top of page
Tissu délicat
Ombres douces

THE DIGITAL GOVERNANCE CASE FILES

True stories… or almost.

Situations inspired by real-life cases that shed light on the often-overlooked risks associated with digital assets, access, licenses, and responsibilities within organizations.

Illustration of a team in the office facing denied access to the company's domain name, still owned by a former employee who cannot be reached.
CASE FILE 002

The Domain Held Hostage

When an asset essential to the company still belongs to someone who no longer works there.

During an intervention requiring access to domain name management, the organization discovers that the account is still registered and administered in the name of a former employee.


The website, email services, and certain technical settings depend directly on this asset. However, the organization lacks the administrative control necessary to perform certain operations without the intervention of the previous owner.

ASSET CONCERNED

Domain Name and Web Infrastructure

GOVERNANCE ISSUE

Ownership and control of a critical digital asset

GOVERNANCE FINDINGS

An asset used by the company is not necessarily an asset controlled by the company. The absence of clearly established organizational ownership creates a dependency on an individual who is no longer part of the organization.

IDENTIFIED RISKS

Operational continuity

Difficulty or impossibility of intervening quickly on the domain, DNS or associated services.


Asset control

The organization does not have complete control over an asset that is essential to its operations.


Access security

Administrative privileges may remain associated with a person who should no longer hold them.


External dependence

Some interventions require finding or contacting the previous holder.


Traceability

Ownership, responsibilities, and access history can be difficult to establish.

RECOMMENDED MEASURES

The domain should be registered under the organization's control and integrated into its digital asset registry.


Administrative accounts, recovery methods, authorized personnel, registrar information, and technical dependencies should be documented.


A procedure for leaving and revoking access should also provide for the transfer of assets and privileges before the end of a relationship with an employee or supplier.

WHAT TO CHECK IN YOUR ORGANIZATION

☐ Who is the official owner of your domains?
☐ Which accounts allow you to manage them?
☐ Who currently holds administrative access?
☐ Do the recovery methods belong to the organization?
☐ Are the DNS and dependent services documented?
☐ Is there a transfer procedure when leaving?

KEY PRINCIPLE

A critical digital asset must remain under the control of the organization, regardless of the people who administer it.

bottom of page