DDoS Protection & Mitigation
Managed DDoS protection that keeps your site, API and network online through L3-L7 floods. Tuned, monitored, fixed monthly price. Get a free scoping call.
DDoS protection keeps your site, API and network reachable when someone is deliberately trying to flood them offline, and it has to work at the exact moment your team is asleep and your customers are not. We design, tune and watch the mitigation so an attack becomes a line on a dashboard instead of an outage on your revenue.
SafetyBis is a European offensive-security team. We work with companies across Europe and remotely worldwide, and we come at defence from the attacker’s side: we know how these floods are built, which layer they hit, and where cheap mitigations quietly fail. A denial-of-service attack is not sophisticated. It is a firehose pointed at whatever part of your stack is cheapest for the attacker to overwhelm, and the fix is knowing your own weak point before they do.
What DDoS protection actually covers
People picture one giant flood of traffic. In practice the attacks that take businesses down split cleanly into two families, and a defence tuned for one does little against the other. Volumetric floods at the network layer try to saturate your bandwidth. Application-layer floods are quieter and often more dangerous, because they mimic real users and target the expensive parts of your app.
Volumetric attacks at layers 3 and 4
These aim to fill your pipe. Reflection and amplification abuse open UDP services so a small spoofed request generates a huge response aimed at you, and a SYN flood exhausts the connection table on your load balancer without ever completing a handshake. The only real answer is capacity you do not own yourself: a scrubbing network with hundreds of gigabits of headroom that absorbs the flood upstream and forwards only clean traffic to your origin.
Application-layer attacks at layer 7
An HTTP flood looks like browsing. Thousands of requests hit your search endpoint or your cart, each one cheap for the botnet and expensive for your database. Because the packets are valid, a network-layer defence waves them through. Stopping them means understanding what normal looks like for your application and challenging what does not, which is where behavioural rules and rate limiting earn their place.
Why “just put it behind a CDN” is not a plan
A content network in front of a static marketing site helps. The same setup in front of a dynamic application with logins, checkouts and an API leaves the expensive dynamic paths exposed, and attackers know to aim there. Configuration is the whole game. We have seen sites with a well-known edge provider still go down because the origin IP was leaking in email headers and DNS history, letting the attacker skip the protection entirely.
How we set up and run your DDoS protection
Good DDoS protection services are not a product you buy once and forget. They are a configuration that has to match your architecture and then be maintained as your traffic changes. We work in four stages, and the aim throughout is that mitigation triggers automatically and correctly without blocking the customers you want.
Mapping your exposure
We start by finding every reachable surface: the web properties, the APIs, the mail and DNS servers, and any origin address that can be discovered through historical DNS, TLS certificate transparency logs or misconfigured subdomains. Attackers do this reconnaissance first, so we do it first too. If your real server IP is findable, no edge protection matters.
Choosing always-on or on-demand
Always-on protection keeps all traffic flowing through the scrubbing layer at all times, so mitigation is instant. On-demand routing only diverts traffic when an attack is detected, which is cheaper but adds a diversion delay of a minute or two while BGP re-routes. For a payment platform or a SaaS product with a strict SLA we usually recommend always-on for the web tier. For a large network estate, on-demand scrubbing triggered by flow monitoring can be the sensible balance. We will tell you which fits, and why.
Tuning rules to your real traffic
This is where most deployments are left half-done. We baseline your normal request rates per endpoint, per country and per user-agent, then set rate limits and challenge rules that bite on abuse without tripping on your Monday-morning peak. A managed rule that blocks a genuine marketing campaign is its own kind of outage.
Testing it before an attacker does
Because we are an offensive team, we can run a controlled load and layer-7 simulation against the protected setup, with your written authorisation, to confirm the mitigation fires and the origin stays hidden. You get evidence the defence works rather than a promise.
Want this tested on your own systems?
Free 20-minute scoping call, a fixed price with no hourly surprises, and a free retest once you fix what we find.
Common ways DDoS defences fail
An attack rarely beats a well-built mitigation head-on. It finds the gap the mitigation was never covering.
The leaked origin IP
Edge protection only works if traffic is forced through the edge. When the origin server answers direct connections, an attacker who finds that address routes straight around your scrubbing. We check for leaks in DNS history, certificate logs, email headers and old subdomains, then lock the origin to accept traffic only from the edge network’s ranges.
The unprotected subdomain or API
The main website is behind protection; the API on api.yourdomain, the staging box, or the mail server is not. Attackers enumerate subdomains as a matter of routine. Protection has to cover the whole footprint, not just the homepage.
