NexusSec deploys Radware DDoS protection and application security for organisations whose availability directly affects revenue or service delivery. A distributed denial-of-service attack does not steal data — it makes you unreachable, which for a customer-facing business can be just as damaging. Protection must be in place before an attack, not arranged during one.
The three kinds of DDoS attack
| Type | How it works | Where it is mitigated |
| Volumetric | Saturates your internet link with sheer traffic volume | Upstream, before it reaches your link — on-premise equipment cannot help once the pipe is full |
| Protocol | Exhausts connection state on firewalls, load balancers or servers | On-premise or hybrid |
| Application layer | Low-volume requests that are expensive for the application to serve | Application-aware inspection; hardest to distinguish from real users |
This distinction matters commercially. If your internet link is 100 Mbps and an attacker sends 10 Gbps, no appliance in your building can help — the link is already saturated upstream. Volumetric protection must be delivered in the cloud or by your provider. Anyone selling you an on-premise box as complete DDoS protection is misrepresenting the problem.
What we deploy
- Attack surface review — what is exposed, what must stay available, and what the business impact of downtime actually is
- Protection architecture — on-premise, cloud-based scrubbing, or hybrid depending on your risk and link capacity
- Baseline learning — establishing normal traffic patterns so anomalies are detectable
- Mitigation policy — tuned to block attacks without blocking legitimate customers
- Application protection — defences against low-and-slow application-layer attacks
- Integration — with your firewall, load balancer and monitoring
- Runbook — a documented, rehearsed response procedure
Preparation matters more than product
Organisations that handle DDoS well are not necessarily those with the most expensive protection. They are the ones that prepared: they know who to call at their ISP, they have contact details for their protection provider, they have tested failover, and they have decided in advance who authorises mitigation decisions.
Organisations that suffer most are those discovering during an attack that nobody knows the escalation path. We build and rehearse that runbook as part of every deployment.
Who needs this
DDoS protection is most justified for e-commerce and customer portals where downtime directly costs revenue, financial services, hosting and service providers, and any organisation that has already been attacked or threatened. For many businesses, ISP-level protection combined with a well-configured firewall is a proportionate starting point — and we will tell you if that is the case rather than overselling.
Frequently asked questions
Can an on-premise appliance stop a volumetric DDoS attack?
No. If the attack volume exceeds your internet link capacity, the link is already saturated before traffic reaches your equipment. Volumetric attacks must be mitigated upstream, in the cloud or by your internet provider. On-premise equipment is effective against protocol and application-layer attacks but cannot solve link saturation.
What is the difference between volumetric and application-layer DDoS?
Volumetric attacks flood your connection with sheer traffic volume to exhaust bandwidth. Application-layer attacks send relatively few requests that are individually expensive for the application to process, exhausting server resources rather than bandwidth. They require different defences, and application-layer attacks are harder to distinguish from legitimate traffic.
Does our business need DDoS protection?
It depends on how much downtime costs you. E-commerce sites, customer portals, financial services and hosting providers usually justify dedicated protection. For many businesses, protection available from your internet provider combined with a well-configured firewall is a proportionate starting point. We assess the business impact before recommending spend.
How quickly can DDoS mitigation activate?
This depends on the architecture. Always-on cloud protection mitigates immediately because traffic already flows through it. On-demand protection requires detection and traffic redirection, which introduces a delay of minutes during which service is degraded. The right choice depends on how much downtime you can tolerate.
What should we do before an attack happens?
Establish and rehearse a runbook: know your ISP's escalation contacts and procedure, hold your protection provider's contact details, understand which services must be prioritised, and decide in advance who authorises mitigation decisions. Organisations that struggle during attacks are usually those working out the escalation path while under attack.