{
  "slug": "ddos-mitigation-cost",
  "title": "DDoS Mitigation Cost Calculator",
  "heading": "DDoS Mitigation Cost vs. Downtime Calculator",
  "category": "financial",
  "url": "https://www.revenuelab.fyi/toolbox/ddos-mitigation-cost",
  "summary": "Compare scrubbing-service subscription cost against expected outage losses.",
  "description": "DDoS mitigation is one of the easier security ROI cases to build because both sides of the ledger are concrete: a scrubbing service or CDN-based mitigation plan has a known annual fee, and an unmitigated attack has a measurable revenue-per-minute cost. This calculator takes your expected attack frequency per year, the average outage duration you'd suffer without mitigation, and your revenue-per-minute rate, then compares expected annual loss to the cost of a mitigation contract. Most volumetric attacks today exceed 1 Tbps at the high end and even mid-size e-commerce or SaaS sites see multiple attempted attacks per month, though only a fraction cause real downtime without protection. The model also accounts for partial mitigation effectiveness, since even paid services rarely stop 100% of sophisticated multi-vector attacks, and for the reputational/SLA-penalty cost that's easy to omit but real for B2B SaaS with uptime guarantees in customer contracts.",
  "formula": "Unmitigated annual loss = attacks/year × avg outage minutes × revenue per minute × (1 − baseline mitigation %). Net benefit = unmitigated loss − (loss with paid mitigation + mitigation cost).",
  "dateModified": "2026-09-30",
  "run_url": "https://www.revenuelab.fyi/api/public/calc?tool=ddos-mitigation-cost",
  "inputs": [
    {
      "id": "attacksPerYear",
      "label": "Expected damaging attacks per year",
      "kind": "number",
      "hint": null,
      "default": 6,
      "unit": null,
      "min": 0,
      "max": 200
    },
    {
      "id": "outageMinutes",
      "label": "Average outage minutes per unmitigated attack",
      "kind": "number",
      "hint": null,
      "default": 90,
      "unit": null,
      "min": 1,
      "max": 2000
    },
    {
      "id": "revenuePerMinute",
      "label": "Revenue at risk per minute of downtime",
      "kind": "number",
      "hint": null,
      "default": 400,
      "unit": null,
      "min": 0,
      "max": null
    },
    {
      "id": "mitigationEffectiveness",
      "label": "Paid mitigation effectiveness (% of downtime prevented)",
      "kind": "number",
      "hint": null,
      "default": 90,
      "unit": null,
      "min": 0,
      "max": 100
    },
    {
      "id": "mitigationCost",
      "label": "Annual mitigation service cost",
      "kind": "number",
      "hint": null,
      "default": 60000,
      "unit": null,
      "min": 0,
      "max": null
    },
    {
      "id": "slaPenaltyPerIncident",
      "label": "Avg SLA/reputation penalty per incident",
      "kind": "number",
      "hint": null,
      "default": 5000,
      "unit": null,
      "min": 0,
      "max": null
    }
  ],
  "outputs": [
    {
      "id": "netBenefit",
      "label": "Net annual benefit of mitigation",
      "format": "currency",
      "hint": null,
      "primary": true
    },
    {
      "id": "unmitigatedLoss",
      "label": "Expected annual loss without mitigation",
      "format": "currency",
      "hint": null,
      "primary": false
    },
    {
      "id": "totalCostWithMitigation",
      "label": "Total cost with mitigation (loss + fee)",
      "format": "currency",
      "hint": null,
      "primary": false
    },
    {
      "id": "mitigatedLoss",
      "label": "Residual loss with mitigation",
      "format": "currency",
      "hint": null,
      "primary": false
    },
    {
      "id": "breakEvenAttacks",
      "label": "Attacks/year to break even on cost",
      "format": "decimal",
      "hint": null,
      "primary": false
    }
  ],
  "worked_example": {
    "inputs": [
      "Expected damaging attacks per year: 6",
      "Average outage minutes per unmitigated attack: 90",
      "Revenue at risk per minute of downtime: 400",
      "Paid mitigation effectiveness (% of downtime prevented): 90",
      "Annual mitigation service cost: 60000",
      "Avg SLA/reputation penalty per incident: 5000"
    ],
    "outputs": [
      "Net annual benefit of mitigation: $161,400",
      "Expected annual loss without mitigation: $246,000",
      "Total cost with mitigation (loss + fee): $84,600",
      "Residual loss with mitigation: $24,600",
      "Attacks/year to break even on cost: 1.6"
    ]
  },
  "how_to": {
    "title": "How to use this",
    "steps": [
      "Enter expected damaging attacks per year.",
      "Enter average outage minutes per unmitigated attack.",
      "Enter revenue at risk per minute of downtime.",
      "Enter paid mitigation effectiveness (% of downtime prevented).",
      "Enter annual mitigation service cost.",
      "Enter avg sla/reputation penalty per incident.",
      "Read your net annual benefit of mitigation on the right — it updates as you type.",
      "Hit Share to keep the scenario or send it to someone."
