Skip to main content
Business Continuity

DDoS test.
Does your DDoS protection actually work?

A DDoS test simulates a real attack in a controlled manner to validate whether your anti-DDoS measures are effective. Not just "does it go down?" but how fast it detects, how well it mitigates and how quickly it recovers.

What is a DDoS Test?

A DDoS Test simulates a Distributed Denial of Service attack on your online services in a controlled manner to validate whether your anti-DDoS measures are effective. The team tests at multiple levels: volumetric (bandwidth), protocol (TCP/UDP) and application layer (HTTP floods). Each type tests a different layer of your defences.

The Service

Validate your defences before attackers do

The test does not just check "does it go down". The team measures the full chain: how quickly does your DDoS protection detect the attack? How effective is the mitigation? What is the residual impact on legitimate traffic? How quickly do you recover after the attack ends?

The team conducts realistic DDoS simulations at different levels: volumetric (bandwidth), protocol (TCP/UDP) and application layer (HTTP floods, slowloris). Each attack type tests a different layer of your defences.

The results provide concrete input for improving your DDoS strategy: configuration adjustments, capacity expansion or selection of a different mitigation solution.

A DDoS test shows whether your infrastructure survives an attack. Want to know if attackers can actually get in? Book a penetration test. Want to detect and stop attacks around the clock? Read about managed detection and response.

Why it matters

DDoS protection that hasn't been tested is an assumption

  • Configuration gaps are only found under real attack conditions

    DDoS mitigation solutions require correct configuration to be effective. Misconfigured solutions may allow attacks through or block legitimate traffic. Only testing reveals these issues.

  • Application layer attacks bypass volumetric protection

    Many organisations have volumetric DDoS protection but no application layer (Layer 7) defences. These attacks use legitimate-looking requests and can take down services with surprisingly low traffic volumes.

  • NIS2 and DORA require demonstrable availability measures

    Both frameworks require organisations to demonstrate that availability measures are in place and effective. A DDoS test provides the evidence that your protection works as intended.

DDoS testing explained

The questions to settle before you book a DDoS test

Is DDoS testing legal?

Yes, as long as the target is yours or you are explicitly authorised to test it. A legal DDoS test has a written agreement that names the systems, the attack vectors, the maximum intensity, the time window and who can stop the test at any moment. Your ISP and DDoS mitigation provider are informed in advance, so the test is not mistaken for a real attack and nobody blocks your legitimate traffic. Flooding a system you do not own, or exceeding the agreed scope, is a criminal offence in the Netherlands, Spain and across the EU. DEFION generates attack traffic from its own controlled infrastructure and never uses botnets or third-party "stresser" services.

How often should you test?

Once a year is the baseline. Test again whenever the thing you are protecting or the thing protecting it changes:

  • You switch DDoS mitigation provider, change its configuration or add a new CDN or WAF layer.
  • You migrate to a new hosting or cloud environment, or expose a new customer-facing platform or API.
  • A peak season is coming (Black Friday, open enrolment, year-end) or your sector is being targeted.
  • You are a financial entity under DORA: the test is part of your annual resilience testing programme.

What does a DDoS test cost?

The price is driven by four things: how many targets, which attack vectors (volumetric, protocol, layer 7 or all three), how high the intensity goes and how long the test windows are. A test of one or a few internet-facing services, including scoping, coordination with your ISP and mitigation provider, execution and the report, is a matter of days of work. You get a fixed price after scoping. Compare that with the cost of a day of downtime for your webshop, portal or payment flow.

DDoS testing for banks and financial institutions: what DORA actually requires

DORA does not contain a separate "DDoS test" obligation. It requires financial entities to run a digital operational resilience testing programme covering their critical ICT systems, with tests such as vulnerability assessments, scenario-based tests and performance testing. Designated entities must additionally perform threat-led penetration testing (TLPT) every three years. A controlled DDoS test fits the first category: it is the scenario-based test that proves your availability controls hold under attack, and the report is the evidence your auditor and supervisor ask for. It does not replace TLPT. For banks, payment institutions and insurers, DEFION aligns the test scope and the report with the testing programme you already document.

What a DDoS test plan contains

Before any traffic is generated you receive a test plan. It is the document your management, your providers and your legal team sign off on:

Targets in scope (IPs, hostnames, services) and explicitly out of scope
Written authorisation and rules of engagement
Attack vectors per phase and the intensity ramp per vector
Time windows, go/no-go criteria and the emergency stop procedure
Contacts at your side, your ISP and your mitigation provider
What is measured: detection time, mitigation effectiveness, impact on legitimate traffic, recovery time

Am I being DDoSed right now?

