Akamai: DNS is still the most overlooked security control

Akamai has published a review of DNS as a security control, arguing that well-governed DNS matters more as both organisations and attackers adopt AI. The review covers six areas: dangling CNAME records and subdomain takeover, lame delegation and domain hijacking, look-alike domains, zone drift and data inconsistency, information leakage through exposed resource records, and missing DNSSEC alongside unencrypted DNS traffic.

What this means for your organisation

DNS is infrastructure almost nobody formally owns, and it is usually managed by a mix of IT operations, marketing and external agencies. A forgotten subdomain from an old campaign can be taken over and used for fraud in your name, and a look-alike domain hits your customers without leaving a trace in your own systems. The result is reputational damage and fraud happening outside the perimeter you actually monitor.

Berigo recommends

  • Build a complete inventory of every domain and subdomain the organisation owns, and assign ownership to a named person.
  • Review your DNS zones for records pointing at services you no longer use, and remove them.
  • Enable DNSSEC for your domains and require encrypted DNS where your platforms support it.
  • Monitor registrations of domains resembling your own so fraud campaigns surface early.

Source

Related services

Security that is understood, governed and works.

Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.

Get in touch