What is a DDoS attack?
Recent government research shows that 43% of UK businesses identified a cyber security breach or attack during the previous year. Cybercrime takes many forms, and DDoS attacks are among the most disruptive. This article explains how they work and what you can do to protect your business.
Updated: 16.07.26
By
Phil Thorpe
DDoS stands for a distributed denial-of-service attack. It’s a type of cyberattack designed to stop the normal flow of internet traffic. Put simply, DDoS attacks send so much traffic to a targeted website that it crashes. Think of it as rush hour, when traffic becomes gridlocked.
How does DDoS work?
Criminals create a network of devices that they can control remotely. They will then instruct those devices to bombard the victim’s website with fake internet traffic, causing it to overload and crash.
The network of devices is called a Botnet, with each individual device known as a bot. Cybercriminals recruit bots for their Botnets by infecting them through malicious software (malware). These can then be directly controlled by the criminals. DDoS attacks aim to cause the business financial loss or reputational damage, demand a ransom, or distract from other cyberattacks.
It sounds like a science fiction plot, but it’s actually one of the simplest types of cyberattack. DDoS attacks are also hard to spot because fake traffic can’t easily be separated from real traffic.
Recent advancements in Artificial Intelligence have made this activity much easier and faster for criminals to undertake.
What happens during a DDoS attack?
If your business is under a DDoS attack, there are several warning signs to look out for. Not all of these will point to an attack; some may have innocent explanations, such as a spike in legitimate traffic. If you notice several at once, act immediately and notify your IT team or provider; ideally, this will be your cyber insurer, which will have appropriate experience and experts within their team to manage the situation.
Common signs of a DDoS attack:
Unusually slow network performance when loading websites or opening files
A website or service that becomes completely unavailable or unresponsive
A sudden and dramatic spike in traffic from an unusual source or with no obvious cause
Services that are intermittently available but extremely sluggish
Unresponsive or unreachable internal tools or applications
Unusual activity flagged in server logs or traffic monitoring systems
What are the different types of DDoS attacks?
DDoS attacks fall into one of three main categories:
1. Volumetric attack
As the name suggests, this type of DDoS attack floods the victim’s website with large amounts of traffic until it cannot cope.
2. Protocol attack
Instead of relying solely on the volume of fake traffic, these attacks disrupt normal network protocols.
These protocols are a little like conversational rules between computer networks. One such protocol, for example, is an initial handshake between networks. Normal protocols mean that device A calls device B, device B answers, and device A acknowledges the answer. The networks can then get on with business.
In a DDoS protocol attack, the last acknowledgement is never made, basically leaving device B hanging. When the Botnet overloads the victim’s network with unacknowledged protocols, the system simply collapses, impacting your ability to trade.
3. Application attack
These attacks aim to exhaust the victim’s web service to the point where it either slows down dramatically or comes to a grinding halt. It’s similar to a protocol attack, but instead of leaving the network hanging, it’s about making complicated requests that use up resources, for example, requesting access to a database or images. If the victim’s network is overwhelmed by the number of requests it receives, it falls over itself and stops working altogether.
A notable variant is the HTTP/2 Rapid Reset attack. This was first seen in 2023. Instead of relying on huge volumes of traffic, it overwhelms a target by opening and then cancelling large numbers of requests in quick succession. Because it exploits the way the protocol itself works, it can be harder for standard defences to spot.
Many DDoS attacks now use multiple methods simultaneously. An attacker might combine different types of attacks or switch between them to see which is most successful. That makes these attacks harder to detect, harder to stop, and more disruptive when they succeed.
How serious are DDoS attacks?
DDoS attacks have become more frequent (an average of 44,000 a day) and more intense in recent years. Research from technology provider Cloudflare indicates that it mitigated 47.1 million DDoS attacks in 2025 – more than double the previous year. Cyber security company NETSCOUT also recorded more than 8 million DDoS attacks worldwide in the second half of 2025 alone.
The impact on a business can vary widely. For some organisations, the main cost is disruption, lost staff time, and the expense of restoring systems to normal. For other businesses, especially those that depend heavily on websites, apps or customer portals, even a short outage can mean lost revenue, delayed service, and damage to customer confidence. Reputational damage often lasts longer than the attack itself.
In recent years, attacks have become larger and faster. One attack in late 2025 peaked at 31.4 terabits per second. It lasted for only 35 seconds. That short timespan creates a challenge in itself, as by the time a human analyst reacts, the attack may already be over. For this reason, automated detection and mitigation are increasingly important.
For a wider look at the cyber threats facing your business, our guide to identifying and mitigating cyber security risks is a useful starting point.
How to stop a DDoS attack
Complete prevention of DDoS attacks is difficult. This is partly because it can be hard to distinguish between real and fake traffic, especially during events such as sales or product launches.
Having said that, there are several steps you can take to reduce your exposure to attacks and limit the damage if one occurs.
1. Use a DDoS mitigation service
Specialist providers can absorb or filter large volumes of malicious traffic before it reaches your systems. Services such as Akamai Prolexic, Cloudflare, and ANS all offer dedicated DDoS protection products.
