{"id":3770,"date":"2015-03-31T19:40:23","date_gmt":"2015-03-31T19:40:23","guid":{"rendered":"http:\/\/kasperskydaily.com\/b2b\/?p=3770"},"modified":"2020-02-26T11:01:00","modified_gmt":"2020-02-26T16:01:00","slug":"whats-so-bad-about-ddos","status":"publish","type":"post","link":"https:\/\/www.kaspersky.com\/blog\/whats-so-bad-about-ddos\/3770\/","title":{"rendered":"What&#8217;s so bad about DDoS?"},"content":{"rendered":"<p>While it would be obvious to say that DDoS attacks are \u201cbad for business\u201d, the threat is often underestimated, overlooked, or neglected. Surveys show less than 40% of companies take preventive measures against DDoS, which clearly means the risks these sort of attacks pose aren\u2019t always clearly understood. At least until the attack takes place. In this post, we take a look at understanding these risks.<\/p>\n<p><strong>\u201cToo\u201d targeted<\/strong><\/p>\n<p>Because a DDoS attack is always a very narrowly-targeted event, the chances of getting hit with such an attack are a bit lower than to \u201ccatch\u201d a Cryptolocker or some other \u2013 generic \u2013 Trojan. However, DDoS attacks have become the most common and affordable cyberweapon (launching it may cost <a href=\"https:\/\/business.kaspersky.com\/fighting-fire-with-fire-about-the-european-launch-of-kaspersky-ddos-protection\/2689\" target=\"_blank\" rel=\"noopener nofollow\">around 50 dollars a day<\/a>), \u2013 i.e. the easiest way to inflict targeted damage that may have long-lasting consequences.<\/p>\n<p><strong>Overwhelmed<\/strong><\/p>\n<p>The first \u2013 and probably primary \u2013 problem with DDoS attacks is that they can bog down all business processes in the company that may require use of the network. The amount of junk traffic, depending on the nature of the attack, overwhelms servers or bandwidth. Either way, the target\u2019s web services or web sites become unreachable from the outside, which means normal workflow stops until the DDoS attack subsides or the junk traffic gets filtered off.<\/p>\n<p>And that\u2019s where most of the risks reside.<\/p>\n<p><strong>Estimates<\/strong><\/p>\n<p>Some businesses are more sensitive to a disruption of their processes than the others, and for them, risks of getting hit with a DDoS attack are far greater. Still, with probably 99.999% of the world\u2019s businesses depending on internet communication, everyone is at risk \u2013 more or less.<\/p>\n<p>What companies fear? A recent <a href=\"https:\/\/www.kaspersky.com\/about\/news\/business\/2015\/Companies-under-DDoS-Attack-Fear-Losing-Business-Opportunities-the-Most\" target=\"_blank\" rel=\"noopener nofollow\">survey<\/a> by Kaspersky Lab and B2B International shows that the majority of companies are afraid of losing seemingly guaranteed revenue and contracts the most. 26% of companies see this as the primary risks.<\/p>\n<p>Reputational risks rank next\u00a0with 23%. This sort of risk is especially problematic for totally web-dependent businesses, whose services should be available 24\/7. Even if the attack is quickly drummed off, recovery of the business itself may take quite awhile.<\/p>\n<p>Losing current customers who could not access the anticipated service due to a DDoS attack came in third place: it was named by 19% of respondents. Technical issues were at the bottom of the pile: 17% of respondents identified a need to deploy backup systems that would keep operations online as the most undesirable consequence, while 14% were most concerned with the costs of fighting the attack and restoring services.<\/p>\n<p><strong>Depending on industry<\/strong><\/p>\n<p>The figures shown above suggest\u00a0that companies \u2013 in general \u2013 are more troubled with the costs of setting up backups (which is, by the way, a normal security measure) than mitigating and recovery costs.<\/p>\n<p>However, this\u00a0depends on the field. For example, industrial and telecoms companies, as well as e-commerce, utilities, and energy organizations, tend to rate reputational risks ahead of lost business opportunities. In the construction and engineering sector there is more concern about the cost of setting up backup systems, perhaps because larger companies face higher expenditure on this kind of system.<\/p>\n<p><strong>Underestimation?<\/strong><\/p>\n<p>Overall it looks as though businesses tend to underestimate the situation with DDoS attacks in general and risks they pose.<\/p>\n<p>According to the results of another recent\u00a0<a href=\"https:\/\/press.kaspersky.com\/files\/2014\/11\/B2B-International-2014-Survey-DDoS-Summary-Report.pdf\" target=\"_blank\" rel=\"noopener\">study<\/a>\u00a0conducted by Kaspersky Lab and B2B International, a DDoS attack on a company\u2019s online resources might cause considerable losses \u2013 with average figures ranging from $52,000 to $444,000 depending on the size of the company. For many organizations these expenses have a serious impact on the balance sheet as well as harming the company\u2019s reputation due to loss of access to online resources for partners and customers.<\/p>\n<p>DDoS attacks on company resources are becoming a costly problem, but only 37% of the organizations surveyed said they currently have measures in place to protect against them. This is an unnecessary oversight at a time when the IT security market can offer reliable and easy-to-deploy security solutions that are able to prevent loss of access to online services caused by a DDoS attack.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>While it would be obvious to say that DDoS attacks are \u201cbad for business\u201d, the threat is often underestimated, overlooked, or neglected. Surveys show less than 40% of companies take<\/p>\n","protected":false},"author":209,"featured_media":15370,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1999,3052],"tags":[1058,1146],"class_list":{"0":"post-3770","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-business","8":"category-smb","9":"tag-ddos","10":"tag-risks"},"hreflang":[{"hreflang":"x-default","url":"https:\/\/www.kaspersky.com\/blog\/whats-so-bad-about-ddos\/3770\/"},{"hreflang":"en-au","url":"https:\/\/www.kaspersky.com.au\/blog\/whats-so-bad-about-ddos\/3770\/"},{"hreflang":"en-za","url":"https:\/\/www.kaspersky.co.za\/blog\/whats-so-bad-about-ddos\/3770\/"}],"acf":[],"banners":"","maintag":{"url":"https:\/\/www.kaspersky.com\/blog\/tag\/ddos\/","name":"ddos"},"_links":{"self":[{"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts\/3770","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/users\/209"}],"replies":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/comments?post=3770"}],"version-history":[{"count":3,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts\/3770\/revisions"}],"predecessor-version":[{"id":33493,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts\/3770\/revisions\/33493"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/media\/15370"}],"wp:attachment":[{"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/media?parent=3770"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/categories?post=3770"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/tags?post=3770"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}