Operations
Operations
A defence is a product plus the people who operate it, and the second half is where most real outages are decided. These pages cover the decisions that have to be made before the pressure: who is allowed to sacrifice a destination, what evidence disappears if nobody captures it, and how to come back down without causing a second outage.
The testing pages exist because a datasheet cannot state efficacy — efficacy is a relationship between a product and your traffic, and only you can measure that pair. The methodology here is written to be handed to a manufacturer as it stands, with a scoring model whose weights you set and whose scores are deliberately empty.
Everything here is defensive. Validation guidance is for the defender, and the page on authorised testing is about what makes a test lawful rather than about how to generate an attack.
Start here
Also in this section
Procurement · Last updated August 2026
The DDoS Buyer's Checklist, and the Claims That Need a Proof of Concept
Everything worth checking before signing, sorted into three piles: what a document can settle, what only a test can settle, and what belongs in the contract. Plus the marketing claims that should never survive without a measurement.
Procurement · Last updated August 2026
A DDoS Mitigation Maturity Model, Level 0 to Level 5
Six levels describing how organisations actually progress, what defines each one, and the specific step that moves you to the next. Not an industry standard — this publication's model, offered as a planning tool.
Operations · Last updated August 2026
How Much Automation Is Too Much in DDoS Mitigation?
Automation wins on speed and loses on judgement, and DDoS response needs both. Where the line sits, why it moves with the cost of being wrong, and the override mechanism that decides whether the whole arrangement is safe.
Operations · Last updated August 2026
DDoS Mitigation KPIs That Actually Matter
Gbps blocked is the metric everyone reports and nobody can act on. Seven measurements that describe whether the defence worked, where each comes from, and the two that a supplier cannot produce for you.
Operations · Last updated August 2026
DDoS Readiness Assessment: How Prepared Is Your Network?
Six areas, each scored on what exists rather than what is planned. Most of the gaps this finds cost nothing to close, and the ones that cost money are worth knowing before a supplier tells you about them.
Procurement · Last updated August 2026
DDoS Mitigation RFP Template: Questions to Ask Every Vendor
A tender questionnaire written so that different products give different answers. Detection architecture, dependency behaviour, layer scope, licensing, tenancy, reporting and availability — each with what a strong answer contains and what an evasive one omits.
Operations · Last updated August 2026
How to Build a DDoS Test Lab, and the Acceptance Criteria to Use in It
A lab that cannot leak, a topology that measures the right thing, runs that reproduce — and an acceptance criteria template with the numbers left blank, because only you can set them.
Operations · Last updated August 2026
How to Test False Positives in a DDoS Mitigation System
"We dropped 99.7% of attack traffic" is not a result. The measurement that matters is how many legitimate transactions completed while it happened — and getting it requires real traffic, a baseline, and an honest look at the arithmetic of rare events.
Procurement · Last updated August 2026
How to Read a DDoS Appliance Datasheet Without Being Misled
Datasheet figures are usually true and usually answer a question you did not ask. The nine substitutions that cause the damage — bit rate for packet rate, family for model, licence for hardware — and the arithmetic that converts each one back.
Operations · Last updated August 2026
DDoS Escalation Matrix
An escalation matrix answers one question under pressure: who is allowed to make this decision. The thresholds worth defining, the decisions that must have a named owner, and why role names are not good enough at 3am.
Operations · Last updated August 2026
DDoS Post-Incident Review Template
A post-incident review structured around what the next incident needs rather than around what went wrong. Six questions, the metrics worth recording, and the actions that make the document worth the hour it takes.