Business Wire

DE-CSC

15.11.2022 15:01:43 CET | Business Wire | Press release

Share
2022 CSC Domain Security Report Finds Nearly Three Quarters of Global 2000 Companies are at Alarmingly High Risk of Exposure to Security Threats

CSC, an enterprise-class domain registrar and world leader in mitigating domain and domain name system (DNS) threats, today released its third annual Domain Security Report that found three out of four Forbes Global 2000 companies have not adopted key domain security measures—exposing them to high risk of security threats. These companies have implemented less than half of all domain security measures.

In addition, lookalike domains are targeting those companies as well—with 75% of homoglyph registrations being registered to unrelated third parties. That means many of the world’s largest brands contend with maliciously registered domains that look like their brands. The intent of these fake domain registrations is to leverage the trust placed on the targeted brand to launch phishing attacks or other forms of digital brand abuse, or IP infringement that leads to revenue loss, traffic diversion, and a diminished brand reputation. Homoglyph domains are just some of the endless domain spoofing tactics and permutations that can be used by phishers and malicious third parties.

Additional key takeaways from CSC’s research include:

  • 137 companies (6.8%) had a domain security score of “0”
    Not deploying any of the recommended domain security measures puts these companies at risk for a variety of attacks, including but not limited to domain and DNS hijacking attacks, network and data breaches, phishing and ransomware attacks, and business email compromise (BEC).
  • 45% of companies that use enterprise-class domain registrars also deploy registry lock
    Registry lock is a highly cost-effective means to protect domain names against accidental or unauthorized modifications or deletions. Only 5% of companies that use consumer-grade registrars have registry lock deployed. Additionally, only six organizations within the Global 2000 had the highest overall domain security score, which correlates with their use of an enterprise-class registrar.
  • DMARC is the only domain security measure with significantly increased adoption this year
    Given all the news about phishing attacks—including their increase in volume and complexity—it’s no surprise that domain-based message authentication, reporting, and conformance (DMARC) adoption has increased by 12 percentage points in the last 12 months. However, growth in other domain security measures, such as registry lock, domain name system (DNS) redundancy, DNS security extensions (DNSSEC), and certificate authority authorization (CAA) records saw limited increases year-over-year.

“This report shows that while some progress has been made, a majority of the companies listed in the Forbes Global 2000 are still overlooking full implementation of foundational domain security measures,” says Mark Calandra, president of CSC’s Digital Brand Services. “A focus on securing legitimate domains while monitoring for malicious domains in parallel needs to be a bigger priority for companies that are advocating for a Zero Trust model to stay protected and thwart cyber risk. Otherwise, companies are exposing themselves to significant enterprise risks that can impact their cyber security posture, data protection, intellectual property, supply chains, consumer safety, revenue, and reputation.”

CSC’s report also found that 82% of the third parties registering homoglyph domains are actively masking their identity. This demonstrates the attempt to hide their ownership, showing they may have some nefarious intentions. Additionally, 48% have MX records in 2022, compared to 43% in 2021. MX records can be used to send phishing emails or to intercept email.

To learn more about CSC’s approach to domain security, visit cscdbs.com. Download the Domain Security Report now at cscdbs.com/securityreport.

About CSC

CSC is the trusted security and threat intelligence provider of choice for the Forbes Global 2000 and the 100 Best Global Brands® in enterprise domain names, domain name system (DNS), digital certificate management, as well as digital brand and fraud protection. As global companies make significant investments in their security posture, CSC can help them understand known cybersecurity oversights that exist, and help them secure their online digital assets and brands. By leveraging CSC’s proprietary technology, companies can solidify their security posture to protect against cyber threat vectors targeting their online assets and brand reputation, helping them avoid devastating revenue loss, and significant financial penalties because of policies like the General Data Protection Regulation (GDPR). CSC also provides online brand protection—the combination of online brand monitoring and enforcement activities—taking a holistic approach to digital asset protection, along with fraud protection services to combat phishing. Headquartered in Wilmington, Delaware, USA, since 1899, CSC has offices throughout the United States, Canada, Europe, and the Asia-Pacific region. CSC is a global company capable of doing business wherever our clients are—and we accomplish that by employing experts in every business we serve. Visit cscdbs.com.

To view this piece of content from cts.businesswire.com, please give your consent at the top of this page.

View source version on businesswire.com: https://www.businesswire.com/news/home/20221115005251/en/

About Business Wire

Business Wire
Business Wire
101 California Street, 20th Floor
CA 94111 San Francisco

http://businesswire.com
DK

Subscribe to releases from Business Wire

Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.

