October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsClean PCRecommendedOne scan can reveal what keeps slowing WindowsLook for cleanup and repair opportunities.Run ScanOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

European Cyber Report 2025: Link11 reports 137% more DDoS attacks—what companies should do now

Link11’s 137% increase is a provider-specific signal, not a universal European risk rate. Here is how companies should assess exposure, choose protection and prepare for fast multi-vector attacks.
From TheFinanceBase Team8 min to read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Short answer: Link11 says the number of distributed-denial-of-service (DDoS) attacks observed on its network increased 137% in 2024 compared with 2023. That means 2.37 times the prior count in a conventional year-over-year calculation—not that every European company faced a 137% higher probability of attack. The provider-specific figure is still an important warning because attacks are increasingly brief, automated, multi-vector and aimed at applications as well as networks.

The practical response is to inventory every internet-facing service, make detection and mitigation automatic where possible, protect both network and application layers, and rehearse failover as part of business continuity.

What the 137% figure actually measures

Link11’s European Cyber Report 2025 announcement compares 2024 with 2023 and counts DDoS attacks observed on Link11’s own network. It is a provider-level signal, not a census of all attacks in Europe.

The number does not, by itself, establish changes in unique victims, aggregate attack traffic, downtime, financial losses, successful compromises or the probability faced by a particular company. Provider datasets also differ in customer mix, geography, event thresholds, deduplication and whether repeated waves are counted separately. Link11’s commercial interest in selling DDoS protection is another reason to treat the statistic as attributed evidence rather than a neutral continent-wide estimate.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Sonicwall 01-SSC-6942 TZ105 UTM Secure Firewall
  • Firewall Protection: Remote Access Authentication, Content Filtering, Malware Protection, URL Filtering, Web Content Filtering, Deep Inspection Firewall, Reassembly-free Deep Packet Inspection, and
  • Firewall Protection (continued): Gateway Antivirus, Anti-spyware, Denial of Service (DoS), Distributed Denial of Service (DDoS), Egress Filtering, Cookies Blocking, Dead Peer Detection
  • Encryption Standard: DES, 3DES, AES (142-bit), AES (128-bit), AES (256-bit), SHA-1, MD5 Intrusion Prevention, NAT, PAT, IPSec NAT Traversal, 5 Network (RJ-45) Ports, Fast Ethernet, 10/100Base-TX
  • Virtualization: 8000 x Maximum UTM/DPI Connections, 8000 x Maximum Connections, 1000 x New Connections/Sec, 1 x SonicPoints Supported, 5 x Site-to-Site VPN Tunnels, 5 x VLANS
  • USB Port, AC Adapter (Power Source) 12 V DC, Management Port, 32 MB Flash Memory, 256 MB Standard Memory, Secure Digital (SD) Card , Height: 1.4", Width: 7.5", Depth: 5.6
Reported finding What it means for a buyer
137% more attacks in 2024 than 2023 More than twice as many events observed on Link11’s network; not a universal European rate.
Two-thirds peaked within 10–60 seconds Controls must detect and act faster than a manual escalation cycle. “Peaked” is not necessarily total attack duration.
1.4 Tbps maximum in the syndicated release A substantial volumetric event, but not a measure of the typical attack or your likely exposure.
120 million requests and more than one million WAF logs in a four-day case Application attacks can exhaust back ends and create a monitoring and logging problem as well as a bandwidth problem.

The syndicated March 17, 2025 release gives the 1.4-Tbps, 10–60-second and case-study figures. Link11’s English page has also displayed a conflicting 4-Tbps wording, so those maximums should not be silently merged. The narrower statement supported by the syndicated release is “1.4 Tbps reported in that announcement.”

Other providers show the same direction of travel but not a directly comparable rate. Cloudflare reported more than twice as many DDoS attacks in its observed 2025 dataset and described a 31.4-Tbps attack lasting 35 seconds in its 2025 Q4 report. Different networks, periods and definitions make cross-provider totals unsuitable for calculating a company’s risk.

Why short, multi-vector attacks defeat manual response

Ten seconds can be shorter than your runbook

An analyst may need to verify an alert, find an on-call engineer, contact a provider, change a route or firewall rule, and confirm that legitimate traffic still works. An attack that peaks and recedes within 10 to 60 seconds can be over before that sequence starts. Repeated bursts can still overload connection tables, queues, databases, autoscaling and customer sessions.

