Vertical Hardening: Closing Every Layer Before Moving On

June 5, 2026 | 9 min read | Security Strategy

Horizontal hardening applies a partial fix across many assets simultaneously. Vertical hardening completes all fixes on one asset or one layer before moving to the next. Both strategies have their place, but for DDoS resilience, the vertical approach produces more predictable outcomes. An attacker targeting a single high-value endpoint does not need a gap to exist across many endpoints -- one unprotected path is sufficient. Closing every gap on the highest-value endpoint before addressing lower-value ones ensures that the most likely targets are fully protected first.

The practical implication of vertical hardening for DDactic customers: when a scan produces 40 findings across 15 endpoints, the recommended approach is to select the 3 highest-value endpoints (by revenue exposure, by breach data proximity, by saturation threshold) and close all findings on those 3 endpoints before addressing the remaining 12. After vertical hardening of the top 3, the OPI score improvement is concentrated and measurable, and those endpoints are protected against realistic attacks. A horizontal approach that partially addresses all 15 endpoints leaves each endpoint partially vulnerable and produces a diluted OPI improvement.

How to Identify the Top Layer

Selecting the layer to harden first requires ranking by attack probability and impact, not by finding count. The relevant questions: Which endpoint, if saturated, would cause the most significant business impact? Which endpoints are directly referenced in the organization's threat model (financial transaction APIs, login, customer data export)? Which endpoints have the lowest current saturation threshold relative to their current rate limit (or absence of one)? The answers identify the vertical hardening target -- the endpoint where an attack would succeed today and where remediation produces the most immediate risk reduction.

Vertical Hardening in Practice

Vertical hardening of a single API endpoint means applying all findings from all layers to that endpoint: the WAF rate limit, the connection limit at the origin server, the per-user authenticated rate limit at the API gateway, the application-level request timeout, and the database query timeout. Each layer adds a defense that attacks the attack at a different point. An attacker who bypasses the WAF rate limit (via distributed botnet) is still caught by the API gateway's per-user limit. An attacker who bypasses the per-user limit via credential stuffing is still caught by the database query timeout. Vertical hardening produces this defense depth on the highest-value endpoint first.

Verifying Completion Before Moving On

The "before moving on" part of vertical hardening requires a verification step: running DDactic's scan specifically against the hardened endpoint to confirm all findings have been resolved. A finding that appeared to be resolved (the WAF rule was added) but was misconfigured (the rule fires on POST but not GET) should be caught by the verification scan, not discovered in a future incident. The completion criterion for vertical hardening of an endpoint is a zero-finding rescan of that endpoint, not just confirmation that the remediation commands were executed.

The vertical hardening cycle integrates with sprint planning

DDactic reports are structured to support vertical hardening: findings are grouped by endpoint, and within each endpoint group they are ordered by implementation effort (fastest to implement first). This makes each endpoint's finding group a self-contained sprint ticket that can be assigned, completed, and verified independently.

Get a Vertical Hardening Plan

DDactic assessments group findings by endpoint to enable vertical hardening. Start with a scan to identify your top 3 hardening targets.

Run a Free Scan
Vertical HardeningSecurity StrategyDefense in DepthPrioritizationDDoS Resilience