The Member Signal is DoGood’s weekly peer-intelligence briefing for the member network. This issue went to members on August 5, 2026, and appears here lightly edited for the web.
The Signal
Eight member companies reopened the same question in July: how people who are not sitting on a corporate laptop, on a corporate network, get to corporate applications.
They did not coordinate. They are in software, finance, government, insurance, construction, healthcare, and utilities. One is replacing an AnyConnect VPN inside a six-month zero-trust program. One is retiring VDI for external contractors. One wants VPN and proxies gone for a remote and semi-remote workforce, with the cost savings as an explicit goal. One is looking for something light enough to put on BYOD machines and contractor laptops. Two are shopping browser security with no incumbent named at all.
What makes this worth your attention is not that remote access is being modernized. It is where the control is landing. Five of the eight name the browser explicitly as the candidate control point, not the device and not the network. The other three are approaching the same problem from the device side, and two of those booked time with a browser-native vendor inside the same month. The layer your organization has treated as a rendering surface for twenty years is being evaluated as the enforcement point, and the members moving first are doing it to remove products, not to add one.
From the Network
“I want to better understand browser-based threat protection, zero trust web security, and techniques for preventing phishing, malware, and credential theft at the user level.”
Information Security Leader, Finance
“need something that can support a remote, and semi remote workforce. replacing the traditonal VPN and proxies and saving money is important as well.”
Deputy CISO, Government
“We’d like to evaluate whether Conceal can help secure unmanaged/BYOD devices, reduce Shadow AI and SaaS risk, strengthen browser-based controls for our AWS and Microsoft environments, and potentially simplify portions of our current security stack.”
Senior Director, IT Operations, Software
Read the third one again. Unmanaged devices, shadow AI, SaaS risk, and stack consolidation are four separate budget lines in most organizations, and this member is testing whether one control point closes all four. That is the reason this category is moving faster than remote access alone would explain.
Top Open Priorities This Week
“We are looking for a flexible, lightweight solution for our BYOD environments and contractors.”
Director, Cyber Security, Energy & Utilities
“We currently use VDI for our external contractors, and I want to replace this with a browser-style access for them.”
Chief Information Officer, Construction
Both of these are open right now, and both are about people the organization does not employ working on machines the organization does not own. If you have run a contractor-access project in the last two years, what you learned about onboarding friction is worth more to them than any architecture diagram.
New to the Network
Twenty-one senior IT leaders joined the DoGood network in July. The senior cohort included:
- Chief Information Officer, U.S. Air Force
- Chief Information Security Officer, Marriott International
- Chief Information Security Officer for ProServe Industries, Amazon Web Services
- Chief Information Security Officer, Parsons
- Chief Information Security Officer, MasterControl
- Vice President, Enterprise Business Systems & IT, The Knot Worldwide
- VP, Director of Associate Technology Services, FirstBank
- Senior Director, IT Corporate Systems, Cvent
- Associate Director, IT Security Risk, Columbia University Medical Center
- Senior Advanced Systems Engineer & Cyber Security Lead, Honeywell
The July cohort skews toward IT services, government, and financial services, which together account for ten of the twenty-one.
Member Spotlight: Scot Burdette, ABB
Six years ago he joined a division with talented technical contributors and no centralized technology organization, and built one. He is Global Division CIO for Measurement & Analytics at ABB, more than four thousand people across sixty-odd countries, and he put it plainly in his DoGood spotlight, “I’m proud of what the team has done, and how we pull together to solve complex problems that some people even question if we could ever solve.”
Deep Dive: Endpoint, Device & Asset Management
Thirty-nine member submissions over the last 90 days touched endpoints, devices, or the access path to them, from 29 different companies. The dominant pattern is that the perimeter is now a person on hardware nobody in IT provisioned.
Where activity is concentrated
- The browser as the control point — 11 submissions, 10 companies. The cluster with the clearest direction of travel: secure browser alternatives, browser-native SSE, browser-based threat protection, and browser access replacing VPN or VDI outright. Members here consistently frame it as removing infrastructure rather than layering on top of it.
- Devices you do not own — 10 submissions, 9 companies. BYOD with a stipend versus corporate-issued hardware, contractor laptops, several hundred remote employees across multiple countries, managed BYOD in healthcare. One organization pulled its cellular fleet to save money and is now planning to reissue devices to a select group, having learned what the savings actually cost.
- Knowing what you have — 11 submissions, 11 companies. Which devices exist, which are compliant, which are patched, and which came back. A government IT leader discovered a non-zero number of connected devices that were never supposed to be on the network. A construction CIO has no asset management software at all. An IT services CISO called asset return one of the organization’s biggest risk and financial burdens.
What your peers are buying
- Conceal — first meetings with sixteen member companies, all in July. That makes it the most-met vendor in the network over the period. Six of the sixteen logged the meeting as evaluation for a committed project rather than exploration; three attached a budget band, two in the $25K to $100K range and one above $100K. Buyers span finance, software, government, business services, and minerals. Two of the sixteen went in explicitly to compare it against Island, Netskope, Talon, and enterprise-managed Chrome, which tells you the shortlist members are actually building.
- Island — five meetings, five companies. A finance risk executive booked one specifically to understand rising demand for endpoint and browser controls.
- Verkada — eight meetings, eight companies on physical security and access hardware, most framed as consolidating point solutions rather than adding a camera vendor.
What is still open
Device inventory and compliance posture. Eleven companies raised it in 90 days; against that, unified asset visibility drew a single meeting in the same period and network device discovery drew two. There is real demand here and no shortlist forming, which means references are scarce and you will be evaluating without a crowd. Patch and image hardening tied to audit obligations is the second gap: raised, and no vendor in the network has taken a meeting on it.
What it means for your stack
Before you renew VPN, VDI, or a secure web gateway this year, price the browser option against all three line items together rather than against the one coming up for renewal. Every member in this data who moved did so on the consolidated number, and the ones evaluating one product at a time are the ones still stuck.
The Context
On July 2, Akamai closed its acquisition of LayerX, a secure enterprise browser company, for roughly $205 million. Gartner published its first Market Guide for Secure Enterprise Browsers in February and put current adoption below ten percent of organizations, forecasting one in four by 2028.
The headlines are catching up to what the network already knew. The acquisition closed in the same month eight members independently opened the same evaluation, and Gartner’s under-ten-percent figure describes a market where the members reading this are ahead of the curve, not behind it.
Bottom Line: A category that infrastructure vendors are buying their way into is a category where the independent options get acquired next, so ask any browser vendor you meet this quarter what happens to your contract and roadmap if they are bought inside eighteen months.
What to Do About It
Pull your renewal dates for VPN, VDI, and secure web gateway and put them on one page this week. If any two land within the same twelve months, you have a consolidation decision, not three renewals, and you should be running one evaluation instead of three. Members who found this out after signing the first renewal lost the leverage.