Distributed denial-of-service (DDoS) security investments are increasing. But DDoS attack readiness isn’t. Why?
To better understand the dynamic of this issue, MazeBolt surveyed 300 CISOs and senior security leaders across the US and Europe and compiled the results into a free report. All survey participants work at Banking, Financial Services, and Insurance companies with 500 to 25,000 employees – and annual revenues of at least $250 million.
Here’s a sneak preview of 5 of the report’s top highlights:
Respondents Faced an Average of 3.85 Damaging Incidents This Year
60% of respondents suffered 2 to 5 damaging DDoS attacks this year, confirming that DDoS is still a major issue for the enterprise. Nearly all respondents reported experiencing at least one damaging DDoS attack in the past 12 months.
But despite the frequency of damaging attacks, respondents said that they run DDoS tests on their deployed DDoS defenses only periodically:
- 14% test their defenses twice a year
- 63% test their defenses once a year
- 23% test their defenses less than once per year
- No respondents test more than twice per year
This limited frequency reflects the disruption that traditional testing methods cause. Manual DDoS testing requires a maintenance window and carries the risk of downtime, making organizations reluctant to schedule it more often. The result is that testing is treated as an infrequent compliance exercise rather than an ongoing assurance and security hardening process.
Over a Third of Respondents Suffered Severe or Extensive Damage in the Last 3 Years
42% of respondents described the impact of their most damaging attack of the last two or three years as severe or extensive. Moreover, the severity of the outcome is linked to company size; larger organizations faced three times the likelihood of suffering from extensive damage. According to the report:
- 5,000 to 10,000 employees – 6% had extensive damage
- Over 10,000 employees – 18% had extensive damage
This situation is not limited to isolated incidents. Enterprises are continuing to encounter significant DDoS downtime – meaning that the risk has remained persistent over time.
Increasing Investment in DDoS Defense is Not Leading to Lower Risk
Not surprisingly, most organizations are increasing their spending on DDoS protection. But the growing spend isn’t leading to a corresponding sense of DDoS resilience. According to the report:
- 85% increased investment in DDoS protection this year
- Only 5% of those who increased investment have full confidence they can block damaging attacks
- 99% rely on DDoS testing requiring a maintenance window
DDoS testing and validation solutions which rely on scheduling a maintenance window on live production services are highly disruptive – which results in organizations:
- Testing only once or twice a year
- Testing that runs for a limited period of time
The result: a low volume of tests – covering a small fraction of the attack surface.
All DDoS Protections Rely on Some Level of Manual Intervention
None of the respondents reported having DDoS protection solutions that are fully automated. This illustrates that even premium DDoS protection solutions still require manual work, in order to minimize the impact of damaging DDoS attacks. According to the report:
- 63% said that their DDoS protections are mostly automated
- 25% said that their protections are half automated
- 12% said that their protections are mostly manual
The data shared here reinforces the fact that while extensive investments are being made in advanced protections, the solutions are not able to provide fully automated defense. Bottom line: DDoS mitigation vendors anticipate manually adjusting configurations and remediating vulnerabilities after an attack starts. In other words, DDoS protection solutions work reactively – and with the best protections deployed, damaging downtime can still take place, before any adjustments have been made.
Automated DDoS Vulnerability Reporting is Seen as Valuable
Nearly all respondents indicated they would benefit from a solution providing automated reporting, which can identify DDoS misconfigurations and vulnerabilities – and provide remediation recommendations, without the need for a maintenance window on live production services. In total:
- 69% said this would be somewhat valuable
- 28% considered it highly valuable
- Only 3% saw little value
- None dismissed it entirely
This finding illustrates that there is an opportunity here for solutions such as RADAR™ by MazeBolt that proactively provide continuous testing and actionable DDoS remediation recommendations, without disturbing live production .
Bottom Line: Continuous, Nondisruptive DDoS Testing Reduces DDoS Risk
Traditional approaches to DDoS testing and validation are proving inadequate. Penetration tests and red team exercises, usually carried out once or twice a year, provide only a narrow, point-in-time snapshot. They rarely cover more than a fraction of an organization’s attack surface and require highly disruptive maintenance windows.
As a result, many enterprises operate with a false sense of confidence in their resilience, without the visibility or means to validate whether protections will hold against the full spectrum of attacks.
To learn more, join MazeBolt’s webinar on Monday, September 29. Register here.
FAQs
Q1. Who participated in the State of DDoS Defenses survey?
The survey included 300 CISOs and senior security leaders from banking, financial services, and insurance companies across the US and Europe, each with 500–25,000 employees and revenues of at least $250 million.
Q2. How often are enterprises testing their DDoS defenses?
The survey respondents indicated that DDoS testing is infrequent: 14% test twice a year, 63% test once a year, and 23% test less than once per year. None reported testing more than twice a year.
Q3. How damaging are DDoS attacks today?A
Very damaging – 42% of survey respondents described their most serious attack in the last three years as severe or extensive. Larger organizations were three times more likely to suffer extensive damage.
Q4. Are rising investments making organizations safer?
Not necessarily. While 85% of respondents increased spending on DDoS protection, only 5% expressed full confidence in their ability to block attacks. Nearly all respondents (99%) still rely on testing that requires maintenance windows.
Q5. What role does automation play in current DDoS defenses?
None of the survey respondents said they had fully automated solutions. 63% reported mostly automated defenses, 25% half automated, and 12% mostly manual. Even premium protections still require human intervention.
Q6. What are CISOs asking for – in order to address the risk of DDoS downtime?
Nearly all respondents said they see value in automated DDoS vulnerability reporting that identifies misconfigurations and provides remediation guidance without requiring downtime.
Skim Summary
- Frequency of DDoS attacks: Nearly all respondents experienced at least one damaging DDoS attack in the past 12 months; 60% faced 2–5.
- DDoS testing practices: 86% test once a year or less, limited by the disruption caused by traditional DDoS testing.
- Impact: 42% reported severe or extensive damage from their most serious recent DDoS attack; large firms suffer disproportionately.
- Investment vs. confidence: 85% increased spend on DDoS protection, but only 5% feel fully confident defenses can stop attacks.
- Automation gaps: No one has fully automated DDoS defenses; manual intervention is still required.
- Demand for new solutions: 97% see value in automated DDoS vulnerability reporting and continuous DDoS validation without downtime.