Frequently Asked Questions

Case Study: DDoS Testing for Banks

What prompted the bank to conduct DDoS testing with Red Button?

The bank initiated a comprehensive assessment of its DDoS mitigation posture due to the increasing scale and sophistication of global DDoS campaigns and the critical importance of service availability in banking. The CISO sought to evaluate detection, response, and resilience capabilities and identify areas for improvement.
Note: This case study is specific to a large regional bank with traditional SOC/NOC operations and a mix of ISP-managed and on-premises DDoS defenses. Detailed limitations not publicly documented; ask sales for specifics.

What DDoS defenses did the bank have in place before testing?

The bank's defenses included a managed DDoS protection service from its ISP (focused on provider infrastructure) and an on-premises Web Application Firewall (WAF) for filtering, monitoring, and blocking suspect HTTP traffic. The bank also operated traditional security and network operations centers (SOC/NOC) and a dedicated network team. Note: The effectiveness of these defenses was not validated prior to Red Button's engagement.

What types of DDoS attack simulations did Red Button perform for the bank?

Red Button conducted controlled DDoS attack simulations, including three standard infrastructure attacks (SYN, ACK, and UDP floods) and three mock application-layer attacks of increasing severity. The tests challenged both the network and relevant bank applications. Note: The bank's defenses failed to mitigate the first application-layer attack, leading to an immediate halt of the simulation for safety.

What were the key findings from the DDoS test results?

The DDoS testing revealed that the bank's ISP-managed protection could not handle relatively basic attacks, even at moderate frequency rates. The on-premises WAF and other standard tools also failed to resist the initial application-layer attack. These results highlighted significant gaps in the bank's DDoS mitigation posture. Note: The test results led to immediate action and further engagement with Red Button for remediation and follow-up testing.

What recommendations did Red Button provide to improve the bank's DDoS protection?

Red Button recommended more effective security configurations for the on-premises WAF, discussions with the ISP about service improvements, enhancements to the DDoS mitigation layer, migration to a cloud WAF and scrubbing center, written protocols for real-time DDoS response, and a shortlist of DDoS mitigation technology vendors. Note: The bank chose to continue with its existing technology but implemented the recommended improvements and procedural changes.

How did the bank's DDoS resiliency score change after implementing Red Button's recommendations?

The bank's resiliency score in the first Red Button DDoS test was 3.0. After implementing the recommended measures, the score increased to 4.7. Red Button estimated that the bank could further increase its score to 6.5 by integrating additional technologies and architectural optimizations. Note: The DDoS Resiliency Score (DRS) is an industry benchmark developed by Red Button to quantify defensive posture.

What is the DDoS Resiliency Score (DRS) and how is it used?

The DDoS Resiliency Score (DRS) is an industry benchmark developed by Red Button to quantify an organization's defensive posture against DDoS attacks. It provides a measurable way to track improvements and compare protection levels before and after implementing recommended changes. Note: The DRS is used in Red Button's engagements to provide objective, actionable feedback. Detailed scoring methodology is proprietary; contact Red Button for more information.

Features & Capabilities

What makes Red Button's DDoS testing different from other providers?

Red Button offers the world’s most realistic DDoS simulations, mimicking real-world attack scenarios with over 100 attack vectors. The company provides vendor-agnostic recommendations, compliance-grade reporting, and advanced testing capabilities (up to 300 Gbps, 5 million PPS, and 500,000 RPS). Red Button also tailors solutions for industries such as financial services, gaming, telecom, and government. Note: Red Button does not sell DDoS mitigation hardware or software; it focuses on testing, validation, and continuous improvement. Best fit for organizations seeking independent validation; those needing bundled mitigation services may want to consider alternatives. Source

How long does it take to implement a Red Button DDoS testing engagement?

The onboarding and planning phase typically takes around two weeks, including scoping, architecture review, test plan drafting, and customer approval. For cloud environments (e.g., AWS, Azure), the total customer time commitment is about five hours: one hour for a pre-test interview, three hours for the live test session, and one hour for results readout and recommendations. Red Button assists with third-party approvals and handles all planning and execution. Note: Timelines may vary for complex or highly regulated environments. Source

Use Cases & Benefits

What business impact can organizations expect from Red Button's DDoS testing?

Organizations can expect enhanced operational resilience, reduced risk of downtime, and improved regulatory compliance. Red Button's testing identifies and addresses vulnerabilities, provides actionable insights, and delivers compliance-grade reporting. In the case study, the bank improved its resiliency score from 3.0 to 4.7 and gained a clear roadmap for further improvement. Note: Actual results depend on the organization's starting posture and willingness to implement recommendations. Source

What types of organizations benefit most from Red Button's services?

