DDactic Research

DDoS Research Library

Primary-source data and regulatory analysis for security and compliance teams. Fill the form below to receive access.

Passive Scan Data · Israel

DDoS Resilience by Israeli Sector

What passive scan data reveals about attack surface readiness across 8 industries, showing where the gaps are widest and which sectors are most exposed.

Banking leads with the strongest CDN and WAF adoption; healthcare trails significantly.
Government and critical infrastructure show the widest gap between declared posture and measured OPI scores, with several orgs still running unprotected origin IPs.
Sector-level OPI scores and n-counts across banking, insurance, healthcare, government, telecom, retail, energy, and transportation.

Access this report

42 Jurisdictions · Primary Sources

What Your Regulator Actually Requires

Verbatim obligations and verbatim quotes across 42 jurisdictions, with exact source locators. Where DDoS testing is explicitly mandated, and where it sits as an unnamed but in-scope gap.

Only two regulators name DDoS testing by name: Turkey's SPK (EK-1 scope list) and Saudi Arabia's SAMA (twice yearly).
DORA, NIS2, CBEST, Reg SCI, and FFIEC mandate real adversarial testing without naming DDoS. This is deliberate: principles-based regulation avoids dating itself by naming vectors. It creates the widest DDoS gap precisely where sophistication is highest.
25 STRICT regimes across 12 jurisdictions, with verbatim quotes and full source locators including article numbers, official gazette references, and direct PDF links.

Access this report