Skip to content

Institutional readiness

The Decision, the Evidence and the Answer: DDoS Readiness for a Knowledge Economy

Last updated: August 2026 · Human capacity, evidence custody and accountability · Reading time ~14 min

Three identical pedestals; the objects on the first two have been lifted clear and are being drawn away along conduits, while the third holds a block cast continuous with the pedestal and the floor, with nothing attached to carry it off.

When a national-scale attack lands, three things have to be in country: the decision, the evidence and the answer. The people authorised to act, the packet-level record of what actually happened, and the organisation that will be asked about it weeks later. An offshore inspection point relocates the first two and leaves only the third — which is the one that cannot be outsourced.

Qatar’s national development vision is built on human and institutional development as much as on infrastructure — the transition toward a knowledge-based economy in which the capability that matters sits in people and organisations rather than in a resource. That framing is stated consistently and this guide needs nothing more specific from it.

Applied to a single, narrow operational question — what happens when a serious denial-of-service attack lands on a nationally significant service — it produces a checklist most organisations have never run. Not a technical checklist. Three questions about where things are.

The three things that have to be in the country

The decision. At some point during a large attack, someone has to choose. Divert or hold. Shed one service to protect the rest, or accept degradation across the board. Terminate TLS at the mitigation tier so the application layer can be classified, or leave a class of attack undetectable. Every one of those is a business decision wearing technical clothes, and every one has to be made while the attack is running by someone who is awake, reachable and authorised.

The evidence. Afterwards — and it is always afterwards, usually weeks — someone asks what happened. To which service, between which times, caused by the attack or by the response, observed how. Answering requires a record with enough detail to address a question nobody anticipated at the time, held long enough to still exist when it is asked for.

The answer. Someone stands in front of a regulator, a board, a customer or a public and accounts for it. That is not a technical artefact. It is an organisational position, and it belongs to the organisation whose name is on the service.

Three things. The third cannot be transferred to anyone, under any commercial arrangement. The first two can be, easily, and are — often without the decision to transfer them ever being made explicitly.

What an offshore default actually relocates

This is where the architecture question and the readiness question turn out to be the same question.

If everyday traffic is inspected in another country by another organisation, then during an attack the observation happens there, the first-order decisions about classification and thresholds happen there, and the detailed record accumulates there. Your team is notified. It receives a graph, an alert, later a summary. It makes the decisions that remain — whether to accept the impact, what to tell customers — but it makes them on information that has already been reduced by someone else, about traffic it did not watch.

Then, weeks later, the questions arrive and land entirely on you. You hold the accountability without having held the observation.

What a scrubbing tier must see to do its job Source IP addresses Request headers & user agent Session cookies / tokens Request bodies (if TLS terminated) Cloud scrubbing Processed abroad crosses the border crosses the border crosses the border crosses the border On-premise mitigation Processed in country stays inside stays inside stays inside stays inside
What passes through a mitigation tier is also what a later question will be about. Custody of the record follows custody of the inspection point.

This is not an argument that providers are unreliable. Large scrubbing providers are competent, see far more attacks than any single organisation, and generally supply what is asked for. It is an argument about a structural mismatch: the party that must answer is not the party that observed, and the gap between them is a support queue.

The decision is the part nobody rehearses

Of the three, the decision is where organisations are weakest, and it is the cheapest to fix.

Almost every organisation with a mitigation capability has a technical runbook. Very few have settled, in writing, who may decide at three in the morning to take one service off the air to protect the others. The result is one of two failures, both of which are the policy’s fault rather than the engineer’s: hesitation while the incident develops, or an unauthorised decision made under pressure that becomes contentious afterwards.

Rehearsing this costs an afternoon and needs no equipment. Take a scenario in which a sacrifice is required and run it against the people:

  • Who believes they may make the call? Ask three people separately and compare the answers.
  • Who must be informed, and within what period? How long does it actually take to reach them?
  • What is the time limit on the decision, and who revisits it?
  • What gets written down, by whom, while it is happening?

Most organisations find the technical answers are fine and the authority question has never been settled. That is the finding, and it is worth the afternoon.

Evidence is a by-product, not a product

The second question has a cleaner answer, because evidence custody follows inspection custody mechanically. You can only capture what passes through equipment you operate.

Where the inspection point is local, producing an incident record is a query against your own storage, on a retention period your compliance function chose, with original source addresses and local timestamps intact. You can pull a full capture without asking permission, at the moment the question is asked rather than several days later, and you can answer a follow-up question that requires detail nobody thought to summarise.

Where inspection is offshore, each of those becomes a request. Within their retention window, which is a term in a contract rather than a decision you made. In their format. On their support model’s timescale, while your reviewer waits.

An organisation can bridge this by keeping a local tap purely for evidence while inspecting elsewhere — and occasionally that is the right design. More often it is a sign that the architecture was chosen before anyone asked what the evidence obligation would be, and the organisation is now paying for two inspection points to satisfy one requirement.

Two structural notes about the market

This guide’s companion piece argues that in a market where international capacity arrives through few physical systems, the local tier has to carry more load than a continental template assumes. That is a structural argument about paths. The argument here is about institutions, and the two support each other without repeating: the first says the offshore tier is less dependable here than the diagram implies, the second says that even when it works perfectly, it takes the decision and the record with it.

The classification analysis is a third, separate lens, and for many organisations it will be the binding one — see the classification guide for why the class of the data can rule out an architecture before any of this is weighed.

What the equipment has to support

Three properties, and they are testable in a proof of concept rather than assessable from a datasheet.

A record granular enough to answer an unanticipated question. Aggregate counters prove the device is working and cannot reconstruct an incident. Ask the vendor to produce, for one named service and one named hour, what was detected, what was dropped and what was forwarded — and to show the query rather than a screenshot.

