Identity Digital Seeks Cybersecurity Reporting Exemption for Domain Registries

Ensuring a Secure Digital Ecosystem: The Case for Centralized Cyber Incident Reporting in the Domain Name Industry

Picture of manilla file folders, with one in front labeled "cyber incident"

The digital landscape is constantly evolving, with cybersecurity threats becoming increasingly sophisticated and pervasive. As governments worldwide intensify their efforts to protect critical infrastructure from cyberattacks, a crucial debate has emerged concerning the most effective and appropriate methods for cybersecurity incident reporting, especially within the unique ecosystem of the Domain Name System (DNS). At the heart of this discussion is a compelling proposal from Identity Digital, a leading domain name registry business, advocating for a specialized carveout for domain name registries and registrars. Their argument is clear: these entities should report cyber incidents directly to ICANN (Internet Corporation for Assigned Names and Numbers), the global multistakeholder organization overseeing the DNS, rather than to individual national governments.

This perspective seeks to harmonize national security imperatives with the inherently global and interconnected nature of the internet. It highlights the potential pitfalls of fragmented reporting regimes and champions a unified approach that leverages existing global governance structures to enhance overall online security and resilience. The implications of this debate extend far beyond mere administrative procedures; they touch upon the foundational principles of internet governance, global interoperability, and the future of the digital economy.

Navigating the Evolving Regulatory Landscape: CIRCIA and NIS2

The impetus for Identity Digital’s proposal stems from a growing wave of national cybersecurity legislation. In the United States, President Biden signed the Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA) into law in March 2022. This landmark legislation mandates that covered entities, particularly those operating within critical infrastructure sectors, promptly report significant cybersecurity incidents and any ransom payments to the Cybersecurity and Infrastructure Security Agency (CISA). CIRCIA aims to provide CISA with timely intelligence to bolster national cybersecurity defenses and facilitate a coordinated response to major threats. While the intention behind CIRCIA is undeniably vital for national security, its broad scope raises questions about its application to entities that are already subject to a global governance framework.

Similarly, across the Atlantic, the European Union has enacted the revised Network and Information Security Directive (NIS2), which came into force in January 2023. NIS2 expands the scope of its predecessor, NIS1, to include a wider range of essential and important entities, imposing stricter cybersecurity risk management requirements and more demanding incident reporting obligations. Like CIRCIA, NIS2 reflects a legitimate governmental concern for digital resilience. However, the proliferation of such national and regional regulations, while well-intentioned, presents a complex challenge for globally operating internet infrastructure providers like domain name registries and registrars. These entities find themselves potentially navigating a labyrinth of disparate reporting requirements, each with its own definitions, timelines, and reporting channels, leading to significant compliance burdens and potential inefficiencies.

Identity Digital’s Vision: A Centralized, Expert-Driven Reporting Mechanism

Identity Digital’s argument for an ICANN-centric reporting model is built on several key pillars, emphasizing efficiency, expertise, and the preservation of the internet’s global architecture. The company highlights that during the rulemaking process for CIRCIA, a carveout for ICANN itself was proposed. Extending this logic, Identity Digital asserts that domain name registries and registrars, which are integral components of the DNS managed under ICANN’s purview, should similarly be exempt from direct national government reporting requirements.

In its comprehensive comments submitted to the U.S. government, Identity Digital articulated its position with clarity and conviction:

…Instead of these piecemeal reporting regimes that apply only to those domain name registries and registrars within their jurisdiction, ICANN, as a global multistakeholder organization that already maintains a robust compliance program with domain name registries and registrars, is better positioned to establish and monitor domain industry cyber incident reporting. An ICANN-managed reporting scheme would ensure that domain name registries and registrars, wherever they operate, are subject to standardized reporting obligations and maintained by a group with relevant experience and expertise. The reporting under such a program would be tailored to ensure the collection of the information most relevant to the DNS industry and the unique threats it might face…

This powerful statement underscores the core of their proposal. Identity Digital posits that ICANN’s established role as a global coordinator for the DNS makes it uniquely qualified to manage cyber incident reporting for its regulated entities. ICANN already oversees a stringent compliance program for registries and registrars, encompassing various operational and contractual obligations. This existing framework provides a solid foundation upon which to integrate a specialized cyber incident reporting mechanism. Such a system would capitalize on ICANN’s deep understanding of the DNS infrastructure, its operational nuances, and the specific types of cyber threats that target domain names and related services.

