Editorial

Your Next Breach is Just Installing

Every unknown application is an open invitation.

Monday, June 01, 2026 | 5 MINS

There was a time when introducing new technology into a business required months of planning, budget approvals, procurement reviews and IT sign-off.


Today, it takes about thirty seconds.

An employee discovers a new AI assistant. Marketing signs up for a SaaS platform. Finance installs a browser extension. Sales connects a productivity tool. None of it feels particularly risky, and individually it rarely is, until you look at the bigger picture.

Every installation creates a new relationship between your business and a third party. Every new application requests permissions, stores data, accesses files or integrates with other systems. Most of those requests are accepted without a second thought because getting the job done is more important than reading the security policy. And of course, attackers understand this better than anyone.

They know organisations spend millions protecting networks, endpoints and email. So instead of trying to break through the front door, they increasingly look for the side entrances that businesses have unknowingly opened themselves. A vulnerable browser extension. An abandoned SaaS account. An AI tool with excessive permissions. A cloud application that nobody realised was still connected.

Your next breach may not begin with a sophisticated cyber attack, it may begin with someone trying to be more productive.

That's what makes modern technology risk so difficult to manage. Employees aren't deliberately bypassing security; they're simply solving problems at the speed the business expects. Security, meanwhile, is left trying to keep track of an environment that's changing every hour.

The answer isn't to stop people adopting new technology. Businesses that do not quickly fall behind competitors who embrace innovation faster.  The challenge is making sure security moves at the same pace as the business.

That starts with visibility because if you don't know what's being installed - and this could be daily occurrence - connected or given access to company data, you can't assess the risk, apply the right controls or respond when something goes wrong.

Because in 2026, breaches don't always start with hackers breaking in. Quite often, they start with someone clicking Install.


This topic is sponsored by Palo Alto Networks, whose commitment to making enterprise-grade security accessible to mid-market organisations helped bring this discussion to the community.


SMB Definitive Guide to Browsers

Here's your "SMB Definitive Guide to Browsers" compliments of the Community

Download

This topic has been sponsored by Palo Alto Networks, whose commitment to making enterprise-grade security accessible to mid-market organisations helped bring this discussion to the community.

Also in this section

}());