Delivering a Browser Security Assessment
Work has moved into the browser, and this guide shows you how to turn always-on browser visibility into strategic QBR conversations that demonstrate the value your team delivers beyond traditional IT support.
Three questions every assessment must answer
Anchor every section of your Browser Security Assessment to these questions, and you move beyond presenting metrics. You start using browser insights to help clients improve security, productivity, and technology investments while strengthening your role as a trusted advisor.
Question 01: What happened?
The key trends and events from the quarter, told at the organizational level.
Question 02: Why does it matter?
The business impact on productivity, risk, compliance, and technology spend.
Question 03: What should we do next?
A short, prioritized set of recommendations tied to the client's goals.
Six areas of browser visibility
To deliver a comprehensive Browser Security Assessment, your reporting should give you visibility into six areas. Each maps to a section in this guide. Select one to jump in.
AI Adoption & Usage
Which AI tools employees use and how usage is trending.
Jump to sectionAI Governance
Whether AI use aligns with policy, and whether sensitive data is protected.
Jump to sectionCredential Monitoring
Exposed credentials, password health, and high-risk accounts.
Jump to sectionExtension Management
Discover installed extensions, flag high-risk ones, align usage with policy.
Jump to sectionData Loss Prevention
Controls on uploads, downloads, and copy/paste, to keep data inside.
Jump to sectionProductivity & App Usage
How time in the browser maps to business vs. non-business activity.
Jump to sectionIf your current tooling can't surface one of these areas, that's worth knowing before your first QBR. Each section identifies the specific data points you'll need. Atakama's platform provides all six natively, and its reports appear throughout as examples of what to look for.
AI Adoption & Usage
AI adoption is one of the fastest-moving technology shifts inside your clients' organizations, and nearly all of it happens in the browser. Employees adopt AI tools long before leadership formally evaluates them; browser-level visibility is often the only accurate picture of how AI is actually being used.
- Which AI applications are employees using most?
- How has AI adoption changed since last quarter?
- Are employees primarily using approved AI applications?
- Where can AI adoption be strengthened or standardized?
Approved vs. unapproved AI
Compare how employees use approved and unapproved AI applications to understand adoption patterns and identify chances to steer usage toward trusted tools.
AI application usage
Identify the platforms employees rely on most, such as ChatGPT, Microsoft Copilot, Google Gemini, GitHub Copilot, and Grammarly, to understand how AI supports day-to-day work.
AI adoption trends
Compare adoption over time to spot growth, changes in usage, and emerging opportunities to integrate AI into workflows. The trend line is the story, not the snapshot.
Shadow AI applications
Review newly adopted AI tools to determine whether they should be evaluated for broader business use, or flagged for the governance conversation in Section 1B.
In practice: Atakama—Atakama's AI Usage report surfaces each of these views natively: approved vs. unapproved usage breakdowns, ranked AI application adoption, quarter-over-quarter trends, and newly detected AI tools. A useful reference for what complete AI adoption reporting looks like.
AI Governance
AI governance is where innovation and risk meet. Employees adopt AI tools faster than policy can keep pace, and sensitive business data can leave the organization in a single paste or upload. Visibility into unauthorized AI applications and attempts to share sensitive information lets an organization embrace AI confidently instead of banning it reflexively.
- Does AI use align with organizational policies?
- Is sensitive business information being shared with AI tools?
- Are current governance practices reducing risk?
- Where can AI governance be strengthened?
Approved vs. unapproved AI
Review the balance between approved and unapproved AI applications to determine whether employees are adopting tools that align with organizational policies.
Protective measures
Evaluate blocked or warned visits, uploads, and other protective actions to see whether controls are actually reducing AI-related risk, and where policies may be too loose or too restrictive.
Sensitive data protection
Review attempts to upload or paste confidential information into AI applications and determine whether existing policies effectively protect business data.
In practice: Atakama—Atakama's AI Governance insights cover the full picture: unauthorized AI application detection, blocked and warned interactions, attempted sensitive-data uploads, and prioritized governance recommendations, giving you a client-ready view of how AI risk is being managed.
