How it works
Attackers use botnets, networks of compromised devices such as routers, cameras and servers, to send huge volumes of requests. Volumetric attacks saturate the connection. Protocol attacks exhaust firewalls and load balancers. Application layer attacks send requests that look legitimate but overload the web server or database, and are the hardest to filter.
Why companies are targeted
Motives include extortion (pay or the attack continues), hacktivism against public bodies and companies in Europe, competition, and distraction while another intrusion takes place. DDoS services are cheap to hire, which makes these attacks accessible to almost anyone.
How to protect against it
Protection is mostly architectural and needs to be in place before an attack: a CDN or DDoS protection service in front of public websites and APIs, a web application firewall, rate limiting, agreements with the internet provider and a response procedure. Knowing which services are exposed, through attack surface management, tells you what needs protecting.
Where it shows up in compliance
Availability is one of the core security properties in ISO 27001, the ENS and NIS2. A DDoS that disrupts an essential service can be a reportable incident under NIS2, and the scenario belongs in the business continuity plan and the incident response plan.




