Are you covered for this kind of attack Dan ?
We are now, technically. Not insurance-wise.
Actually, with most hosts, it's in their terms to just terminate the account with the issues, as it has such a knock-on effect. I asked our previous hosts to host a few of the websites that weren't being attacked but were down as a result and he said no. Am close friends with them. He did explain why he didn't just say no. Quite understandably they aren't covered themselves for it. My current host who is more of a dedicated server provider than an actual host, said this his is second ddos in 14 years. The other one 14 years ago (he's been hosting longer than that).
So hats off to them for fetching in staff 24 hours a day over the last few days. I owe him a drink.
I felt quite helpless. When we had to shut the server(s) down, we can't even run tests and things to see what might work, as we literally are shut down. So we'd creep back online a site at a time to test what was being attacked and try to just shut those down. Each time we did so, when we got attacked again, all of his customers went down.
So they're not covered either really.
And if you imagine a rack of servers on top of each other like this...
... and ours just being one or two of them, the rest have the same connectivity. And then when that goes down the rest get stressed. At one short point they shut the lines to the whole area to make sure it was just mine being attacked (turning only mine on). So quite a problem for everybody, and nobody is really covered.
We called a firm who deal with banks who said they can help. We'd move our server to their rack and use their protected lines and extra routers etc, and they were like "okay so that'll be 10k for a GB" my host was like oooooo we don't need that much protection we don't have that much traffic.
There seems to be a lot of options for banks and whatnot. At the higher level. And nothing for the small guys.
I got told to sit it out at one point with everything shut. I said no chance. So took a decision. Do I shut everything that doesn't make money and pay for the things that do. Or do I split everything and and spread them over the country paying still a lot to host each one dedicated, but have a lot of bandwidth to "out bandwidth the ddos" (what a lot of firms do, so they just server the bad traffic too so it has no effect) or what.
Really pleased I had an awesome team behind me.
Pleased to say all of our traffic has come straight back after sending out an email on the forums too. A lot said they had to speak to the wives and everything. booooooo.