{"id":34251,"date":"2026-07-24T20:28:29","date_gmt":"2026-07-24T20:28:29","guid":{"rendered":"https:\/\/www.dotcom-monitor.com\/blog\/?p=34251"},"modified":"2026-07-24T20:28:29","modified_gmt":"2026-07-24T20:28:29","slug":"external-synthetic-monitoring-dora","status":"publish","type":"post","link":"https:\/\/www.dotcom-monitor.com\/blog\/external-synthetic-monitoring-dora\/","title":{"rendered":"External Synthetic Monitoring for DORA Operational Resilience"},"content":{"rendered":"

Operational resilience \u00b7 ICT risk management \u00b7 Financial services<\/em><\/p>\n

\"External
External synthetic monitoring verifies customer-facing services from outside the network perimeter, along the path a user follows.<\/figcaption><\/figure>\n

The Digital Operational Resilience Act (DORA), Regulation (EU) 2022\/2554<\/a>, has applied to European Union financial entities since 17 January 2025. Among its central objectives is the requirement that firms detect ICT (information and communications technology) incidents promptly and maintain the availability of services that support critical or important functions.<\/p>\n

Meeting that objective requires monitoring that reflects the actual availability of customer-facing services, not only the internal health of the systems behind them. Internal observability tools report on infrastructure from within the corporate network. They do not confirm whether a service is reachable and functional from the position of an external user. External synthetic monitoring addresses this by executing scripted transactions against production services from locations outside the network, on a defined schedule.<\/p>\n

This article identifies the specific DORA obligations that bear on continuous monitoring and detection, and sets out how external synthetic monitoring<\/a>, and the Dotcom-Monitor platform in particular, addresses each of them.<\/p>\n

DORA Detection and Availability Obligations<\/h2>\n

DORA is outcome-based rather than prescriptive about tools. It does not mandate a specific monitoring product or check frequency. It establishes obligations for detection, availability, and oversight, and monitoring is the operational control through which several of those obligations are met. Four provisions are most relevant.<\/p>\n

Article 9 (Protection and Prevention)<\/strong> requires financial entities to continuously monitor and control the security and functioning of ICT systems and tools. The obligation is continuous, which excludes periodic or manual checks as a sufficient control on their own.<\/p>\n

Article 10 (Detection)<\/strong> requires mechanisms to promptly detect anomalous activities, including ICT network performance issues and ICT-related incidents, and to identify potential material single points of failure. Article 10(2) further requires that detection mechanisms enable multiple layers of control, define alert thresholds, and include automatic alerts for the staff responsible for incident response.<\/p>\n

“Financial entities shall have in place mechanisms to promptly detect anomalous activities, including ICT network performance issues and ICT-related incidents.”
\nDORA, Article 10 (Detection)<\/cite><\/p><\/blockquote>\n

Articles 17 and 19 (Incident Management and Reporting)<\/strong> require a documented process for managing ICT-related incidents and, for incidents classified as major, notification of the competent authority on a regulator-set deadline measured in hours rather than days. The speed of that notification depends directly on the speed of detection.<\/p>\n

Article 28 (ICT Third-Party Risk)<\/strong> requires entities to manage and monitor the risk arising from ICT third-party service providers. Where a provider supports a critical or important function, its availability falls within the entity’s monitoring responsibility.<\/p>\n

From these provisions, five monitoring capabilities are required: continuous monitoring, prompt incident detection, availability validation, third-party ICT oversight, and early warning of service degradation. The sections below address each in turn.<\/p>\n

The Role of External Verification<\/h2>\n

Internal tools, including application performance management (APM), server metrics, and log analysis, observe systems from within the network. They report accurately on infrastructure state but do not detect a category of failures that occur between the user and the servers. These include:<\/p>\n