Infrastructure. Asset. Identity. Three roles, one domain, zero accountability.
A domain is the cheapest line on your invoice — and at once your operational foundation, a traded asset, and your company's identity. Because three departments each see one face, no one owns all three
It is the cheapest line on your invoice.
A few dollars a year, filed under software subscriptions.
At most companies, no one can say from memory whose name it is registered under.
And it is the one line that can erase the company.
The foundation everything stands on
Start with what the domain name actually carries.
Your email runs on it. Your website resolves through it. Your single sign-on, your VPN, your customer logins, the certificates that tell a browser you are really you — all of it hangs from the same domain name.
It sits below the layer everyone watches. No dashboard tracks it, because a working domain produces no signal. It resolves, every millisecond, until it doesn’t.
Ask who renews it, and the honest answer is often a credit card that belonged to someone who left two years ago.
When the domain name stops, nothing degrades gracefully. Email stops. Logins break. Certificates turn invalid. All at once — because all of it was keyed to one name.
This is not hypothetical. In February 2019, ICANN, the body that coordinates the name system, warned of an “ongoing and significant risk” to key parts of the DNS infrastructure — an active campaign of attackers rerouting traffic by altering the records that sit beneath the name.
NIS2 elevates DNS providers and top-level domain registries to the EU’s highest tier of critical infrastructure oversight — alongside energy and banking — and extends cybersecurity obligations across the wider domain name ecosystem, including domain registration providers.
The domain is the foundation the building stands on, not the sign above the door.
The asset someone else can buy
Now look at the same name from the outside.
That cheap invoice line trades on a live, global market. At the end of 2025 there were 386.9 million domain names registered worldwide — a deep, liquid market where names are bought, sold, brokered, and parked. The number is enormous, but the scarcity that drives price sits in the few names that matter: the short, the memorable, or the one that is exactly yours.
In 2019 a single name, voice.com, changed hands for $30 million — the highest price ever publicly disclosed for a domain name.
The asymmetry is the whole point. The name costs almost nothing to hold and can be ruinous to lose.
Its value is not fixed to you. It is whatever the market — or a competitor, or an attacker — decides it is worth the moment you let go.
And letting go is not abstract. A missed renewal frees the name, and specialised firms watch the expiry queues to register the ones worth money the instant they drop, faster than any human could react.
You never sold the name. You let it lapse — and that difference is invisible until someone else is holding it.
The identity that is you
The third face turns a nuisance into a crisis.
The domain is not only what you run on and what you could sell. It is who you are.
To your customers, it is your brand. To a mail server, it is the proof that a message is really from you. To a login system, it is the authority that says an account belongs to you.
Control the domain, and you can be the company.
The password-reset link is the quiet one. Hold the name, receive its mail, and the reset links for everything else begin arriving in your inbox.
This is measured. In its 2024 Domain Security Report, the corporate registrar CSC found that 107 of the world’s largest public companies scored zero on the basic protection of their own domains.
Not weak. Zero.
And taking over your domain is only the direct route. The same report found that 80% of registered domains resembling a Forbes Global 2000 brand do not belong to that brand — and 42% of those lookalikes carry mail records. To send mail as you, an attacker often does not need your name at all. A close enough copy will do.
The blind spot on the org chart
Stack the three faces, and the real problem appears.
The infrastructure belongs to IT. The asset belongs to finance, or to legal, or to whoever signs the acquisition paperwork. The identity belongs to marketing and brand. One object, three natures, three different owners — each quietly assuming one of the others is watching it.
So it falls into the gap between them.
This is the part the industry itself admits. Authentic Web, a company that sells corporate domain management, describes the typical large enterprise plainly: domains handled across siloed departments, with “single-point accountability for the end-to-end domain management lifecycle” simply missing. Organisations, it notes, cannot clearly say who internally is responsible.
There is a whole industry of tools to close this gap. Mature, capable, and sold to exactly these companies — the best-resourced buyers on earth. And 107 of them still score zero, not because the fix is unaffordable, but because the job belongs to no one.
Which tells you the missing piece was never a tool.
The blind spot is on the org chart.
Who holds the key?
So this is what the cheapest line on your invoice actually is. The foundation your operation runs on. An asset someone else can take the instant you forget it. The identity that lets the world believe you are you. One name carrying all three, defended by no one in particular.
A tool can manage that name. It cannot decide who is responsible for it.
A tool is the second question. The first one is simpler, and harder.
In your company, who holds the key?
Magyar változat: [zona.hu/infrastruktura-vagyonelem-identitas-harom-szerep-egy-domain-nulla-felelos/]