    ]
  },
  "scenarios": [
    {
      "name": "Conservative",
      "description": "Lower-end numbers — what if things land soft?",
      "values": {
        "attacksPerYear": 4,
        "outageMinutes": 55,
        "revenuePerMinute": 240,
        "mitigationEffectiveness": 55,
        "mitigationCost": 36000,
        "slaPenaltyPerIncident": 3000
      }
    },
    {
      "name": "Typical",
      "description": "Defaults — the most common real-world setup.",
      "values": {
        "attacksPerYear": 6,
        "outageMinutes": 90,
        "revenuePerMinute": 400,
        "mitigationEffectiveness": 90,
        "mitigationCost": 60000,
        "slaPenaltyPerIncident": 5000
      }
    },
    {
      "name": "Ambitious",
      "description": "Higher-end numbers — what if things really pop?",
      "values": {
        "attacksPerYear": 10,
        "outageMinutes": 145,
        "revenuePerMinute": 640,
        "mitigationEffectiveness": 100,
        "mitigationCost": 96000,
        "slaPenaltyPerIncident": 8000
      }
    }
  ],
  "limitations": [
    "Results are estimates before tax, fees, and inflation unless an input explicitly covers them.",
    "Rates are treated as fixed for the whole period — variable-rate products will drift from this projection.",
    "This is educational maths, not financial advice. Check anything contractual with the lender or your accountant."
  ],
  "faq": [
    {
      "q": "How many DDoS attacks should I assume per year?",
      "a": "Internet-facing services with any public profile see attempted attacks constantly, but damaging ones (that actually cause outage without protection) are more useful to estimate from your own logs or your ISP/host's abuse reports. Six to twelve per year is a reasonable starting assumption for a mid-size site with no existing mitigation; adjust up for gaming, crypto, or politically exposed targets."
    },
    {
      "q": "Is 90% mitigation effectiveness realistic?",
      "a": "For well-configured commercial scrubbing services against common volumetric and protocol attacks, yes, 90%+ is typical. Effectiveness drops for sophisticated application-layer (Layer 7) attacks that mimic real user traffic, which is why layered defense including rate limiting and WAF rules still matters even with a paid mitigation contract."
    },
    {
      "q": "What's missing from this model?",
      "a": "Customer churn from a bad outage, which compounds beyond the immediate revenue loss, and the cost of your own engineering time spent responding versus building product. Add a churn estimate manually if a past outage caused measurable customer loss."
    },
    {
      "q": "Does a CDN alone count as DDoS mitigation?",
      "a": "Partially. A CDN absorbs a meaningful share of volumetric traffic simply by distributing load across edge nodes, but dedicated DDoS mitigation adds traffic scrubbing, anomaly detection, and always-on or on-demand routing specifically tuned for attack patterns, which a general-purpose CDN doesn't guarantee."
    }
  ],
  "related": [
    "https://www.revenuelab.fyi/toolbox/ransomware-downtime-cost",
    "https://www.revenuelab.fyi/toolbox/mttd-mttr-cost-impact",
    "https://www.revenuelab.fyi/toolbox/third-party-saas-sprawl-risk"
  ],
  "license": "CC-BY-4.0",
  "citation": "RevenueLab — DDoS Mitigation Cost Calculator (https://www.revenuelab.fyi/toolbox/ddos-mitigation-cost)"
}