September 2026 - Domains | Data Sovereignty

Digital Sovereignty Has a Governance Gap in Your Domain Portfolio

Daniel Strauß, CEO of InterNexum, argues that digital sovereignty depends on clear domain ownership. Drawing on 2.7 million DomainSecurity Audits across more than 475,000 domains, he shows why governance matters.

Digital Sovereignty Has a Governance Gap in Your Domain Portfolio-web

AI generated image

Nothing has happened for 30 years, so we must be safe

“A company has run its domains for 30 years, nothing has visibly gone wrong, so the assumption is that nothing ever will. I hear some version of that claim almost every week. It is one of the most dangerous assumptions in corporate IT, and almost never the result of an actual check. More often, it rests on trust in a provider that was never asked to report back.”

That gap between self-image and reality shows up in eco’s own data too. In the association’s 2025 IT Security Survey, more than half of companies rated their own security as good or very good, while around three-quarters said German businesses generally remain inadequately prepared.

Three statistics: 88% rate the threat level as high or very high, 75% say German businesses are generally not prepared, and 500,000 domains were analyzed in InterNexum’s audits.

The question came up at a panel discussion on ‘digital sovereignty’ at eco Interaction Day 2026. Together with registry and registrar leaders and the BSI’s Caroline Krohn-Atug, I found that, despite approaching the issue from different angles, we kept coming back to the same conclusion. SPF, DKIM, DMARC, DNSSEC – none of these technologies is new or exotic, and none of them require us to wait for a breakthrough. What is often missing inside companies is something more basic: clear responsibility for putting them to work. Most companies don’t have a tooling problem. They have an ownership problem.

The seatbelt was never the problem

When I speak about who is actually responsible for domain security, I use a comparison that tends to land better than any chart of risk scores. A carmaker builds the seatbelt and makes sure it works. The driver still has to buckle it. Nobody expects the manufacturer to reach into the car and do that for you.

Domain security runs on the same logic. Registries and providers can hand a company DNSSEC, DMARC policies, and monitoring dashboards. Whether anyone actually reads the reports, sets the policy to reject, and revisits it after an org change is a management decision, not a product feature. A security mechanism nobody owns is not protection. It is a line item nobody checks. That is why “just automate it” is not an answer I can give a client. A script cannot decide to care about the outcome.

Prophylactic domains are a phishing trap

Here is a pattern that shows up in nearly every audit we run. Companies register dozens, sometimes hundreds, of domains purely to keep a competitor or a scammer from getting hold of something close to their brand. But the security measures that regulation increasingly treats as standard are often applied to just one of them: the main website.

Everything else sits parked, officially registered under the company’s name, and completely unmonitored. That combination, ownership without oversight, is precisely what makes these domains such an efficient phishing vector. An attacker does not need to create a convincing lookalike if a genuine company-owned domain is already sitting there unguarded. This is what happens when domain strategy and domain security sit with two different teams that rarely talk to each other.

A branded top-level domain is not a trophy

Part of the discussion focused on the current ICANN application window for company-branded top-level domains, where the brand sits to the right of the dot rather than the left. Done properly, that can be a real security gain: no one else can register a lookalike under your own extension, and DNSSEC and DMARC can be enforced across the entire namespace instead of managed domain by domain.

But a branded top-level domain is not a one-time purchase. The application alone costs roughly a quarter of a million dollars, and what follows is an ongoing legal and technical commitment: audits, contractual obligations to ICANN, and infrastructure that has to keep running long after the original project team has moved on. We saw after the 2012 application round what happens when companies apply without a clear use case and later discover how difficult and expensive it is to unwind the decision. An unused top-level domain does not sit quietly in a drawer. It keeps sending invoices.

What domain governance actually looks like

So what separates the companies that get this right from the ones we keep finding in our audits? In practice, it comes down to a few things.

