Denial-of-Service Attack
A denial-of-service attack is a deliberate attempt to make a website, system, or network unavailable to the people who are supposed to use it. Attackers commonly do this by flooding the target with so many requests or so much traffic that it becomes overloaded and stops responding. The result is disruption of access rather than theft of data.
A denial-of-service (DoS) attack is a malicious action that prevents authorized users from accessing information systems, devices, or network resources, or that delays time-critical operations. It is typically accomplished by flooding a targeted machine or resource with superfluous or excessive requests in an attempt to overload systems, exhaust capacity, and disrupt normal operations, thereby rendering the service unusable. As an availability-impacting threat, DoS is distinct from confidentiality- or integrity-focused attacks; note that from an insurance perspective, whether resulting losses (such as business interruption or extra expense) are covered depends on the specific policy wording, applicable waiting periods, sublimits, and exclusions, and is not addressed by this definition. This entry describes single-source DoS; distributed denial-of-service (DDoS), which uses multiple coordinated sources, is a related but separate concept.
Why it matters
A denial-of-service attack targets availability rather than confidentiality or integrity, which means its primary business impact is disruption of access. For organizations that depend on customer-facing websites, transaction platforms, or time-critical operations, even a temporary loss of availability can translate into lost revenue, contractual penalties, reputational harm, and cascading operational delays. Because DoS attacks aim to make services unusable rather than to steal data, they may fall outside the scope of controls and coverages designed around data breach, which is why they warrant distinct attention in both resilience planning and insurance review.
From a risk-transfer perspective, losses arising from a DoS attack, such as business interruption or extra expense, may potentially be addressed under a cyber policy, but whether they are covered depends entirely on the specific policy wording. In many policies, business interruption coverage is subject to a waiting period (an hourly threshold that must be exceeded before coverage responds), sublimits, retentions, and exclusions. A short-duration DoS event may fail to exceed a waiting period, and certain events may be affected by exclusions such as infrastructure or war exclusions. Organizations should not assume that a disruption is automatically covered, and coverage analysis is a separate exercise from the technical description of the attack itself.
Critically, insurance does not reduce the likelihood of a DoS attack occurring, nor does it restore availability during an event. Risk transfer through insurance is complementary to, not a substitute for, mitigation measures and resilience planning. An organization's ability to absorb, respond to, and recover from a DoS event depends on its technical defenses, incident response readiness, and business continuity arrangements, which operate independently of any policy that may indemnify a portion of the resulting financial loss.
Who it's relevant to
Inside DoS
Common questions
Answers to the questions practitioners most commonly ask about DoS.
