- Step one: Know what is vulnerable
- Resilient Architecture: No Single Point of Failure
- Multi-layered protection: Because one layer isn’t enough
- The four paths to mitigation—and why timing is critical
- Organization and Compliance: No Readiness Without Preparation
- Resilience is built before the attack, not during it
DDoS attacks affect companies of all sizes, and they rarely come at a convenient time. To remain capable of responding in an emergency, you must lay the groundwork well in advance. What this means in concrete terms must be clarified from technical, organizational, and regulatory perspectives.
Reports are piling up: websites are down, services have failed, and customer portals are paralyzed for hours. DDoS attacks are behind many of these disruptions—and their numbers are growing year after year. It is no longer just large corporations or critical infrastructure that are being targeted. Mid-sized e-commerce companies, logistics providers, healthcare providers: Anyone who needs to be available online is a potential target.
What many underestimate: The crucial question is not whether an attack will come, but whether your own infrastructure is prepared for it. Because protection cannot be purchased on the fly. Those who only start looking for solutions once traffic has already exploded lose valuable time—and in the worst case, much more.
Step one: Know what is vulnerable
Before protective measures can take effect, you must first identify your own attack surface. A structured network audit reveals which services, ports, and IP addresses actually need to be accessible from the outside and which should not be. Anything unnecessary must be consistently shut down or secured.
One area that is regularly overlooked is the DNS. As the central entry point into the corporate network, the Domain Name System is a prime target for attacks. The DNS infrastructure should therefore be designed with redundancy, actively monitored, and secured by specialized protection mechanisms.
Learn how the new Network DDoS Protection protects you even more effectively
Faster mitigation, IPv6 parity, greater transparency, and significantly less manual effort.
Resilient Architecture: No Single Point of Failure
Anyone who operates all critical applications via a single location or network path creates a dangerous gateway. Redundancy is not a nice-to-have feature, but the foundation of any resilient infrastructure. By utilizing multiple data centers at different physical locations, independent connections, and the deliberate avoidance of network bottlenecks, the risk of an attack paralyzing entire business processes is drastically reduced.
Equally important are the performance and configuration of edge components. Routers, firewalls, and load balancers must remain stable even under attack load. Anyone who only discovers this in an emergency has a problem. Additional bandwidth capacity won’t stop an attack, but it gives the other protective mechanisms the time they need to intervene.
Multi-layered protection: Because one layer isn’t enough
Modern DDoS defense is based on the principle of layered defense. No single tool offers complete protection—it is the interaction of multiple layers that makes the defense robust. Content Delivery Networks (CDN) distribute content globally and relieve the origin server. WAAP (Web Application and API Protection) platforms analyze requests at the application level and detect even sophisticated Layer 7 attacks that mimic legitimate traffic. Rate limiting restricts requests per source, thereby preventing simple overload scenarios. And specialized mitigation services with globally distributed scrubbing centers filter out malicious traffic before it even reaches the corporate network.
The crucial point, however, is that these protection mechanisms must be integrated in advance and tested regularly.
The four paths to mitigation—and why timing is critical
Anyone relying on an external mitigation service in an emergency must know the following: The technical connection cannot be improvised. Four models have become established, which differ significantly in their requirements and response times.
Direct Layer 2 coupling within the same data center is the most technically sound solution: It is virtually latency-free, stable, and easy to activate. However, it requires physical proximity.
“Cloud Connect” via peering platforms offers dedicated connections outside the public internet and thus predictable, stable performance. However, setting it up requires lead time and contractual coordination, which is why it is not suitable as a spontaneous solution during an ongoing attack.
A dedicated Layer 2 line offers maximum control and performance, but requires several days to weeks to set up. It is ideal for permanently protected environments, but is out of the question as an emergency option.
The GRE tunnel is often the most flexible choice, as it runs over existing internet connections. However, it is also the most demanding solution: The tunnel runs over a regular uplink. On this uplink, packet loss or jitter can directly impair the defensive effect. Technically, all involved devices must support GRE. The Maximum Segment Size must be adjusted to approximately 1,476 bytes on all uplinks due to the 24-byte overhead. In addition, asymmetric routing must be properly configured: Outgoing traffic goes directly to the internet, and sanitized incoming traffic returns via the mitigation provider.
Anyone who has never tested these configurations will find, in a real emergency, that rapid emergency onboarding is then hardly possible.
Organization and Compliance: No Readiness Without Preparation
Technology alone does not provide protection if the organizational foundations are lacking. A clearly defined incident response playbook specifies who makes decisions in the event of an attack, how escalation paths are managed, and how communication—both internal and external—is coordinated. Since attacks rarely occur during office hours, designated contact persons who are available around the clock are required.
In parallel, an up-to-date overview of critical systems and a simple data classification scheme are required. The latter helps set priorities when not everything can be protected simultaneously. For external service providers, technical profiles should be available that include IP ranges, domains, typical traffic patterns, and the correct contact persons.
On the compliance side, the following applies: data processing agreements, role assignments, technical and organizational measures, and retention policies must be established in advance. A structured vendor risk management program with clear minimum requirements—such as for certifications, logging, and access controls—closes the final gaps. Clear rules for emergency changes enable quick decisions without compromising traceability.
Resilience is built before the attack, not during it
DDoS attacks cannot be avoided. However, whether they escalate into a serious crisis is in the hands of the companies—and this is determined long before the first attack strikes. Those who set up their infrastructure and processes correctly today gain the most important thing in an emergency: time. And it is precisely this time that determines whether an attack remains a brief disruption or causes lasting damage.
Link11 supports companies in approaching this preparation in a structured manner: from analyzing the attack surface to technical integration and securing systems during ongoing operations.
Lisa Fröhlich