Ask five UK providers to price protection for the same ecommerce site and the quotes will range from a small monthly subscription to an annual contract many times larger, all of them described as DDoS protection. That spread is not a negotiating tactic. The DDoS protection cost UK buyers face varies by two orders of magnitude because the word “protection”is being used to sell at least three different products, bought by three different sorts of customer, with wildly different amounts of human engineering attached. Work out which product you are actually being quoted and the numbers stop looking random.
What follows is a cost anatomy from the buyer’s side: what each pricing model charges for, which line items stay invisible until the first attack, and how to turn downtime into a figure your finance director will sign.
Why DDoS protection quotes in the UK swing so wildly
Three markets hiding behind one search term
The first market is bundled protection: filtering included with a hosting plan, a content delivery network (CDN) tier or a cloud load balancer. Marginal cost near zero, tuning near zero.
The second is mid-market managed service: a monthly fee, a named provider, some human involvement, usually a reverse proxy or a small scrubbing arrangement in front of a handful of properties. This is where most UK mid-market buyers end up, and where the contract language matters most.
The third is enterprise Border Gateway Protocol (BGP) scrubbing with committed capacity: you announce your own /24, traffic is diverted to scrubbing centres, clean traffic comes back over GRE tunnels or a cross-connect. You are buying network capacity, a routing relationship and an engineering team. It has a high floor because all three cost money whether or not you are attacked.
What an entry-level plan genuinely covers
Entry-level proxy plans advertised in the UK market at low monthly prices are real products, not bait. They buy a share of a large anycast proxy estate, automated volumetric filtering, a rate-limiting engine and a dashboard. For a brochure site or a small SaaS front end, that is often proportionate.
What they do not buy is anyone’s attention. Best-effort means exactly that: your traffic is defended by the same automated policy as everyone else on the shared tier, and if a layer 7 attack slips through the generic rules, the rule changes are yours to write. If nobody on the provider’s side is authorised to change policy at 03:00 without your written sign-off, you have bought monitoring, not management.
Why G-Cloud day rates are quoting people, not bandwidth
Public sector buyers looking at the Crown Commercial Service’s Digital Marketplace will see mitigation services listed at a price per unit per day. Those unit prices confuse people who assume they are paying for gigabits. They are not. G-Cloud style day rates typically price consultancy, onboarding, incident response time and diversion support, in other words a human being for a day. Comparing a day rate against a monthly subscription is comparing a plumber’s call-out charge with a water bill.
The question that explains most of the gap
Several UK “providers”do not own a scrubbing centre. They resell capacity on a larger network, wrap it in a portal and a support contract, and add margin. Sometimes there are two resale layers. Each one is another party that must be woken up before a mitigation policy changes, and another margin on your invoice.
So before you compare headline prices, ask who owns the scrubbing centres, whose autonomous system number (ASN) the traffic is cleaned on, and what your escalation path looks like in the middle of the night. Two quotes that differ by 10x for the “same”protection are usually not describing the same distance between you and the engineer who tunes the filter.
The pricing models behind the number on your quote
Per protected property or per protected IP. A flat monthly fee covering a defined number of domains, hostnames or IP addresses. The trap is counting creep. Staging, a customer portal, an API endpoint, a mail relay and a second data centre each add a chargeable unit, and the tidy monthly figure can multiply by the time the estate is honestly documented. Count every public-facing address before signing, not after.
Clean traffic bands with overage. The contract commits you to, say, 100 Mbps of clean traffic delivered, with an overage rate per Mbps or per GB beyond it. This is the single most common source of a surprise invoice after an attack, because attacks change traffic shape. Legitimate users refresh, bots retry, and some providers meter the traffic they forward after scrubbing rather than the flood they dropped. Read the metering definition, ask whether it is 95th percentile or peak, and ask what happens to billing during a declared incident.
Committed capacity and per-Gbps pricing. BGP scrubbing deals price a committed clean bandwidth tier plus the plumbing: GRE tunnel provisioning, or a cross-connect in a shared facility with its own monthly port fee. Budget for the network engineering time too. Announcing a /24 to a scrubbing provider, testing failover and documenting the withdrawal procedure is not a half-day job.
