Infocentric
← Back to Blog

Always-On or On-Demand DDoS: Which Fits Your Network?

Infocentric5 min read
Filipino security leaders comparing DDoS traffic-routing options on wall monitors in a Metro Manila network operations room

Which DDoS protection model should you choose?

Choose always-on DDoS protection when an internet-facing service cannot tolerate detection and rerouting delay, and your team accepts continuous traffic steering through the provider. Choose on-demand protection when normal routing must remain unchanged and a tested team can activate mitigation quickly. Approve neither model until routing, failover, monitoring, and ownership are proved.

Key takeaways

  • Always-on protection favors immediate inspection for services with very low outage tolerance.
  • On-demand protection favors normal-path control but makes activation speed an operating requirement.
  • A purchase decision should follow a timed routing exercise, not a slide-deck comparison.
  • Philippine security and banking rules make availability, response, and recovery evidence part of the decision.

The attack data supports planning for short warning times, but it does not select a deployment model for you. In its 2025 second-quarter DDoS report, Cloudflare said it mitigated 7.3 million attacks during the quarter and observed an attack count 44% above the second quarter of 2024. Those figures describe Cloudflare's global network, not a Philippine incident rate.

The right choice starts with the service you must keep reachable. Record the public IP ranges, DNS dependencies, upstream carriers, critical applications, acceptable interruption, and people authorized to change routing. Compare that map with Infocentric's DDoS protection service and network monitoring capability, then ask each bidder to show exactly where traffic goes before, during, and after an attack.

The joint CISA, FBI, and MS-ISAC DDoS guide published in 2024 explains why capacity alone is not the test: “They possess the expertise and specialized infrastructure to handle large-scale attacks and can help filter out malicious traffic before it reaches your network.” Your decision must prove that the service, your carriers, and your own team can operate that filtering path together.

What should decide between always-on and on-demand protection?

Your outage tolerance and activation capability should decide between always-on and on-demand DDoS protection. Price matters, but a cheaper design fails the buying test if its activation path takes longer than the business can remain unavailable or if continuous routing creates an untested dependency.

This original decision matrix compares the operating conditions that a Philippine CISO can verify. It is not a promise that every provider implements either model in the same way.

Decision evidenceAlways-onOn-demand
Traffic pathProvider inspection remains in the production path.Normal routing remains until mitigation is activated.
Primary strengthNo incident-time diversion decision is required.The organization retains its usual path outside an attack.
Primary exposureProvider-path health and return routing become daily dependencies.Detection, authorization, and route change add incident-time steps.
Acceptance testProve steady-state latency, failover, return-path symmetry, and provider outage handling.Prove alert-to-activation time, route propagation, staffing, and safe withdrawal.

Cloudflare's current documentation provides a concrete example of both mechanics. Its Magic Transit DDoS documentation, updated May 2026, says managed rulesets are always enabled for protected traffic. Its separate on-demand documentation, updated April 2026, describes enabling prefix advertisement during an attack and disabling it after the incident. Use those pages to understand one implementation, then require every bidder to document its own routing, detection, activation, and withdrawal behavior.

Scale also changes the test. Cloudflare reported more than 6,500 hyper-volumetric attacks in the second quarter of 2025, averaging 71 per day, and a largest reported attack peaking at 7.3 terabits per second. These are vendor-observed global measurements. They support testing upstream scrubbing and carrier coordination; they do not establish the capacity your network needs.

What proof should you require before signing a DDoS contract?

Require a witnessed exercise that proves detection, routing, filtering, application availability, communication, and recovery before signing a DDoS contract. A proposal that lists mitigation capacity without showing who acts, how traffic moves, and how service returns leaves the hardest risks unresolved.

Use this five-part acceptance process:

  1. Set the service objective. Name the applications and public prefixes in scope, establish an approved outage tolerance from the business impact analysis, and identify dependencies such as DNS, authentication, carriers, and cloud origins.
  2. Draw both traffic paths. Document steady-state ingress, mitigation ingress, clean-traffic return, route ownership, asymmetric-routing controls, and the rollback path; reconcile the design with your enterprise networking environment.
  3. Run a timed activation. Measure alert receipt, decision, authorization, route change, provider confirmation, application recovery, and withdrawal; do not replace a production-safe exercise with a verbal estimate.
  4. Test the operating model. Confirm 24-hour contacts, escalation authority, evidence retention, customer communications, carrier coordination, and the boundary between your team, the provider, and any managed security service.
  5. Retest failure and recovery. Exercise provider-path failure, tunnel failure, a false positive, a route leak safeguard, and restoration to the normal path without losing monitoring or logs.

The Philippine anchor is specific. Section 20 of the Data Privacy Act of 2012 requires safeguards against interference with or hindering a computer network's functioning or availability when personal information is involved. It does not prescribe an always-on or on-demand product.

For BSP-supervised financial institutions, BSP Circular No. 982 issued in 2017 goes further: it includes DDoS in business impact and risk assessment, calls for multiple layers of prevention, detection, correction, monitoring, and analysis, and says incident response plans should cover DDoS response and recovery. That makes the exercise record part of the approval evidence, not an optional technical appendix.

What do Philippine security leaders ask about DDoS protection?

Philippine security leaders ask whether protection activates fast enough, preserves legitimate traffic, survives a failed route, and produces evidence for management and regulators. The answers should come from measured exercises and contract terms, with global threat reports used only as context.

Is always-on DDoS protection always the safer choice?

No. Always-on protection removes an incident-time diversion step, but it places the provider path in normal operations. The safer choice is the model whose routing, failover, latency, filtering, and recovery behavior meets your approved service objective and passes a witnessed exercise under conditions close to production.

Can a firewall replace a DDoS mitigation service?

A firewall is one control, not proof that upstream attack traffic cannot exhaust your connection or another dependency. The 2024 CISA, FBI, and MS-ISAC guide recommends combining monitoring, traffic analysis, response planning, provider coordination, filtering, capacity planning, redundancy, and recovery rather than relying on one device.

What is an acceptable on-demand activation time?

There is no universal acceptable number. Set the maximum from the business impact analysis, then measure the complete interval from detection through authorization, route propagation, mitigation confirmation, and application recovery. If the tested interval exceeds the service's outage tolerance, change the process or choose a different deployment model.

Does the Data Privacy Act require a named DDoS product?

No. Section 20 requires reasonable and appropriate safeguards for personal information, including protection against interference with network functioning or availability. It does not name DDoS technology or a deployment mode. Your recorded risk assessment should connect the selected controls to the data, network, operating complexity, and foreseeable harm.

What evidence should a BSP-supervised institution retain?

Retain the risk and business impact assessment, approved architecture, provider and carrier responsibilities, timed exercise results, incident and communication procedures, exceptions, remediation owners, and retest evidence. BSP Circular No. 982 specifically places DDoS in risk assessment and requires response and recovery procedures within the incident plan.