The Signal
Nine member companies in seven industries pointed at the same place last month. Not the endpoint. The browser.
The DoGood network logged 138 priority submissions from 65 member companies between July 2 and July 31. Nine of those companies want their controls to sit in the browser. Three named what they plan to remove. A Construction CIO runs VDI for external contractors and wants browser access instead. A Software IT director is six months into replacing AnyConnect VPN. A Government deputy CISO wants the traditional VPN and proxy stack gone, and says the savings matter.
Read the nine together and the common thread is not a product category. It is a population. Contractors. BYOD. Remote and semi remote staff. In each case the company does not own the device and cannot manage it. So the control point moved to the one layer the company can still reach.
That changes what these purchases are. They look like security projects. They are remote access replacements.
From the Network
"need something that can support a remote, and semi remote workforce. replacing the traditional VPN and proxies and saving money is important as well."
"We'd like to evaluate whether Conceal can help secure unmanaged/BYOD devices, reduce Shadow AI and SaaS risk, strengthen browser-based controls for our AWS and Microsoft environments, and potentially simplify portions of our current security stack."
"I want to better understand browser-based threat protection, zero trust web security, and techniques for preventing phishing, malware, and credential theft at the user level."
Two of the three led with cost or stack consolidation. Only one led with threat protection.
Top Open Priorities This Week
Two raw asks pulled directly from member submissions in the last 14 days, unedited:
"We currently use VDI for our external contractors, and I want to replace this with a browser-style access for them."
"We are looking for a flexible, lightweight solution for our BYOD environments and contractors."
Both members are solving for people they do not employ, on hardware they do not own.
New to the Network
Twenty one IT leaders joined the DoGood network in July. The senior cohort included the CISO at Marriott International, the CIO at the U.S. Air Force, and the CISO for ProServe Industries at Amazon Web Services. Also joining: the CISO at Parsons, the CISO at MasterControl, the VP of Enterprise Business Systems and IT at The Knot Worldwide, the Director of IT at CDW Corporation, and the Director of Security at Remitly. IT services, government, and finance accounted for 10 of the 21.
The Context
The headlines are catching up to what the network already knew.
Arctic Wolf Labs published findings on July 21 on Qilin ransomware affiliates exploiting CVE-2026-0257, an authentication bypass in Palo Alto Networks PAN-OS. The flaw lets an unauthenticated attacker open a VPN session without valid credentials. Arctic Wolf detected those intrusions in June. Verizon's 2026 DBIR put the pattern in numbers. Edge devices and VPN appliances accounted for 22% of exploitation-driven breaches, up from 3% a year earlier. Vulnerability exploitation also passed stolen credentials as the top initial access vector, a first in the report's 19 years.
Members are not pulling contractors off VPN because a vendor briefed them. They are moving because the box that grants the access has become the thing worth attacking.
Bottom Line: You bought the concentrator as a control; the incident data now treats it as an asset to count, patch, and shrink.
What to Do About It
Pull the list of every account that reaches your network through VPN or VDI and does not belong to an employee. Contractors, vendors, temps, M&A staff. Name the applications each one actually needs, then decide whether the concentrator is still the only way to deliver them.
The CXO Brief is powered by the DoGood network, 5,000+ IT leaders sharing what they are actually working on.
Know a CIO who needs this? Forward it and they can subscribe here.
Enterprise IT leader at a $100M+ company? Apply to join DoGood.
