Cybersecurity
6 min readFinding the balance: managed devices or browser-based access?
Should you keep shipping and maintaining company laptops with a full security agent stack, or move part of your workforce to browser-based access? The hard questions to ask so costs stay down without shrinking your security footprint.
Neither model is right for everyone, and most organisations end up with both. The real question is who gets a managed laptop with a full security agent stack, and who gets browser-based access, where the control lives in the browser and the device matters less. Every growing company hits this eventually: keep buying, imaging, shipping and supporting hardware for everyone, or move part of the workforce to the browser. The money, and the risk, is in deciding who gets which, and most teams pick a side before they have asked the hard questions.
Two models, two cost structures
The managed device model is the one most people know. You own the laptop. You image it, ship it, patch it, support it and eventually replace it. A secure access agent on the device steers traffic, checks posture, connects people to private apps and inspects what leaves the machine. It gives you deep control over everything the person does, and it costs you hardware, logistics, a stack of per-user licences and a steady stream of help desk hours.
The browser-based model flips the perimeter. The person works from their own device or a lightly managed one, and a hardened enterprise browser or isolated session becomes the control point. Copy and paste, downloads, uploads, printing, screenshots and session recording are all governed there, and the data stays server side. There is nothing to ship and very little hardware to own. Its weak spot is anything that lives outside the browser: thick clients, local development tooling, specialised software and offline work.
Where the money actually goes
When we model this for clients, the shipped-hardware path is almost always more expensive than the finance team thinks, because the laptop price is the smallest line. The real costs are the ones nobody tracks in one place.
- Procurement and depreciation on devices that a three-month engagement will use for three months.
- Courier, customs and return shipping, especially across borders, plus the devices that never come back.
- Imaging and provisioning time before day one, and the help desk tickets for agent and connectivity problems after it.
- Licence stacking: endpoint protection, device management, the secure access agent and data loss prevention, each priced per user, often overlapping.
- Offboarding lag. Access lives on a device you have to physically recover, so revocation takes days instead of minutes.
The browser model has its own hidden costs
It is not free either. Identity becomes the whole perimeter, so phishing-resistant multi-factor authentication stops being a nice-to-have. Apps that do not run in a browser need an exception path, and if you do not design one, people build their own and you get shadow IT. Some workflows, like heavy engineering or finance systems with local components, still need a real managed endpoint. If you pretend otherwise, you buy the browser licence and the laptop.
The hard questions to ask before you choose
The goal is not to pick a winner. It is to stop paying for control you do not use, without leaving a gap you cannot see. These are the questions we push clients to answer with data rather than instinct.
- Who genuinely needs a managed endpoint? Map roles to the data they touch and the apps they use, not to seniority.
- What share of your workforce is short-term, seasonal, partner or based in another country? Every laptop shipped to a short engagement is a cost you can measure.
- How much of the actual work happens in a browser today? If most of your apps are SaaS, an agent on the device is protecting a shrinking surface.
- What does day one and the last day look like? Measure hours to provision and hours to fully revoke.
- What are you paying per user per month across every agent, and what does each one do that nothing else in the stack already does?
- When a device is lost or a person leaves badly, what is the recovery story, and how long does it take?
- Where does the data land at the end of a session: on a disk you have to chase, or nowhere?
- What evidence will your auditor, insurer or customer ask for, and which model produces it with fewer moving parts?
A split that works for most businesses
The pattern that holds up in practice is simple. People with local data, administrative rights, development tooling or thick-client software get a managed device with the full agent stack. Everyone whose work lives in the browser, which is typically sales, support, operations, partners, short-term hires and offshore teams, gets browser-based access on a device you do not have to ship or recover.
The rule of thumb: if their work lives in the browser, secure the browser. Done well, this cuts the number of devices you own and ship, moves licence spend from device tools toward access tools that cover more people for less, and turns offboarding into a single click in your identity provider.
Keeping the security footprint whole
The failure mode is not choosing browser-based access. It is choosing it and leaving the controls behind. Whichever path a person is on, a few things do not change.
- Phishing-resistant MFA for everyone, with conditional access tied to device or browser posture.
- One data handling policy, enforced at two points. The rule about what can leave the company is the same whether it is enforced by an agent or a browser.
- Logs from both paths in one place, so an investigation does not depend on which model the person was on.
- A written exception process, so the first app that does not fit the browser does not become a quiet workaround.
How HuCortex approaches this
We do not start from a vendor. We start from a workforce map: who your people are, what data they touch, which apps they use, how long they will be with you and where they sit. Then we model the total cost of both paths for each role, design the split, and tell you plainly which licences you can stop paying for. We work across the major secure access and enterprise browser platforms and will say so when you do not need one of them.
The outcome is a documented access model your board can read, a smaller pile of hardware to manage, and a security footprint that is the same size or larger than the one you have now, for less money.
Ready to take the next step?
HuCortex works with Canadian businesses on CPCSC readiness, PIPEDA compliance, and managed security. Start with a free assessment.