Credential Monitoring
Compromised credentials remain one of the most common paths to account takeover, and the browser is where credentials live. Employees enter passwords into dozens of sites, reuse them across services, and rarely learn when one has been exposed in a breach. Visibility into exposed credentials, password strength, and high-risk accounts lets you catch credential risks before they lead to compromise.
- Which user accounts present the greatest credential risk?
- Have credential risks improved since last quarter?
- Are password policies effectively protecting the organization?
- What remediation efforts should be prioritized?
Most at-risk users
Identify the accounts with the highest number of compromised credentials and prioritize by business impact: an exposed admin or finance account matters more than a dormant one.
Credential risks
Review exposed credentials, leaked accounts, leaked passwords, and weak or reused passwords to understand where immediate action is required.
Credential trends
Compare credential health over time to measure progress, identify recurring issues, and evaluate whether previous remediation efforts have reduced organizational risk.
In practice: Atakama—Atakama's Credential Monitoring insights surface all of these views: ranked at-risk users, leaked and weak credential detection, quarter-over-quarter credential health trends, and prioritized remediation recommendations, a solid benchmark for complete credential reporting.
Browser Extension Management
Browser extensions are software installed inside the very place work now happens, yet in most organizations, no one is tracking them. Employees grant broad permissions to read and change data on every site they visit. A single malicious or compromised extension can capture credentials, exfiltrate data, or inject content across the entire session. Visibility turns an invisible risk surface into a manageable inventory.
- Which extensions are installed across the organization?
- Do any carry high-risk permissions or unverified publishers?
- Do any duplicate or undermine sanctioned tools?
- How has the extension footprint changed this quarter?
Extension inventory
Identify installed extensions and how widely each is deployed. Broad adoption of an unsanctioned extension is a signal: it may be filling a genuine workflow gap worth solving with an approved tool.
Risk & permissions assessment
Review extensions with high-risk permissions, such as reading data on all sites, capturing keystrokes or clipboard contents, or modifying page content, and prioritize those combining broad permissions with wide deployment.
Unapproved & emerging extensions
Compare installed extensions against the approved list, and review newly appearing extensions to determine whether they should be evaluated, sanctioned, or removed.
In practice: Atakama—Atakama's extension visibility surfaces the full organizational inventory: extensions ranked by deployment, permission-based risk scoring, unapproved and newly detected extensions, and quarter-over-quarter changes, an attack surface most reporting misses entirely.
Data Loss Prevention
The browser is now the primary channel through which data leaves an organization: a file uploaded to a personal cloud drive, a customer list pasted into an AI tool or webmail, sensitive data downloaded from a business app. Traditional network DLP often can't see inside encrypted browser sessions, which makes browser-level controls the most direct way to govern data movement.
- Is sensitive data going to unsanctioned destinations?
- How often are protective controls being triggered?
- Are DLP policies calibrated correctly, or are they too permissive or disruptive?
- Have data movement risks improved since last quarter?
Blocked & warned activity
Review upload blocks, download blocks, and copy/paste interventions to understand what your controls prevented, and translate those events into the business data they protected.
Data movement patterns
Identify where data is flowing: which destinations receive uploads, which site categories trigger interventions most, and whether personal cloud storage, webmail, or AI tools lead.
Policy effectiveness
Frequent warnings employees click through may signal policies that need tightening; heavy blocking of legitimate work signals rules that need refining.
DLP trends
Compare intervention volumes and destinations over time to measure whether risky data movement is declining as policies and employee awareness mature.
In practice: Atakama—IN PRACTICE: ATAKAMA —Atakama's data protection insights capture this activity at the browser level: blocked and warned uploads and downloads, copy/paste interventions, destination breakdowns, and quarter-over-quarter trends. Evidence you can share with a client to show exactly what their controls prevented.
Business Productivity & Browser Insights
Browser activity data is what elevates a Browser Security Assessment from a metrics summary to a business conversation. Visibility into how employees use business and non-business web applications tells a story no other dataset can: whether technology investments are being adopted, where workflows are efficient or fragmented, and how work patterns change over time. This is usually the strongest section to open your QBR with, and it speaks to outcomes every stakeholder cares about, not just the security-minded ones.
