Domain security

600x338-rid_98dabc55-db66-4859-a09c-a201d0e1c366.png

After a recent report found that poor domain security has left most Global 2000 companies vulnerable to the threats of phishing and brand abuse, we take a closer look at domain security and how businesses can maximise their protection against popular threats,

CSC Research – Domains Dangerously Under-Protected

Recent research by US-based CSC, which describes itself as “a world leader in business, legal, tax, and domain security” has shown that web domains of the Global 2000 companies remain dangerously under protected. The research revealed some worrying statistics, including:

81 per cent of companies are not using registry locks. Not using a registry lock means that (for example) a registrar could move your domain to another registrar on its own and/or the domain could be hijacked. 70 per cent of homoglyph (i.e. fuzzy match) domains are owned by third parties . This is a tactic known to be commonly used in phishing and brand abuse (refer ‘typosquatting’) . A homoglyph (name spoofing) attack uses processes or domain names that are visually similar to legitimate and recognised names to fool unsuspecting users, who may not notice a minor difference (e.g. Unicode characters from non-Latin character sets) in the domain name, into clicking on a malicious link. Only 50 per cent are using Domain-based Message Authentication, Reporting, and Conformance (DMARC) records as an email authentication method. 43 per cent are configured with MX (email) records that can be used to send phishing emails or to intercept email. 57 per cent of the Global 2000 are relying on off-the-shelf consumer-grade registrars who offer limited domain security mechanisms to protect against domain and DNS hijacking.

Also, the research found that among the 70 per cent of the third-party domains deemed suspicious:

56 per cent were pointing to advertising, pay-per-click content, or being used for domain parking (registering a domain name but not linking it to any services e.g., e-mail or a website). 38 per cent had inactive web content (there are technical problems, problems with the account, or they don’t have nameservers associated with them).

What Are The Main Risks and Threats To Domain Security?

Some of the main risks and threats to your domain security include:

Your registrar being compromised or hackers gaining access to your account with the company where you registered your domain name, or to the e-mail address that “reset password” forms on their websites send emails to. This can allow hackers to transfer the domain to another registrar, gaining complete ownership over it. Domain spoofing, used by phishers and malicious third parties to fool users into clicking onto domains that are visually similar to the legitimate domain e.g., Fuzzy matches/typo squatting, Homoglyphs – IDNs, Cousin domains, Keyword match, and Homophones (Soundex). Cybersquatting/brand jacking/name jacking i.e., the unauthorised registering and use of a domain name that is identical or similar to trademarks, service marks, company names, or personal names. In the US, this is a crime under the 1999 Anti-Cybersquatting Consumer Protection Act (ACPA). Sophisticated DNS attacks that can allow hackers to create confusion and redirect some of your website users to their servers. Reverse domain hijacking – i.e. whereby another entity deliberately registers something with the name of your domain/trademark and accusing you of stealing their domain. Not having DNS redundancy – i.e. a lack of a failsafe solution or a backup mechanism for DNS outages, such as having a having secondary DNS. A lack of DNS redundancy can leave the business open to threats like a reduced resiliency to DDoS attacks, and the associated problems of down-time, disruption to business continuity, revenue loss and diminished reputation. Not using certificate authority authorisation (CAA) records i.e., not designating a specific certificate authority (CA) to be the sole issuer of certificates for your company’s domains. Not using CAA could allow a cybercriminal to use the appointed certificate authority to get a new certificate and could represent a threat to compliance. Not authenticating the company’s email channel with DMARC, SPF, or DKIM. Sender Policy Framework /SPF, for example, enables a domain to state which servers can send emails on its behalf, and DMARC is an email validation system. Not authenticating the company’s email channel can leave the business open to threats like having the company’s email domain being used for email spoofing, phishing scams, and other cybercrimes. Not staying on top of matters relating domain renewals, thereby potentially allowing a company domain to be purchased and used by another party, perhaps for malicious purposes. Not having a security certificate (https). This protocol uses encryption to protects the integrity and confidentiality of data between the user’s computer and the site. The authentication aspect proves that users are communicating with the intended website, and can, therefore, protect against man-in-the-middle attacks and build/maintain user trust, not to mention improving the search engine profile and ranking.

