4 MIN READ
The DDoS attack in 2026 costs the typical mid-size company somewhere between $20K and $200K for every hour the site is dark. Most of them see 5 to 20 attacks a year, ranging from a few Gbps that the edge CDN shrugs off to multi-Tbps floods that saturate the upstream link and last anywhere from an hour to a day. The mitigation in 2026 is no longer the multi-million-dollar scrubbing centre only the banks could afford. There is a real path for a small team on a realistic budget.
The market has caught up. Cloudflare, Akamai, Fastly, AWS Shield, and Azure DDoS Protection all ship an always-on tier any startup can subscribe to in an afternoon, and the WAF plus bot management that used to be a separate procurement exercise are bundled in. The hard part is not whether the protection exists. The hard part is picking the right combination for the attack profile a company is most likely to face.
What the attacks look like
Three broad categories, in roughly the order of how often the small operation sees them. Volumetric attacks try to saturate the internet link. UDP floods, TCP SYN floods, ICMP floods, all aimed at pushing more bits at the network than the link can carry. Modern CDNs eat most of this at the edge before it ever reaches the origin, which is why the volumetric attack that worked in 2015 is mostly a footnote now.
Protocol attacks exploit weaknesses in the connection setup. SYN floods, ping of death, smurf attacks, all of them aimed at exhausting the server’s connection table before the server can answer real requests. The damage shows up as a server that is technically online but cannot serve anything.
Application layer attacks are the ones doing the damage in 2026. HTTP floods, slow loris, API floods, all shaped to look like legitimate traffic so the basic rate limiter does not catch them. They get inside the application logic and exhaust the worker pool, the database connections, or the API quota. A 5 Gbps application layer attack takes down more mid-size sites than a 500 Gbps volumetric one, because the CDN cannot tell the difference between a real user and a slow loris connection.
What the mitigation does
The defensive side has the same three-layer shape. The network layer puts the CDN at the edge, Cloudflare or Akamai, absorbing the volumetric flood before it ever reaches the origin. The protocol layer puts the WAF in front of the connection setup, AWS Shield, Cloudflare WAF, Azure DDoS Protection, dropping the malformed packets and the connection exhaustion attempts. The application layer puts the bot management and the behavioural analysis in the request path, DataDome, PerimeterX, Cloudflare Bot Management, looking at the request pattern and not just the request shape. Skipping any one of the three opens a gap the attacker will find within a week.
What to do on the small budget
Three moves for a small team without a dedicated security org. First, get the Cloudflare free or pro tier in front of the origin. The free tier handles the small volumetric attacks and gives the basic WAF. The pro tier at around $20 a site a month absorbs the medium-sized flood and adds the bot management and the analytics. Second, add the rate limiting on the public API, which costs nothing to implement and stops the API flood the CDN will not catch on its own. A good starting rule is 100 requests per minute per user and 1,000 per hour per IP, then tune from there. Third, turn on the uptime monitoring with the response time alerts, so the team finds out about the attack in minutes rather than when a customer files a ticket.

The bottom line
CDN in front of the origin, rate limiting on the public API, monitoring with the right alerts. The small team that does those three handles the 95 percent of DDoS attacks the small team will actually see. The remaining 5 percent is the multi-Tbps nation state flood, and no small team was going to handle that alone anyway.
Sources & Further Reading
All claims in this article are sourced from primary documentation, vendor advisories, and reputable security researchers.
Spotted an error? Email the editor. Corrections are issued with a visible correction note.
Editorial standards. Every article on humanrequired.org is reviewed by a human editor before publication. AI may assist with drafting or research; final editorial control is human. Read the full standards.