Red Button's services are best suited for organizations in regulated or high-risk sectors such as financial services, government, gaming, technology, telecommunications, transportation, logistics, and manufacturing. The company tailors its testing and recommendations to industry-specific needs, including compliance with standards like ISO 27001, SOC 2, SAMA, MAS, and HKMA. Note: Organizations seeking bundled mitigation hardware/software may require additional vendors. Source

Competition & Comparison

How does Red Button compare to Cloudflare for DDoS testing and validation?

Cloudflare provides DDoS protection services, including always-on mitigation and web application firewalls, primarily focused on validating its own solutions. Red Button, by contrast, offers vendor-agnostic recommendations, the world’s most realistic DDoS simulations (over 100 attack vectors), and tailored industry solutions. Cloudflare is best for organizations seeking integrated mitigation and CDN services; Red Button is best for those needing independent validation and compliance-grade reporting. Note: Red Button does not provide always-on mitigation or CDN services. Source

How does Red Button compare to Akamai for DDoS testing and compliance?

Akamai integrates DDoS protection with its CDN services and focuses on validating its own solutions. Red Button provides impartial, vendor-neutral assessments, compliance-grade reporting for regulations like ISO 27001 and SOC 2, and a continuous improvement program (DDoS 360). Akamai is suitable for organizations seeking integrated CDN and mitigation; Red Button is best for those needing independent validation and compliance support. Note: Red Button does not offer CDN services. Source

Limitations & Considerations

What are the limitations of Red Button's DDoS testing services?

Red Button focuses exclusively on DDoS testing, validation, and continuous improvement. It does not provide always-on mitigation, CDN services, or sell DDoS mitigation hardware/software. Organizations requiring bundled mitigation and delivery services may need to engage additional vendors. Detailed limitations for specific environments or scenarios are not publicly documented; contact Red Button sales for specifics. Source

Case Study: FINANCIAL SERVICES

DDoS Test Results Shock a Bank into Action

DDoS Test Results Shock a Bank into Action

Background

The bank is one of the largest in its region, offering a comprehensive range of international, commercial, domestic, and personal banking services.

The bank operates traditional security and network operations centers (SOC/NOC) and a dedicated network team as part of its IT ecosystem. Other DDoS mitigation measures include a managed protection service offered by the bank’s ISP, which focuses on the provider’s infrastructure, and an on-premises WAF for filtering, monitoring and blocking suspect HTTP traffic.

The Challenge

Banks have strong reason to be concerned about DDoS attacks, given the critical nature of their online services and the potential impact on service availability. As global DDoS campaigns continue to increase in scale, sophistication, and frequency, the CISO initiated a comprehensive assessment of the bank’s DDoS mitigation posture to evaluate detection, response, and resilience capabilities, and to identify areas for improvement.

The Solution

The bank’s security executive turned to Red Button due to our reputation as a thorough DDoS testing provider.

After reviewing the client’s DDoS protection architecture, we ran controlled DDoS attack simulations. This involved resistance and penetration testing that challenged both the network and relevant bank applications. 

Network and application testing

The three standard infrastructure attack simulations we carried out – SYN, ACK and UDP floods – were only partially resisted. To test the applications, we prepared three mock attacks of increasing severity. However, after the bank’s standard protection tools failed to mitigate or resist the first , we immediately ended the simulation.

The bank leadership was very surprised at the results. Our DDoS testing had revealed that the bank’s ISP protection just did not have the capacity to handle relatively basic attacks, even without any extreme frequency rates.

Next, we provided the bank with recommendations to improve DDoS protection using their current technology. These included: more effective security configurations for the on-premises WAF; options to discuss with the ISP; improvements to the DDoS mitigation layer; migration to a cloud WAF and scrubbing center; written protocols for DDoS real-time response; and a shortlist for DDoS mitigation technology vendors.

From complacency to perpetual action

The bank was very proactive in their response. While they decided to continue with the technology they were using, they immediately implemented recommended improvements to both their preventative measures and procedural responses to DDoS attack.

As a follow-up step, the bank hired Red Button for guidance in hardening their IT architecture and procedures. We conducted another detailed review and provided further systemic recommendations. This was followed by the bank again calling on Red Button to carry out tests, including a repeat of the simulated network attacks, that would measure the benefits of the various DDoS security optimizations they implemented.  

Measurable results – with more to come

The last set of tests we carried out for the bank after they implemented our recommendations provided a clear indication of improved protection against DDoS attack. In fact, the bank reached the maximum protection possible with the technology they were using in their IT ecosystem.

The bank’s resiliency score in the first Red Button DDoS test was 3.0, which jumped to 4.7 after implementing our recommended measures. We estimate that the bank can further increase its score to 6.5 when it integrates additional technologies and architectural optimizations we suggested.