Distributed Denial-of-Service (DDoS)
A distributed denial-of-service (DDoS) attack is a malicious attempt to disrupt the normal traffic of a targeted server, service, or network by overwhelming it from many machines at once. Because the attack originates from multiple sources operating together against a single target, the affected system can become slow or unavailable to its intended users. It is a form of denial-of-service (DoS) attack, distinguished by the fact that it comes from more than one source.
A distributed denial-of-service (DDoS) attack is a cyberattack in which a perpetrator seeks to make a machine or network resource unavailable to its intended users by coordinating multiple machines to attack a single target simultaneously. It is a variant of the denial-of-service (DoS) attack that originates from more than one source, and such distributed attacks are typically more difficult to defend against than single-source DoS attacks. Attacks are often carried out using many compromised (for example, trojan-infected) systems directed against a particular target, disrupting the normal traffic of the targeted server, service, or network. Note: this entry describes the technical attack mechanism only; whether resulting business interruption, extra expense, or third-party liability is covered under a cyber policy depends on the specific policy wording, endorsements, exclusions, and conditions, and is out of scope here.
Why it matters
DDoS attacks matter to the readers of Readiness Authority because they threaten availability, the ability of customers, employees, and partners to reach a system when they need it. Unlike attacks that steal or corrupt data, a DDoS event does not necessarily involve a breach of confidentiality; instead it overwhelms a targeted server, service, or network with coordinated traffic from many sources, rendering it slow or unavailable. For organizations that depend on continuous online availability, such as e-commerce, financial services, and public-facing digital platforms, even a temporary disruption can translate into lost revenue, operational disruption, and reputational harm.
From an insurance perspective, a DDoS attack is a threat vector, not a coverage term. Whether the downtime, response costs, or knock-on losses arising from a DDoS event are insured depends entirely on the specific policy wording, endorsements, exclusions, and conditions of the cyber policy in question. First-party losses such as business interruption or extra expense are treated differently from any third-party liability that might arise, and many policies impose waiting periods, retentions, or sublimits that shape how much of a DDoS-related loss is ultimately recoverable. This entry describes the attack itself; the coverage analysis is a separate exercise governed by the policy, not by the nature of the attack.
Because DDoS attacks originate from more than one source, they are typically more difficult to defend against than single-source denial-of-service attacks. This makes them a recurring concern for resilience planning. Purchasing insurance transfers some financial consequences of an attack but does nothing to reduce the likelihood or technical impact of the event; mitigation controls and continuity planning address that dimension separately. Risk managers should treat insurance and resilience as complementary but distinct, rather than substitutes for one another.
Who it's relevant to
Inside DDoS
Common questions
Answers to the questions practitioners most commonly ask about DDoS.