 years of cybersecurity experience, having previously served as a four-time Chief Information Security Officer (CISO) and worked in US federal law enforcement. His career has focused on threat intelligence, identity risk and enterprise security strategy.

During the session, Dorrington and Andreu explored what Andreu describes as the “security reality gap” — the disconnect between how organisations believe their environments are protected and how modern attackers actually exploit them.

Their discussion addressed several critical themes shaping today’s security environment, including the industrialisation of identity data, the limitations of authentication assumptions within zero trust architectures, the visibility challenges introduced by cloud ecosystems, and the structural weaknesses of traditional third-party risk management.

    Identity Data and the Industrialisation of Cybercrime

    One of the central points raised by Andreu was the industrialisation of identity data.

    In the past, organisations typically treated data breaches as isolated incidents. A breach would occur, security teams would investigate, remediate the issue and move forward. However, this model no longer reflects the reality of modern cybercrime.

    Instead, attackers now collect data from multiple breaches and correlate those datasets to construct fully exploitable identities.

    These identity profiles may include credentials, behavioural information, session artefacts and other personal data. Once aggregated, they allow attackers to operate with far greater precision and scale.

    This development has major implications for zero trust security models, which rely on the assumption that authentication processes confirm legitimate users.

    Many organisations continue to view multi-factor authentication (MFA) as a reliable safeguard. However, Andreu explained that attackers increasingly exploit information-stealing malware that captures active session objects.

    When attackers obtain these session tokens, they can perform session replay attacks, effectively bypassing MFA controls.

    As a result, the core assumption that an authenticated session represents a legitimate user can become unreliable.

    When Authentication Assumptions Break Down

    Zero trust environments are built around the principle that once a user is authenticated, security policies such as least privilege access and behavioural monitoring can be applied effectively.

    However, if the authentication event itself has already been compromised, the enforcement mechanisms that follow may operate on false assumptions.

    This creates a fundamental weakness within many security architectures.

    Attackers recognise this vulnerability and increasingly focus their efforts on identity compromise and authentication bypass techniques rather than attempting to breach systems through traditional perimeter attacks.

    The challenge for organisations is that once attackers gain authenticated access, they may be able to move within the environment with relatively little resistance.

    Rethinking Security Metrics and Vulnerability Management

    Another topic discussed during the session was the way organisations measure security success.

    Many security programmes still rely heavily on metrics such as reducing the number of vulnerabilities.

    Andreu argued that this approach can create a misleading sense of progress.

    Software vulnerabilities will continue to exist due to the complexity of modern technology environments. Attempting to eliminate them entirely creates an ongoing cycle that resembles a “whack-a-mole” scenario.

    Instead, organisations should focus on understanding and managing their attack surface.

    One common oversight occurs when companies secure their web applications but neglect their API ecosystems.

    APIs often interact directly with the same backend databases as web interfaces, yet they may not receive the same level of monitoring or protection.

    For example, while brute force attacks against a web login page may be detected, similar attacks targeting API keys or endpoints might go unnoticed.

    Understanding both ingress and egress pathways across applications and APIs is therefore essential for managing risk effectively.

    The Data Visibility Problem

    A recurring theme throughout the discussion was the issue of data visibility.

    Many organisations claim that protecting data is a priority. However, Andreu challenged a fundamental question: do organisations truly know where their data is stored?

    Years of system upgrades, platform migrations and accumulated technical debt often leave data scattered across multiple environments.

    When organisations deploy Data Security Posture Management (DSPM) tools to analyse their environments, they frequently discover that sensitive data exists in unexpected locations.

    These may include:

    • Legacy databases still responding to queries
    • Archived systems retaining sensitive records
    • Duplicate datasets within shadow IT environments
    • Forgotten storage repositories containing historical data

    Without accurate visibility into data locations and access permissions, it becomes difficult to implement effective protection strategies.

    Cloud Technology and the Expanding Attack Surface

    Cloud infrastructure has introduced additional challenges for security teams.

    Traditional security tools were designed for static infrastructure, where servers and systems remained relatively stable over time.

    Cloud environments operate differently.

    Modern cloud platforms rely on elastic and ephemeral infrastructure, where instances can be created and destroyed dynamically based on demand.

    This dynamic behaviour complicates efforts to maintain an accurate inventory of assets and services.

    Identity management also becomes more complex within cloud ecosystems. In some organisations, identity administration is handled primarily by IT teams, while security teams only act as advisors.

    This separation can create visibility gaps, particularly when dealing with:

    • SaaS platform expansion
    • Shadow administrative accounts
    • Rapid provisioning of new identities and permissions

    Together, these factors contribute to an increasingly complex attack surface that organisations may struggle to fully understand.

    The Blurring of Personal and Corporate Identities

    Workplace changes have also contributed to identity-related security risks.

