DDoS protection services look remarkably similar on paper. Every sales deck promises "Tbps-scale scrubbing" and "global nodes." But the real differences only become visible during the ten minutes that an attack is happening.
Here are five hard metrics you can take directly to vendors.
Metric 1: Scrubbing capacity — and whether it is actually usable
When a vendor quotes "10Tbps of scrubbing capacity," ask three follow-up questions:
- Is that total or per-site? Some vendors sum bandwidth across all global nodes for marketing, but during an attack your traffic is only diverted to the one or two nodes nearest you.
- Shared or dedicated? A shared pool gets crowded during large-scale attacks.
- What happens when you exceed it? This is the decisive question. Many providers blackhole your service once you exceed your plan — the attack succeeds by default.
AwayDDoS's approach: capacity is the sum of our global nodes with no hard cap. During attacks we never blackhole and never surge-price. Plan costs stay fixed.
Metric 2: How many layers of architecture
Single-layer scrubbing struggles against mixed attacks: it may absorb a volumetric flood while L7 CC traffic slips through, or focus on application-layer signatures while a UDP flood saturates the uplink.
A two-layer cleaning architecture is the more mature design:
- Near-source scrubbing — dilutes volumetric floods close to the attack source
- Deep cleaning — performs fine-grained filtering on protocol and behavioral signatures
That division of labor is what holds up against combined volumetric + application-layer campaigns. See the full explanation at Protection Solutions.
Metric 3: Pricing model — fixed or variable
This is the most commonly overlooked point during procurement, and the most painful afterward. Pin down:
- Is billing based on scrubbed traffic volume or a fixed plan fee?
- Does the price increase during an attack?
- Are there minimum commitments or hidden bandwidth overage fees?
Volume-based billing creates a perverse incentive: the worse you get hit, the larger your bill. Fixed pricing makes costs predictable and aligns the vendor's interests with yours — they are motivated to actually stop the attack rather than profit from it.
Metric 4: Response time and expert operations
Attacks often start at 3 a.m. At that moment, ask:
- Can you reach a technician within minutes?
- Is it a ticket queue, or do you have a dedicated technical contact?
- Does the vendor proactively intervene, or must you file tickets repeatedly?
AwayDDoS provides 7×24 expert operations: our security team actively monitors and tunes policies during an attack rather than waiting to be asked.
Metric 5: Onboarding cost and compatibility
Even the strongest protection is worthless if adopting it requires re-architecting your stack. Evaluate:
| Dimension | What to ask |
|---|---|
| Onboarding method | Just DNS changes? Or network changes and agents? |
| Time to effect | Minutes? Hours? Manual provisioning? |
| Compatibility | UDP game protocols? Non-standard ports? |
| Origin return | Does it support your current origin topology? |
| Migration cost | Can you leave at any time? Any lock-in terms? |
Bonus: privacy and compliance
If your business handles user data or operates in a regulated industry, confirm whether the vendor logs your payload content, where data is stored, and what compliance certifications they hold.
A quick checklist
Take this to every candidate vendor and see who answers without hesitation:
- [ ] Will you blackhole my service if the attack exceeds my plan?
- [ ] Will my price increase during an attack?
- [ ] Is your architecture single-layer or two-layer scrubbing?
- [ ] What is the concrete response-time SLA in minutes?
- [ ] Do I get a dedicated technical contact?
- [ ] What onboarding methods are supported, and how fast do they take effect?
- [ ] Do you log my payload content?
Key takeaways
Choosing DDoS protection is really about choosing a partner you can rely on when things go wrong. Price and bandwidth figures are just the entry ticket. What actually determines whether you survive an attack is architectural depth, pricing honesty, and response speed.
To see AwayDDoS's full protection stack and fixed-fee model, get in touch for a consultative assessment. New to DDoS entirely? Start with What Is a DDoS Attack? A Complete Beginner's Guide.