Application logic that amplifies the attack
A single request that triggers a heavy database query, an unbounded export or a costly third-party call turns a modest flood into an outage. We flag these amplifiers during setup so the app itself is not the weapon.
DDoS protection and your compliance obligations
Availability is a security property, not just an operations concern, and European regulators now treat it that way. For financial firms the Digital Operational Resilience Act expects you to withstand and recover from disruptive incidents, and a denial-of-service attack is exactly the scenario it has in mind. ISO 27001 control A.8.6 covers capacity management and A.5.30 covers ICT readiness for continuity, while SOC 2 availability criteria ask you to show the controls that keep the service up.
Evidence an auditor accepts
We document the mitigation architecture, the detection thresholds and the results of any attack simulation, so you can hand an assessor proof rather than a marketing datasheet. When a customer’s security team sends a vendor questionnaire asking how you handle volumetric attacks, you have a real answer with numbers behind it.
Reporting after an incident
If you are ever hit, you get a clear write-up: what the attack looked like, which layer it targeted, how the mitigation responded and what we changed. That record matters for insurers, for regulators and for your own board.
Why choose SafetyBis as your DDoS protection provider
Plenty of DDoS protection companies will sell you a licence and disappear. We are a small European team of certified offensive engineers, and we treat protection as something to be tested and maintained, not shipped and forgotten. Because we spend our days attacking systems for a living, we configure defences the way an attacker would try to beat them.
Manual tuning over default templates
A default rule set is a starting point, not a finished defence. We baseline your traffic and tune the rules by hand so the mitigation fits your application, which is what separates the best DDoS protection services from a checkbox deployment. When you compare ddos protection providers, ask each one who tunes the rules and how often; with us it is a named engineer, reviewed as your traffic changes.
Vendor-neutral advice
We work across the major edge and scrubbing platforms rather than pushing one product, so the recommendation you get is the one that fits your architecture and budget, not the one that pays the best margin.
Pricing
DDoS protection cost depends on what you are protecting and how it is architected: the number of web properties and APIs, whether you need always-on or on-demand routing, and the level of monitoring you want on top. Cloud-native options such as AWS Shield or a large CDN provider have their own ddos protection plan cost, and part of what we do is configure and manage those correctly rather than resell a licence badly. Here is the shape of a typical monthly engagement.
| Plan | What’s covered | Response | Price per month |
|---|---|---|---|
| Starter | One web property behind managed edge protection, L7 rules and rate limiting tuned to your traffic, origin-IP hardening, expiry and health alerts | Automated mitigation, next-business-day support | from €120/month |
| Growth | Multiple sites plus APIs and subdomains, always-on scrubbing, custom WAF rules, monthly traffic and attack review | Automated mitigation, same-day analyst support | from €450/month |
| Enterprise | Full web and network estate, L3/L4 network scrubbing with BGP/GRE routing, tuned detection, quarterly attack simulation | 24/7 monitored, rapid analyst escalation | from €900/month |
| Managed defence retainer | Everything in Enterprise plus a named engineer, on-call attack response and change management for your whole edge and firewall config | 24/7 with agreed SLA | from €800/month |
| Custom / large estate | Many properties or a complex multi-cloud network, scoped after a free call | on scoping | custom |
Every engagement is fixed-price, quoted after a free 20-minute scoping call, and there are no hourly surprises. Prices are confirmed once we have seen your setup. Get a fixed quote
FAQ
How much does DDoS protection cost?
What is the difference between always-on and on-demand protection?
Can you protect against both network and application-layer attacks?
We already use AWS Shield or a CDN. Do we still need you?
How fast do you respond when an attack starts?
Will DDoS protection slow down my site for real users?
Can you test that the protection actually works?
Does this help with compliance?
Related services
Any business that loses money or trust when it goes offline: SaaS platforms, e-commerce and payment sites, gaming and streaming services, and financial firms under DORA. If an outage during a launch, a sale or a Monday peak would hurt, DDoS protection belongs in your budget before the first attack, not after.
Security you can prove
The same standard on every engagement, big or small.
Evidence, not opinions
Every finding ships with a reproduction and proof of concept — no vague "maybe vulnerable".
Humans over scanners
Certified engineers find the logic flaws and chained attacks automated tools walk straight past.
Fixed price, free retest
You know the cost up front, and verifying the fix is part of the deal — not a second invoice.
Ready to lock this down?
Free scoping call, fixed price, free retest. Tell us what you're running and we'll take it from there — usually within one business day.
Tell us what you're running
Scoping is free. We reply within one business day, and under 30 minutes for active incidents.