DDoS Protection for UK Businesses: What Actually Matters
A practical UK buyer’s guide to DDoS protection — always-on vs scrubbing, why Gbps alone is not enough, downtime costs, colo/BGP questions, and how Fast2Host protects hosting and colo customers.
A DDoS attack does not need to breach your app — it only needs to exhaust bandwidth or overwhelm stateful devices. For UK merchants, agencies, SaaS operators and anyone taking card payments online, the difference between “we have a firewall” and “we have real mitigation” shows up during the first ransom email or the first Black Friday flood.
This guide is the buyer’s view: what to demand from a UK host, what marketing claims to ignore, and how to layer network DDoS with application security. For the platform deep-dive (Corero SmartWall, 600Gbps capacity, sub-second mitigation), see 600Gbps Corero DDoS at Fast2Host.

Who actually gets hit (and why it matters in the UK)
You do not need to be a household brand. Attackers target:
- Checkout and booking flows — cart and payment APIs are high-leverage; a short outage is expensive
- Agencies and resellers — one saturated uplink can take many client sites offline at once
- Game servers and voice — UDP-heavy stacks feel volumetric floods immediately
- APIs and SaaS login — state exhaustion on firewalls and load balancers looks like “the site is down”
- Colo and BYO ASN — your prefixes are visible; without edge filtering, your port is the bottleneck
UK buyers also care about data residency and ops accountability. Mitigation that depends on a distant scrubbing centre and a US-hours ticket queue is a different product from always-on filtering on a UK network your provider actually operates (AS48825 in our case).
What a DDoS is (in plain English)
| Layer | What the attacker does | What you feel |
|---|---|---|
| Volumetric (L3/L4) | Floods your pipe with junk (UDP/ICMP, reflection) | Port saturates; everything times out |
| Protocol / state | SYN floods, fragments, table exhaustion | Firewalls and load balancers fall over first |
| Application (L7) | Abusive HTTP(S), slowloris-style, bot GETs | Origin CPU and WAF burn while bandwidth looks “fine” |
| Multi-vector | Mix and rotate the above | One tool rarely stops all of it |

Edge DDoS platforms are built for the first three at network scale. They are not a replacement for a web application firewall against SQLi, plugin exploits or account takeover — you still need that layer (see below).
Always-on vs on-demand scrubbing
This is the decision that matters most for UK ecommerce and SaaS.
- Always-on / in-line — traffic is filtered continuously at the network edge. Latency stays predictable; you do not wait for a BGP redirect after the attack starts.
- On-demand scrubbing — cheaper on paper. When the blast starts you (or your host) detect, escalate, and divert traffic to a scrubbing centre. That divert often takes minutes, not milliseconds.

| Approach | Typical delay before mitigation | Risk window |
|---|---|---|
| Always-on in-line (e.g. Corero on AS48825) | Under 1 second | Minimal |
| Manual “please enable DDoS” ticket | ~5 minutes if someone responds | Cart / VoIP already failing |
| Classic on-demand scrubbing | Often 15–30+ minutes | Full outage for the wait |
We run always-on Corero SmartWall as part of the Fast2Host network — included, not an emergency upgrade. Product page: DDoS protection.
Capacity is not the whole story
Marketing posters shout “600 Gbps” (we publish that figure because it is our engineered edge headroom). Useful — but detection quality, automated signatures and how quickly bad traffic is dropped matter more than the biggest number on a slide.
Ask every UK host:
- Is mitigation always-on or on-demand?
- Is it included with hosting/colo, or billed as an emergency upgrade?
- Do you null-route (blackhole) customer IPs under load, or filter surgically so clean traffic continues?
- Who is watching at 2am — a UK NOC, or a ticket queue?
- Does coverage include new services automatically when they go live?
Fast2Host answers: always-on Corero, included free, surgical filtering (no null-route culture), 24/7 Cambridge NOC visibility, 100% of services on AS48825. Numbers and platform detail: Corero deep-dive.
What downtime actually costs
Industry studies regularly put serious online outages in the thousands of pounds per hour once cart and payment fail. Using a simple illustrative peak of ~£2,000/hour:

| Mitigation delay | Illustrative revenue at risk (@ £2k/hour) |
|---|---|
| <1 second | ~£0 material cart loss |
| 5 minutes | ~£170 |
| 15 minutes | ~£500 |
| 30 minutes | ~£1,000 |
Illustrative only — reputation damage, SLA credits, support overtime and SEO “site down” chatter often dwarf the cart line. The point is the wait, not the exact pound figure.
If your host’s plan is “we will scrub you once we notice”, you are buying the wait.
What you should still harden (edge DDoS is not a WAF)
Network DDoS and application security solve different problems. Keep both:
- WAF / malware layer — Imunify360, ModSecurity, or your own WAF for SQLi, XSS and plugin abuse
- Rate-limit login, checkout and expensive API routes
- Sane DNS TTLs so you can shift traffic in a genuine disaster
- Origin hygiene — patch CMS/plugins, disable unused services, separate admin origins where practical
- Monitoring — know when latency or error rates spike before customers tweet
Edge filtering keeps the pipe and stateful devices alive. It will not fix an unpatched WordPress plugin.
Colo, dedicated and BYO networks
If you colocate hardware or announce your own ASN from a cabinet, clarify:
- Whether mitigation covers your prefixes, not only shared hosting IPs
- How BGP communities / signalling work during an event
- Whether the provider null-routes your space under pressure (bad) or filters in-line (good)
- Who you phone at 2am — and whether they can walk the path from transit to your rack
Our team engineers that path with colo customers — not a generic cloud ticket. See colocation and remote hands for the operational side; DDoS sits on the same AS48825 edge as everything else.
A short UK buying checklist
Use this on sales calls:
| Ask | Good answer looks like |
|---|---|
| Always-on or scrubbing? | Always-on / in-line at the edge |
| Included or upsell? | Included on every plan |
| Vendor / capacity? | Named platform + honest Gbps headroom |
| Null-routes? | No — surgical drop of attack traffic |
| Time to mitigate? | Sub-second / automatic, not “open a ticket” |
| Colo / BYO ASN? | Documented prefix coverage and BGP options |
| Ops | UK engineers who own the network |
If answers are vague (“we have Cloudflare in front of some sites” / “we can enable protection if you are attacked”), keep shopping.
How Fast2Host fits
For hosted, VPS, dedicated, gaming and colo customers on our network:
- 600Gbps Corero SmartWall always-on filtering
- Typical mitigation in under one second
- Included free — no mid-attack upsell
- No null-routes as the default “protection”
- AS48825 multi-homed UK network (LINX / LONAP peering)
- Same edge for new services when they go live
Full service overview: DDoS protection. Network design: our network. Platform stats and attack classes: Corero 600Gbps guide.
Bottom line
Buy network-level DDoS that is on by default, then layer application security on top. Capacity headlines help; always-on detection, surgical filtering and UK ops decide whether your checkout survives the first serious flood.
Questions about coverage for colo prefixes or a specific workload — contact us or open a ticket from the client area.