Skip to content

Procurement

A DDoS Mitigation Maturity Model, Level 0 to Level 5

Last updated: August 2026 · Six levels, measured by what is verified · Reading time ~13 min

Six broad stone steps rising out of dark amber water into clear teal-green light, the lowest submerged and wet, the highest dry and evenly lit.

Maturity here is not about how much equipment you own. It is about how much of your defence has been verified rather than assumed. Level 0 finds out from customers; Level 5 knows its own numbers because it measures them on a schedule. Most organisations sit at Level 2 — equipment installed, thresholds never calibrated, response never rehearsed — and the step to Level 3 costs attention rather than money.

Maturity models in security usually measure how much has been bought. This one measures how much has been verified, because in this field the gap between installed and working is where incidents happen.

The distinction shows up immediately: buying equipment moves an organisation from Level 1 to Level 2 and no further. Everything above that is earned with measurement and rehearsal.

At a glance

ApplianceLevelHow you find out about an attackWhat has been verified
0 — UnawareA customer tells youNothing
1 — ReactiveMonitoring alerts, after impactThat someone can be reached
2 — EquippedThe mitigation device alertsThat the equipment powers on
3 — CalibratedThresholds derived from your own peaksLegitimate peaks, and what the device does at its limits
4 — RehearsedDetection you have testedResponse, failover, and evidence export, by exercise
5 — Continuously verifiedDetection you re-test on a scheduleAll of the above, repeatedly, with the trend recorded

The third column is the model. Equipment moves you from 1 to 2 and no further; every level above that is bought with attention rather than capital.

Level 0 — Unaware

No detection specific to availability, no upstream relationship for this purpose, no runbook. An attack is discovered when someone calls, and the response is improvised.

This is more common than it sounds, and it is not always wrong. An organisation with no internet-facing revenue and a high tolerance for downtime may be correctly allocating attention elsewhere. It becomes wrong the moment availability starts to matter to someone and nobody notices the change.

Step to Level 1: volume alerting on the internet-facing path, and one named upstream contact. A day’s work.

Level 1 — Reactive

Monitoring exists and fires, though usually after users are affected. The upstream provider can be called and will do something, the extent of which is discovered during the call. No dedicated mitigation.

The characteristic weakness is elapsed time. The first thirty minutes of every incident are spent establishing who to call, what they can do, and who is allowed to authorise it.

Step to Level 2: decide whether dedicated mitigation is warranted. The readiness assessment and the sizing record answer this better than a supplier can, and the answer is sometimes no.

Level 2 — Equipped

Mitigation exists — an appliance, a service, or both. It has default thresholds. It has never been calibrated against the organisation’s own traffic, and the response has never been rehearsed.

This is where most organisations sit, and it is the most dangerous level in the model, because the equipment produces a feeling of coverage that has not been tested. Two failure modes are characteristic: thresholds set from vendor defaults refuse legitimate traffic at the first genuine peak, and thresholds set too permissively let an attack through while the dashboard shows green.

Step to Level 3: measure your own peaks over a full business cycle, then set thresholds from them. Weeks of passive measurement, one afternoon of decisions, no purchase.

Level 3 — Calibrated

Thresholds derive from measured legitimate peaks rather than from defaults. Someone knows the organisation’s own numbers: bits and packets per second at peak, new sessions per second, the packet rate the circuit can deliver, and what each stateful device does when its table fills.

Alerting distinguishes a busy day from an attack, because the baseline includes busy days. The division of responsibility between the upstream tier and the local one is written down.

Step to Level 4: rehearse. A tabletop with the people who would actually be called, then a controlled trigger of a real mitigation control in a maintenance window.

Level 4 — Rehearsed

Response has been practised with the actual on-call people. Failover or bypass has been triggered deliberately and its time measured. Evidence export has been performed by your own staff in the format a regulator or insurer would require. Decision authority for disruptive action is delegated in writing, with named alternates.

The KPIs are collected during exercises, not only during incidents, so the trend exists before it is needed.

Step to Level 5: put the rehearsal on a schedule, and re-measure after every material change.

Level 5 — Continuously verified

Everything at Level 4, repeated on a cadence, with the results trended. Thresholds are reviewed as traffic grows. Capacity is re-tested when the estate or the circuit changes. Post-incident findings produce changes that are implemented and confirmed.

The honest characterisation of Level 5 is that it is not a state but a habit, and it is the level organisations most often reach once and then lose, because the recurring commitment competes with everything else. Reaching it is a project; staying there is a budget line.

Using the model

Two rules keep it useful.

Score by area, not overall. Visibility, upstream, capacity, response, evidence and practice each have their own level, and the mismatch is the finding. Equipment at 4 with practice at 1 is a specific, expensive, common shape.

Never let a level be sold to you. Every level above 2 is defined by verification the buyer performs, so no product confers one. A supplier presenting their equipment as a maturity level is describing the one step that money can buy and skipping the rest.

The gaps to close first come from the readiness assessment, which asks what exists today. This model answers where to head next, and the two are meant to be used in that order.

Frequently asked questions

Is this an industry standard?
No, and the Sources note says so plainly. It is this publication's model, offered because staged planning is easier to fund than open-ended improvement. If a supplier ever tells you their product places you at a particular level, they have misread it — no product confers a level here, because every level above 2 is defined by verification the buyer performs.
What level should we aim for?
Level 3 is the point at which the defence stops being a hope, and it is reachable by nearly every organisation because it costs attention rather than money. Level 4 is proportionate wherever downtime has a material cost. Level 5 is for estates where availability is the product, and it is genuinely expensive to sustain.
Can you be at different levels in different areas?
Almost everyone is, and the pattern is informative. High equipment maturity with low practice maturity is the most common shape in well-funded estates, and it is the shape that produces the worst surprises, because the technology works and the organisation does not.
How long does a level take?
The step from 2 to 3 is weeks of measurement and one afternoon of decisions. From 3 to 4 is a quarter, because rehearsals have to be scheduled with people who have other jobs. From 4 to 5 is not a project at all — it is a recurring commitment, which is why it is the level organisations most often reach and then quietly lose.

Sources

  1. The NIST Cybersecurity Framework (CSF) 2.0

    NIST · standard · accessed 2026-08-17

    The tiering concept this model borrows, applied to one threat class rather than a whole programme.

  2. SP 800-61 Rev. 3 — Incident Response Recommendations and Considerations for Cybersecurity Risk Management

    NIST · standard · accessed 2026-08-17

Published: August 2026 · Last reviewed: August 2026

Reviewed means the sources above were re-read on that date; the text is only reissued when something material changed.

This guide is updated as vendors release new models and pricing. How we compare vendors