Yatra.com down for 2 days due to delay in domain renewal


Newspapers reported that the travel web site Yatra.com was unavailable over the weekend from August 9th and came back on August 11th ( “Yatra.com’s inactive site impacts sales” The Hindu August 12, 2013). During this period users could not access yatra.com and instead were redirected to a generic domain registrar’s page with the message “domain has expired”. It is understood that the outage was due to its domain name expiring on 9th August 2013.

The website was unavailable for business and losses of around Rs. 20 – 30 crore in sales have been estimated by the media; after all it is one of the most widely used travel booking website in the country. In addition to the direct losses, there could also be reputation issues.

The domain name was renewed after 2 days on 11th August 2013 and web site came back online. The learning from this incident is that this is a key risk that often gets ignored. The consequences could be serious ranging from lost business to someone else appropriating the expired domain name. We suggest that risk managers consider website risks as one of the strategic risks and not just an IT risk.

Here are few takeaways to manage this very important risk.

• The domain name registrars require at least two contact names & their contact details (administrative & technical) so that renewal or other emails can be sent. These should be current at all times otherwise renewal mails may go to the wrong email addresses or to people who have left the company. Most companies (ex Yatra) have kept one name from IT for both administrative & technical contact. It is suggested that two separate individuals be mentioned, one of which could be one of the key executives such as CIO, CTO, COO or even the CEO so that registrar’s mails will get the right seriousness.

• The IT department should keep a list of all its domains and their renewal details. Domain names are assets and should be protect like other assets in the company. Expiries should be tracked along with other services, software, contracts renewals.

• All other risks connected with domain name & website should be included in the risk assessment and controls evaluated. Audit and other internal controls functions should get involved in auditing the controls.

Other Services of Interest

  • Assurance Services

    In Riskpro we believe that Internal audit function has to align its activities with business activities of any organisation to achieve its objectives. IA can be of significant value if it maintains...
  • Risk Based Internal Audit Services

    Why Internal Audit Matters In order to run your business, you develop processes to manage the factors that drive performance and help control internal and external risks that could prevent you from...
  • GDPR Training: India gets ready for GDPR

    Riskpro welcomes you to GDPR Training Background GDPR and privacy issues, along with infrastructure management and emerging technologies, rank as the top technology challenges organisations face...
  • Digital Forensic Services

    Riskpro has partnered with a specialist Digital Forensics Services firm to offer digital forensic services. This involves analysis of digital assets for specified objectives. Whether it is a...
  • COSO ERM 2017 - Know the risks that matter

    In risk management, the end goal is to manage the risks that matter, and not to manage all the risks that can exist. For this, a welcome update to COSO ERM 2017 is the shift from process based risk...
  • Automating Legal Compliance Management

    Never miss a compliance. Register by sending an email to info@riskpro.in
  • Cybersecurity Checklist - NIST Framework

    Riskpro has developed a cybersecurity checklist based framework to perform a self assessment of cyber risk preparedness. Please email info@riskpro.in to obtain more information on this.
  • Legal and Compliance Audits

    Regulations and legal / compliance burden is affecting organisations of all sizes and across industry sectors. The challenge to timely identify updates to regulatory changes and the time consuming...
  • Part time and Staff Augmentation

    With the Companies Act, 2013 placing a lot of importance on Audit, Risk...
  • Go to top