    Practices such as Bring Your Own Device (BYOD), remote working and the gig economy have blurred the boundaries between personal and corporate identities.

    Earlier in the development of corporate IT environments, an employee’s professional identity was largely separate from their personal digital presence.

    Today, that distinction has largely disappeared.

    Attackers can combine publicly available information, breached datasets and behavioural patterns to construct detailed identity profiles.

    According to Andreu, adversaries often possess more contextual information about individuals than the organisations those individuals work for.

    This shift makes identity-based attacks increasingly effective.

    Third-Party Risk: Management or Paperwork?

    The session concluded with a discussion on third-party risk management.

    Modern organisations rely heavily on vendors, suppliers and software providers. However, these relationships often extend beyond direct partners to include second-, third- and fourth-tier suppliers.

    Andreu questioned whether organisations are truly managing this risk or simply managing compliance paperwork.

    Many programmes rely on questionnaires, contractual requirements and audit documentation. While these measures provide some level of oversight, they do not offer true control over external systems.

    Even fundamental transparency challenges remain.

    For instance, many vendors struggle to provide a complete Software Bill of Materials (SBOM) detailing the components within their software.

    Without this visibility, organisations cannot fully understand the technologies operating inside their environments.

    The rapid adoption of artificial intelligence technologies adds another layer of uncertainty. Third-party applications may integrate AI services or external APIs without the customer organisation’s awareness, potentially introducing unknown dependencies or vulnerabilities.

    Looking Ahead: AI and the Future of Cybersecurity

    Looking toward the future, Andreu expressed concern about the scale of cybercrime enabled by artificial intelligence.

    AI technologies are lowering the barrier to entry for cybercriminal activity while also increasing the speed and scale of potential attacks.

    At the same time, AI also presents opportunities for defenders.

    Security teams are beginning to deploy defensive AI capabilities designed to detect anomalies, identify identity compromise and respond to threats more quickly.

    This evolving landscape may lead to an ongoing contest between offensive AI used by attackers and defensive AI deployed by security teams.

    For organisations navigating this environment, closing the security reality gap will require stronger visibility, improved identity intelligence and a clearer understanding of how modern attack ecosystems operate.

    Key Takeaways

    • Identity data is increasingly industrialised, allowing attackers to construct exploitable identity profiles.
    • Authentication alone cannot be fully trusted, particularly when session tokens can be stolen and replayed.
    • Reducing vulnerabilities is not enough; organisations must understand and manage their full attack surface.
    • Data visibility remains a major challenge, particularly in environments with legacy systems and technical debt.
    • Cloud ecosystems expand complexity, introducing ephemeral infrastructure and identity sprawl.
    • Third-party risk management often focuses on compliance rather than true control.

    Key Questions from the Audience

    What is the “security reality gap” in modern cybersecurity?

    As discussed during the session, the security reality gap refers to the difference between how organisations believe their systems are protected and how attackers are actually able to exploit them.

    How are cybercriminals industrialising identity data?

    Andres Andreu explained that attackers are now aggregating stolen credentials and personal data from multiple breaches to construct exploitable identity profiles, allowing them to scale attacks and bypass traditional authentication mechanisms.

    Can multi-factor authentication (MFA) still be bypassed by attackers?

    While MFA remains an important security control, attackers are increasingly using techniques such as session token theft and session replay attacks to bypass authentication systems that organisations assume are secure.

    Why do organisations struggle to understand their full attack surface?

    Cloud infrastructure, APIs, shadow IT and legacy systems can create visibility gaps. Many organisations do not have a complete inventory of their assets, identities or data locations, making it difficult to fully understand their attack surface.

    Is reducing vulnerabilities the most effective cybersecurity strategy?

    According to Andreu, focusing solely on reducing vulnerabilities can create an endless cycle. A more effective approach is understanding how attackers interact with systems and managing the attack surface and potential blast radius.

    Are organisations truly managing third-party risk, or just managing compliance paperwork?

    Third-party risk management programmes often rely on questionnaires and compliance documentation. However, organisations frequently lack real visibility into the software components, dependencies or AI integrations used by their vendors.

      Watch the Full Session On-Demand

      If you would like to hear the full discussion between Peter Dorrington and Andres Andreu, the session is available to watch on demand:
      CyberSecure Online Summit | Virtual Event for Cybersecurity Leaders

      The replay includes additional insights from cybersecurity experts discussing identity risk, cloud security and emerging threat trends.

      #securityrealitygap #identitysecurity #cyberriskvisibility #identitydataindustrialisation #zerotrustauthenticationlimits #MFAbypass #sessiontokentheft #identitycompromise #APIsecurityrisks #attacksurfacemanagement #datavisibilitychallenges #DSPMtools #cloudattacksurface