Itnetic logo Itnetic Technologies
  • Pricing
  • Discord
Game protectionMinecraft serversBot joins, ping floods and connection attacks stopped before they reach your server. No plugin, no mod, nothing for players to install.Explore game protection →

For websites and APIs

  • DDoS ProtectionLayer-7 mitigation for attacks that look like real traffic.
  • Web CDNEdge caching on the network that filters your attacks.
  • PricingFree tier, then plans from €5/month.

How it works

  • The edge pipelineChallenge gate, behavioral signatures, WAF, rate limits and cache.
  • Logs & analyticsPer-request visibility and the exact verdict behind every block.
  • NetworkPoints of presence across Europe, North America and Asia Pacific.

Learn

  • GuidesPlain-English explainers on DDoS, WAFs, rate limiting and CDNs.
  • HTTP header checkGrade any site’s security headers in a few seconds.
  • FAQThe questions we get asked before people sign up.
  • ChangelogWhat shipped, and when.

Compare

  • vs Cloudflare
  • vs DDoS-Guard
  • vs CDN77
  • vs WEDOS
  • Status ↗
Log inUnder attack?
Game protectionDDoS ProtectionWeb CDNPricing
The edge pipelineLogs & analyticsNetwork
GuidesHTTP header checkFAQChangelogvs Cloudflarevs DDoS-Guardvs CDN77vs WEDOSStatus ↗
PricingDiscord
Log inUnder attack?

Learn · DDoS economics

How much does a DDoS attack cost?

Lost sales are the line everyone reaches for first, and for most businesses it is not the biggest one. Here is how to work out your own number instead of borrowing someone else’s.

Updated August 1, 2026 · Itnetic team — reviewed by Petr Chlíbek, founder

Key takeaways

  • Lost revenue is only one line on the bill — engineering hours, infrastructure overage, support load, refunds and churn usually add up to more.
  • Calculate an hourly downtime cost from your own figures, using a peak hour rather than an average: attackers pick your busiest window on purpose.
  • Multiply by how attacks really behave — waves rather than one block, degradation that converts like an outage, and repeat targeting once an attempt succeeds.
  • The economics are asymmetric: attack capacity is rented by the hour for pocket money, while your cost scales with your revenue — which is why protection is cheap by comparison.

The bill is longer than "lost sales"

Ask what a DDoS attack costs and most people answer with revenue: the site was down for four hours, we normally take this much per hour, there is the number. That figure is real, but it is usually the smallest column in the table — and it is the only one that stops when the site comes back.

Cost lineWhen it landsUsually measured as
Lost gross profitDuring the outageRevenue per hour × gross margin
Engineering responseDuring, and for days afterResponders × fully loaded hourly rate
Infrastructure overageOn next month’s invoiceAutoscaling, egress, per-request platform fees
Support loadDuring and afterExtra tickets and calls × handling cost
Refunds, goodwill and SLA creditsDays to weeks afterContractual credits, discretionary refunds
Wasted acquisition spendDuring the outageAd budget delivered to a page that will not load
Churn and lost pipelineWeeks to months afterRetention delta, abandoned trials and signups
Emergency mitigation feesImmediatelyPer-incident onboarding, "under attack" surcharges

The last line is worth sitting with. Buying mitigation while you are already down is the most expensive moment to buy it, and it is the moment most people do.

Work out your hourly downtime number

Borrowed industry averages are useless for a decision about your budget — they average a bank and a blog together. Use your own figures:

Hourly cost = (hourly revenue × gross margin) + (responders × loaded hourly rate) + infrastructure overage per hour + support handling per hour

Two rules make the answer honest:

  • Use a peak hour, not a daily average. Attackers do not fire at 04:00 on a Tuesday. Ransom campaigns and competitive attacks are timed for your busiest window, because that is where the leverage is.
  • Use gross profit, not revenue, if you sell goods — you did not lose the cost of goods you never shipped. For SaaS and advertising businesses, the margin figure is high enough that revenue is a fair proxy.

