The DDoS Metrics That Actually Matter

June 5, 2026 | 9 min read | For Security Leadership

Most DDoS protection is marketed and measured in gigabits per second. This is the right metric for one specific attack type: volumetric network-layer floods. It is the wrong metric for L7 application attacks, authentication abuse, and slow-rate behavioral attacks -- the categories that dominate the current threat landscape for enterprises with basic network-layer protection already in place. The metrics below are the ones that measure resilience against the attacks you are actually likely to face.

Time to Automated Mitigation (TTAM)

The most important operational metric: how long does an attack run before automated controls stop it, without human intervention? An organization with a 30-second TTAM absorbs negligible availability impact from most attacks. An organization with a 20-minute TTAM -- where the SOC must first detect the attack, identify the right rule to apply, and deploy it -- absorbs substantial impact before mitigation. TTAM is a function of pre-configured rules, not of scrubbing capacity. Measure it by tracking the timestamp of attack onset versus first automated block action in your edge logs.

Endpoint Rate Limit Coverage

The percentage of endpoints in your API surface that have explicit rate limit rules configured. This is distinct from having a global rate limit: a global limit of 10,000 requests per minute provides no protection against 9,999 requests per minute targeted at a single expensive endpoint. Coverage is endpoint-specific. Track: total API endpoints (from your API gateway inventory), endpoints with rate limit rules, endpoints without rate limit rules. Target 100% coverage for any endpoint that performs database queries or external service calls.

Detection-to-Impact Gap

The time window between when an attack begins generating anomalous traffic and when user-facing impact (latency increase, error rate increase) occurs. A large detection-to-impact gap means your defenses absorb attacks before they affect users. A small or negative gap means users experience impact before detection -- the worst possible outcome. This gap is determined by the headroom between your rate limit thresholds and your origin's saturation point. If your login endpoint is limited to 100 requests per minute and origin saturation occurs at 150, your gap is the 50 requests per minute buffer. If you have no rate limit, the gap is zero.

Origin Exposure Surface

A count of origin IP addresses and services accessible without CDN protection. Zero is the target; anything above zero is a risk, because each exposed origin can be attacked without traversing your edge protection. This number changes with every infrastructure change, which is why it requires periodic measurement rather than one-time verification. DDactic tracks this as a component of the OPI score.

False Positive Rate on Rate Limits

The rate at which legitimate users are blocked by rate limiting rules. This metric is often neglected but critical for calibration: rules set too strictly block legitimate users and generate support tickets; rules set too loosely fail to stop attacks. Track the volume of 429 responses that were followed by successful completions after retry (indicator of legitimate users hitting limits) versus 429 responses not followed by any further traffic from the same source (indicator of attacks blocked). A ratio above 10% legitimate blocks indicates your thresholds need recalibration.

OPI Score as Summary Metric

The DDactic OPI score aggregates the above dimensions into a single 0-100 number suitable for board reporting. It moves when any underlying metric moves, making it a reliable summary indicator without requiring boards to understand the detail of each component metric. Track OPI quarter over quarter as a lagging indicator of security posture and as a driver of hardening investment decisions.

Measure Your DDoS Metrics

DDactic's assessment produces OPI scores and the component metrics that drive it, giving you a complete measurement framework for DDoS resilience.

Run a Free Scan
DDoS MetricsMTTDMTTROPISecurity KPIs