8 Things DDoS Protection Vendors Won't Tell You When You're Buying


Donny Chong
Nexusguard

Share to:
We're a DDoS protection and mitigation company. So read this with the appropriate suspicion. But after enough years on the mitigation side, you notice the whole industry, us included, keeps publishing the same scary numbers and quietly leaving out the parts that would actually help you buy well.
Every DDoS threat report this year led with the same headline: a 31.4 Tbps record-breaking attack, the biggest ever recorded. Terrifying. Tweetable. Mostly irrelevant to you.
Here's the thing about those reports, and yes, our company publishes them too. They're built to document attack trends and emerging threats — that part is genuine. But the framing around what those threats mean for your buying decision tends to serve the vendor more than the reader. And the most useful facts for someone actually procuring DDoS protection tend to be the ones that never make the glossy PDF.
So here are eight of them. Some of this makes our own industry look bad. You should hear it anyway, because a buyer who understands the tradeoffs is a better customer than one running on fear.
1. The giant Tbps number is not your problem
That record-breaking attack got the headlines. It is not what takes you down.
The attack that actually kills your business is small. A short, surgical, application-layer hit that slips under your mitigation threshold and exhausts your web server while every dashboard stays green. Vendors love the terabit headline because it justifies selling you enormous scrubbing capacity. But capacity isn’t your gap.
You’re being sold a fire truck for a problem that’s death by a thousand paper cuts.
Nexusguard's own 2025 data tells the same story: peak volumetric attacks grew 45.7% year over year, while peak application-layer attacks surged 67.6%, hitting 1.04 million requests per second. The L7 fight is accelerating faster than the volumetric one. Ask any vendor what percentage of the attacks they mitigate actually exceed 100 Gbps, and watch them change the subject. The record-breaker is the billboard, not the threat.
2. Your “time to mitigate” SLA measures the wrong thing
Vendors advertise mitigation in seconds. “Under 3 seconds.” “Sub-10-second response.” Sounds great.
Read the fine print on what’s being measured. Most SLAs start the clock when the system detects the attack, not when it starts, and not when your users start seeing errors. The gap between “traffic arrives” and “we flagged it” is exactly the window you bleed in.
Many flash attacks last under 60 seconds, start to finish. A "sub-10-second mitigation" SLA sounds fast until you do that math. By the time mitigation fully kicks in, a flash attack is already over and the damage is done.
What to ask instead: measure time-to-mitigate from the first malicious packet to full mitigation, in writing, not from detection. The vendor that agrees to that definition is the one worth talking to.
3. “Unlimited” and “always-on” have fine print
“Unlimited mitigation.” “Always-on protection.” Beautiful words. Now go find the fair-use clause.
Plenty of plans marketed as unlimited carry burst caps, monthly mitigation-event limits, or a “we reserve the right” clause that bumps you to a pricier tier the moment you get attacked seriously. The protection is unlimited right up until you need a lot of it.
Read the clause that activates on your worst day, not the headline that sold you on your best one.
This isn’t hidden out of malice. “Unlimited\*” with an asterisk just converts better than honest tiering. Find the asterisk before you sign, not during an incident.
4. The real threat is Layer 7, and it’s getting cheaper
Volumetric floods get the coverage because they make impressive charts. The attacks quietly winning are at Layer 7, the application layer.
L7 attacks mimic real users. They request real pages, hit real APIs, fill real shopping carts. They don’t need to be huge, they need to be expensive for your server to answer. And thanks to cheap botnets and AI-generated requests, launching one costs almost nothing. Qrator clocked Layer 7 attacks up 74% year over year in 2025.
Here’s why vendors underplay it: L7 mitigation is hard, it’s nuanced, and done badly it blocks your real customers. Selling raw scrubbing capacity is easier than admitting the sophisticated attacks need a more careful conversation.
5. The scary growth percentage includes their own improvements
“DDoS attacks up 121% year over year.” “Up 168%.” The numbers climb every report, every year, forever.
Some of that growth is real, attacks genuinely are increasing. But part of that eye-popping percentage is simpler than it looks: the vendor got better at counting. Better sensors, more customers, finer detection. When you install more cameras, you record more crime. That doesn’t always mean more crime happened.
A growth stat is only as honest as the footnote explaining how they measured last year versus this year.
No report I’ve seen cleanly separates “more attacks occurred” from “we detected more of the attacks that were always occurring.” Both inflate the headline. Only one should scare you. Treat the trend as directional, not gospel.
6. The uptime guarantee pays you in service credits, not revenue
“100% uptime guarantee.” Read what you collect when they miss it.
