
As artificial intelligence reshapes our digital landscape, one question is being asked with increasing urgency. What is the single most important thing a business can do to protect itself online in an AI-first world? My answer is always the same. Secure your domain. Everything else follows from there.
The internet is no longer just a supporting channel for commerce and communication. It is *the* channel. For billions of people, it functions like water or electricity, always on, always reliable, and always trustworthy. And just as we wouldn’t tolerate contaminated water or unstable power, we cannot accept a Domain Name System (DNS) riddled with vulnerabilities.
Security teams today have more tools, visibility, and support than ever before, and that’s a good thing, because the threat landscape has evolved dramatically. Bad actors are creating more sophisticated attacks that are more authentic looking, more customised and at machine speed, while defenders stay at human speed. This is a fundamental asymmetry that AI is creating.
Phishing campaigns that once required human effort can now be generated and deployed in seconds. Domain hijacking, DNS spoofing, and ransomware operations have become industrialised. The good news? So have the defences.
A recent report from the Corporation Service Company revealed that 67 per cent of Global 2000 companies have implemented fewer than half of their recommended DNS security measures.
Domain Name System Security Extensions (DNSSEC) authenticate DNS records, ensuring users reach legitimate destinations rather than impersonators. HTTPS encrypts connections end-to-end, safeguarding data in transit. Sender Policy Framework (SPF) and Domain-based Message Authentication, Reporting, and Conformance (DMARC) work together to authenticate email senders, which can reduce phishing and business email compromise, two of the most financially damaging attack vectors today.
These are not enterprise-only solutions. They are foundational controls that organisations of all sizes can and must implement. Whether you are a small retailer or a multinational bank, the vulnerabilities of an unprotected DNS are the same. The consequences differ only in scale.
What makes this moment particularly urgent is AI’s dual role in both amplifying threats and enabling defences. At Identity Digital, we are committed to fostering a secure and resilient internet, and combating DNS abuse is central to that mission.
One of the most effective strategies against DNS abuse is proactive monitoring, which uses real-time threat intelligence to flag and block malicious domain activity at the point of registration. Machine learning, combined with behavioural analytics, helps us detect suspicious domain patterns and take quick action.
But technology alone isn’t enough. The DNS ecosystem, composed of registries, registrars, law enforcement agencies, and governance bodies, must operate as a coordinated network. We collaborate closely with ICANN and other organisations to build policy frameworks that raise the security baseline across the entire ecosystem.
Technology may be a powerful shield, but the human element remains the most exploitable vulnerability. A workforce unable to recognise a spoofed domain or fraudulent email is a liability. Employee education must stand alongside technical controls as an equal priority, not an afterthought.
The internet’s evolution from novelty to essential utility has placed an enormous responsibility on those of us who build and maintain its infrastructure. In an era where AI accelerates both the sophistication of attacks and the pace of business, securing the DNS is no longer a technical afterthought. It is a foundational business imperative.
The question is no longer whether your organisation can afford to invest in DNS security. The question is whether it can afford not to.
Ram Mohan is Chief Strategy Officer at Identity Digital
Main image courtesy of iStockPhoto.com and Aree Sarak
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543