返回列表頁

Network Trust Is an Asset, Not a Tool: Building It into Enterprise Security Governance

  • 2026/09/07
  • 分類

    Development Community Cybersecurity

  • 瀏覽次數

    40

Network Trust Is an Asset, Not a Tool: Building It into Enterprise Security Governance

In most companies’ cybersecurity frameworks, domain names, DNS configurations, and routing information have long been treated as technical matters that the IT department simply needs to “set up properly.” Once certificates are installed and firewalls are in place, the job is considered done. This way of thinking is increasingly costing businesses dearly.

As the technical barriers to impersonation and cyberattacks continue to fall, a domain name that is treated merely as a “tool” rather than managed as an “asset” can easily become the first point of failure in brand trust. In an era of rampant fraud, enterprise security governance is no longer just about purchasing another cybersecurity appliance. It requires companies to rethink foundational infrastructure such as domain names and routing information through the lens of asset management.

TWNIC CEO Jo-Fan Yu noted, “Enterprises and organizations should regard their websites and domain names as digital assets, rather than merely as tools. If a tool is damaged or lost, it can simply be replaced. But once a digital asset is hijacked or impersonated, the organization risks losing consumer trust and suffering reputational damage that is difficult to quantify.”

When Threats Shift Toward a Company’s External-Facing Channels

In the past, enterprise cybersecurity focused largely on internal systems: whether firewalls were up to date, whether systems contained vulnerabilities, and whether employee accounts had been compromised. Yu has observed that, in recent years, the fastest-growing risks have actually emerged on the outward-facing side of enterprises—official websites and email, which serve as the main channels through which companies communicate with consumers, customers, and suppliers.

One key reason is that generative AI has dramatically lowered the barrier to carrying out impersonation attacks. Even people with limited technical expertise can now quickly create fake websites with highly similar designs and content. At the same time, consumers are finding it increasingly difficult to distinguish authentic websites from fraudulent ones. More and more people arrive at websites through AI tools or search engines, while ordinary users often find it difficult to tell whether a site is genuine or to scrutinize every character in a URL.

Once a corporate website is compromised or injected with malicious content, the company itself is not the only victim. Anyone visiting the website may be redirected to malicious pages, have their information stolen, and become the next victim. The security of a company’s public-facing website is therefore no longer simply an internal matter; it has become a broader issue affecting the entire chain of trust. Moving domain names from something users simply “trust” to something that can be verified and controlled is the first line of defense.

Turning Trust from Something Assumed into Something Verifiable

The first step in building consumer trust begins when a company chooses its domain name. The domain should have a clear and intuitive connection to the company’s brand and should be as short and memorable as possible. Long strings of English text or complex combinations of symbols that may confuse consumers should be avoided. The more complicated and unintuitive a domain name is, the more likely users are to mistype or confuse it, increasing the risk that they may visit a similar-looking fraudulent domain. Companies should also continuously monitor whether anyone has registered domain names that closely resemble their trademarks or brands, allowing them to identify and address potential abuse as early as possible.

The next step is to strengthen the technical protection of websites and email so that authenticity does not depend solely on user judgment.

DNSSEC can be understood as an anti-counterfeiting mechanism for the Internet’s “phone book.” Ordinary DNS resolution is like looking up a phone book to translate a domain name into its corresponding network address. Without an authentication mechanism, however, the contents of that “phone book” may be tampered with. When DNSSEC is enabled, validation is added at each stage of the lookup process, reducing the risk that altered DNS responses will go undetected.

In its early years, DNSSEC was relatively difficult to deploy because the available tools were less mature, while key management and configuration were more complex. Even minor mistakes could make a website inaccessible. Today, however, the tools are much more complete, and most DNS hosting providers support DNSSEC. In many cases, it can be enabled with a single click, significantly lowering the barrier to adoption. Even so, companies still need to take the initiative to turn the feature on.

At the routing layer, TWNIC continues to promote mechanisms related to RPKI. ROA, or Route Origin Authorization, can be thought of as a “route registration” made by the holder of an IP address block, specifying which ASN, or Autonomous System Number, is authorized to announce that IP block on the Internet. ROV, or Route Origin Validation, is the corresponding “route check” performed by the receiving network to determine whether a route announcement is legitimate.

Taiwan’s current ROA coverage has reached nearly 90 percent, making it a relatively mature area. The next priority is to encourage more network operators to deploy ROV validation mechanisms.

Yu also pointed out that verification mechanisms themselves have limitations. If domain settings can be changed freely or without proper controls, even the most comprehensive verification system may not be enough to protect the asset. TWNIC has therefore established additional control mechanisms that allow organizations to maintain greater visibility over the status of their domains. Registry Lock is one example.