A DDoS test validates your protection before an attack. If you suspect an attack is happening now, look for these signs: services that slow down or time out while your servers are not busy, a sudden spike in traffic from many unrelated IP addresses or countries, your mitigation provider or ISP raising alerts, and legitimate users reporting errors while internal systems work normally.

What to do: contact your ISP or mitigation provider to activate or tighten mitigation, keep logs and traffic captures as evidence, and if the attack is a smokescreen for intrusion attempts or you need help coordinating, call the DEFION 24/7 incident response team at +31 (0)88 733 13 38.

Scope

What we test

Volumetric DDoS simulation
Protocol-based attacks (SYN flood, UDP flood)
Application layer attacks (HTTP flood, slowloris, API abuse)
Anti-DDoS protection effectiveness measurement
Failover and recovery validation
Impact on legitimate traffic during attack
Methodology

How we run a DDoS test

01

Scoping

Target systems, attack types, intensity levels, timing and emergency stop procedures. Alignment with your DDoS provider and ISP.

02

Preparation

Coordination with ISP and DDoS mitigation provider. Establishing monitoring and measurement baseline.

03

Execution

Phased DDoS simulation with escalating intensity. Multiple attack vectors tested sequentially.

04

Monitoring

Real-time monitoring of availability, mitigation effectiveness and impact on legitimate traffic throughout the test.

05

Reporting

Report with test results, effectiveness assessment per attack type, and concrete recommendations for improvement.

What You Receive

Deliverables

  • DDoS test report
  • Effectiveness assessment per attack type
  • Availability measurements during the test
  • Mitigation response times
  • Recommendations for improvement
  • Executive summary
For Whom

Who needs a DDoS test

Organisations with customer-facing online services

If your online services are unavailable, customers go elsewhere. Validate that your protection keeps them available.

E-commerce companies dependent on availability

Revenue stops when your platform goes down. Validate that your DDoS protection handles peak attack traffic.

Financial institutions with online services

DORA requires a digital operational resilience testing programme. A DDoS test is one of the scenario-based tests in that programme and documents that your availability controls hold.

Organisations wanting to validate their DDoS mitigation investment

You pay for DDoS protection. This test validates whether you are getting what you are paying for.

Frequently Asked Questions

FAQ

Can a DDoS test disrupt our services?
That is precisely the point: testing what happens under attack conditions. The test is conducted in a controlled manner with escalating intensity and an emergency stop procedure. Timing is coordinated to minimise impact on end users.
Should we inform our DDoS provider?
Yes. The DDoS mitigation provider and ISP are informed in advance to prevent the test being treated as a real attack and to avoid false positive mitigation.
How high is the test intensity?
Determined together based on your bandwidth, mitigation capacity and risk tolerance. The test starts low and scales up. The goal is to find the limits of your protection.
Do you also test at the application layer?
Yes. Application layer DDoS attacks (Layer 7) are often harder to mitigate than volumetric attacks. The team specifically tests these attack types.
How often should a DDoS test be performed?
At least once a year, and again after every significant change: a new mitigation provider or configuration, a migration, a new customer-facing platform or before a peak season. Financial entities under DORA include it in their annual resilience testing programme.
Is DDoS testing legal?
Yes, when it is done against systems you own or are explicitly authorised to test, under a written agreement with a defined scope, time window and emergency stop. Flooding systems without that authorisation is a criminal offence. DEFION tests only under signed rules of engagement and informs your ISP and mitigation provider beforehand.
What does a DDoS test cost?
The price depends on the number of targets, the attack vectors, the intensity levels and the duration. A test of one or a few internet-facing services, including scoping, coordination with your providers and the report, is a matter of days of work. You receive a fixed price after scoping, with no surprises.
Does DORA require a DDoS test?
Not as a separate obligation. DORA requires financial entities to run a digital operational resilience testing programme and, for designated entities, threat-led penetration testing (TLPT) every three years. A DDoS test is one of the scenario-based tests that programme can include to prove your availability controls work. It is not a substitute for TLPT.
How do I know if I am being DDoSed right now?
Typical signs: services that suddenly slow down or time out while your own systems are not overloaded, traffic spikes from many different IP addresses or countries, and alerts from your ISP or mitigation provider. If that is happening now, contact your provider to activate mitigation and call the DEFION 24/7 incident hotline. A DDoS test is for validating your protection before an attack, not during one.

Validate your DDoS protection
before it matters.

Request a controlled DDoS test. Know your protection works when you need it most.