Remote browser isolation
Remote Browser Isolation was built to protect users from web-based threats by moving risky browsing activity into a separated environment.
Instead of allowing content to run locally, RBI renders pages in the cloud and streams them back to the user.
That can work for isolating known risk. It doesn’t when an attack looks like normal browsing activity.
Isolation isn’t coverage
RBI only activates when something is flagged as risky. In practice, that means most browsing isn’t isolated at all. Policies decide when to trigger isolation based on URL reputation, categorization, or risk scoring. Everything else runs as normal.That creates a gap.
Push takes a different approach. It operates inside every browser session, giving security teams continuous visibility and real-time detection without relying on isolation triggers or introducing latency.
| Dimension | Push Security | RBI |
|---|---|---|
| Security approach | Yes — Detects and responds to attacker behavior in real time | Partial — Isolates sessions based on policy triggers |
| What it's designed to stop | Yes — Phishing, session hijacking, and credential abuse | Partial — Malware and known high-risk web content |
| Visibility into real activity | Yes — Sees how users authenticate, access apps, and interact in any browser | No — No visibility into actions inside isolated sessions |
| Coverage across browsing | Yes — Continuous visibility across all browser sessions | No — Limited to a small subset of traffic |
| Modern attack detection | Yes — Detects browser-based attacks in real time | No — Focused on containment, not attacker behavior |
| User experience | Yes — Native browsing with no added friction | No — Latency and degraded UX in isolated sessions |
| Time to security value | Yes — Immediate visibility and detection after deployment | No — Dependent on policy tuning and selective use |
Frequently asked questions
RBI executes web content in a remote environment — a cloud-hosted server renders pages and streams a visual representation to the user's browser. The theory is that malicious content executes in the remote environment rather than on the user's device.
RBI was designed for browser exploits, which have hit historic lows. The dominant threats — AiTM phishing, ClickFix, credential theft — operate through user interaction, not browser exploitation. RBI doesn't detect or prevent identity-based attacks.
Significant latency (all browsing rendered remotely), degraded user experience (rendering fidelity, copy/paste limitations), high infrastructure costs, application breakage (JavaScript-heavy apps, video conferencing), and no detection of identity-based attacks.
The attacks driving most breaches — AiTM phishing, credential theft, session hijacking — all work through an RBI environment because they exploit user interaction, not browser execution.
For most use cases, no. RBI's original value — preventing browser exploits — is less relevant as browser zero-days hit historic lows. The dominant threats operate through user interaction and aren't prevented by execution isolation.
Push provides better detection against the threats that drive breaches, at a fraction of the cost and without UX degradation.
Browser security extensions like Push provide threat detection inside the user's existing browser — without remote rendering, latency, or UX degradation. Push detects phishing, ClickFix, session hijacking, and credential theft behaviorally.
The trade-off is that Push doesn't provide execution isolation. But browser exploits are at a historic low, and the attacks that matter are identity-based — where Push excels and RBI falls short.
RBI requires cloud compute resources to render every page for every user remotely. Each session consumes server-side CPU, memory, and bandwidth. Infrastructure scales linearly with users and browsing activity.
Push deploys as a browser extension requiring no additional infrastructure.
RBI executes web content remotely and streams the result, isolating the browser process. A browser security extension runs inside the user's existing browser, detecting and blocking threats at the session level.
RBI prevents browser exploitation (rare). Browser extensions detect identity attacks (common, driving most breaches). See the comparison.
Yes, and it provides better phishing protection. RBI doesn't detect phishing — it isolates execution, but phishing works through user interaction which happens the same way through isolation. Push detects phishing behaviorally by analyzing page structure and kit mechanics. See Push's phishing detection.
Yes. Every page is rendered remotely and streamed. Visual quality is lower, interactive elements may respond slowly, and some applications break entirely. Users consistently report degraded experience, which drives workarounds.
Push runs inside the existing browser with no rendering changes, latency, or compatibility issues.
Not typically. RBI isolates the browsing environment — it doesn't analyze page content for phishing indicators. A phishing page renders normally in the remote environment. The user sees the content, enters credentials, and completes MFA just as they would without RBI.
Push's behavioral detection catches phishing on novel infrastructure by analyzing page behavior. See Push's detection approach.
RBI renders pages remotely and streams the output. Enterprise browsers replace the user's browser with a managed Chromium application running locally. Both are browser-layer security but with fundamentally different architecture — RBI adds latency, enterprise browsers require migration.
Push avoids both by deploying as an extension — no remote rendering, no browser replacement. See the comparison.
The answer depends on what you're trying to solve. If you specifically need execution isolation for high-risk browsing (classified environments, malware analysis), evaluate RBI vendors like Zscaler, Menlo Security, and Cloudflare on rendering fidelity, latency, and application compatibility.
If you're trying to stop phishing, credential theft, and session hijacking — the attacks driving most breaches — RBI isn't the right tool category. These attacks operate through user interaction, not browser exploitation, and work identically through an RBI environment. Push provides behavioral threat detection without remote rendering, latency, or UX degradation. Read the comparison.
Latest resources