Furthermore, an ICANN-managed approach promises standardization. In a global industry where registries and registrars operate across multiple jurisdictions, a unified reporting framework would eliminate the inefficiencies and potential conflicts arising from diverse national requirements. This standardization would not only streamline compliance for businesses but also ensure that the collected data is consistent, comparable, and actionable on a global scale. The expertise within ICANN and its associated community of technical experts is unparalleled in understanding the intricate workings of the DNS. This collective knowledge would enable the design of a reporting scheme truly “tailored to ensure the collection of the information most relevant to the DNS industry and the unique threats it might face,” leading to more effective threat intelligence and response capabilities.

Preserving the Multistakeholder Model and Global Internet Interoperability

Beyond the practicalities of reporting, Identity Digital’s argument carries a profound message about the fundamental principles governing the internet. The company expresses significant concern that direct governmental regulation of the DNS, including its critical components like domain name registries and registrars, could inadvertently undermine the internet’s long-standing multistakeholder governance model. This model, characterized by the collaborative participation of governments, civil society, the private sector, and technical communities, has been instrumental in fostering the internet’s open, free, and interoperable nature.

Identity Digital articulates this concern vividly:

When governments act to directly regulate the DNS, including domain name registries and registrars, the DNS and the internet become more fractured. The interests of the United States are best served by an open, free, interoperable internet governed by ICANN’s multistakeholder-developed policies and regulations.

The “fractured internet” scenario is a serious warning. If each nation or regional bloc imposes its own distinct regulatory framework on the foundational layers of the internet, it could lead to a balkanization of the digital space. This fragmentation might manifest in inconsistent data handling policies, varying access restrictions, and differing security standards, ultimately hindering global communication, commerce, and innovation. An internet where different parts operate under different, potentially conflicting, rules would lose its essential character as a single, unified global network.

The United States, along with many other nations, has historically championed the principles of an open, free, and interoperable internet. These principles are not merely ideals; they are critical enablers of economic growth, democratic discourse, and global connectivity. Identity Digital’s argument suggests that allowing ICANN to manage cyber incident reporting for its regulated entities aligns perfectly with these broader strategic interests. By entrusting this function to a globally recognized, expert-driven body, governments can ensure that national security concerns are addressed without inadvertently destabilizing the very global infrastructure they seek to protect.

Strategic Implications and The Path Forward

The debate ignited by Identity Digital’s proposal transcends the technicalities of cyber incident reporting; it touches upon the delicate balance between national sovereignty and global internet governance. While governments have a clear and undeniable responsibility to protect their national critical infrastructure and citizens from cyber threats, the global nature of the internet demands a nuanced approach. Direct, unilateral regulation of core internet functions by individual states, without careful consideration for global interoperability, risks unintended consequences that could harm everyone.

A strategic path forward involves acknowledging the legitimate concerns of national security agencies while empowering existing global governance mechanisms. ICANN, with its established infrastructure, diverse stakeholder base, and deep technical expertise, represents a unique asset in this regard. By allowing ICANN to coordinate and standardize cyber incident reporting for domain name registries and registrars, national governments can benefit from consolidated, high-quality threat intelligence specific to the DNS, without imposing redundant or conflicting requirements on these global operators. This collaborative model would reinforce the multistakeholder approach, ensuring that the internet remains a unified, resilient, and open platform for future generations.

Ultimately, Identity Digital’s proposition is a call for smart governance – leveraging the right entities with the right expertise to address complex global challenges. It’s about ensuring that cybersecurity measures enhance, rather than impede, the global digital ecosystem that underlies so much of modern life. The decision on how to integrate global internet infrastructure providers into national cybersecurity frameworks will have lasting impacts on the internet’s structure and resilience.

For those interested in delving deeper into the specifics of Identity Digital’s comprehensive arguments and proposals, the full letter submitted to the U.S. government offers valuable insights and can be accessed via the link below:

The full letter is available here (pdf).