How To Protect Your Business From A DDoS Attack

The technology world isn’t exactly starved for acronyms. These days, however, one stands out: DDoS.

It is short for distributed denial of service, tech-speak for cyberattacks that overwhelm computers and make websites disappear. The cost in revenue, customer service and brand equity is often huge.

No perfect security

The stark reality is that organisations need to wake up and recognise that, no matter how much time, effort and resources they put into defending themselves against a possible DDoS attack, the bad guys will always find a way in. Unfortunately, there simply is no such thing as perfect security or an ideal solution. Organisations should, instead, focus on adopting a risk management approach to protect their business assets.

For instance, organisations don’t hold back when it comes to investment in CCTV, 24 hour security, loss prevention offices and theft insurance to mitigate and deter against theft. In other words, they have already accepted the fact that criminals will steal from them, and so they put systems in place to help limit the damage. The attitude towards cyberspace should not be any different.

Just as in the physical world, organisations need to make themselves as unappealing to attacks in the cyberworld as possible. The way to do this is to reduce the criminals’ return on investment by raising the costs of an attack with things like strong encryption, distributed data sources and compartmentalisation of customer data.

Earlier this year, Neustar published an EMEA-wide DDoS Report including responses to a survey of 1,500 IT professionals across a wide range of industries. Worryingly, the report found that a huge number of organisations are hit by cyberattacks on multiple occasions. Almost forty percent of respondents claimed to have been attacked two to five times in the past twelve months, with twenty four percent claiming to have been hit six to ten times. The lesson should be clear: learn from these attacks, and plan for the next one accordingly because it will happen again.

So, in the event of an inevitable attack, what needs to happen?

The primary concern for any business are customers. And in this case, customer data. In the event of an inevitable attack, a standard of care needs to be in place to ensure there are measures and systems to detect, as early as possible, when a breach occurs, and following this, what are the immediate next steps. This includes everything from preparing public statements for customers and employees, to regulatory and media notification processes. Responses need to be rehearsed. The sooner breaches are recognised and the faster the response process is enacted, the less damage is likely to result from it.

The good news is that although attacks will happen, technology does exist that can combat the problem. When it comes to technology, it’s important to understand that that an effective defence against DDoS is both an art and a science, a blend of man and machine. This is because like any other type of warfare, cyberattacks evolve constantly. Sophisticated new tools crop up all the time. As soon as defences harden, so do attackers resolve, spurring new tactics.

Investing in cloud-based defence systems can provide security capable of defusing attacks before they even reach the network. Utilising massive bandwidth and traffic-cleaning capacity, with teams of experts’ working 24/7 to fight against attacks. Additionally, a so-called ‘hybrid’ approach involves both on-premise DDoS mitigation appliances and the use of services that are delivered by DDoS protection providers able to help mitigate attacks.

It’s often said that those who don’t know history are doomed to repeat it. The same sad ending beckons those who know but don’t take action. When it comes to protecting against DDoS attacks, inertia is the deadliest enemy of all.

Duncan Macrae

Duncan MacRae is former editor and now a contributor to TechWeekEurope. He previously edited Computer Business Review's print/digital magazines and CBR Online, as well as Arabian Computer News in the UAE.

Recent Posts

Is the Digital Transformation of Businesses Complete?

Digital transformation is an ongoing journey, requiring continuous adaptation, strong leadership, and skilled talent to…

7 hours ago

Craig Wright Faces Contempt Claim Over Bitcoin Lawsuit

Australian computer scientist faces contempt-of-court claim after suing Jack Dorsey's Block and Bitcoin Core developers…

8 hours ago

OpenAI Adds ChatGPT Search Features

OpenAI's ChatGPT gets search features, putting it in direct competition with Microsoft and Google, amidst…

8 hours ago

Google Maps Steers Into Local Information With AI Chat

New Google Maps allows users to ask for detailed information on local spots, adds AI-summarised…

9 hours ago

Huawei Sees Sales Surge, But Profits Fall

US-sanctioned Huawei sees sales surge in first three quarters of 2024 on domestic smartphone popularity,…

9 hours ago

Apple Posts China Sales Decline, Ramping Pressure On AI Strategy

Apple posts slight decline in China sales for fourth quarter, as Tim Cook negotiates to…

10 hours ago