Operations
DDoS Escalation Matrix
Last updated: August 2026 · Who decides, at which threshold · Reading time ~10 min

An escalation matrix maps observable conditions onto named people and the decisions they are authorised to make. Its value is not the diagram — it is that the expensive decisions, diverting traffic and sacrificing a destination, have an owner before the pressure rather than during it.
A runbook says what to do. An escalation matrix says who is allowed to do it, and it exists because the two most expensive decisions in a DDoS incident — divert, and sacrifice — are not technical decisions at all.
The five levels
| Appliance | Trigger | Decision available | Who |
|---|---|---|---|
| Level 0 — automatic | Detection threshold crossed | Pre-authorised mitigation engages; nobody is woken | No human; the policy was the decision |
| Level 1 — on call | Mitigation engaged and service still degraded | Tune within pre-agreed bounds; open the incident record | Named on-call engineer |
| Level 2 — service owner | Degradation exceeds the stated service threshold | Request upstream assistance; authorise diversion | Named decision owner, named deputy |
| Level 3 — business | A destination must be sacrificed, or a customer-visible decision made | Blackhole a service; accept a stated commercial loss | Named executive, reachable out of hours |
| Level 4 — legal and regulatory | The written significance threshold is met | Start the notification clock | Named compliance owner |
Every cell in the third column is a person's name in the real version of this table. "The on-call engineer" is not an owner; it is a rota with gaps.
What belongs at each level
Level 0 is a policy, not a person. Whatever your detection is authorised to do without waking anyone should be written down as a decision that was already made. If always-on mitigation engages at a threshold, that threshold is the decision and it was taken in peacetime, which is the right time.
Level 1 is the rota, and its authority should be genuinely useful. An on-call engineer who can classify, record and tune within bounds resolves most incidents without escalating. One who has to escalate before touching anything turns every event into a phone tree.
Level 2 owns diversion. Requesting upstream assistance, authorising a diversion to a scrubbing tier, and committing to the latency and cost consequences belong here. This is the level most often missing from real matrices, which jump from the engineer straight to an executive who cannot evaluate the technical question.
Level 3 owns sacrifice. Blackholing a destination completes the attacker’s goal for that service, as the RTBH page sets out. Someone should sign for that whose job includes signing for a commercial loss.
Level 4 owns the clock. Regulatory notification is not an engineering decision and its timer starts at awareness rather than at resolution. Reaching this level late is the single most common compliance failure in a genuine incident.
Thresholds worth defining in advance
Vague triggers produce vague escalation. Each level should be reachable from something observable:
- Service metrics: connection success rate below a stated figure, p99 latency above a stated figure, error rate above a stated figure — sustained for a stated period.
- Duration: any incident still active after a stated number of minutes escalates regardless of severity, because a long small incident deserves attention too.
- Blast radius: more than one service affected escalates a level.
- Evidence: any incident that might meet the significance threshold notifies level 4 immediately, even if the answer turns out to be no.
The last one is worth arguing for. Involving compliance early costs a conversation; involving them late costs a missed deadline.
The contact reality
Three fields per person and no more:
- Primary contact that is actually monitored out of hours.
- A second channel that does not depend on the same infrastructure as the first — if your alerting and your phone system share a provider, that is a single point of failure in the escalation path.
- A deputy, with the same two fields.
Test all of them on a schedule. The most common finding of a tabletop exercise is not that the plan was wrong but that a number in it was.
What to record when escalating
Escalation without context restarts the analysis at each level. A handover needs four things: what is being exhausted, what has already been tried and with what effect, what decision is being requested, and what happens if the answer is no.
That last item converts an escalation from a request for help into a decision with stated consequences, which is what makes a fast answer possible.
How to exercise it
Run it as a tabletop rather than a technical drill, because the failures are human. Start the clock, present a scenario, and measure: how long to reach level 2, how long to reach level 3, and how many people had to be contacted before a decision was made.
Then fix the numbers that were wrong, and re-run it after the next reorganisation rather than after the next incident.
Frequently asked questions
- Why insist on names rather than roles?
- Because a role does not answer a phone. Under pressure the useful question is not "who is responsible for this" but "who do I call now, and who do I call if they do not answer". A matrix that resolves to a job title sends the on-call engineer to an org chart at the worst possible moment.
- What should be pre-authorised so nobody has to be woken?
- Anything reversible and bounded. Engaging always-on mitigation, applying a rate limit within a pre-agreed range, and requesting upstream assistance under an existing contract are all decisions that cost little if wrong and cost a great deal if delayed by an hour of phone calls.
- What must never be pre-authorised?
- Anything that deliberately makes a service unavailable. Blackholing a destination is the clearest case: it is a commercial decision with a customer-visible cost, and the person who signs it should be someone whose job includes signing for that. Pre-authorising it to an engineer transfers a business decision to whoever happened to be on the rota.
- How often should this be exercised?
- At least as often as the people in it change, which for most organisations is more frequently than the annual review they actually do. The cheapest possible test is a tabletop that starts with "call the level 2 owner now" and measures how long it takes to reach a human.
Published: August 2026 · Last reviewed: August 2026
Reviewed means the sources above were re-read on that date; the text is only reissued when something material changed.
This guide is updated as vendors release new models and pricing. How we compare vendors