
Most security teams in banking are not short of controls. They have a secure web gateway, URL filtering, signature-based detection, and endpoint tooling, all configured carefully and all working as designed. The problem is that the attacks arriving through the browser stopped being the kind those controls were built to catch.
Alliance Bank reached that conclusion and acted on it. In a recent conversation, two of the bank's leaders described why they moved away from detection as the primary defense. Group Chief Digital and Information Officer Nantha Kumar Subramanian and Head of Cyber and Information Security Management Derrick Tan also covered what changed operationally once they did.
Detection-based web security stopped working because the attacks got faster than the detection cycle. Signature-based tools and URL blocking both depend on prior knowledge, and the threats arriving at Alliance Bank increasingly had no prior anything.
The biggest driver was generative AI. It compressed the time between a new technique appearing and that technique showing up in ordinary traffic. A model that has to detect before it can respond runs out of room quickly.
You secure a browser without slowing employees down by changing the assumption rather than tightening the filter. Alliance Bank stopped trying to sort good web traffic from bad and started treating all of it as potentially risky, then isolating it.
In practice, web traffic runs in a disposable cloud container and only safe visual content reaches the user. The active code never arrives at the endpoint, so an exploit has nothing to execute against.
That architecture also addresses the everyday risk rather than only the exotic one. Credential theft and phishing remain the most common way into a bank. Menlo Threat Prevention can place a suspicious site into read-only mode, so an employee cannot type credentials into a page that has not been classified yet.
For a regulated institution, the compliance angle matters as much as the security one. Isolation gives the bank a demonstrable control at the browser layer, which supports its obligations without adding steps to anyone's day.
The operational impact shows up as fewer alerts worth chasing and less remediation work. When threats are contained before they reach the endpoint, the volume of low-confidence detections that a SOC would otherwise triage drops substantially.
The deployment characteristics mattered as much as the outcome. Alliance Bank did not ask employees to switch browsers or install an agent, which is usually where adoption for security tooling stalls. Staff kept working in the browser they already used.
What changes is where the work happens. Detection and response is inherently reactive, so the security team is always operating after exposure has occurred. Removing the attack surface moves the effort earlier, before there is any response needed.
Derrick Tan described the value as resilience, achieved by removing the attack surface rather than attempting to detect and respond after exposure. That is a different claim from better detection. It is a claim about not needing to detect in the first place.
Other regulated organizations should start by asking whether their browser defenses depend on recognizing an attack, because that dependency is where advanced phishing and zero-day threats get through.
The key phrase here is “safer by default.” A control that requires correct classification, current signatures, and a user making the right decision has several ways to fail. A control that assumes risk and contains it has fewer.
You can watch the full conversation with Alliance Bank for the complete discussion.
Why isn't signature-based detection enough for browser-based threats? Signature-based detection requires prior knowledge of a threat, and zero-hour phishing, novel web exploits, and zero-day malware have none by definition. Generative AI has shortened the gap between a technique appearing and appearing at scale, which leaves less time for signatures to catch up. These evasive techniques are categorized as highly evasive adaptive threats.
How does browser isolation work without changing the browser? Remote browser isolation executes web content in a disposable cloud container and delivers only safe rendering information to the device. Because that happens in the cloud rather than on the endpoint, users keep their existing browser and no agent or extension is installed.
Does isolation slow down browsing for employees? No, and this was a specific requirement for Alliance Bank. Content renders normally and staff continue working in the browser they already use. The containment happens in the cloud, out of the user's way.
How does isolation help with credential theft and phishing? Suspicious sites can be placed into read-only mode. That prevents an employee entering credentials into a page not yet classified as malicious. That protects against the phishing sites that reputation and classification tools have not caught up to. Menlo covers this under zero-day phishing.
Does browser isolation support regulatory compliance requirements? It provides a demonstrable technical control at the browser session layer, which is where a large share of web risk now sits. For regulated institutions that must evidence their controls, this creates an auditable enforcement point without adding friction for employees. Menlo's compliance solutions cover this in more detail.
About the Author
Sameep Gidda is a Digital Marketing Campaigns Specialist at Menlo Security. Focused on GEO strategy, content marketing, and AI visibility, Sameep works to ensure Menlo's expertise in browser security and agentic AI reaches the security professionals who need it most.
See how Menlo secures the browser without agents or browser replacement. Schedule a Demo Here.
Menlo Security
