Security, made operationalPractical guides / September 2026
Inforbasket

Home / Security practice

Infrastructure security

Questions to ask about DDoS protection and hosting

Evaluate hosting protection by scope, exclusions, origin exposure and response procedures.

· 2 min read

Security, made operational
The useful takeawayAsk what happens during an incident, not just whether protection exists.

Define the service you need to protect

List the public endpoints and protocols the application depends on. Include the website, APIs and any directly exposed origin addresses. Protection that covers one request path may not cover every service on the machine.

Distinguish availability concerns from other security controls. Traffic filtering does not replace application patching, access management or backups. Keep the threat discussion tied to the service rather than treating a single product as a complete security programme.

Ask about scope and exclusions

Request a description of the traffic and attack types covered by the plan, the conditions under which filtering activates, and any operational limits. Ask how legitimate traffic is treated during mitigation and what visibility the customer receives.

Discuss a specific scenario: the public site is unreachable while the server console still works. Who should collect evidence? How is the incident escalated? What action might the provider take? Written answers are easier to compare than broad terms such as advanced or enterprise-grade.

Prepare your side of the response

Keep an inventory of exposed services and an escalation route outside the affected website. Establish a normal traffic baseline so an unusual pattern has context. Protect diagnostic evidence because access logs can contain sensitive data.

Rehearse communication and failover procedures without generating hostile traffic. Any technical resilience test must have an agreed scope and authorisation from the affected providers. After an incident, compare the observed response with the plan and update the questions you ask at renewal.

Koddos offers DDoS protection services through hosting, dedicated-server and remote proxy options. These represent different deployment choices: review which endpoints the selected service covers and how its incident process fits the system you already operate.

Before you finish

  • Public endpoints inventoried
  • Protection scope confirmed
  • Escalation route documented
  • Evidence handling planned

Technical reference
OWASP: logging cheat sheet