
Andrey Slastenov at Gcore describes how cyber-criminals are evolving their tactics for more potent DDoS attacks
The evolving nature of Distributed Denial of Service (DDoS) attacks is causing growing concern in the cyber-security realm. Threats are increasing in number and growing more complex and intense, necessitating more advanced security preparations for businesses.
This article examines the factors fuelling the rise of DDoS attacks, industry-specific vulnerabilities, and evolving tactics of cyber-criminals based on insights from Gcore’s expert analysis.
The growth of IoT devices, easy access to hacking tools, and commercialisation of DDoS attacks (DDoS-as-a-service) have all contributed to the surge in DDoS attacks. The situation is further complicated by the growing number of motives behind these attacks, which now include corporate competition and political agendas in addition to simple mischief.
As businesses deal with these obstacles, understanding the evolving techniques and causes behind these cyber-attacks becomes critical for successful security planning.
According to the Gcore Radar report from Q1 to Q2 2023 there have been several significant shifts in the DDoS landscape:
Even though our aim to is help businesses understand cyber-security vulnerabilities, we are not immune to being attacked.
Following the publication of our recent Radar report, our infrastructure and clients were quickly targeted by 854 diverse attacks of varying intensity and complexity within a week, the most potent peaking at 750 Gbps. The longest of these assaults stretched over 14 hours, and the most powerful reached an intensity of about 750 Gbps. Despite the onslaught, we repelled each attack due to the resilience of our security.
This surge in attacks post-report highlights the ongoing tug-of-war between cyber-security defences and attackers. Our real-world experience of defending against these cyber-criminals has added a layer of urgency to our protection against DDoS attacks.
Understanding the changing landscape of DDoS attacks is critical, but so is taking action. A successful defensive plan for any organisation should combine evaluation, technical countermeasures, and continual monitoring to increase security.
Let’s look at the main points that will help businesses to harden their security posture.
Assessment and planning
Start with a security audit to find infrastructure weaknesses. After identifying these, create a comprehensive security policy with countermeasures and best practices.
Technical measures
Incorporate a multi-layered security approach combining physical, network, and software measures:
Management and monitoring
Consider implementing an auditing or security information and event management (SIEM) system for real-time monitoring. That way, you can notice traffic spikes and take action immediately.
Education, analytics, and intelligence
Educate your staff on fundamental security principles and regularly simulate phishing attacks to test their awareness. A well-trained workforce is essential for effective cyber-security. Train your security team to spot the early warning signs of compromise.
Collaboration and partnerships
Connect with professional networks like Information Sharing and Analysis Centers (ISACs) to stay abreast of emerging threats and solutions and learn about attacks that could potentially target your organisation. Partnering with internet service providers can offer added layers of protection.
Consider a third-party IT solution
In addition to extensive knowledge of the subject, developing safe and robust infrastructure from scratch necessitates large sums and takes time. Consider adopting third-party security solutions if you lack the resources to construct your secure infrastructure.
While these countermeasures provide a robust framework for enhancing your cyber-security posture against DDoS attacks, the evolving nature of threats requires specialised expertise, continuous monitoring, time to implement, and investments.
Andrey Slastenov is Head of Security at Gcore
Main image courtesy of iStockPhoto.com
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543