2. Put a response plan in place
It’s good practice to have a documented DDoS response plan as part of an overall wider business continuity plan, which is reviewed regularly. If employees know who to contact and what steps to take in the event of an attack, it can save the business financial and reputational costs.
3. Build resilience into your networks
If your network infrastructure has been designed to absorb or redistribute large volumes of traffic, you will be better able to withstand a DDoS attack. Cloud-based or hybrid architectures are often better in this respect than in-house systems. Talk to your Internet Service Provider about upstream DDoS mitigation. Many of them can filter attack traffic before it reaches your network. If you have web-facing services, a content delivery network (CDN) provides an additional layer of protection. This is because it distributes requests across multiple server networks, providing much greater resilience.
4. Limit requests and block suspicious traffic
If you configure your servers and firewalls to limit the rate of incoming requests and block suspicious traffic patterns, it can help reduce the impact of lower-volume attacks. In addition, web application firewalls (WAFs) can help filter out malicious application-layer traffic.
5. Monitor traffic continuously
Real-time traffic monitoring makes it easier to spot early signs of an attack, unusual spikes, strange request patterns, or an abnormal geographic distribution of traffic. The faster you can identify an attack, the faster you can respond.
For more guidance, our article on building a cyber incident response plan and our guide to cyber security procedures are both helpful resources.
Why do hackers use DDoS?
As with many other types of cybercrime, criminals use DDoS for a variety of reasons, including the following:
Competition. Some businesses experience DDoS attacks that appear to be commercially motivated, with competitors suspected as the source.
Hacktivism or politics. Activists can use DDoS attacks to bring down websites, businesses, or organisations they disagree with for ethical or political reasons.
Revenge. Angry ex-employees are sometimes behind DDoS attacks.
Extortion. DDoS attacks can be hugely disruptive, and criminals may demand a ransom to stop the attack or minimise the damage.
Smokescreen. In some cases, DDoS attacks act as a distraction while hackers carry out other criminal activities, such as data theft or ransomware deployment.
Entertainment. Not all cyberattacks are launched by master criminals. Some hackers might simply see it as a bit of fun. DDoS-for-hire services have made launching an attack increasingly accessible, even to those with little technical knowledge.
Does cyber insurance cover DDoS attacks?
Cyber insurance covers a range of consequences arising from a DDoS attack, including business interruption losses, costs associated with data loss, third-party liability, and reputational harm. The level of cover you need will depend on the nature, size, and risk profile of your business, but all cyber policies provide emergency response services which are a key component in helping mitigate an issue before it becomes a real problem.
However, cyber insurance policies differ considerably, and it can be complex trying to understand what they do and don’t cover. This is where working with a specialist broker like Alan Boswell Group can make all the difference. If you would like our expert team to help you find cover that fits your specific needs, please get in touch today on 01603 218000.
Need help with your insurance?
At Alan Boswell Group, we understand how important it is to keep your data and networks safe, particularly as the number of contactless transactions rise. To find out more about how we can help, visit our cyber insurance hub or contact us directly.
Many DDoS attacks are short-lived. They can be over in seconds, and Cloudflare says most are over in 10 minutes. However, some attacks, particularly those motivated by extortion or geopolitical conflict, can persist for hours or days.
Financial services, telecoms, and technology businesses are regular DDoS targets. Online services such as gaming and retail are also frequently hit. Public sector and critical infrastructure organisations have also faced increased disruption from politically motivated and hacktivist DDoS campaigns in recent years.
Yes, and they’re increasing. Cloudflare blocked over 20.5 million DDoS attacks in Q1 of 2025 alone. The availability of DDoS-for-hire services means launching an attack requires little technical skill or expense, contributing to the sharp rise in frequency.
All three main types of DDoS attack – volumetric, protocol, and application – can cause serious disruption. In practice, the most dangerous attacks today are multi-vector, combining two or more techniques simultaneously. Application-layer attacks are often considered the hardest to defend against, as they mimic legitimate user behaviour and require more resource-intensive traffic inspection. The most damaging incidents tend to involve large, sophisticated, multi-vector campaigns that can overwhelm even well-prepared defences.
Recent advances in Artificial Intelligence have exacerbated and expedited criminal networks’ ability to launch multi-vector DDoS attacks.
Related guides and insights

Small business guide to cyber attacks – prevention and loss
More than 600,000 UK businesses experienced a cyber breach or attack in the last 12 months. We look at the most common types of cyber attacks and what you can do to minimise the risk to your business.

What is a cyber incident response plan?
A cyber incident response plan (IRP) outlines your business’s approach to handling a cyber security incident. Here’s why all businesses should have a plan to protect against the threat of cyber attacks.

Identifying and mitigating cyber security risks in your business
Human error accounts for 95% of all cyber breaches, while more than one in four businesses experienced a cyber security breach in the last 12 months. Here’s how to identify and mitigate cyber security risks for your business.

What is an SQL injection attack?
Many businesses are aware of what and how phishing works, there are other, less well-known attacks that are just as disruptive or damaging. Our article looks at what an SQL injection attacks is.