What dominates the section
- Cyberattacks, infrastructure failures and internet-routing weaknesses dominate the risk section for this critical internet infrastructure operator.
- Revenue is highly concentrated in the .com and .net registries, making agreements, pricing and ICANN decisions especially important.
- Regulation, registrant-data requirements and internet-governance changes could raise costs or constrain operations.
The risks most specific to Verisign
Attempted security breaches, including from the exploitation of vulnerabilities, cyber-attacks and Distributed Denial of Service (“DDoS”) attacks against our systems and services increase our costs, expose us to potentially material liability, and could materially harm our business and reputation
Frequent sophisticated attacks, including zero-day exploits, ransomware, social engineering and DDoS attacks, could disrupt services, increase costs and create liability.
We may introduce undetected or unknown defects into our systems or services, which could materially harm our business and harm our vendors or our customers
Undetected defects in Verisign’s complex systems could cause outages, expose DNS or customer data and trigger legal claims.
Our infrastructure and services are subject to vulnerabilities in the global routing system for the internet, as well as risks arising from internet services providers’ increasing adoption of the Resource Public Key Infrastructure system
BGP routing weaknesses and increasing ISP adoption of Resource Public Key Infrastructure could make Verisign’s internet services vulnerable to routing disruptions.
Our data centers, our data center systems, including the Shared Registration Systems located at our data centers, and our resolution systems are vulnerable to damage or interruption, which could impede our ability to provide our services, expose us to material liability, and materially harm our reputation
Concentrated data centers hosting the Shared Registration System and customer information could be disrupted by disasters, power loss or hardware failures.
We face risks from the operation of the root server system and our performance of the Root Zone Maintainer functions under the RZMA
Failures affecting the global root server system or Verisign’s Root Zone Maintainer functions could impair .com and .net authoritative services.
Any loss or modification of our right to operate the .com and .net gTLDs could have a material adverse impact on our business and result in loss of revenues
Losing or modifying Verisign’s rights to operate the .com and .net gTLDs could eliminate substantially all of its registry revenue.
Changes or challenges to the pricing provisions in the .com Registry Agreement could have a material adverse impact on our business
Challenges to .com pricing provisions could limit Verisign’s ability to raise annual registration and renewal fees by up to 7%.
New laws, regulations, directives or ICANN policies that require us to obtain and maintain personal information of registrants of domain names in the .com and .net gTLDs could impose material compliance costs and could create new, material legal and other risks to our business
GDPR, NIS 2 or similar rules requiring registrant information for .com and .net could create substantial compliance costs and legal risks.
Our business faces risks arising from ICANN’s consensus and temporary policies, technical standards and other processes
ICANN consensus policies and temporary policies could impose unfavorable requirements on Verisign as the operator of .com, .net and other gTLDs.
The evolution of technologies or internet practices and behaviors, the adoption of substitute technologies, or wholesale price increases of domain names in the gTLDs we operate may materially and negatively impact the demand for the domain names for which we are the registry operator
Social media, mobile apps, search engines and other substitutes could reduce demand for the domain names Verisign operates.
All 25 risk factors
Headings as the filing states them, in filing order.
Other
- 01Cybersecurity and Technology Risk Factors
- 02Attempted security breaches, including from the exploitation of vulnerabilities, cyber-attacks and Distributed Denial of Service (“DDoS”) attacks against our systems and services increase our costs, expose us to potentially material liability, and could materially harm our business and reputation
- 03agreements could be negatively impacted, and our ability to provide reliable service to our customers and the broader internet community could be impeded
- 04We may introduce undetected or unknown defects into our systems or services, which could materially harm our business and harm our vendors or our customers
- 05Our infrastructure and services are subject to vulnerabilities in the global routing system for the internet, as well as risks arising from internet services providers’ increasing adoption of the Resource Public Key Infrastructure system
- 06We could encounter system interruptions or system failures resulting from activities beyond our direct control that could materially harm our business
- 07Our data centers, our data center systems, including the Shared Registration Systems located at our data centers, and our resolution systems are vulnerable to damage or interruption, which could impede our ability to provide our services, expose us to material liability, and materially harm our reputation
- 08We face risks from the operation of the root server system and our performance of the Root Zone Maintainer functions under the RZMA
- 09Any loss or modification of our right to operate the .com and .net gTLDs could have a material adverse impact on our business and result in loss of revenues
- 10Changes or challenges to the pricing provisions in the .com Registry Agreement could have a material adverse impact on our business
- 11Government regulation and the application of new and existing laws in the U.S. and internationally may slow business growth, increase our costs of doing business, create potential material liability and could have a material adverse effect on our business
- 12New laws, regulations, directives or ICANN policies that require us to obtain and maintain personal information of registrants of domain names in the .com and .net gTLDs could impose material compliance costs and could create new, material legal and other risks to our business
- 13Our international operations expose us and our business to additional economic, legal, regulatory and political risks that could have a material adverse impact on our revenues and business
- 14Changes in, or interpretations of, tax rules and regulations or our tax positions may materially and adversely affect our income taxes
- 15Our business faces risks arising from ICANN’s consensus and temporary policies, technical standards and other processes
- 16Weakening of, or changes to, the multi-stakeholder form of internet governance could materially and adversely impact our business
- 17Claims, lawsuits, audits or investigations in which we are or could become involved may result in material adverse outcomes to our business
- 18Challenging global economic conditions have in the past and may in the future negatively impact our business
- 19The business environment is highly competitive and, if we do not compete effectively, we may suffer material adverse impact to our business, including lower demand for our products, reduced gross margins, and loss of market share
- 20The evolution of technologies or internet practices and behaviors, the adoption of substitute technologies, or wholesale price increases of domain names in the gTLDs we operate may materially and negatively impact the demand for the domain names for which we are the registry operator
- 21result in, a decrease in demand and/or the renewal rate for such domain names. In addition, if spending on online advertising and marketing is reduced, this may result in a further decline in the demand for domain names used for this purpose
- 22If we fail to expand our services into developing and emerging economies in international locations, our business may not grow
- 23Our business depends on registrars and their resellers maintaining their focus on marketing our products and services
- 24We depend on highly skilled employees to maintain and provide innovative solutions for our business, and our business could be materially harmed if we are not able to attract and retain such qualified talent
- 25We rely on our intellectual property rights to protect our proprietary assets, and any failure by us to protect or enforce, or any misappropriation of, our intellectual property could materially harm our business
Other Verisign 10-Ks
- 2026 10-K risk factors
29 risks. Verisign faces critical cybersecurity risks operating essential internet infrastructure like the .com and .net domains under strict regulatory oversight. The company depends heavily on ICANN policies, continuous registrar partnerships, and stable routing protocols to maintain business operations. Emerging threats include sophisticated AI-driven cyber-attacks and shifting global internet governance models.
Filed Feb 05, 2026
About this page
Item 1A of the 10-K on EDGAR was split into its risk factors and, where the company's previous 10-K is on file, each heading was matched to last year's and the text compared word for word. The headings are the filing's own. The one-line readings and the overview were written by a language model from the text of the new, dropped, and rewritten risks; they refer to risks by position and cannot misquote a heading.