On-demand and emergency onboarding. On-demand looks cheaper on the monthly line because you pay for standby, not for constant traffic handling. The costs move elsewhere: diversion time while routes propagate, and in many contracts an emergency onboarding fee if you are attacked before you are provisioned. Compare the annual always-on premium against that fee plus the extra minutes of downtime, not against zero. Our breakdown of always-on versus on-demand DDoS protection works through where each model genuinely fits.
What each deployment model really costs once you add everything up
Reverse proxy or CDN-fronted protection
Lowest entry cost, priced on requests and bandwidth, quick to deploy with a DNS change. Its weakness is not capacity. It is origin leakage. If your server’s real IP address is still visible in historic DNS records, mail headers, TLS certificate transparency logs or an old subdomain, attackers route around the proxy entirely and hit the origin directly.
No pricing tier fixes an exposed origin. Budget for the remediation instead: new origin addressing, firewall allow-lists restricted to the provider’s published ranges, cleaning up stale A records and moving outbound mail off the web server. That work is usually a few days of engineering, and it is the difference between a paid proxy service that protects you and one that decorates your invoice.
BGP scrubbing and always-on routing
Higher floor, because you are buying capacity and a route rather than a shared proxy slot. It suits ASN holders, hosting companies, data centre operators and anyone protecting non-HTTP services such as game servers, VPN concentrators or VoIP. Costs to model: committed Gbps, tunnel or cross-connect fees, a /24 you actually control, and the internal staff time to run the diversion.
Hosting-level filtering
Bundled with a DDoS protected hosting package, near-zero marginal cost, and genuinely useful against crude volumetric floods. What you rarely get is tuning, a named escalation contact or a forensic report afterwards. If the provider’s answer during an incident is to null-route your IP to protect their other tenants, your site is down either way.
Whichever model you choose, the sticker price is not the total. Add web application firewall (WAF) licensing if it is not included, TLS termination and certificate management, log egress charges if you ship traffic logs into a SIEM, and internal staff hours. On a mid-market deployment those adders routinely equal the mitigation fee itself.
The line items buyers forget until the first invoice
Authoritative DNS. Left off the quote more often than any other component, then added later and billed separately by query volume. A site sitting behind a fully mitigated proxy is still unreachable if its name servers fold, and name servers are a soft target precisely because they are UDP-based and often hosted with a registrar nobody has thought about since 2019. Price network and transport layer, application layer and DNS as one budget line. Our buyer’s guide to authoritative DNS protection covers what to demand from that part of the stack, and the NCSC’s guidance on denial of service attacks is worth putting in front of anyone who thinks the web tier is the whole problem.
Attack reports and forensic exports. Sometimes a paid add-on, sometimes only available on enterprise tiers. Yet a vector breakdown with timestamps, source distribution and packet rates is the evidence you need for an insurer, a regulator, your own customers under an uptime clause, or any legal action following a DDoS attack. If the report costs extra, that is a line item, not a nicety.
What “managed”buys. The most expensive undefined word in a DDoS contract. Pin it down in writing: will the provider change rules mid-attack on their own authority, or does every tuning decision wait on a ticket and your approval? The approval model is cheaper monthly and far more expensive per incident, because the clock runs while your on-call engineer finds the portal password. Ask how many rule changes are included per year and what a change request costs beyond that.
SLA credits. Time-to-mitigate commitments are meaningful only if the measurement method is stated. There is a large practical difference between “60 seconds from detection”and “60 seconds from customer report”, and credits are almost always capped at a percentage of the monthly fee. A 100% credit on a £900 month does not cover a £20,000 trading outage. Treat credits as a signal of confidence, not as compensation.
Price your downtime before you price the protection
The business case is arithmetic, not fear. Build it from three components: revenue or transaction value per hour, incident staff cost, and contractual exposure to your own customers.
