Velkina
Velkina / Insights / How company websites actually die

2026-08-18 · Ömer Can Nalbant

How company websites actually die

Almost none of it is technical. The failure modes are administrative, they are all preventable in an afternoon, and they are nobody’s explicit job.

Ask why a company website went down and the expected answer involves hackers or an outdated framework. In practice the causes are duller and more preventable than that, and they repeat with striking consistency.

The expired card

A domain is on auto-renew. The card on file expires. The renewal fails silently, notices go to an address nobody checks — often one on the domain that is about to stop working — and the name lapses. The company discovers it when email stops.

Auto-renew is not a control unless someone verifies the payment method annually. Register for multiple years and put the expiry in a calendar that has nothing to do with the registrar.

The account in someone else’s name

The domain is registered to the agency that built the site, or to a developer who left two years ago, or to a personal address nobody can access. Everything works fine until the relationship ends or the person becomes unreachable, at which point the company discovers it does not own its own name.

Recovering a domain from an uncooperative or absent registrant is slow and sometimes impossible. The fix costs nothing at the start and is expensive later: register everything in the company name, with a company email and company payment details, from day one.

The DNS nobody wrote down

Mail routing, verification records, subdomain delegations — these accumulate over years, each added by someone solving a problem, none documented. Then a migration happens and email stops for two days because a record nobody knew about was not carried over.

A DNS zone export takes one minute and belongs in the company’s files, not only in a provider’s dashboard.

The certificate that was manual

Most TLS certificates renew automatically now, which is why the ones that do not are dangerous: nobody is watching them. A manually-issued certificate on an internal tool or a legacy subdomain expires, browsers refuse the connection, and it takes half a day to work out why.

The single point of human failure

One person holds the registrar login, the hosting account, the analytics property and the ad accounts. They are not malicious; they are simply the only one. Then they change job, or go on leave during an incident, and the company is locked out of its own infrastructure.

Two people should be able to reach every account. That is the whole control.

The audit that takes an afternoon

  • List every account: registrar, DNS, hosting, email, analytics, ad accounts, code repository
  • For each: who owns it, who can access it, and what payment method it is on
  • Confirm the registrant on the domain is the company, not a person or a supplier
  • Check every card on file is in date
  • Export the DNS zone and store it outside the provider
  • Make sure at least two people can reach everything

None of this is difficult and none of it is interesting, which is exactly why it does not get done. It is also, in our experience, the single highest-return afternoon a company can spend on its digital operations.

Start a conversation

Tell us what the system needs to do. We will tell you what it takes to build, and what it costs, before any work begins.

Office
Istanbul, Türkiye
Working languages
Turkish, English
Delivery languages
English, Turkish, Russian, German