DDoS Protection for UK Businesses: What Actually Matters
How always-on edge mitigation differs from scrubbing centres, why capacity (Gbps) alone is not enough, and how Fast2Host protects hosted and colo customers.
A DDoS attack does not need to breach your app — it only needs to exhaust bandwidth or overwhelm stateful devices. For UK merchants and SaaS operators, the difference between “we have a firewall” and “we have real mitigation” shows up during the first ransom email.
Always-on vs on-demand scrubbing
- Always-on / in-line — traffic is filtered continuously at the network edge. Latency stays predictable; you do not wait for a BGP redirect after the attack starts.
- On-demand scrubbing — cheaper on paper, slower when every second of checkout downtime costs money.
We run always-on Corero SmartWall mitigation as part of the Fast2Host network — see DDoS protection.
Capacity is not the whole story
Marketing posters shout “600 Gbps”. Useful — but detection quality, automated signatures and how quickly bad traffic is dropped matter more than the biggest number on a slide. Ask whether mitigation is included with hosting/colo or billed as an emergency upgrade.
What you should still harden
Edge DDoS is not an application WAF. Keep Imunify360 / ModSecurity (or your own WAF), rate-limit login endpoints, and keep DNS TTL sane so you can shift traffic if needed.
Colo and BYO networks
If you announce your own ASN from a colo cabinet, clarify whether mitigation covers your prefixes and how BGP communities work during an event. Our team engineers that path with you — not a generic cloud ticket.
Takeaway: buy network-level DDoS that is on by default, then layer app security on top.