Webinar Description
Key Takeaways
- Examines security gaps created by third-party JavaScript executing in customer browsers
- Compares client-side protection approaches including CSP, SRI, WAF, RASP and behaviour-based controls
- Addresses PCI DSS requirements 6.4.3 and 11.6.1 for client-side script management
- Designed for CISOs, security architects, compliance officers and application security teams
- Relevant to e-commerce, financial services and healthcare organisations processing sensitive data online
Introduction
The Truth About Client-Side Risk: What Security Vendors Don’t Tell You is a webinar examining the limitations of conventional security tools when protecting against threats originating from third-party JavaScript. Hosted by Source Defense, the session targets security and compliance professionals responsible for web applications that handle sensitive customer data. The discussion arrives at a critical moment for organisations subject to PCI DSS, as recent updates to the standard have introduced explicit requirements for managing scripts executing in customer browsers—an area where traditional server-side defences provide limited visibility.
About This Event
This virtual session offers a practical, comparative analysis of client-side security approaches rather than a product demonstration. The webinar format allows security teams to evaluate different protection methodologies and understand where common controls fall short. Source Defense, a specialist in browser-side protection, hosts the event with an educational focus on the technical and compliance challenges that enterprises face when third-party code operates beyond the reach of their existing security infrastructure.
The Client-Side Visibility Problem
Modern websites routinely load dozens of third-party scripts for analytics, advertising, chat functionality, payment processing and customer experience optimisation. These scripts execute directly in the visitor’s browser, outside the perimeter where Web Application Firewalls and Runtime Application Self-Protection tools operate. The result is a significant blind spot: security teams may have comprehensive visibility into server-side activity while remaining unaware of what third-party code is doing with customer data in the browser.
The challenge intensifies because these scripts frequently update without notice. A tag management platform might load different code on each page view, or a vendor might push changes to their hosted JavaScript at any time. This dynamic behaviour makes static controls difficult to maintain and creates opportunities for supply chain compromises where trusted vendors inadvertently distribute malicious code.
Comparing Security Controls
The webinar provides a structured comparison of the security controls commonly deployed to address client-side risk. Content Security Policy restricts which domains can serve executable content but cannot control what approved scripts actually do once loaded. Subresource Integrity verifies that fetched resources match expected cryptographic hashes, though this becomes impractical when vendors update their scripts frequently.
Server-side tools such as WAFs and RASP inspect traffic between the browser and origin server but have no visibility into JavaScript execution within the browser itself. Monitoring solutions can detect anomalies and generate alerts, yet they typically lack the ability to prevent data exfiltration in real time. Behaviour-based protection represents a newer approach that analyses script activity at runtime and can block suspicious actions before sensitive data leaves the browser.
Each approach involves trade-offs between implementation complexity, operational overhead and protection coverage. The session examines these trade-offs to help security teams make informed procurement decisions.
PCI DSS Compliance Requirements
PCI DSS version 4.0 introduced requirements 6.4.3 and 11.6.1, which specifically address the management and monitoring of scripts executing on payment pages. Requirement 6.4.3 mandates that organisations maintain an inventory of scripts, justify their presence, and implement controls to ensure script integrity. Requirement 11.6.1 requires mechanisms to detect unauthorised modifications to payment page content.
These requirements acknowledge that client-side attacks—such as digital skimming and formjacking—have become a significant threat to payment card data. Organisations processing card payments must now demonstrate controls that extend beyond server-side protection to encompass browser-based activity, making client-side security a compliance obligation rather than merely a best practice.
Who Should Attend
The session is designed for professionals responsible for securing web applications and maintaining compliance with data protection standards. CISOs and security architects will benefit from the strategic comparison of protection approaches, while application security teams can apply the technical insights to their evaluation processes. Compliance officers preparing for PCI DSS assessments will find the discussion of requirements 6.4.3 and 11.6.1 particularly relevant. Procurement specialists evaluating client-side security platforms can use the comparative framework to structure vendor assessments.
Organisations in e-commerce, financial services and healthcare—sectors with substantial compliance obligations and high volumes of sensitive data processed through web interfaces—represent the primary audience for this content.

