Skip to main content
Category: Cyber Threats & Attacks

Distributed Denial-of-Service (DDoS)

Also known as: DDoS, distributed denial-of-service attack, DDoS attack
Simply put

A distributed denial-of-service (DDoS) attack is a malicious attempt to disrupt the normal traffic of a targeted server, service, or network by overwhelming it from many machines at once. Because the attack originates from multiple sources operating together against a single target, the affected system can become slow or unavailable to its intended users. It is a form of denial-of-service (DoS) attack, distinguished by the fact that it comes from more than one source.

Formal definition

A distributed denial-of-service (DDoS) attack is a cyberattack in which a perpetrator seeks to make a machine or network resource unavailable to its intended users by coordinating multiple machines to attack a single target simultaneously. It is a variant of the denial-of-service (DoS) attack that originates from more than one source, and such distributed attacks are typically more difficult to defend against than single-source DoS attacks. Attacks are often carried out using many compromised (for example, trojan-infected) systems directed against a particular target, disrupting the normal traffic of the targeted server, service, or network. Note: this entry describes the technical attack mechanism only; whether resulting business interruption, extra expense, or third-party liability is covered under a cyber policy depends on the specific policy wording, endorsements, exclusions, and conditions, and is out of scope here.

Why it matters

DDoS attacks matter to the readers of Readiness Authority because they threaten availability, the ability of customers, employees, and partners to reach a system when they need it. Unlike attacks that steal or corrupt data, a DDoS event does not necessarily involve a breach of confidentiality; instead it overwhelms a targeted server, service, or network with coordinated traffic from many sources, rendering it slow or unavailable. For organizations that depend on continuous online availability, such as e-commerce, financial services, and public-facing digital platforms, even a temporary disruption can translate into lost revenue, operational disruption, and reputational harm.

From an insurance perspective, a DDoS attack is a threat vector, not a coverage term. Whether the downtime, response costs, or knock-on losses arising from a DDoS event are insured depends entirely on the specific policy wording, endorsements, exclusions, and conditions of the cyber policy in question. First-party losses such as business interruption or extra expense are treated differently from any third-party liability that might arise, and many policies impose waiting periods, retentions, or sublimits that shape how much of a DDoS-related loss is ultimately recoverable. This entry describes the attack itself; the coverage analysis is a separate exercise governed by the policy, not by the nature of the attack.

Because DDoS attacks originate from more than one source, they are typically more difficult to defend against than single-source denial-of-service attacks. This makes them a recurring concern for resilience planning. Purchasing insurance transfers some financial consequences of an attack but does nothing to reduce the likelihood or technical impact of the event; mitigation controls and continuity planning address that dimension separately. Risk managers should treat insurance and resilience as complementary but distinct, rather than substitutes for one another.

Who it's relevant to

Risk managers and resilience planners
For those responsible for organizational readiness, DDoS represents an availability threat that continuity and disaster recovery planning must address directly. Because a DDoS attack degrades or removes access to a service without necessarily compromising data, response planning focuses on maintaining or restoring availability. Insurance may transfer some financial consequences, but it does not reduce the likelihood of an attack or restore service, mitigation and continuity measures remain the operative controls.
Insurance brokers and underwriters
Brokers and underwriters should treat DDoS as an attack vector rather than a coverage grant. Whether resulting business interruption, extra expense, or any third-party liability is insured turns on the specific policy wording, including waiting periods, retentions, sublimits, and exclusions. Underwriters assessing exposure may consider an insured's dependence on continuous availability and the mitigation controls in place, while recognizing that the presence of coverage does not by itself improve the insured's technical defenses.
CISOs and security teams
Security leaders confront the technical difficulty that distributed attacks pose relative to single-source DoS: traffic arrives from many, often compromised, sources at once, complicating source-based defense. This makes DDoS a distinct planning consideration within a broader security program. The attack's disruption of availability, rather than confidentiality, shapes both detection and response priorities.
Legal and compliance professionals
Legal and compliance teams may become involved where a DDoS event affects the availability of services subject to contractual or regulatory obligations, or where any downstream liability is alleged. Because how a DDoS-related loss is treated depends on policy terms and applicable jurisdiction, coordination between counsel, the risk function, and insurers is important; the attack mechanism itself does not determine legal or coverage outcomes.

Inside DDoS

Volumetric attack
A DDoS technique that seeks to saturate available network bandwidth by flooding the target with high volumes of traffic, often generated through amplification or reflection methods.
Protocol attack
An attack that consumes server or intermediary network resources (such as firewalls and load balancers) by exploiting weaknesses in protocol behavior, for example state-exhaustion techniques targeting connection tables.
Application-layer attack
An attack directed at the application layer that mimics legitimate requests to exhaust server processing capacity, typically harder to detect because individual requests can appear valid.
Botnet
A network of compromised devices coordinated by an attacker to generate the distributed traffic that characterizes DDoS, distinguishing it from a single-source denial-of-service event.
Mitigation and scrubbing services
Security controls that filter or absorb malicious traffic, such as upstream scrubbing centers or content delivery networks. These are risk-mitigation measures and are distinct from any insurance coverage.
Insurance coverage interaction
A DDoS-driven outage may implicate first-party business interruption or system failure coverage for the insured's own lost income and extra expense, and separately may raise third-party liability where the insured's inability to deliver services harms others. Whether either applies depends on the specific policy wording, triggers, waiting periods, and exclusions.