Retention under your control. Whether the period is yours to set, whether export is a supported operation, and what the storage cost of a realistic retention period actually is. This is frequently the item that changes a design after it has been chosen.

Detection that does not depend on reachability of something outside the country. During a national-scale event the international path is one of the things that may be degraded, and a mitigation tier whose classification quality depends on reaching a manufacturer-operated service has placed a dependency outside the border inside a duty that sits inside it. An appliance that runs detection on the customer’s own infrastructure makes a degraded border a capacity problem rather than a detection problem, and manufacturers differ on this point — it is a question for the tender, not an assumption. Products that do consult an external service should be assessed on how far they degrade and against which attack classes, not on whether they degrade — most degrade gracefully, and the honest question is how gracefully, for how long.

Three things, and only one of them cannot be moved
ApplianceThe decisionThe evidenceThe answer
What it isAuthority to act while the attack is runningThe packet-level record of what occurredAccountability to the regulator, board or public
Offshore inspectionHeld by a provider's operations centreHeld by a provider, in their retention windowStill yours
In-country inspectionHeld by your team, on your escalation pathHeld by you, on your retention policyStill yours
What determines the timescaleProvider's runbook and change windowProvider's support queueThe reviewer's calendar, either way
Can it be outsourcedYes, and often sensiblyYes, at a cost in latency and detailNo
What happens if the relationship endsReverts to you, unrehearsedReverts to whatever you exportedUnchanged — it was never theirs

Read the last two rows together. The only column that cannot be transferred is the one whose inputs are the easiest to transfer, which is what makes this an architecture question rather than a governance one.

The honest limit

Capacity is not affected by any of this. An attack larger than your access circuit has already succeeded before your equipment sees a packet, and no amount of local readiness changes that arithmetic. The upstream tier remains necessary; what this guide argues is that it should be an exception with a rehearsed procedure rather than the default path, so that the decision and the record live locally on ordinary days as well as extraordinary ones.

And a small organisation with no security operations function should be honest about which of the three columns it can actually hold. An organisation that will not staff, train or rehearse is better served by a competent provider than by equipment nobody operates — and the useful version of this guide, for that organisation, is the list of questions to ask the provider about evidence custody and response authority before signing.

Sources and further reading

The national vision’s objectives are published by the state and are the right primary source for any policy framing; nothing here depends on a specific target, timeline or figure. For the regional threat picture that motivates the exercise, see the Middle East threat landscape guide. For the state-level version of the capability question, see sovereign cyber defence in the Gulf.

Frequently asked questions

How is this different from the sovereignty argument made elsewhere on the site?
The sovereignty guide is about national capability at the level of a state — a national scrubbing tier, who operates it, under whose authority. This is about a single organisation's readiness, and it is deliberately smaller and more testable. The question here is not whether the country can defend itself; it is whether your organisation can make a decision, prove what happened and answer for it, without depending on a party in another timezone.
Isn't a provider's operations centre better staffed than ours?
Usually, and that is a genuine argument for using one. A large scrubbing provider sees more attacks in a week than most organisations see in a decade. What it does not have is the authority to decide anything about your business, knowledge of which of your services matter most this month, or a relationship with the regulator that will ask you about it. Those are the parts that stay with you regardless, and they are the parts that need practice.
What does "evidence custody" mean concretely?
Whether you can produce, from your own systems, what arrived and what you did about it for a named service between two named times — with original source addresses, local timestamps and enough packet detail to answer a question you have not thought of yet. Where the inspection point is yours, that is a query. Where it is a third party's, it is a support request, answered in their format, within their retention window, at their pace.
Does keeping evidence in country require keeping mitigation in country?
For the traffic that matters, yes, because the evidence is a by-product of inspection. You can only capture what passes through equipment you control. An organisation that inspects everyday traffic offshore and keeps a local tap for evidence has built two inspection points and paid for both, which is occasionally the right answer and usually a sign the architecture question was decided before the evidence question was asked.
How do you rehearse a decision rather than a technical procedure?
By running the exercise against the people rather than the equipment. Take a scenario in which one service must be sacrificed to protect the rest, at three in the morning, and see who believes they are authorised to make that call, who they think they must inform, how long it takes to reach that person, and what they would write down. Most organisations discover the technical runbook is fine and the authority question has never been settled.
What does this have to do with a knowledge-economy goal?
A knowledge economy is an economy whose critical capability sits in institutions and people rather than in a resource. Applied narrowly to this problem, that means the ability to run a significant cyber incident is itself a national asset — and it is built the same way any operational competence is built, by an organisation doing the work and keeping what it learns. An arrangement in which the decision and the record both live abroad produces compliant organisations that have never actually run an incident.
Where does this leave the upstream tier?
Exactly where the architecture guides leave it: necessary above your circuit capacity, engaged as a deliberate and rehearsed exception rather than as the default path. The point of this guide is not that upstream capacity is undesirable. It is that if the default path is offshore, then the decision and the evidence are offshore on ordinary days as well as extraordinary ones, and the muscle never develops.

Sources

  1. Qatar National Vision 2030 — official planning portal

    State of Qatar · regulator · accessed 2026-08-20

    The primary source for the national vision's declared objectives. The host did not respond to this publication's network on 20 August 2026 — the address is the state's own, but it could not be fetched during this revision.

  2. National Cyber Security Agency — official site

    National Cyber Security Agency (Qatar) · regulator · accessed 2026-08-20

    The national cybersecurity regulator; the source of the classification and incident-notification obligations described here.

Published: August 2026

This guide is updated as vendors release new models and pricing. How we compare vendors