The Controls That Actually Prevent Hijacking
Most domain hijackings exploit a small set of predictable weaknesses: reused or weak account passwords, absent or SMS-based (rather than app- or hardware-based) two-factor authentication, registrar accounts without transfer locks, and DNS or registrar email accounts vulnerable to takeover. Registry lock — a registry-level control requiring out-of-band verification before any change to a domain's core records — is the strongest available protection for business-critical domains.
Portfolio-Level Governance
For organizations managing many domains, prevention is as much a governance problem as a technical one: consistent registrar choice, documented account-access policies, and regular audits of who has administrative access matter as much as any individual technical control.