This summary aggregates findings from DDactic scans completed in May-June 2026 across financial services, SaaS, and enterprise software organizations. All findings are anonymized. The patterns represent the current state of DDoS resilience posture across a cross-sector assessment population, weighted toward mid-to-large enterprises in regulated industries.
Most Common Finding: Missing API Rate Limits
In 76% of assessed environments, one or more API endpoints had no rate limiting configured. This was the most common finding by occurrence count and by OPI impact. The typical pattern: the main authentication endpoint had a rate limit (often added after a credential stuffing incident), but secondary API paths serving the same application had none. The search endpoint, recommendation endpoint, and export endpoint were the most frequently unprotected in this cohort.
Second Most Common: Discoverable Origin IP
In 43% of environments using a CDN or reverse proxy, the origin IP address was discoverable through one or more passive reconnaissance techniques: certificate transparency logs (28%), historical DNS records (19%), SPF record IP disclosure (12%), or direct IP scan returning a matching certificate (9%). In each case, direct HTTP requests to the origin IP bypassed all CDN-level protections including DDoS scrubbing, WAF rules, and rate limiting.
Third Most Common: Default Connection Timeout Settings
In 67% of environments, connection timeout settings on origin servers reflected OS or web server defaults rather than explicit hardening. The most common default found: Nginx keepalive_timeout at 75 seconds (default), and Linux TCP keepalive idle time at 7200 seconds. These defaults enable Slowloris and slow-body attacks that hold connections open until the origin's connection table exhausts.
gRPC Service Exposure
In 18% of SaaS and enterprise software environments, one or more gRPC services (typically ML inference or internal microservice APIs) were accessible on internet-facing addresses without WAF coverage. These are almost uniformly unintentional exposures -- the services were designed for internal consumption but acquired an internet-routable address through infrastructure configuration. All were found via port 50051 scanning during Stage 2.
Sector OPI Distribution
- Financial services: median OPI 65 (range 41-89)
- SaaS platforms: median OPI 57 (range 32-81)
- Enterprise software: median OPI 59 (range 38-83)
- Healthcare: median OPI 52 (range 29-74)
Remediation Velocity
Among organizations that ran a follow-up scan within 90 days of the initial assessment, the median OPI improvement was 14 points. Quick wins (missing rate limits on identified endpoints) were closed in 82% of cases within 30 days. Strategic items (origin IP protection, gRPC service migration behind proxy) had closure rates of 41% within 90 days, reflecting the higher coordination cost of architectural changes.
See Where You Stand
A DDactic assessment produces your OPI score and positions it against the sector distribution -- so you know where you fall relative to your peers.
Run a Free Scan