Support & operations · Practical guide

Distinguish a blocked monitor from a public website outage

The alert reports an outage even though ordinary visitors can reach the site. The probe receives a security challenge.

Healthcare website support desk with a system checklist, telephone and orange notebook.
Know who to call and what help your support arrangement includes.

What to change

Compare the monitor's response with an authorised ordinary visitor request before declaring a public outage. Ask the host to identify the relevant security rule and the monitoring service's documented request behaviour. A narrowly scoped approved adjustment may be appropriate, but retain protection against unwanted traffic. Also consider whether the check's method realistically represents the public task. Preserve the distinction between monitor accessibility and visitor availability in incident reporting.

A worked example

Illustrative example

Illustrative test: The authorised probe succeeds while the intended security protections remain effective. A monitor may receive a challenge while an authorised ordinary browser opens the same guide. The hosting owner identifies the matching rule and tests an approved targeted adjustment using the provider's documented behaviour. Intended protection remains in place. The incident record states whether the issue concerned monitor access or wider visitor availability, avoiding both an exaggerated outage claim and a broad firewall shutdown simply to silence one check.

Healthcare website maintenance with infrastructure, a status panel, tools and an operational checklist.
Monitor the useful journey, not just whether a server responds.
Healthcare backup and recovery illustrated by storage copies, an archive folder and a restoration route.
Test whether a backup can restore a usable service.

What this means for your practice

A security challenge may stop the monitoring service while ordinary visitors can still use the page. Compare the exact monitor response with an authorised public visit before declaring a general outage. Ask the host to identify the relevant rule and the monitoring provider's documented request behaviour. If an adjustment is appropriate, keep it narrowly scoped and preserve intended protection. Also review whether the check represents the public task realistically. The report should state the distinction between monitor access and visitor availability, rather than hide the alert or disable the whole firewall. Useful monitoring depends on understood access assumptions as well as a working notification channel.

How to check the result

The monitoring result and its access assumptions are documented.

A mistake to avoid

Disabling the whole firewall to silence one alert creates unnecessary exposure.

Turn reading into a next step

Your action checklist

Work through these checks with your team or supplier. Tick the ones you have resolved and leave unknowns open.

Checks to discuss

Record what you know, what is still missing and the answer you need from your team or supplier.

Use project decisions only, without personal, patient or confidential details. Entries stay in this page and are not submitted to Kay & Co. Copy or download before leaving; this page does not save your notes.

Further reading

These sources provide background for the topic. The practice examples and checklist are illustrative planning suggestions from Kay & Co.

Related guides

Need help with this?

Tell us what is getting in the way. Kay & Co. can help you understand the options and turn the next step into something that works for your practice.

Explore support & operations services or discuss your project.

Try the free Healthcare Digital Planner to find your starting priority.