Common questions

Answers to the questions practitioners most commonly ask about DDoS.

Does my cyber policy automatically cover losses from a DDoS attack?
Not necessarily. Whether DDoS-related losses are covered depends on the specific policy wording, applicable endorsements, exclusions, and conditions precedent. Many cyber policies address DDoS through business interruption or network interruption coverage (a first-party category), but coverage is conditional rather than automatic. Some policies require the interruption to result from a covered 'security failure' or 'system failure,' and definitions vary by insurer form. Exclusions, such as infrastructure exclusions where the outage stems from a third-party provider, or failure-to-maintain-standards exclusions, may also apply. Review the actual wording rather than assuming coverage exists.
Is a DDoS attack the same thing as a data breach?
No. A DDoS attack aims to disrupt the availability of systems or services by overwhelming them, typically without accessing or exfiltrating data. A data breach involves unauthorized access to or acquisition of information. These map to different coverage considerations: DDoS-driven downtime is usually analyzed under first-party business or network interruption coverage, whereas a data breach more often implicates third-party liability (such as privacy claims) and breach-response costs. A single incident could, in principle, involve both, but the two concepts are distinct and should not be conflated when assessing coverage.
How does a waiting period affect a DDoS-related business interruption claim?
Many first-party business or network interruption coverages include a waiting period (sometimes called a time retention or time deductible), a qualifying period of outage that must elapse before loss becomes recoverable. Because some DDoS attacks are relatively short in duration, an outage may resolve before the waiting period is satisfied, leaving the loss uncovered. The length of the waiting period, how it is measured, and whether it applies per event are governed by the specific policy wording. This is a coverage term, not a resilience metric, and it should not be confused with an RTO.
What documentation should we retain to support a potential DDoS claim?
To support a first-party interruption claim, insureds typically need to demonstrate both the occurrence and duration of the outage and the resulting financial loss. Relevant records may include traffic and monitoring logs showing the attack timeline, incident response records, communications with mitigation or hosting providers, and financial documentation supporting income loss or extra expense. Because recovery is subject to the policy's proof-of-loss conditions and definitions, aligning documentation with the specific wording and any conditions precedent is important. Consult the policy and, where appropriate, the broker or coverage counsel.
Does buying DDoS-inclusive cyber insurance reduce our likelihood of an attack?
No. Insurance is a risk-transfer mechanism that addresses the financial consequences of an event; it does not reduce the likelihood of a DDoS attack occurring and does not by itself constitute resilience. Reducing likelihood or impact requires risk mitigation, such as traffic filtering, upstream scrubbing services, capacity provisioning, and rehearsed incident response. Insurance and mitigation are complementary: some insurers also weigh the presence of such controls when underwriting or applying failure-to-maintain-standards conditions. Treat coverage as one layer alongside, not a substitute for, technical and operational measures.
How should DDoS scenarios be reflected in our continuity and recovery planning?
DDoS scenarios generally sit within incident response and business continuity planning for availability disruptions, and should be distinguished from disaster recovery of damaged or lost systems and from crisis management of broader organizational impact. Planning considerations often include defining acceptable downtime relative to an RTO, identifying alternate routing or mitigation arrangements, and clarifying escalation paths. These are resilience concepts and operate independently of policy terms such as waiting periods, sublimits, or retentions, which should not be treated as substitutes for recovery objectives. Coordination between resilience planning and coverage terms helps ensure the two are consistent.

Common misconceptions

A DDoS attack means the organization's data has been breached.
A DDoS attack aims to disrupt availability, not necessarily to exfiltrate or access data. It can occur without any compromise of confidentiality, though it is sometimes used as a distraction. Coverage analysis differs accordingly: a pure availability event may engage business interruption wording rather than privacy liability, subject to the specific policy.
Having cyber insurance protects an organization against DDoS attacks.
Insurance is a risk-transfer mechanism that may reimburse certain resulting losses; it does not reduce the likelihood of an attack or keep systems online. Availability during and after an event depends on mitigation controls and resilience planning, not on the existence of a policy. Whether a DDoS loss is payable is also conditional on triggers, waiting periods, and exclusions such as infrastructure exclusions.
Any DDoS-caused outage automatically triggers business interruption coverage.
Coverage is conditional. Many first-party cyber forms apply a waiting period (a time-based retention) before business interruption loss accrues, and some distinguish security-failure triggers from system-failure triggers. Whether a given DDoS outage is covered turns on the specific wording, applicable sublimits, and exclusions.

Best practices

Distinguish availability risk from data-breach risk when assessing DDoS exposure, and map each to the relevant coverage part rather than assuming a single trigger applies.
Review first-party business interruption wording for the waiting period, the distinction between security-failure and system-failure triggers, and any sublimits, so expectations align with what the policy actually pays.
Treat DDoS mitigation controls (such as scrubbing services, CDNs, and traffic filtering) as risk mitigation that reduces likelihood and impact, and recognize these are separate from and not a substitute for insurance.
Define and test recovery objectives (RTO and RPO) for services exposed to availability attacks, keeping business continuity and disaster recovery planning distinct from the incident response process.
Check policy exclusions that may affect DDoS claims, including infrastructure and failure-to-maintain-standards exclusions, and confirm any conditions precedent regarding security controls are being met.
Coordinate incident response with crisis management and communications planning in advance, since prolonged outages can create third-party exposure alongside first-party loss, subject to the specific wording.
Promotional banner for the Penetration Report Template Kit