Latest releases from Business Wire

ThreatAware Secures $25M from One Peak to Give Security Teams the Power to Build26.2.2026 11:00:00 CET | Press release

Bootstrapped to profitability and 100+ clients, ThreatAware launches its AI-powered security workspace that gives security teams the freedom to build exactly what they need. ThreatAware, the cyber asset management and cyber hygiene platform trusted by enterprises across sectors including retail, financial services, and energy, today announced it has raised $25 million in funding from One Peak, the growth equity firm specialising in high-growth software scale-ups. The investment will help ThreatAware scale its rapidly growing North American operations and accelerate its ambitious product roadmap, including the launch of ThreatAware's AI-powered security workspace. At the heart of ThreatAware's platform is its proprietary cyber asset management technology, which solves a problem most organisations don't even know they have. ThreatAware's data consistently reveals that, on average, 10% of devices accessing corporate networks go completely undetected by existing tools, while 30% of securit

Cyviz Unveils Containerized C2 Solution During HEIMDALL26.2.2026 11:00:00 CET | Press release

During Exercise HEIMDALL, organized by the Norwegian Joint Headquarters (FOH/NJHQ) this week, Cyviz is presenting its fully integrated, containerized solution for command, control, and collaboration environments. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260226587573/en/ From deployment to operations: Cyviz’ container‑based C2 solution demonstrated during Exercise HEIMDALL. James Munt, Sales Director from Cyviz, took part in the demonstration. The solution is designed for secure, standardized, and agile operations, enabling operators to fight at the edge with assured information and supporting faster decision-making, in line with the company’s strategic focus on the defense and security sector. The container solution has been developed in collaboration with Nordic Shelter, providing the container platform. The modular platform combines control room technology, visualization, and software into one integrated system. It’s

Infobip is Set to Launch AgentOS to Orchestrate Autonomous AI-Driven Customer Journeys at Scale26.2.2026 10:00:00 CET | Press release

New platform reinforces Infobip’s shift to AI-first customer experience in its 20th year Global AI-first cloud communications platform Infobip, which celebrates its 20th anniversary this year, is set to launch its AI-native fully managed solution AgentOS. The new platform builds on Infobip's recently launched AI Agents, the intelligent foundation for autonomous customer communications. AgentOS is a major step in Infobip’s evolution from communications platform to intelligent orchestration layer for the AI era, enabling businesses to move from campaigns and workflows to autonomous, goal-driven interactions. AI communication models enable autonomous customer communications, hyper-personalization and highly engaging content across multiple channels. However, AI agents need a unified view of all customer touchpoints to deliver such benefits. Businesses must eliminate data silos. Yet readiness is low. Few enterprise AI agent projects reach production due to unstructured data and internal ba

Vonage Brings Network Innovation to Mobile World Congress 202626.2.2026 09:33:00 CET | Press release

Vonage, part of Ericsson (NASDAQ: ERIC), is set to make an impact at Mobile World Congress (MWC) 2026, the connectivity industry’s most influential exhibition, taking place March 2–5 in Barcelona. Vonage’s presence will include product demos, thought leadership sessions, and ecosystem collaborations, showcasing how the Company is leading the transformation of mobile networks into the enterprise platform of the future. “The digital arena is undergoing a fundamental shift as mobile networks transform into platforms and redefine the enterprise technology stack,” said Neelam Sandhu, Chief Marketing Officer at Vonage. “Mobile World Congress is where possibilities turn into real-world applications, and we demonstrate the capabilities and intelligence embedded in mobile networks to developers and enterprises, showcasing how they are becoming engines of innovation for industries worldwide. I am excited for Vonage to be at the helm of the thought leadership conversation and to reveal our latest

KAYTUS Enhances KSManage with Full-Stack O&M Visibility for AI Data Centers26.2.2026 09:02:00 CET | Press release

KSManage is designed for next-gen AI data center, with four-level visibility across components, servers and cabinets, clusters, and AI jobs, and ensures the AI data centers’ high availability As AI data centers scale to support increasingly complex AI workloads, traditional IT monitoring can no longer provide the visibility required for reliable operations. KAYTUS, a leading provider of end-to-end AI and liquid cooling solutions, has significantly upgraded KSManage, introducing full-stack, four-level visibility across components, servers and cabinets, clusters, and AI jobs, to address the challenges of complex troubleshooting, higher component failure rates, intricate application dependencies and delayed responses to operations and maintenance (O&M) incidents generated by demanding AI data center operations. The enhanced platform enables precise fault localization, faster incident response, and proactive operations. With KSManage, KAYTUS helps customers maximize availability, improve o

In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.

Visit our pressroom
World GlobeA line styled icon from Orion Icon Library.HiddenA line styled icon from Orion Icon Library.Eye