What About GDPR Domain Masking?

The introduction of GDPR meant that the identity of a domain name registrant couldn’t be published in the public WHOIS database (without consent) and without the risk of penalties. This, however, is a two-edged sword, as it gives criminals more anonymity for registering domain names for malicious purposes, and can stop investigators and security professionals from uncovering dangerous/malicious/phishing website owners. There are, however, ways for cybercriminals and investigators to find out the identity of a domain owner.

How To Boost Your Domain Security

Despite significant potential domain security risks and threats, there are a number of measures that you can take to plug this potential gap in your business cyber security strategy. These measures include:

Choosing a professional, reliable, and reputable business-focused registrar. Authenticating your email channel with DMARC, SPF, or DKIM to minimise the incidence of email spoofing and potential phishing. Using enterprise-grade DNS hosting. This could mean consolidating your domain, DNS, and digital certificate providers into one enterprise-class provider. Incorporating secure domain, DNS, and digital certificate practices into the overall cyber security posture. Using a registry lock for your domain to prevent the risks of administrative and technical hijacking. Using domain privacy services and ensuring that WHOIS details are redacted. Ensuring that there is DNS redundancy (a failsafe/backup for DNS outages e.g., a secondary DNS). Adding CAA records to allow for policy enforcement and to mitigate cyber threats such as HTTPS phishing of hijacked sub domains. Buying security certificates for domains (https). Continuous monitoring of the domain space and key digital channels e.g., marketplaces, apps, social media, and email for any evidence of brand abuse, infringements, phishing, and fraud. Minimising third-party risk by looking at/auditing the business practices of the domain registrar to make sure they are not contributing to fraud and brand abuse e.g., through operating domain marketplaces, domain name spinning, and more. Maintaining good basic cyber security practices that can prevent hacks or accounts being compromised that could lead to domains being hijacked and more.

What Does This Mean For Your Business?

The security of your company domain(s) is an often overlooked part in the cyber security strategy of a business and yet, a domain is direct, public part of your brand and reputation that (if successfully attacked and compromised) could lead to huge technical, legal, monetary, and reputational damage to your business. Research, such as that by CSC, confirms that businesses are still taking big risks by not addressing domain security, and cybercriminals use domains as a key part of popular attack methods such as phishing.

There are, as outlined in the article, basic measures that businesses can take to make sure that their domains are protected, and that threats to domain security are addressed.

About Us

J700 Group are a Lancashire-based, family-run, professional and responsive, Managed Solutions Provider helping Businesses, the Education Sector, and the Healthcare Sector to utilise Innovative IT Consultancy Services, Cloud Solutions, Cyber Security, Microsoft 365, Telecoms, Web Design and SEO solutions to propel their organisation to the next level and beyond.

As an experienced IT Support Provider, helping businesses across Lancashire & Manchester, if you need any assistance with your IT including IT Hardware, a Disaster Recovery Policy or Managed Backup Solutions; Contact us today to see how we can help your business.

Enjoyed this? Read more from J700 Group Limited

Latest news

1

Net Zero Conference returns to help businesses meet green goals Net Zero Carbon Conference 24

Net Zero Conference returns to help businesses meet green goals

08 May 2024

2

Proposed 251-home development in Garstang approved 251 Homes Garstang Plan

Proposed 251-home development in Garstang approved

07 May 2024

3

Daisy to join with Wavenet to create £500m-revenue IT company Wavenet Head Office In Solihull

Daisy to join with Wavenet to create £500m-revenue IT company

07 May 2024

4

Why choosing independent ERP consultancy is important Gradient Bus Serv Independent.png.png

Why choosing independent ERP consultancy is important

07 May 2024

5

Do I need a nuptial agreement? Nuptial-Agreement-web.jpg.jpg

Do I need a nuptial agreement?

