The cheapest security measures for a domain are also the most effective. Losing a domain is rarely a clever attack on your server. It is usually a stolen password, an expired card or an email account nobody was watching, and every one of those is fixable in an afternoon.
What follows is a short order of work. Do the first four tonight, and think about the fifth if the name pays your wages.
Lock the domain at the registrar
Enable registrar lock, which prevents transfers without an extra step. When it is on, requests to move the name to another registrar are refused until you unlock it yourself. Most panels show it as a simple switch. You can see the result in the status lines of a WHOIS lookup:
whois example.com | grep -i status
Domain Status: clientTransferProhibited
Many registrars also apply a 60-day transfer restriction after registration or after a change of registrant details. That is separate from the lock and is there to give you time to notice a hijack.
Protect the account that holds it
Use two-factor authentication on the registrar account. An authenticator app or a hardware key is better than text messages, because phone numbers can be taken over. Use a strong, unique password, ideally from a password manager, and never reuse the one from your email. The registrar account is the master key: anyone who gets in can unlock the domain, change the nameservers and point your site wherever they like.
Keep the transfer authorisation code private as well. Treat it like the password it effectively is, and do not send it by email unless you are in the middle of a move.
Keep the contact email current and reachable
Keep the contact email current and accessible. The registrar uses it for renewal notices, transfer approvals and verification. Put it on an address you read, ideally a role address rather than one tied to a single person, and keep it on a different domain from the one it protects. If the address lives on the domain and the domain lapses, the warning never arrives.
Registry lock for names that matter
If your registrar offers it, add a registry lock for important names. It is a stronger lock set at the registry itself, and changing it requires a manual, out-of-band verification, often a phone call to a named person, rather than a click in a panel. It costs extra and is not offered for every ending, so it fits a name that carries the business, not a hobby site.
Defensive registrations, in proportion
If you own a brand name, consider the obvious typos, plurals and common alternative endings, but do not go overboard. Registering fifty variations costs money every year and rarely changes the outcome. Registering the two or three that people actually mistype is a much better use of budget. Point them all at the main site with a 301, and turn on the same locks.
If it has already gone wrong
Signs of a hijack are a registrar email you did not expect, a changed nameserver, or the site suddenly showing someone else's page. Act in this order: change the registrar password and sign out other sessions, turn on 2FA, check the contact details, restore the nameservers, and then contact the registrar's abuse or support team with the time of each change. Speed matters, because a name moved to a new registrar can be harder to recover than one still in your account. Write the sequence into a note now, while nothing is on fire.
Common questions
Does WHOIS privacy protect the domain from theft?
It hides personal details from spammers, but it does not stop a transfer. The locks do that.
Will the lock block my own move later?
Only until you switch it off. Unlock, collect the code, start the transfer, and lock again at the new registrar.