Rank #2
FortiGate-120G Network Security Appliance Plus 1 Year FortiGuard Unified Threat Protection (UTP) and FortiCare Premium (FG-120G-BDL-950-12)
  • Comprehensive Hardware and Service Package: Includes FortiGate-120G appliance with 1 year of FortiCare Premium and FortiGuard Unified Threat Protection (UTP).
  • Unified Threat Protection (UTP) Bundle: Protects against sophisticated web and DNS-based threats with advanced filtering and security features including ATP, DNS filtering, URL filtering, video filtering, and anti-botnet services.
  • Enhanced Web Security: Offers high-level web security suitable for varied enterprise environments needing strong protective measures against online threats.
  • Extended Support and Service: FortiCare Premium provides dependable technical support ensuring seamless operation and efficient issue resolution.
  • Optimal for Diverse Deployment: Ideal for organizations with complex network environments looking for comprehensive security solutions.

Cloudflare’s documentation says its managed Layer 3/4 and HTTP DDoS rules can detect and mitigate in up to three seconds; that is a vendor-specific performance statement, not an industry benchmark. The architectural lesson is broader: critical services need always-on or automatically activated controls. Cloudflare’s 2025 Q1 reporting likewise explains why many short attacks are impractical to handle manually.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Layer 3/4 and Layer 7 require different defenses

  • Layer 3/4: Volumetric, UDP, SYN, amplification and other network or transport floods can saturate links, routers, firewalls, VPN gateways or connection tracking.
  • Layer 7: Apparently valid HTTP or API requests consume application workers, CPU, memory, database connections or expensive business operations.
  • Multi-vector: Attackers combine methods or switch vectors during an incident.

Bandwidth protection will not necessarily stop an expensive API query, while a WAF will not protect a non-HTTP service or an already saturated internet circuit. Effective designs apply upstream capacity and filtering together with application-aware controls.

Which organizations and assets are most exposed?

No organization is automatically safe because it is small. A modest flood can saturate a small business’s access link, while a modest request rate can overwhelm an unoptimized application. Risk is highest where availability has direct financial, safety or contractual consequences.

Rank #3
ASURION 3 Year Major Appliance Protection Plan ($350 - $399.99)
  • No Additional Cost: You pay nothing for repairs – parts, labor, and shipping included.
  • Coverage: Plan starts on the date of purchase. Malfunctions covered after the manufacturer's warranty. Power surges covered from day one. Plan includes food loss reimbursement up to $250 per approved claim for refrigerators & freezers and laundry services reimbursement up to $25 per approved claim for washers & dryers that are out for service for more than seven (7) consecutive days.
  • Easy Claims Process: File a claim anytime online or by phone. Most claims approved within minutes. If we can’t repair it, we’ll send you an Amazon e-gift card for the purchase price of your covered product or replace it.
  • Product Eligibility: Plan must be purchased with a product or within 30 days of the product purchase. Pre-existing conditions are not covered.
  • Terms & Details: More information about this protection plan is available within the “Product guides and documents” section. Simply click “User Guide” for more info. Terms & Conditions will be available in Your Orders on Amazon. Asurion will also email your plan confirmation with Terms & Conditions to the address associated with your Amazon account within 24 hours of purchase.
  • Public websites, mobile back ends and customer-facing APIs.
  • Checkout, ticketing, gaming, gambling, financial, healthcare and media services.
  • Authoritative DNS, public authentication, VPN and remote-access gateways.
  • Real-time or latency-sensitive systems.
  • Hybrid or on-premises infrastructure with limited upstream capacity.
  • Single-region, single-link or single-provider architectures.
  • Origins whose IP addresses remain discoverable behind a CDN or reverse proxy.
  • APIs with expensive queries, weak quotas or unauthenticated endpoints.
  • Services subject to uptime commitments or regulatory resilience requirements.

Protect the whole delivery chain: DNS, routing and transit links, edge proxies, TLS termination, load balancers, origin hosts, databases, third-party APIs and partner connections. A protected web page does not automatically protect an exposed DNS server, VPN concentrator or game protocol.

A prioritized DDoS-readiness plan

First 24–72 hours

  1. Inventory public IP ranges, autonomous-system numbers, domains, APIs, DNS authorities, VPN gateways and third-party-hosted assets.
  2. Map business-critical traffic paths and identify single points of failure, including direct origin access.
  3. Name an incident owner and verify that provider escalation works nights and weekends.
  4. Monitor bandwidth, packets per second, requests per second, connection counts, status codes, latency, origin CPU, database load, WAF events and bot activity.
  5. Test whether the origin can be reached while bypassing the CDN or scrubbing service; close that path or restrict it to approved provider ranges.
  6. Check DNS TTLs, BGP announcements, GRE or IPsec tunnels, certificates and firewall rules against the intended failover design.