A worked example for a store turning over €120,000 a month, attacked during an evening peak:

ComponentWorkingPer hour
Lost gross profit€670 peak-hour revenue × 45% margin€300
Engineering response3 people × €60 loaded rate€180
Infrastructure overageAutoscaling and egress during the flood€100
Support load20 extra contacts × €6 handling€120
Hourly total€700

Nothing in that table is exotic, and it already ignores everything that arrives later. Run it with your own numbers before reading on — the rest of this page is about what multiplies it.

Multiply by how attacks actually behave

A single clean four-hour outage is the friendliest possible shape, and it is not the usual one.

  • Attacks arrive in waves. An attacker who gets a result stops, watches you recover, and starts again — often with a different technique. Each wave restarts your incident, your paging and your recovery tail.
  • Degradation costs almost as much as an outage. A checkout that answers in eight seconds is technically up and converts like a site that is down. If you only count hard downtime you will under-count most application-layer attacks.
  • Recovery is not instantaneous. Caches are cold, queues are backed up, and the first minutes after mitigation are frequently the slowest ones your real customers experience.
  • Success invites repetition. A target that went down once is a target with a proven method. This is the mechanism behind ransom DDoS: the first attack is a demonstration, and it is priced as marketing.

The costs that arrive after the site is back

Customers who leave quietly. Nobody sends an email to say they gave up at the payment step. The loss shows up as a dent in a cohort weeks later, which is exactly why it never gets attributed to the incident.

Search visibility. If crawlers meet errors or timeouts for hours, that is what gets recorded about your availability. It is rarely catastrophic, and it is rarely free.

Acquisition spend delivered into a wall. Paid campaigns keep spending through an outage unless somebody remembers to pause them, which means you pay full price for clicks that land on a broken page.

The paperwork. Post-incident review, customer notifications, questions from your board, and — if you carry cyber insurance — an evidence pack. Per-request logs and analytics turn that from a week of archaeology into an export, and they are the difference between "we think we were attacked" and a defensible account of what hit you and what stopped it.

The asymmetry is the whole argument

Attack capacity is a commodity. Botnet time is rented by the hour on underground markets for the price of a couple of coffees, and the attacker’s cost does not rise with the value of the target. Yours does: the bigger and busier your business, the more each hour costs you.

That asymmetry is why "we are too small to be attacked" is backwards. The attack is cheap regardless of who you are — so the deciding factor is not whether you are worth attacking, but whether attacking you is easy.

What protection costs, and the traps in the pricing

Mitigation is priced in tens of euros a month. That comparison is only fair, though, if the pricing does not have a trapdoor in it. Five questions to put to any provider, yours included:

  1. Is attack traffic metered against my quota? If it is, being attacked produces an invoice on top of the downtime — a second bill for the same incident.
  2. Is there a per-incident or emergency onboarding fee? Prices that appear when you are already down are not prices you get to negotiate.
  3. Does mitigation start automatically, or after a support ticket? Every minute between "attack starts" and "filtering starts" is billed at your hourly downtime rate. This is the practical case for always-on filtering, covered in what is DDoS mitigation.
  4. What do false positives cost me? A defense that answers every flood by showing a CAPTCHA to real customers is converting an availability problem into a conversion problem.
  5. Can I prove what was blocked? You will need that for customers, insurers and your own post-incident review.

Itnetic answers the first one plainly: attack traffic is scrubbed and never metered against your bandwidth quota, so an attack does not turn into a bandwidth bill. Filtering is always-on rather than something you switch on mid-incident, there are no per-attack fees, and every blocked request is logged. The Starter plan is free, Hobby is €5 a month and Pro €29 — see pricing — and going live is two DNS records and about five minutes.

Put that next to the worked example above. A single six-hour incident at €700 an hour costs roughly €4,200, which is more than a decade of the plan that would have been filtering it. That is the arithmetic; the cost of a DDoS attack is high mostly because the alternative is so cheap.