In almost every contract, the remedy for downtime is a service credit, a discount on next month’s bill. You lose six figures in transactions during an outage; you get a few hundred dollars off your invoice. The “guarantee” caps the vendor’s accountability at roughly what you paid them, not what you lost.
That’s standard across the industry, ours included, and there are real reasons for it, no vendor can underwrite your entire revenue. But the word “guarantee” implies a promise it doesn’t make. Know what you’re actually owed before you need to collect it.
7. Always-on protection has a latency tax nobody quotes
Routing all your traffic through a scrubbing network full-time has a cost, and it’s not just the invoice.
Every packet now detours to a scrubbing center and back. If that center is far from your users, a Singapore scrubbing hub for your Manila traffic, say, you've added latency to every single request, attack or no attack. And during an active attack, some platforms will dynamically reroute legitimate local users through out-of-country paths, meaning the attack was "successfully mitigated" on paper while real users were still experiencing degraded sessions.
For a media site, that’s a slower page. For a payments platform or a trading API, that’s a number your customers feel and your engineers get yelled about.
What vendors won’t volunteer: ask where their scrubbing centers physically sit relative to your users, and what latency they add at baseline. A vendor with infrastructure close to your market answers instantly. One that hedges is telling you something.
8. You’re probably already part of someone else’s attack
Here’s the one nobody wants on the cover, because there’s no product to sell against it.
That botnet in the threat report runs on hijacked devices, and some are almost certainly yours. Routers, cameras, and IoT gear inside ordinary companies make up the millions of nodes behind record attacks.
One tracked botnet grew from 1.33 million devices in March 2025 to 5.76 million by Q3. The 2026 record ran on an estimated 1 to 4 million such devices.
Your office printer might be attacking a bank right now. Vendors sell you protection from incoming attacks. Almost none help with the fact that your own infrastructure is out there as ammunition. It’s not billable, so it stays off the report.
So what do you actually do with this
None of this means DDoS protection is a scam. You need it, the threat is real, and a serious attack without a plan is a genuinely terrible day. We sell it because it works.
It means buy like a skeptic. Ask how time-to-mitigate is measured. Find the fair-use asterisk. Make them talk about Layer 7, not just terabits.
Ask where their scrubbing sits relative to your users. Check what the uptime guarantee actually pays. And audit your own devices before they end up in someone’s botnet.
For what it’s worth, this is the lens we built our own stack around. Application Protection for the Layer 7 attacks that hide under the headline number. Origin Protection that reroutes volumetric traffic to scrubbing centers via BGP. A multi-region architecture spanning the globe, built to deliver low latency and data sovereignty wherever you operate.
We’d rather you interrogate that than take it on faith.
The vendor worth hiring is the one that answers these questions without flinching, the one that tells you what its protection doesn’t do, not just what it does.
FAQ
How much does DDoS protection cost?
It ranges widely. Entry cloud tiers start free or near-free; mid-market managed services run roughly $500–$3,000 a month; enterprise and carrier-grade protection is custom-priced on capacity and SLA. The bigger cost question is hidden overages and fair-use clauses, not the sticker price, read those before comparing numbers.
Is DDoS protection worth it?
For most businesses with revenue tied to uptime, yes. Protection costs are measured in hundreds or thousands per month, while a serious attack costs thousands per minute of downtime plus brand damage. The math only fails if your real attack risk is genuinely near zero, which is rarer than most owners assume.
What should I look for in a DDoS provider?
Ask four things: how time-to-mitigate is measured (from first packet, not detection), where scrubbing centers sit relative to your users, whether “unlimited” hides a fair-use cap, and how they handle Layer 7. A provider that answers all four plainly, and admits its limits, beats one selling headlines.
How long does DDoS mitigation actually take?
Always-on solutions can mitigate within seconds, while reactive detection-based setups may take minutes to hours. The catch is how the vendor defines “start.” Since flash attacks now last under a minute, insist the SLA measures from the first malicious packet to full mitigation, not from the moment their system noticed.
Do firewalls or CDNs provide enough DDoS protection?
Usually not on their own. Firewalls are vulnerable to state-exhaustion attacks and can’t see malicious traffic inside trusted protocols like HTTPS. CDNs absorb many volumetric attacks but miss targeted Layer 7 hits. Both help, but neither replaces dedicated mitigation tuned to your actual traffic and risk profile.
What are the hidden costs in DDoS protection pricing?
The big ones: overage charges during sustained attacks, metered bandwidth billed at attack-scale volumes, paying twice for redundant services, and add-on fees for extra domains or ports. The latency tax of always-on routing is a real cost too, it just shows up in your performance, not your invoice.
(Image: Gemini)
Protect Your Infrastructure Today