Within 30 days

  1. Run a controlled readiness exercise with your provider and internal teams.
  2. Set authentication-aware API quotas, rate limits, query-complexity controls, caching and circuit breakers.
  3. Put sensitive web and API services behind an appropriate reverse proxy or WAAP service.
  4. Establish normal traffic baselines and automatic alerts.
  5. Document rollback procedures so a defensive rule cannot become the outage.
  6. Test WAF-log ingestion, storage cost and retention. High-volume security logs need sampling or aggregation plans.

Longer term

  • Add provider, region, link or DNS-authority redundancy where the business impact justifies it.
  • Separate public, administrative and internal services.
  • Use bot and behavioral controls rather than relying only on IP blocklists.
  • Include DDoS scenarios in business-continuity and incident-response exercises.
  • Measure time to restore clean service, not only whether malicious packets were blocked.
  • Cover IPv4 and IPv6 routing, filtering, DNS records and monitoring.

Choosing an architecture

Always-on versus on-demand mitigation

Model Advantages Trade-offs
Always-on Handles seconds-long attacks without a routing change; consistent protection for critical services. All traffic may traverse a third party; privacy, latency, residency, configuration and cost require review.
On-demand Can reduce cost for lower-risk environments and preserve the normal path. Manual activation may be slower than the attack; BGP, GRE or DNS failover must be tested under pressure.

CDN, reverse proxy and WAF

These are usually the first choice for websites and HTTP APIs. They provide TLS termination, caching, origin shielding, rate controls, bot management and application-layer filtering. They do not automatically cover arbitrary ports, prevent origin bypass or replace application-aware API policies.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Network scrubbing or transit protection

Scrubbing is suited to large volumetric events, routed networks, DNS, VPN, gaming and other non-HTTP protocols. It may require BGP, GRE, IPsec or provider-specific integration, and it does not replace WAF, authentication, secure coding or application controls.

Rank #4
ASURION 3 Year Major Appliance Protection Plan ($500 - $599.99)
  • No Additional Cost: You pay nothing for repairs – parts, labor, and shipping included.
  • Coverage: Plan starts on the date of purchase. Malfunctions covered after the manufacturer's warranty. Power surges covered from day one. Plan includes food loss reimbursement up to $250 per approved claim for refrigerators & freezers and laundry services reimbursement up to $25 per approved claim for washers & dryers that are out for service for more than seven (7) consecutive days.
  • Easy Claims Process: File a claim anytime online or by phone. Most claims approved within minutes. If we can’t repair it, we’ll send you an Amazon e-gift card for the purchase price of your covered product or replace it.
  • Product Eligibility: Plan must be purchased with a product or within 30 days of the product purchase. Pre-existing conditions are not covered.
  • Terms & Details: More information about this protection plan is available within the “Product guides and documents” section. Simply click “User Guide” for more info. Terms & Conditions will be available in Your Orders on Amazon. Asurion will also email your plan confirmation with Terms & Conditions to the address associated with your Amazon account within 24 hours of purchase.

Cloud-native controls

Cloud-native DDoS and WAF services fit teams already operating in a major cloud with infrastructure-as-code, centralized identity and native logging. Model the full bill: WAF rules and requests, CDN, load balancer, API gateway, bot controls, logs and premium protection can all contribute. Mixed and multi-cloud estates may need provider-neutral or hybrid protection.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Commercial options and fit

Provider Useful starting point Best fit Important limitation
Cloudflare Public plans list $0 Free, $20 monthly billed annually ($25 monthly) Pro and $200 monthly billed annually ($250 monthly) Business; enterprise is custom. Website plans advertise unmetered DDoS protection, while capabilities and support vary by plan. Websites and APIs needing quick reverse-proxy, CDN, WAF and bot deployment. Deep bespoke routing, private connectivity, non-HTTP protocols and complex hybrid operations may require enterprise services.
AWS Shield and AWS WAF Usage-based charges apply to web ACLs, rules and requests, with additional CloudFront, load-balancer, API, logging and bot costs. Shield Advanced includes limited AWS WAF usage, but other architecture charges can remain. AWS-native estates using CloudFront, IAM and infrastructure-as-code. Less attractive for provider-neutral or on-premises environments; billing and architecture dependencies need careful modelling.
Akamai Prolexic Public list pricing was not shown. Akamai describes always-on or on-demand cloud, on-premises and hybrid deployment, 32 anycast scrubbing centers, more than 20 Tbps dedicated capacity and 24/7/365 SOC support. Large enterprises, service providers and hybrid or non-HTTP networks needing managed operations. Enterprise quotation, routing work and integration complexity make it excessive for a small brochure site.
Link11 Public list pricing was not identified; purchasing is quote-led. European organizations seeking specialist managed DDoS and hybrid or critical-infrastructure protection. No immediately comparable public price or independent cross-vendor benchmark; its report is also a vendor marketing source.

