TK Keanini, Field CTO, DNSFilter.

​A million books in a warehouse is a fire hazard. The same million books, cataloged and shelved, is a library. Nothing about the books changed. The organization changed, and organization is what unlocked the new capabilities of search, discovery, curation and policy. Organization is not tidiness; it is capability.

​There’s a second truth hiding in that library. Scale changes who can do the organizing. A hundred books, a person can shelve. A hundred million, and machines must do the work. And there’s a third truth that matters even more: When the collection changes by the second, organizing it once is meaningless. Only a continuous, automated strategy can keep up with something that dynamic. By the time you’ve finished organizing, it has already changed.

​The internet has exactly this problem, and it lives in the Domain Name System (DNS).

You Already Use DNS Every Day

If you have ever typed www.apple.com or www.google.com into a browser, you are already using DNS. That’s all it is: the internet’s naming system, translating a name a human can remember into a machine’s location.

​Underneath, DNS is a hierarchical namespace. Read www.apple.com from right to left: “com” is the top-level domain, “apple” is level two and “www” is level three. It is elegant, distributed and has scaled beautifully for four decades. But don’t confuse structured with organized.

There were an estimated 401.6 million registered domain names as of mid-2026—the first time the namespace has crossed the 400 million mark. Roughly 150,000 domains expire every day, and between 200,000 and 300,000 new ones are registered each day. This is the internet’s namespace, and while it is structured, it is not organized for functionality. Every building on earth has a structured address, but the address tells you nothing about what goes on inside.

What It Means To Organize The Internet

Organizing the internet means categorizing it continuously, automatically and at machine speed. Do that, and at least three capabilities fall out.

​1. Access Policy Becomes Possible

Suppose you want a policy that says, “Thou shalt only go to domain names relevant to your job role.” You certainly don’t want to implement that manually. You want to click a few categories and be done.

This is the only practical way to deliver a zero-trust access policy to your employees, devices, robots and AI agents. You set and manage the categories, not the domain names.

​2. Insight Becomes Possible

Want to see the top 1,000 most visited sites across your organization? Ranked, categorized views of DNS activity answer a question every executive should be asking: How does my company actually behave on the internet, day to day?

​3. Protection Becomes Possible

Categorize the internet by what is appropriate for a minor, and suddenly a school, a library or a household can express one intention—”This network is for children”—and have it enforced across hundreds of millions of domains.

​None of these capabilities exists at the level of the individual domain name. They only exist at the level of the category.

No One Needs The Whole Internet

Here is a general rule I stand behind: No person and no device needs access to every domain name on the internet.

​Attackers understand the churn better than defenders do. They stand up novel domains that are seconds old to deliver malware and phishing, and they are counting on you having access to them by default.

Research from Palo Alto Networks’ Unit 42 found that more than 70% of newly registered domains are malicious, suspicious or not safe for work. Research from my team at DNSFilter found that new domains accounted for nearly 40% of requests categorized as malicious.

​Automated organization turns this from an impossible problem into a simple one. Adopt a rule: Any domain name newer than 30 days is categorized as NEW. Then set one policy: None of your employees have access to NEW domain names.

The risk in blocking new domains is generally low, as most business sites that employees need to access should be live for at least 30 days. A block page that explains why and offers a path to request access catches the rest. If you need to make an exception, you can easily allow new domains on an as-needed basis. That’s the entire point of organization. It shrinks the problem to human scale while machines handle the rest.

The same discipline applies to category policy more broadly. Start in observation mode. A few weeks of monitoring will show you which categories each role uses. Build role-based profiles from that baseline. Then watch three signals: threat blocks, exception requests and help desk tickets. If exception volume keeps climbing in a single department, fix the role profile rather than accumulating one-off exceptions.​

AI agents create a new challenge by generating requests on equal footing with their human counterparts. An employee might hesitate at a suspicious page; an AI agent following poisoned instructions never will. Hold your non-human identities to stricter defaults. Give each agent only the categories its job requires; deny NEW and uncategorized domains outright; and keep human oversight wherever an agent can reach critical system domains.

The Directory Becomes The Policy Layer

The internet’s namespace is more than 400 million registered domains, churning by hundreds of thousands of names every day. No human team can organize that; only continuous, automated categorization keeps pace.

​DNS is no longer just a giant structured directory. It needs to be used as a directory with categories that let you set the right access policy for every employee, device and AI agent, and other categories that hand you intelligence about how your business interacts with the internet.

​A generation ago, Google and other search engines set out to organize the world’s information, and they largely succeeded. But that mission covered the web’s content, never its namespace. Structure gave us a way to find everything. Organization gives us a way to decide what we should reach, what we should block and what we should learn from the rest. That is what it means to organize the internet.

Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?

Share.
Leave A Reply

Exit mobile version