Yatra.com down for 2 days due to delay in domain renewal

SHRIRAM GOKTE)

Newspapers reported that the travel web site Yatra.com was unavailable over the weekend from August 9th and came back on August 11th ( “Yatra.com’s inactive site impacts sales” The Hindu August 12, 2013). During this period users could not access yatra.com and instead were redirected to a generic domain registrar’s page with the message “domain has expired”. It is understood that the outage was due to its domain name expiring on 9th August 2013.

The website was unavailable for business and losses of around Rs. 20 – 30 crore in sales have been estimated by the media; after all it is one of the most widely used travel booking website in the country. In addition to the direct losses, there could also be reputation issues.

The domain name was renewed after 2 days on 11th August 2013 and web site came back online. The learning from this incident is that this is a key risk that often gets ignored. The consequences could be serious ranging from lost business to someone else appropriating the expired domain name. We suggest that risk managers consider website risks as one of the strategic risks and not just an IT risk.

Here are few takeaways to manage this very important risk.

• The domain name registrars require at least two contact names & their contact details (administrative & technical) so that renewal or other emails can be sent. These should be current at all times otherwise renewal mails may go to the wrong email addresses or to people who have left the company. Most companies (ex Yatra) have kept one name from IT for both administrative & technical contact. It is suggested that two separate individuals be mentioned, one of which could be one of the key executives such as CIO, CTO, COO or even the CEO so that registrar’s mails will get the right seriousness.

• The IT department should keep a list of all its domains and their renewal details. Domain names are assets and should be protect like other assets in the company. Expiries should be tracked along with other services, software, contracts renewals.

• All other risks connected with domain name & website should be included in the risk assessment and controls evaluated. Audit and other internal controls functions should get involved in auditing the controls.

Other Services of Interest

  • GDPR - Data Privacy Trainings - Six Webinar on GDPR Anniversary - Riskpro

    GDPR turns ONE on 25 May 2019. On this Anniversary, lets explore what the last 12 months meant for global companies as it relates to Data Protection and Privacy. Riskpro India has organised 6 GDPR...
  • HIPAA Awareness Training (Mandatory) - Riskpro India

    EVENT OVERVIEW: HIPAA stands for the Health Insurance Portability and Accountability Act and is a US regulation that deals with security measures for protecting patient’s medical records. Employees...
  • SEBI's Insider Trading Amendment - Free Webinar by Riskpro India

    Another important compliance topic that kicks off today. SEBI Amendment to Insider Trading Regulations. Join us for an hour to learn the important changes and how to deal with these. Register -...
  • Sox Training

    Our sox training covers the following points. 1. What is SOX? 2. The Act and its Sponsorors. 3. The background for bringing in this act. 4. Major Sections in the Act 5. Section 404 overview 6...
  • EUC Risks : Manage Spreadsheet risks - Riskpro India

    EVENT OVERVIEW Uncontrolled and untested spreadsheet models pose significant business risks. These risks include: lost revenue and profits; mispricing and poor decision making due to prevalent but...
  • 1 Day AML Training by Riskpro India - Mumbai

    Training event in Bangalore on Anti Money Laundering (AML) and KYC “Are we doing enough to protect integrity of Indian financial sector?” Banks face growing costs to comply with AML requirements...
  • GDPR Countdown

    Riskpro is working hard so that clients can GDPR deadline as the clock ticks away.
  • EU-US Privacy Shield for Data Transfers

    Come GDPR (General Data Protection Act) and EU-US PRivacy shield will assume more importance. Privacy Shield Overview The Privacy Shield program, which is administered by the International Trade...
  • Reduce your GDPR implementation Costs - Hire GDPR Experts in India

    Reduce cost for GDPR Compliance - Remote Consulting from India GDPR readiness assessment and implementation can be costly. And time is short. Instead of paying premium fees to local GDPR consultants...
  • Go to top