Browser isolation is a lot like social distancing.

“Isolation is isolation,” said Zuly Gonzalez, co-founder and CEO of Light Point Security, which McAfee recently bought.

Light Point Security pioneered browser isolation technology, and now that the acquisition closed, McAfee has begun integrating it into its Secure Web Gateway and Unified Cloud Edge products to round out its secure access service edge (SASE) architecture.

In Gonzalez’s first interview since the deal closed, she likened browser isolation security to social distancing.

“When you look at in social distancing, we don’t necessarily know who’s sick and who’s not just by looking at them. So we have to assume everybody’s potentially contagious. And then we physically isolate ourselves from everybody while still being able to communicate and interact with them in a safe manner,” she explained. “That’s the same sort of idea and concept behind browser isolation.”

But instead of protecting people from pandemics, browser isolation focuses on web browsing and protecting users from malicious code. Instead of downloading a website — that may have malware, unbeknownst to the user — onto an endpoint, Light Point Security’s technology runs the browser in an isolated environment.

“So if they come across something malicious, then that malware stays contained in that remote, virtual environment and never even reaches the user’s computer network in the first place,” Gonzalez said.

Keep It Simple

And, this technology provides protection without any disruption to the user experience, so it looks and feels no different than browsing the web from a device. “It’s really important for browser isolation, and security in general, that any security product from a user’s perspective is simple, easy, seamless,” Gonzalez said. “Because if it’s not, users are always going to find a workaround and potentially make things worse from a security perspective.”

Browser isolation becomes increasingly important as attackers use the pandemic and COVID-19-related themes to deploy malware and gain access to corporate networks. Last week, the FBI issued a safety alert noting that “cyber actors have engaged in phishing campaigns against first responders, launched DDoS attacks against government agencies, deployed ransomware at medical facilities, and created fake COVID-19 websites that quietly download malware to victim devices.”

And today, in a joint alert from the United States Department of Homeland Security (DHS) Cybersecurity and Infrastructure Security Agency (CISA) and the United Kingdom’s National Cyber Security Centre (NCSC), the agencies warned about cybercriminals using COVID-19-related domain names, emails, applications, and files “for commercial gain, deploying a variety of ransomware and other malware.”

Browser Isolation Boosts WFH Security

A McAfee blog post echoed these threats, and warned “the volume of threats related to COVID-19 has been significant, with lures used in all manner of attacks.” This includes fake face-mask websites and advanced persistent threat groups “spreading documents that talk about the pandemic and are weaponized with malicious macro-code to download malware to the victim’s system.”

McAfee VP Sadik Al-Abdulla describes browser isolation technology “as a trump card that you can layer together with other web protection methods.” This is why the security vendor will integrate the newly acquired technology with its cloud-native Unified Cloud Edge, which also includes McAfee’s cloud access security broker (CASB), secure web gateway (SWG), and data loss prevention (DLP) capabilities. Together these pieces aim to provide a distributed, holistic approach to threat protection and securing data and users from endpoints to the cloud.

“We see this as two sides of a coin,” he said. One side involves protecting the user from potentially malicious code. “But the other part is protecting the data that the user is working with.”

Protecting both corporate users and data becomes more challenging when companies’ entire workforces now work from home because of the pandemic. “But it’s just as important when an executive is on an airplane or a hotel in a foreign country,” Al-Abdulla said. “Protections should be just as strong for remote users as they are when they’re sitting in their office behind all of the on-premise defenses.”