Skip to main content

Why Domain and DNS Security Deserve a Bigger Place on the Cybersecurity Agenda

As part of The CISO Outlook 2026 report, CSC surveyed 300 senior executives—including chief information security officers (CISOs), chief technology officers (CTOs), chief information officers (CIOs), and heads of cybersecurity—to find out what is moving up their list of cybersecurity priorities.

Domains and the Domain Name System (DNS) form foundational infrastructure for digital businesses. However, cybercriminals exploit them in ways that can cause outages, redirect users to fake sites, and support brand impersonation.

At the same time, these criminals employ AI to create and scale cyberattacks, pushing the topic higher on executive agendas. This attention focused on AI can make foundational risks look settled—when they’re not.

In 2026 and beyond, organizations may find they need to manage foundational infrastructure, such as domains and DNS, with the same intensity they apply to newer technologies competing for leadership attention.

A leading threat, not a legacy concern

According to our research from The CISO Outlook 2026 report, 72% of respondents said the cybersecurity threats their organizations faced in 2025 were “critical” or “very critical.” Domain and DNS hijacking and subdomain takeover attacks ranked as the No. 1 cyber threat that year, ahead of cybersquatting and ransomware or malware.

That finding challenges the assumption that domain and DNS security belong to an earlier phase of the internet. In reality, the risks associated with domain and DNS have evolved alongside the adoption of cloud platforms, advanced digital campaigns, and increasingly complex infrastructure.

Consider this: In 2025, a cybersecurity intelligence and advisory group exposed a phishing and brand impersonation operation had run for more than three years across Google Cloud and Cloudflare platforms. The infrastructure hijacked abandoned or expired domains and paired them with cloned websites belonging to global brands. It also used “hidden cloaking” to make the activity harder for the original brands to discover.

The harm extended beyond the fake websites themselves. It exposed users to fraudulent content, eroded trust, and raised potential legal and regulatory liabilities against the affected brands.

The example illustrates how neglected foundational infrastructure can become part of a much larger attack operation.

The confidence gap is hard to ignore

The significance of domain and DNS threats grows even greater when set against an organization’s confidence in handling them. According to our research, only 14% of respondents said they were “very confident” in their company’s ability to mitigate domain attacks. Although that marks an improvement from 7% a year earlier, it still leaves a substantial gap between awareness and assurance.

This reflects the challenges businesses face in keeping protection aligned within a constantly changing digital environment. Plus, as infrastructure grows, cloud dependencies evolve, and seasonal campaigns increase, it introduces additional risks. Not to mention domain management may span multiple teams within an organization—including IT, security, legal, and marketing. This also spread ownership of the problem—and the task of solving it—beyond just a single technical team.

DNS outage readiness is uneven

Confidence around DNS outages also is thin. In fact, in our survey, one in 10 respondents believed their companies were significantly underprotected against these types of outages. Another 25% considered their organizations slightly underprotected. And only about one-third (34%) believed their companies were very protected against DNS outages.

Purpose-built DNS redundancy can increase resilience, but the broader issue is dependency. Many organizations rely on a small number of major cloud platforms for DNS hosting, and when those providers experience outages, the downstream impact can take entire organizations offline. Building resilience means accounting for risks that originate outside your own infrastructure.

Protection changes as the business changes

Many organizations also assume that measures put in place once will remain effective indefinitely. For example, organizations may establish protection against distributed denial-of-service (DDoS) attacks, then fail to review it as their systems grow. In the meantime, infrastructure scales and new risks emerge.

Domain and DNS security is therefore better understood as an ongoing requirement rather than as a project with a clear finish line.

Detection is only half the story

Proactive monitoring remains key, of course. And malicious activity can appear anywhere across domains and the DNS.

But merely flagging a risk isn’t enough, as it can still develop into an incident if organizations can’t contain it or thwart it.

The same nuance applies to automation functions. According to our research, 72% of technology leaders said AI-driven automation plays a protective role against DNS and similar attacks. But as mentioned earlier, cybercriminals also use AI to launch and scale dangerous and widespread threats.

For executives, the takeaway is straightforward: AI may dominate cybersecurity discussions, but it hasn’t replaced the importance of domain and DNS security. Instead, the two should now coexist in the same threat environment. While AI is changing how attacks are launched and detected, domains and DNS remain key infrastructure targets and protective barriers.

The foundations of digital trust haven’t become less important. But they have become easier to overlook.

Download The CISO Outlook 2026 report for the full findings.