DDoS test.
Does your DDoS protection actually work?
A DDoS test simulates a real attack in a controlled manner to validate whether your anti-DDoS measures are effective. Not just "does it go down?" but how fast it detects, how well it mitigates and how quickly it recovers.
What is a DDoS Test?
A DDoS Test simulates a Distributed Denial of Service attack on your online services in a controlled manner to validate whether your anti-DDoS measures are effective. The team tests at multiple levels: volumetric (bandwidth), protocol (TCP/UDP) and application layer (HTTP floods). Each type tests a different layer of your defences.
Validate your defences before attackers do
The test does not just check "does it go down". The team measures the full chain: how quickly does your DDoS protection detect the attack? How effective is the mitigation? What is the residual impact on legitimate traffic? How quickly do you recover after the attack ends?
The team conducts realistic DDoS simulations at different levels: volumetric (bandwidth), protocol (TCP/UDP) and application layer (HTTP floods, slowloris). Each attack type tests a different layer of your defences.
The results provide concrete input for improving your DDoS strategy: configuration adjustments, capacity expansion or selection of a different mitigation solution.
A DDoS test shows whether your infrastructure survives an attack. Want to know if attackers can actually get in? Book a penetration test. Want to detect and stop attacks around the clock? Read about managed detection and response.
DDoS protection that hasn't been tested is an assumption
-
Configuration gaps are only found under real attack conditions
DDoS mitigation solutions require correct configuration to be effective. Misconfigured solutions may allow attacks through or block legitimate traffic. Only testing reveals these issues.
-
Application layer attacks bypass volumetric protection
Many organisations have volumetric DDoS protection but no application layer (Layer 7) defences. These attacks use legitimate-looking requests and can take down services with surprisingly low traffic volumes.
-
NIS2 and DORA require demonstrable availability measures
Both frameworks require organisations to demonstrate that availability measures are in place and effective. A DDoS test provides the evidence that your protection works as intended.
The questions to settle before you book a DDoS test
Is DDoS testing legal?
Yes, as long as the target is yours or you are explicitly authorised to test it. A legal DDoS test has a written agreement that names the systems, the attack vectors, the maximum intensity, the time window and who can stop the test at any moment. Your ISP and DDoS mitigation provider are informed in advance, so the test is not mistaken for a real attack and nobody blocks your legitimate traffic. Flooding a system you do not own, or exceeding the agreed scope, is a criminal offence in the Netherlands, Spain and across the EU. DEFION generates attack traffic from its own controlled infrastructure and never uses botnets or third-party "stresser" services.
How often should you test?
Once a year is the baseline. Test again whenever the thing you are protecting or the thing protecting it changes:
- You switch DDoS mitigation provider, change its configuration or add a new CDN or WAF layer.
- You migrate to a new hosting or cloud environment, or expose a new customer-facing platform or API.
- A peak season is coming (Black Friday, open enrolment, year-end) or your sector is being targeted.
- You are a financial entity under DORA: the test is part of your annual resilience testing programme.
What does a DDoS test cost?
The price is driven by four things: how many targets, which attack vectors (volumetric, protocol, layer 7 or all three), how high the intensity goes and how long the test windows are. A test of one or a few internet-facing services, including scoping, coordination with your ISP and mitigation provider, execution and the report, is a matter of days of work. You get a fixed price after scoping. Compare that with the cost of a day of downtime for your webshop, portal or payment flow.
DDoS testing for banks and financial institutions: what DORA actually requires
DORA does not contain a separate "DDoS test" obligation. It requires financial entities to run a digital operational resilience testing programme covering their critical ICT systems, with tests such as vulnerability assessments, scenario-based tests and performance testing. Designated entities must additionally perform threat-led penetration testing (TLPT) every three years. A controlled DDoS test fits the first category: it is the scenario-based test that proves your availability controls hold under attack, and the report is the evidence your auditor and supervisor ask for. It does not replace TLPT. For banks, payment institutions and insurers, DEFION aligns the test scope and the report with the testing programme you already document.
What a DDoS test plan contains
Before any traffic is generated you receive a test plan. It is the document your management, your providers and your legal team sign off on:
Am I being DDoSed right now?
A DDoS test validates your protection before an attack. If you suspect an attack is happening now, look for these signs: services that slow down or time out while your servers are not busy, a sudden spike in traffic from many unrelated IP addresses or countries, your mitigation provider or ISP raising alerts, and legitimate users reporting errors while internal systems work normally.
What to do: contact your ISP or mitigation provider to activate or tighten mitigation, keep logs and traffic captures as evidence, and if the attack is a smokescreen for intrusion attempts or you need help coordinating, call the DEFION 24/7 incident response team at +31 (0)88 733 13 38.
What we test
How we run a DDoS test
Scoping
Target systems, attack types, intensity levels, timing and emergency stop procedures. Alignment with your DDoS provider and ISP.
Preparation
Coordination with ISP and DDoS mitigation provider. Establishing monitoring and measurement baseline.
Execution
Phased DDoS simulation with escalating intensity. Multiple attack vectors tested sequentially.
Monitoring
Real-time monitoring of availability, mitigation effectiveness and impact on legitimate traffic throughout the test.
Reporting
Report with test results, effectiveness assessment per attack type, and concrete recommendations for improvement.
Deliverables
- DDoS test report
- Effectiveness assessment per attack type
- Availability measurements during the test
- Mitigation response times
- Recommendations for improvement
- Executive summary
Who needs a DDoS test
Organisations with customer-facing online services
If your online services are unavailable, customers go elsewhere. Validate that your protection keeps them available.
E-commerce companies dependent on availability
Revenue stops when your platform goes down. Validate that your DDoS protection handles peak attack traffic.
Financial institutions with online services
DORA requires a digital operational resilience testing programme. A DDoS test is one of the scenario-based tests in that programme and documents that your availability controls hold.
Organisations wanting to validate their DDoS mitigation investment
You pay for DDoS protection. This test validates whether you are getting what you are paying for.
FAQ
Can a DDoS test disrupt our services?
Should we inform our DDoS provider?
How high is the test intensity?
Do you also test at the application layer?
How often should a DDoS test be performed?
Is DDoS testing legal?
What does a DDoS test cost?
Does DORA require a DDoS test?
How do I know if I am being DDoSed right now?
Validate your DDoS protection
before it matters.
Request a controlled DDoS test. Know your protection works when you need it most.
®