Once Registry Lock is enabled, any change to a domain must first be communicated to the owner and can only be carried out after approval has been obtained, helping to prevent unauthorized modification or transfer.

Companies can also use TWNIC’s free self-check service at check.twnic.tw. By entering a website address, users can see whether protections such as HTTPS, DNSSEC, and Registry Lock have been enabled and use the results as a basis for further security improvements.

▲ TWNIC’s website security check service: check.twnic.tw

Yu noted that most of these basic measures do not require major additional spending. The real key is a change in mindset among business owners.

“When you start treating your website as an asset rather than just a tool, the way you think about protection naturally changes. You begin to ask what condition that asset is currently in and whether it is being properly protected.”

Benefits Beyond Enterprises: From Outsourcing Governance to Green Domains

The benefits of these verification mechanisms are not limited to ordinary businesses. TWNIC’s “Green Domain” service, which began trial operations last year, was designed to address the needs of another group that must be trusted but often lacks the resources to build its own security safeguards, such as nonprofit organizations.

In recent years, Taiwan has seen many donation scams involving the impersonation of charitable organizations. Once people are deceived, they may also lose trust in the legitimate organizations being impersonated, which can in turn reduce their willingness to donate.

Through the Green Domain service, a nonprofit organization can complete verification of the domain registrant’s identity with TWNIC and then obtain a badge to display on its website. Members of the public can click the badge to view information about the domain’s actual registrant and confirm whether the website they are viewing truly belongs to the organization they intend to support.

The Green Domain service is available to enterprises and organizations that use .tw or .台灣 domain names. TWNIC plans to gradually expand promotion of the service to sectors including finance, logistics, and government agencies.

Another critical aspect of Internet security governance is clearly defining responsibility and accountability.

Because Taiwanese companies commonly outsource domain registration, website development, DNS configuration, and related tasks, Yu has identified several governance details that enterprises should address before entering into outsourcing arrangements.

First, domain names and related accounts should be registered under the company’s own name rather than under the name of an outsourced service provider. If the vendor controls the account, it may later become difficult for the company to prove that it is the legitimate owner or to regain control of the account.

Second, outsourcing contracts should explicitly require service providers to complete basic configurations such as DNSSEC, SPF (Sender Policy Framework), DMARC (Domain-based Message Authentication, Reporting, and Conformance), and DKIM (DomainKeys Identified Mail), and should also specify that future changes require the company’s approval.

Third, notification procedures and cooperation requirements should be clearly defined at the time the contract is signed, rather than waiting until an incident occurs only to discover that the two parties have different expectations.

Fourth, when a contract ends or the service provider changes, the company should require the outgoing vendor to fully return all access privileges and configuration information, avoiding any ambiguity over control or responsibility.

A Shift in Mindset: From Victim to Guardian of the Trust Chain

For enterprises, this entire governance approach begins with a shift in mindset.

Yu has observed that when companies experience a cyberattack, their first reaction is often to see themselves as the victim. Their website was compromised, their data was altered, and therefore they regard themselves as the injured party.

She believes, however, that this perspective is incomplete.

“If malicious content is planted on your website, the real victims are every user who passes through that website and trusts it.”

Once a company’s public-facing channel is compromised, the consequences do not stop with the company itself. They spread along the chain of trust to every visitor and every customer.

This is why domain and website security governance cannot be treated merely as an internal question of “who should be held responsible after something goes wrong.” Instead, companies need to proactively take on the role of protecting the trust chain.

Trust Is Also an Asset—and It Requires Long-Term Protection

Yu emphasized that as Taiwan continues to advance toward greater digitalization and AI adoption, trust in the Internet is an essential form of infrastructure that cannot be ignored. Without trust, further digital development will be difficult to sustain.

She also warned that if the broader environment becomes saturated with fraud, people will become suspicious of every link and every email and will hesitate before clicking anything. In the long run, the impact will extend beyond individual companies and may constrain the growth potential of Taiwan’s digital economy as a whole.

▲ TWNIC CEO Jo-Fan Yu

Going forward, TWNIC will continue to advance several areas of work: promoting Internet governance concepts among enterprise IT professionals and business leaders, sharing issues observed on the front lines, helping the public develop basic skills for identifying authentic and fraudulent domain names, and continuing to provide tools for website security checks and domain verification and management so that companies can quickly assess the state of their own defenses.

Building a trustworthy Internet environment has never been something that a single organization or company can accomplish alone. It requires collective effort.

The more trustworthy the overall environment becomes, the easier it will be for companies to do business and to develop new services and technologies, because users will be more willing to place their trust in them. Conversely, once trust is exhausted by repeated incidents, the damage is ultimately borne by the digital environment on which everyone depends.

返回列表頁
域名
申請
IP/ASN
申請
客服
機器人
TOP