Centralize ownership. Domain strategy cannot live half in marketing and half in IT, with security bolted on whenever someone has time. Legal, marketing, and IT all have a stake, and none of them can fix this alone. Someone needs to own the entire portfolio, including the domains nobody 

Give it a budget line, deliberately. Domain governance keeps losing out simply because nobody has ever assigned it a budget of its own. If security work depends on which department feels generous that quarter, it will not happen consistently.

Isolate risk with subdomains. Marketing campaigns and landing pages do not belong on the main corporate domain. Keep them separate so that, if a campaign page is compromised, the damage stays contained instead of spreading to the systems that carry your actual reputation.

Treat regulation as the floor, not the target. The NIS2 Directive is starting to turn domain-level security into a compliance obligation rather than a nice-to-have, and the BSI’s own TR-03108 guideline on secure email transport spells out what state of the art actually looks like technically. Waiting for an auditor to force the issue is not a governance strategy. It is a delay tactic.

Before your next board meeting, it is worth asking three questions out loud.

  1. Who owns our domain portfolio, not just the main site?
  2. When was DMARC last set to reject, and who verified it?
  3. And if we needed to shut down a rogue subdomain today, do we know who has the login?

Usable security and the cybernation

Caroline Krohn-Atug made a point that stayed with me more than any statistic. Technology, she argued, can never be judged outside the social context people actually use it in. Her department promotes what they call usable security, protection designed so an ordinary person, not just a specialist, can tell whether a digital space is trustworthy. She tied that back to what her president calls the Cybernation, a shared responsibility across government, business, and civil society to keep raising the baseline of digital trust together.

Domain governance is one of the more concrete ways a company can hold up its end of that responsibility. It is not a policy document. It is a person, a budget, and a recurring check.

The time to fix this is before the incident

None of this needs new technology. The protocols exist, the monitoring exists, and the regulatory pressure is only increasing. What is missing in most companies is a decision. Name someone accountable for the domain portfolio, fund the work, and check on it regularly instead of assuming thirty quiet years means the belt was never needed.

Digital sovereignty does not start with a bigger firewall. It starts with knowing, in writing, who owns every domain your company has ever registered – and who is checking on them this month.

 

📚 Citation: 

Daniel Strauß. (September 2026). Digital Sovereignty Has a Governance Gap in Your Domain Portfolio. dotmagazine. https://www.dotmagazine.online/issues/security-compliance-digital-sovereignty/domain-governance-digital-sovereignty

 

Daniel Strauß is Managing Director of InterNexum GmbH and founder of nicmanager. With more than 25 years of experience in the domain industry, he is recognized as one of the leading voices in corporate domain management and email security. As a lecturer and innovator, he helps organizations and public institutions strengthen digital trust and resilience through modern domain security and risk management strategies.

 

Daniel Strauß of InterNexum argues that domain governance means assigning clear responsibility for an organization’s entire domain portfolio, including security, monitoring, and maintenance. In his dotmagazine article, published by eco – Association of the Internet Industry, he presents this organizational accountability as a practical foundation for digital sovereignty.

According to Daniel Strauß of InterNexum, technologies such as DNSSEC and DMARC only provide effective protection when someone is responsible for configuring, monitoring, and reviewing them. His dotmagazine article, published by eco – Association of the Internet Industry, emphasizes that security mechanisms without clear ownership can remain unused or inadequately managed.

Daniel Strauß of InterNexum recommends centralized domain governance that brings together Legal, Marketing, and IT while assigning overall responsibility to a clearly identified owner. In his dotmagazine article, published by eco – Association of the Internet Industry, he also stresses the need for a dedicated budget and regular reviews of the complete portfolio.

Daniel Strauß of InterNexum explains that companies often register additional domains to protect their brands but may not apply the same security controls and monitoring used for their primary domain. In his dotmagazine article, published by eco – Association of the Internet Industry, he argues that these overlooked domains should remain part of the company’s active governance and security processes.

 

Please note: The opinions expressed in articles published by dotmagazine are those of the respective authors and do not necessarily reflect the views of the publisher, eco – Association of the Internet Industry.