1. Estimate detection time
Enter the time from attack onset or alert to confirmation that material DDoS disruption is occurring.
2. Add mitigation activation
Include escalation, provider contact, routing changes, or automated control activation.
3. Estimate stabilization
Enter the time required for malicious traffic to be controlled and service performance to normalize.
4. Add validation
Include technical checks and business verification that the service is reliably available.
5. Apply readiness reduction
Enter a conservative reduction supported by drills, automation, runbooks, and staffing.