# How Much Does a DDoS Attack Cost Your Business?

> Downtime, lost sales, emergency engineering, churn and reputation — a DDoS attack costs far more than the bandwidth. Here's how to estimate your real exposure.

- Category: Explainer
- Author: Akarguard Team, Security Engineering
- Published: Aug 22, 2025
- Canonical: https://akarguard.net/blog/cost-of-a-ddos-attack

---

The bandwidth a DDoS attack consumes is the cheapest part of it. The real cost is what the outage does to your business while it lasts — and, increasingly, the ongoing bill from a provider that meters you during the attack. If you're deciding whether protection is worth it, here's how to think about the true exposure.

## The Direct Costs

- Lost revenue: every minute an e-commerce store, SaaS or ad-supported site is down is sales or usage that simply doesn't happen.
- Emergency engineering: your team drops everything to respond, often out of hours, sometimes pulling in paid incident support.
- Bandwidth overage: some providers bill you for the attack traffic itself — the victim pays for the attacker's flood.
- SLA penalties: if you promise uptime to your own customers, an outage can trigger credits or refunds.

## The Indirect Costs (Usually Bigger)

- Customer churn: users who hit a dead site during a launch or a sale may not come back.
- Reputation: repeated or public outages erode trust, especially for a security or infrastructure product.
- Extortion follow-on: attackers who see an outage sometimes return with a ransom demand (a ransom DDoS, or RDoS).
- Opportunity cost: the roadmap slips while your team fights fires instead of building.

> **A rough way to estimate it** — Take your revenue per hour, multiply by the hours a realistic attack keeps you down, add the fully-loaded cost of the engineers who respond, then add a churn factor for the customers you lose. Compare that to a monthly protection subscription — for most sites the first prevented outage pays for years of protection.

## Why 'We'll Deal With It If It Happens' Is Expensive

Setting up protection after an attack starts is slow: you're changing DNS under pressure, propagation takes time, and every minute counts against you. Protection put in place beforehand means the attack is filtered automatically from the first second — and with automatic mitigation, escalation doesn't wait for someone to wake up and react.

## Protection Is the Cheap Line Item

Compared to a single serious outage, DDoS protection is inexpensive — often the price of a few lost sales per month. Akarguard starts at €9/mo, filters application-layer attacks at a reverse proxy, hides your origin, and — importantly for cost — does not bill you for attack traffic: a fair-use allowance covers your normal traffic, and the flood is never on your invoice.

---

Source: Akarguard Security Blog (https://akarguard.net/blog). Akarguard provides DDoS protection: traffic is proxied through our edge, attack traffic is filtered, and clean traffic reaches your origin. Reuse of this article with attribution and a link to the canonical URL is permitted.