- Are employees using the applications the client invested in?
- How has browser productivity changed since last quarter?
- Can browser policies improve productivity?
- Which activity trends should be monitored going forward?
Productive vs. non-productive activity
Compare productivity trends over time to understand how browser activity aligns with business goals. A single quarter's snapshot is far less valuable than the trend line: what changed, and why?
Business application usage
Identify the applications employees rely on most, such as Slack, Gmail, Teams, Quickbooks, Grammarly, etc. High adoption validates technology spend; low adoption of a tool the client pays for is a finding worth raising.
Non-business activity
Look for organization-wide browsing trends that may warrant a policy conversation. Frame these as patterns, not incidents: the goal is refining policy, not naming names.
In practice: Atakama—Atakama's Business Productivity & Browser Insights report packages each view in a client-ready format: productive vs. non-productive trend comparisons, ranked business application usage, organization-wide browsing patterns, and prioritized productivity recommendations.
Quarterly Trends & Progress
The trends section brings together key insights from all six areas to show how the client's security posture, productivity, and technology adoption have evolved over time. Rather than reviewing individual metrics again, highlight measurable progress, reinforce the impact of previous recommendations, and identify priorities for the next quarter. This is where the assessment stops being a collection of metrics and becomes a progress story.
- What progress has the organization made since the last QBR?
- Which initiatives delivered the greatest business value?
- Where have security and productivity improved?
AI trends
Compare AI adoption and governance metrics over time to understand how usage is evolving, evaluate policy effectiveness, and strengthen the AI strategy.
Credential monitoring trends
Measure improvements in password hygiene, identify recurring risks, and confirm whether previous remediation strengthened the security posture.
Extension management trends
Track new extensions introduced, high-risk extensions removed, and movement toward approved tools. Is extension risk shrinking quarter over quarter?
Data loss prevention trends
Compare intervention volumes and destinations over time to confirm risky data movement is declining and DLP policies are better calibrated to how employees actually work.
Business productivity trends
Review changes in browser productivity and business application usage to identify improvements in operational efficiency.
Key wins & improvement opportunities
Highlight measurable successes while identifying areas that need continued attention or additional support next quarter.
In practice: Atakama—Because Atakama captures productivity, AI adoption, AI governance, credential, extension, and data protection insights in one place, its quarter-over-quarter views make it straightforward to assemble this progress story without stitching together exports from multiple tools.
Delivering an Effective Browser Security QBR
A successful QBR transforms your Browser Security Assessment into a meaningful business conversation. Rather than reviewing metrics one by one, use the QBR to explain what has changed, why it matters, and what actions will deliver the greatest value moving forward.
Prepare the story
- Review the key insights from your browser security reporting.
- Compare current results with previous periods to identify meaningful trends.
- Prepare recommendations tied to the client's posture and priorities.
- Identify measurable progress to highlight since the last QBR.
Guide the conversation
- Frame the discussion around business outcomes, not technical metrics.
- Ask: Have your business priorities changed since our last review?
- Ask: Which recommendations would create the greatest value?
- Ask: What goals should we focus on before next quarter?
End with a plan
- Summarize the key insights and measurable progress.
- Confirm agreed-upon action items and priorities.
- Establish goals to review during the next QBR.
- Schedule the next Quarterly Business Review.
MSP Tip—The best QBRs are collaborative conversations. Listen carefully, encourage client participation, and tailor your recommendations to their business objectives.
Your QBR prep checklist
The browser is where modern work happens, and where modern risk concentrates.
A Browser Security Assessment built on the six pillars in this guide transforms browser visibility into strategic conversations that demonstrate measurable value and build stronger client relationships. Whichever platform powers your reporting, the discipline is the same, and if your current stack leaves gaps in any of the six areas, Atakama's Managed Browser Security Platform provides all six natively.
Stay ahead of browser threats
Get monthly security insights, product updates, and expert guides delivered to your inbox.
No spam. Unsubscribe anytime.