Every phone call once went through a human operator: trusted, essential, and an obvious single point of failure. DNS, or the Domain Name System, is the internet’s switchboard equivalent. In Singapore and across Asia-Pacific, it facilitates web traffic. Every device asks DNS for directions before connecting to anything. Without it, nothing works. With it compromised, nothing is safe.
For years, most organisations have treated DNS as background infrastructure, quietly routing users where they needed to go. However, new guidance is calling for a change in how organisations manage DNS, recognising it as more than just a switchboard and instead as a piece of critical infrastructure.
The National Institute of Standards and Technology recently updated its guidelines (NIST SP 800-81r3) on how organisations should design and secure DNS, the first major revision in more than a decade. NIST frameworks are not formally mandated in Singapore, but they are widely referenced by enterprises aligning their security strategies and often inform how local organisations interpret requirements from the Cyber Security Agency of Singapore.
For technology leaders managing complex, cloud-driven environments, the update offers a clearer picture of how one of the internet’s most foundational, yet often overlooked, systems should be governed.
What attackers already know
DNS has not been a focal point for most IT teams, resulting in critical gaps that have not gone unnoticed by attackers.
Research from Infoblox has tracked thousands of threat actor clusters that made DNS central to their operations, not because it is the hardest system to break, but because it is among the most trusted and least scrutinised. Groups like “Hazy Hawk” and “Horrid Hawk” quietly claim abandoned or poorly maintained domains and repurpose them for malware distribution and credential theft. Others, like “Loopy Lizard,” register lookalike domains, slight variations on legitimate names, to intercept traffic meant for trusted organisations.
None of this is sophisticated; it just requires organisations to leave their switchboard unattended.
While contributing to the updated NIST guidance, what struck me most was not the technical complexity of what needed to change. It was how simple the oversights were. The attacks exploiting DNS are structural failures: domains left unclaimed, configurations left unchecked, and monitoring that was never set up in the first place. The operators had walked away from the switchboard, and nobody had noticed.
The view from the middle
What makes DNS useful to both attackers and defenders is where it sits.
Modern networks stretch across cloud platforms, SaaS tools, remote devices, and distributed offices. There is no single perimeter to defend anymore. Traffic flows in every direction, and visibility has not kept up.
DNS is in the middle of it all. Every device must query DNS before it connects to anything. That makes it the one consistent vantage point across otherwise fragmented infrastructure. A switchboard that logs every call, wherever it originates.
The updated NIST guidance recognises this. Where previous versions treated DNS as an infrastructure concern, the new publication positions it as both an information source and an enforcement point. Malicious destinations can be blocked before connections are established. Threat signals can feed into detection workflows. Security policy can be applied the moment a connection is requested, before anything bad has happened.
This is a different job than the one DNS was originally designed to perform.
Acting upstream, not just faster
Security has long been measured by response time: how fast a threat is detected, how quickly damage is contained. That framing assumes something has already gone wrong.
Blocking a malicious domain at the point of DNS resolution is a different kind of action. The connection never happens, the malware never lands, and there is nothing to contain because there was no breach in the first place.
This matters even more in Singapore and across Asia-Pacific, where the pace of digitalisation has left many organisations’ security strategies playing catch-up. The updated NIST guidance aligns with the zero-trust principles that regulators and enterprise security teams increasingly expect. Unlike previous versions, it provides more concrete implementation guidance rather than broader principles.
Where to start
The updated NIST guidance is not asking for a rip-and-replace. It is asking organisations to address something they have been overlooking for years. Know what domains you own, know which ones have lapsed, and whether someone else has quietly claimed them. Understand where your visibility ends.
Most organisations already have what they need. What has been missing is the decision to treat DNS as something worth watching, not just as plumbing, but as a line of defence. Attackers decided to pay attention to DNS years ago. Will you?














