DDoS Protection for UK Businesses: What Actually Matters

A practical UK buyer’s guide to DDoS protection — always-on vs scrubbing, why Gbps alone is not enough, downtime costs, colo/BGP questions, and how Fast2Host protects hosting and colo customers.

A DDoS attack does not need to breach your app — it only needs to exhaust bandwidth or overwhelm stateful devices. For UK merchants, agencies, SaaS operators and anyone taking card payments online, the difference between “we have a firewall” and “we have real mitigation” shows up during the first ransom email or the first Black Friday flood.

This guide is the buyer’s view: what to demand from a UK host, what marketing claims to ignore, and how to layer network DDoS with application security. For the platform deep-dive (Corero SmartWall, 600Gbps capacity, sub-second mitigation), see 600Gbps Corero DDoS at Fast2Host.

Fast2Host DDoS stats: 600Gbps, under 1 second, 24/7 always-on, 100% services covered

Who actually gets hit (and why it matters in the UK)

You do not need to be a household brand. Attackers target:

  • Checkout and booking flows — cart and payment APIs are high-leverage; a short outage is expensive
  • Agencies and resellers — one saturated uplink can take many client sites offline at once
  • Game servers and voice — UDP-heavy stacks feel volumetric floods immediately
  • APIs and SaaS login — state exhaustion on firewalls and load balancers looks like “the site is down”
  • Colo and BYO ASN — your prefixes are visible; without edge filtering, your port is the bottleneck

UK buyers also care about data residency and ops accountability. Mitigation that depends on a distant scrubbing centre and a US-hours ticket queue is a different product from always-on filtering on a UK network your provider actually operates (AS48825 in our case).

What a DDoS is (in plain English)

LayerWhat the attacker doesWhat you feel
Volumetric (L3/L4)Floods your pipe with junk (UDP/ICMP, reflection)Port saturates; everything times out
Protocol / stateSYN floods, fragments, table exhaustionFirewalls and load balancers fall over first
Application (L7)Abusive HTTP(S), slowloris-style, bot GETsOrigin CPU and WAF burn while bandwidth looks “fine”
Multi-vectorMix and rotate the aboveOne tool rarely stops all of it

Attack coverage cards: volumetric, protocol, application-layer and multi-vector

Edge DDoS platforms are built for the first three at network scale. They are not a replacement for a web application firewall against SQLi, plugin exploits or account takeover — you still need that layer (see below).

Always-on vs on-demand scrubbing

This is the decision that matters most for UK ecommerce and SaaS.

  • Always-on / in-line — traffic is filtered continuously at the network edge. Latency stays predictable; you do not wait for a BGP redirect after the attack starts.
  • On-demand scrubbing — cheaper on paper. When the blast starts you (or your host) detect, escalate, and divert traffic to a scrubbing centre. That divert often takes minutes, not milliseconds.

Bar chart comparing Fast2Host Corero under 1 second vs manual activate ~5 minutes vs on-demand scrubbing often 15–30+ minutes

ApproachTypical delay before mitigationRisk window
Always-on in-line (e.g. Corero on AS48825)Under 1 secondMinimal
Manual “please enable DDoS” ticket~5 minutes if someone respondsCart / VoIP already failing
Classic on-demand scrubbingOften 15–30+ minutesFull outage for the wait

We run always-on Corero SmartWall as part of the Fast2Host network — included, not an emergency upgrade. Product page: DDoS protection.

Capacity is not the whole story

Marketing posters shout “600 Gbps” (we publish that figure because it is our engineered edge headroom). Useful — but detection quality, automated signatures and how quickly bad traffic is dropped matter more than the biggest number on a slide.

Ask every UK host:

  1. Is mitigation always-on or on-demand?
  2. Is it included with hosting/colo, or billed as an emergency upgrade?
  3. Do you null-route (blackhole) customer IPs under load, or filter surgically so clean traffic continues?
  4. Who is watching at 2am — a UK NOC, or a ticket queue?
  5. Does coverage include new services automatically when they go live?

Fast2Host answers: always-on Corero, included free, surgical filtering (no null-route culture), 24/7 Cambridge NOC visibility, 100% of services on AS48825. Numbers and platform detail: Corero deep-dive.

What downtime actually costs

Industry studies regularly put serious online outages in the thousands of pounds per hour once cart and payment fail. Using a simple illustrative peak of ~£2,000/hour:

Illustrative revenue at risk: ~£0 under 1s mitigation vs ~£170 at 5 min, ~£500 at 15 min, ~£1,000 at 30 min

Mitigation delayIllustrative revenue at risk (@ £2k/hour)
<1 second~£0 material cart loss
5 minutes~£170
15 minutes~£500
30 minutes~£1,000

Illustrative only — reputation damage, SLA credits, support overtime and SEO “site down” chatter often dwarf the cart line. The point is the wait, not the exact pound figure.

If your host’s plan is “we will scrub you once we notice”, you are buying the wait.

What you should still harden (edge DDoS is not a WAF)

Network DDoS and application security solve different problems. Keep both:

  • WAF / malware layer — Imunify360, ModSecurity, or your own WAF for SQLi, XSS and plugin abuse
  • Rate-limit login, checkout and expensive API routes
  • Sane DNS TTLs so you can shift traffic in a genuine disaster
  • Origin hygiene — patch CMS/plugins, disable unused services, separate admin origins where practical
  • Monitoring — know when latency or error rates spike before customers tweet

Edge filtering keeps the pipe and stateful devices alive. It will not fix an unpatched WordPress plugin.

Colo, dedicated and BYO networks

If you colocate hardware or announce your own ASN from a cabinet, clarify:

  • Whether mitigation covers your prefixes, not only shared hosting IPs
  • How BGP communities / signalling work during an event
  • Whether the provider null-routes your space under pressure (bad) or filters in-line (good)
  • Who you phone at 2am — and whether they can walk the path from transit to your rack

Our team engineers that path with colo customers — not a generic cloud ticket. See colocation and remote hands for the operational side; DDoS sits on the same AS48825 edge as everything else.

A short UK buying checklist

Use this on sales calls:

AskGood answer looks like
Always-on or scrubbing?Always-on / in-line at the edge
Included or upsell?Included on every plan
Vendor / capacity?Named platform + honest Gbps headroom
Null-routes?No — surgical drop of attack traffic
Time to mitigate?Sub-second / automatic, not “open a ticket”
Colo / BYO ASN?Documented prefix coverage and BGP options
OpsUK engineers who own the network

If answers are vague (“we have Cloudflare in front of some sites” / “we can enable protection if you are attacked”), keep shopping.

How Fast2Host fits

For hosted, VPS, dedicated, gaming and colo customers on our network:

  • 600Gbps Corero SmartWall always-on filtering
  • Typical mitigation in under one second
  • Included free — no mid-attack upsell
  • No null-routes as the default “protection”
  • AS48825 multi-homed UK network (LINX / LONAP peering)
  • Same edge for new services when they go live

Full service overview: DDoS protection. Network design: our network. Platform stats and attack classes: Corero 600Gbps guide.

Bottom line

Buy network-level DDoS that is on by default, then layer application security on top. Capacity headlines help; always-on detection, surgical filtering and UK ops decide whether your checkout survives the first serious flood.

Questions about coverage for colo prefixes or a specific workload — contact us or open a ticket from the client area.

Share this article

Speak to our UK team — we're here to help