07 May 2024

Background image for hub sign up block

LBV Hub

Reach 50,000 members of the Lancashire business community

Post your news
Post your events
Post your offers
Company profile
Social reach
Magazine coverage
Sign-up
Events
Business Networking in Lancaster - Eden Business Network
EVENT LISTING Eden Business Network.png.png
LBV Hub Networking
08 May 2024

Business Networking in Lancaster - Eden Business Network

The Borough, 3 Dalton Square, Lancaster, LA1 1PP

18:30 - 20:30

Business Networking in Preston - BNI Diamond
EVENT LISTING BNI Diamond.png.png
LBV Hub Networking
08 May 2024

Business Networking in Preston - BNI Diamond

The Marriot Hotel, Garstang Road, Broughton, PR3 5JB

07:15 - 09:00

Achieving more with your money, your options at retirement
YOUR OPTIONS AT RETIREMENT.png.png
LBV Hub Seminars
08 May 2024 - 08 May 2024

Achieving more with your money, your options at retirement

PM+M Solutions for Business LLP, Blackburn, BB1 5QB

12:00 - 14:00

FREE online event - 30 Minutes: What is Net Zero 5 things you need to know
BU 2024 Events3.jpg.jpg
LBV Hub Webinar
08 May 2024

FREE online event - 30 Minutes: What is Net Zero 5 things you need to know

Online, Blackpool , FY4 1EW

10:00 - 10:30

Business Networking in Accrington - BNI Zeus
EVENT LISTING SIZING Zeus.png.png
LBV Hub Networking
08 May 2024

Business Networking in Accrington - BNI Zeus

The Mill House, Corn Mill Yard, Accrington, BB5 5HX

06:45 - 08:30

Sub36 Networking Event - Mrs Dowsons Farm
Sub36 Socialmrs Dowsons720px
Networking
09 May 2024

Sub36 Networking Event - Mrs Dowsons Farm

Mrs Dowsons Farm, Blackburn, BB2 7JA

15:00 - 17:30

Business Networking in Burnley - BNI Kudos
EVENT LISTING BNI Kudos.png.png
LBV Hub Networking
09 May 2024 - 09 May 2024

Business Networking in Burnley - BNI Kudos

Prairie Sports Village, Windemere Avenue, Burnley, BB10 2FU

06:45 - 08:30

30 Minutes: What is Net Zero - 5 things you need to know - FREE online event
BU 2024 Events3.jpg.jpg
LBV Hub Webinar
09 May 2024

30 Minutes: What is Net Zero - 5 things you need to know - FREE online event

Online, Blackpool , FY4 1EW

14:00 - 14:30

Business Networking in Lancaster - BNI Castle
EVENT LISTING BNI Castle.png.png
LBV Hub Networking
09 May 2024

Business Networking in Lancaster - BNI Castle

Vale of Lune RUFC, Powder House Lane, Lancaster, LA1 2TT

06:45 - 08:30

Business Networking in Preston - BNI Brunch
EVENT LISTING SIZING Brunch .png.png
LBV Hub Networking
10 May 2024

Business Networking in Preston - BNI Brunch

Samlesbury Hotel, Preston, PR5 0UL

09:30 - 11:00

Business Networking in Blackburn - BNI Infinity
EVENT LISTING BNI Infinity.png.png
LBV Hub Networking
10 May 2024

Business Networking in Blackburn - BNI Infinity

Hampton by Hilton, 2 Frontier Ave, Blackburn, BB1 3AL

06:30 - 08:30

Business Networking in Chorley - BNI Endeavour
EVENT LISTING SIZING Endeavour.png.png
LBV Hub Networking
14 May 2024

Business Networking in Chorley - BNI Endeavour

Oak Royal, Bury Lane, Chorley, PR6 8SW

06:30 - 08:30

Advertise with us

Reaching 50,000 members, our print, digital and event platforms offer a fantastic way to raise your business profile and help you grow.

Find out more Lbv115 Online Graphic
Subscribe now

Weekly news bulletin