

THE DIGITAL GOVERNANCE CASE FILES
True stories… or almost.
Situations inspired by real-life cases that shed light on the often-overlooked risks associated with digital assets, access, licenses, and responsibilities within organizations.

CASE FILE 002
The Domain Held Hostage
When an asset essential to the company still belongs to someone who no longer works there.
During an intervention requiring access to domain name management, the organization discovers that the account is still registered and administered in the name of a former employee.
The website, email services, and certain technical settings depend directly on this asset. However, the organization lacks the administrative control necessary to perform certain operations without the intervention of the previous owner.
ASSET CONCERNED
Domain Name and Web Infrastructure
GOVERNANCE ISSUE
Ownership and control of a critical digital asset
GOVERNANCE FINDINGS
An asset used by the company is not necessarily an asset controlled by the company. The absence of clearly established organizational ownership creates a dependency on an individual who is no longer part of the organization.
IDENTIFIED RISKS
Operational continuity
Difficulty or impossibility of intervening quickly on the domain, DNS or associated services.
Asset control
The organization does not have complete control over an asset that is essential to its operations.
Access security
Administrative privileges may remain associated with a person who should no longer hold them.
External dependence
Some interventions require finding or contacting the previous holder.
Traceability
Ownership, responsibilities, and access history can be difficult to establish.
RECOMMENDED MEASURES
The domain should be registered under the organization's control and integrated into its digital asset registry.
Administrative accounts, recovery methods, authorized personnel, registrar information, and technical dependencies should be documented.
A procedure for leaving and revoking access should also provide for the transfer of assets and privileges before the end of a relationship with an employee or supplier.
WHAT TO CHECK IN YOUR ORGANIZATION
☐ Who is the official owner of your domains?
☐ Which accounts allow you to manage them?
☐ Who currently holds administrative access?
☐ Do the recovery methods belong to the organization?
☐ Are the DNS and dependent services documented?
☐ Is there a transfer procedure when leaving?