Already under attack while reading this? Skip the budgeting and go to how to stop a DDoS attack.

FAQ

Quick answers

How much does a DDoS attack cost a business?

There is no useful universal figure, because the number scales with your revenue per hour, your margin and your team’s hourly cost. Build it yourself: hourly gross profit at peak, plus responder hours, plus infrastructure overage, plus support handling. For most small and mid-sized businesses the total lands in the hundreds to low thousands of euros per hour, and the lines other than lost revenue usually add up to more than the lost revenue itself.

How much does it cost to launch a DDoS attack?

Very little, which is the core of the problem. Attack capacity is rented by the hour on underground markets for amounts measured in single-digit currency units, and the price does not rise with the value of the target. Defenders pay per hour of downtime; attackers pay per hour of attack — and those two numbers are not remotely comparable.

Does DDoS protection increase my bandwidth bill?

It should not, but check — some providers meter scrubbed attack traffic against your quota, which means an attack produces an invoice as well as an outage. Itnetic never counts attack traffic against your bandwidth quota; only legitimate delivered traffic is metered. Ask every vendor this question explicitly and get the answer in writing.

Is DDoS downtime covered by cyber insurance?

Business-interruption cover often extends to denial-of-service events, but policies vary widely and commonly include a waiting period measured in hours, which shorter attacks never reach. Whatever your policy says, a claim needs evidence: timestamps, traffic volumes and a record of what was blocked. Per-request logs make that an export rather than a reconstruction.

Is it ever cheaper to just pay a ransom demand?

No. Paying marks you as a target that pays, funds the next attack, and buys no technical protection at all — the same botnet is available to the next person who rents it. The money is better spent on filtering that also covers every attack after this one. See our guide to ransom DDoS extortion emails.

Keep reading

01

What is the best DDoS protection?

Every provider claims to be the best DDoS protection. The claim is unfalsifiable on its own — but the properties that decide whether a service keeps you online are short, concrete and easy to check before you buy.

02

What is a DDoS attack?

A distributed denial-of-service (DDoS) attack overwhelms a website or API with traffic from many machines at once, until real visitors can no longer get through.

03

What is a Layer 7 DDoS attack?

Layer 7 (application-layer) DDoS attacks imitate legitimate visitors instead of flooding the network — which is exactly why traditional defenses miss them.

04

What is a DNS amplification attack?

A DNS amplification attack forges your IP address on small DNS queries so that thousands of innocent servers answer with far larger replies — all of them aimed at you.

05

What is a SYN flood attack?

A SYN flood does not try to fill your pipe. It opens thousands of TCP connections a second and never finishes them, until the queue that tracks half-open connections is full and the next real visitor is simply never let in.

06

How to stop a DDoS attack on your website.

A practical, ordered checklist for the moment your site goes down — and for making sure the next attack never reaches it.

Protect my website freeHow our protection works
Itnetic logo Itnetic Technologies

DDoS protection that keeps your customers online. Attacks filtered at the edge in every region, real visitors served straight through.

Find us on GoogleAdd as preferred source

Product

  • Under attack?
  • DDoS Mitigation
  • Web CDN
  • Game Protection
  • Network
  • Pricing

Resources

  • Learn
  • HTTP header check
  • Changelog
  • FAQ
  • Status
  • Discord

Legal

  • Acceptable Use
  • SLA
  • Security
  • Abuse
  • Sub-processors
  • Data Retention
  • Incident Response

Company

  • Founder
  • Contact
Petr ChlíbekIČO: 21210756Neplátce DPH
© 2026 Itnetic Technologies. All rights reserved.
Terms of ServicePrivacy PolicyCookie PolicyDPAIP geolocation by DB-IP (CC BY 4.0)Powered by Startup FastLiftOff launch badgeFeatured on IndieHunt