These are fit-based options, not a universal ranking. Cloudflare is the most accessible public-price starting point for many web properties; AWS is strongest for AWS-native estates; Akamai and Link11 are more natural candidates for enterprise, hybrid, managed or specialist requirements.

Provider due-diligence checklist

  1. Which protocols, ports, IPv4 and IPv6 ranges are covered?
  2. Is protection always-on or activated on demand, and what routing changes are required?
  3. How are detection, mitigation and escalation handled, including outside office hours?
  4. What are the actual SLA terms, exclusions and service credits?
  5. How is origin exposure prevented?
  6. How are false positives, allowlists and emergency rollback handled?
  7. What telemetry, forensic data and log-retention options are included?
  8. What charges are triggered by requests, bandwidth, rules, logs or an attack?
  9. Where is traffic inspected and stored, and who controls TLS keys?
  10. Can you test the service, failover and exit process before signing a long contract?

Failure modes that deserve explicit testing

Origin bypass

Attackers who discover an origin address can bypass the edge. Restrict origin firewalls to approved proxy or scrubbing ranges while retaining controlled emergency administration.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
ASURION 3 Year Major Appliance Protection Plan ($1000 - $1249.99)
  • No Additional Cost: You pay nothing for repairs – parts, labor, and shipping included.
  • Coverage: Plan starts on the date of purchase. Malfunctions covered after the manufacturer's warranty. Power surges covered from day one. Plan includes food loss reimbursement up to $250 per approved claim for refrigerators & freezers and laundry services reimbursement up to $25 per approved claim for washers & dryers that are out for service for more than seven (7) consecutive days.
  • Easy Claims Process: File a claim anytime online or by phone. Most claims approved within minutes. If we can’t repair it, we’ll send you an Amazon e-gift card for the purchase price of your covered product or replace it.
  • Product Eligibility: Plan must be purchased with a product or within 30 days of the product purchase. Pre-existing conditions are not covered.
  • Terms & Details: More information about this protection plan is available within the “Product guides and documents” section. Simply click “User Guide” for more info. Terms & Conditions will be available in Your Orders on Amazon. Asurion will also email your plan confirmation with Terms & Conditions to the address associated with your Amazon account within 24 hours of purchase.

DNS dependence

An application can be perfectly filtered yet unreachable if authoritative DNS fails. Review registrar security, DNSSEC operations, secondary DNS and emergency change authority.

Legitimate-looking API abuse

Valid syntax does not make a request safe. Combine identity-aware quotas, per-token limits, query-cost controls, caching and backend circuit breakers.

False positives and logging overload

Mobile carrier NAT, partners, VPN users and sudden legitimate surges can resemble attacks. Use staged policies, challenge or monitor modes where available, verified allowlists and rollback. Sampling and tiered retention prevent millions of WAF events from becoming a second incident.

Autoscaling and encryption misconceptions

Autoscaling can multiply costs while an attacker continues exhausting databases, queues or third-party services. TLS inspection can improve filtering but requires documented privacy, residency, key-management and access controls.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Bottom line

“137% more” should be read as a Link11 network signal, not a universal European probability. The actionable finding is that attacks can be brief, automated, multi-vector and application-aware. Companies should automate mitigation, protect network and application layers, close origin and DNS gaps, and rehearse recovery as part of business continuity rather than treating DDoS response as an improvised firewall exercise.

Quick Recap

Bestseller No. 3
ASURION 3 Year Major Appliance Protection Plan ($350 - $399.99)
ASURION 3 Year Major Appliance Protection Plan ($350 - $399.99)
No Additional Cost: You pay nothing for repairs – parts, labor, and shipping included.
$68.99
Bestseller No. 4
ASURION 3 Year Major Appliance Protection Plan ($500 - $599.99)
ASURION 3 Year Major Appliance Protection Plan ($500 - $599.99)
No Additional Cost: You pay nothing for repairs – parts, labor, and shipping included.
$89.99
Bestseller No. 5
ASURION 3 Year Major Appliance Protection Plan ($1000 - $1249.99)
ASURION 3 Year Major Appliance Protection Plan ($1000 - $1249.99)
No Additional Cost: You pay nothing for repairs – parts, labor, and shipping included.
$149.99

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase07 MAR 2625 minWhat Is a 457 Plan?
  2. The Money DeskBlogTheFinanceBase07 MAR 2621 minTime Value of Money: What It Is and How It Works
  3. The Money DeskBlogTheFinanceBase07 MAR 2627 minAre You Living in One of These Top 10 Most Expensive Cities to Retire?
Recommended PC Tool
Recommended PC Tool
Outdated Drivers Are Slowing You DownFree scan - exact matches
PC Slower Than It Used to Be?Free scan - under a minute

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.