February 27, 2018 By Douglas Bonderud 2 min read

Recovering after a distributed denial-of-service (DDoS) attack is expensive, and recent research showed that costs are on the rise.

According to Kaspersky Lab’s “IT Security Risks Survey 2017,” small and midsized businesses (SMBs) were on the hook for $17,000 more in 2017 than the year before. Meanwhile, the average DDoS protection cost jumped from $1.6 to $2.3 million for enterprises over the same period, as reported by Infosecurity Magazine.

Even more worrisome, previous research from the cybersecurity firm found that the rate of DDoS attacks nearly doubled from 2016 to 2017 and, much like malware, there’s no sign of slowdown. Are increased costs simply par for the course, or is there hope for scaling back DDoS spend?

Breaking Down Increasing DDoS Protection Cost

It’s one thing to consider grand totals — it costs hundreds of thousands for SMBs and millions for enterprises to recover after a DDoS attack. But how do these costs break down? Where are organizations hit hardest?

When asked, 33 percent of respondents pointed to the cost of fighting DDoS attacks directly and restoring services, while 25 percent focused on the money required to maintain backup and recovery systems. Lost revenue opportunities and damaged reputations were cited by 23 and 22 percent of companies, respectively.

It’s also worth considering the multiplicative nature of DDoS attacks. As noted by Information Security Buzz, costs can quickly climb outside the average. According to Andrew Lloyd, president of Corero Network Security, “It’s helpful to think about what a DDoS attack might cost an organization for every minute that it goes unmitigated.”

For companies that have large-volume e-commerce stores or depend upon available web services to empower mobile transactions or remote worker productivity, the longer an attack goes on, the more difficult it becomes to predict (and rein in) DDoS protection cost.

The Good News and Bad News About DDoS Protection

The news around DDoS isn’t all bad. Security solutions are getting better at detecting DDoS attacks and protecting key systems, even as researchers backtrack malicious actors.

In addition, both SMBs and enterprises now recognize the potential use of DDoS as distraction for other attacks. Instead of putting all their eggs in one basket, they can better distribute DDoS protection cost across the entire organization. Evolving cognitive security tools are also helping enterprises go beyond simple detection to discover new attack vectors and indicators of compromise.

Given the results of the study, security professionals should expect the average DDoS protection cost to keep trending upward. They should also anticipate a shift in security spending as cognitive tools give companies a fighting chance against DDoS damage.

More from

When ransomware kills: Attacks on healthcare facilities

4 min read - As ransomware attacks continue to escalate, their toll is often measured in data loss and financial strain. But what about the loss of human life? Nowhere is the ransomware threat more acute than in the healthcare sector, where patients’ lives are literally on the line.Since 2015, there has been a staggering increase in ransomware attacks on healthcare facilities. And the impacts are severe: Diverted emergency services, delayed critical treatments and even fatalities. Meanwhile, the pledge some ransomware groups made during…

AI and cloud vulnerabilities aren’t the only threats facing CISOs today

6 min read - With cloud infrastructure and, more recently, artificial intelligence (AI) systems becoming prime targets for attackers, security leaders are laser-focused on defending these high-profile areas. They’re right to do so, too, as cyber criminals turn to new and emerging technologies to launch and scale ever more sophisticated attacks.However, this heightened attention to emerging threats makes it easy to overlook traditional attack vectors, such as human-driven social engineering and vulnerabilities in physical security.As adversaries exploit an ever-wider range of potential entry points…

4 trends in software supply chain security

4 min read - Some of the biggest and most infamous cyberattacks of the past decade were caused by a security breakdown in the software supply chain. SolarWinds was probably the most well-known, but it was not alone. Incidents against companies like Equifax and tools like MOVEit also wreaked havoc for organizations and customers whose sensitive information was compromised.Expect to see more software supply chain attacks moving forward. According to ReversingLabs' The State of Software Supply Chain Security 2024 study, attacks against the software…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today