Take an illustrative mid-size UK retailer selling online. Spread across realistic trading hours, its annual online turnover gives an average revenue per hour, but peak Saturday afternoons in the run-up to Christmas might run several times that. A four-hour partial outage on a peak weekend, assuming half of attempted orders are lost rather than deferred, removes a meaningful slice of a trading weekend’s gross revenue. Add the people pulled onto an incident bridge for a day, plus an out-of-hours agency callout, and the total climbs again before anyone mentions refunds or reputational damage.
Against that, the annual cost of a managed DDoS protection UK contract is a fixed, known number. The break-even question becomes concrete: does your organisation expect more than roughly one significant outage a year? For an ecommerce operator during peak trading, a law firm running a client document portal under a professional obligation, a healthcare supplier with booking systems, or a B2B platform with liquidated damages in its uptime clauses, the answer is usually yes.
Resist the temptation to inflate. The Department for Science, Innovation and Technology publishes an average cost of the most disruptive breach in its annual Cyber Security Breaches Survey, and boards increasingly recognise that figure. It covers all breach types, skews low because it includes micro-businesses, and will be picked apart if you present it as a DDoS number. Quote the current edition by name and date if you use it, then rely on your own revenue-per-hour model for the actual case.
How to compare UK quotes on evidence rather than sales decks
Send every shortlisted provider the same ten questions and compare the answers side by side:
- Who owns the scrubbing centres, and are you a reseller of another network’s capacity?
- What is the total mitigation capacity, and what capacity is committed to me contractually?
- Is mitigation always-on or on-demand, and what is the measured time to divert?
- Can your engineers change mitigation policy mid-attack without my written approval?
- How is time-to-mitigate measured, from detection or from my report?
- What clean traffic is included, how is it metered, and what is the overage rate?
- How many protected IPs or hostnames are included, and what does each additional one cost?
- Is authoritative DNS protection included, and is it billed by query volume?
- Is a post-incident attack report with vector breakdown included at no extra charge?
- What is the named escalation path at 03:00 on a bank holiday, and what phone number do I call?
Then ask for something sales teams rarely offer: a redacted attack report from a real incident in the last twelve months. A capability slide proves nothing. A report showing attack start time, vectors, peak packet rate and the minute mitigation engaged tells you whether the operations team exists. If you want a structured starting point for evaluating vendors, our DDoS protection service comparison sets out how the main approaches differ in practice.
Terms worth negotiating: minimum term (push back on 24 months if you have not tested the service), a burst allowance that waives overage during a declared attack, waiver of emergency onboarding fees, and an exit clause that includes DNS TTL handover so you can leave without a self-inflicted outage.
Red flags, in order of seriousness: “unlimited”capacity claims, which no network can honour once you read the fair use clause; “fully managed”with no definition of who is authorised to act; mitigation SLAs with no stated measurement method; and any provider who will not name the network their traffic is cleaned on. One more, quieter one: a quote that covers only HTTP when half your revenue runs through an API or a DNS zone nobody has audited.
The honest summary of DDoS protection cost UK-wide is that you are pricing three things at once: capacity, authority to act, and evidence afterwards. Cheap plans give you the first. Only the contract tells you whether you are getting the other two, and only the second attack tells you whether you were right. Read the clauses before you compare the prices.
Frequently Asked Questions
How much does DDoS protection cost in the UK per year?
Entry-level proxy plans advertised in the UK market start at modest monthly subscriptions. Mid-market managed services typically land in the low thousands to low tens of thousands annually, depending on protected IP counts and committed clean traffic. Enterprise BGP scrubbing with committed capacity runs higher again, and public sector day rates on G-Cloud listings are quoted per unit per day for incident and consultancy work. Check current pricing directly, as published rates change.
Why is there such a big gap between cheap and enterprise DDoS protection pricing?
Partly technology, mostly people and margin. Cheap plans share automated filtering across thousands of customers with no dedicated engineering time; enterprise contracts commit capacity, a routing relationship and named responders. The resale chain matters too, because each layer between you and the network that owns the scrubbing centres adds margin and removes direct access to the engineers tuning the mitigation.
Does free or bundled protection from a host or CDN count as enough?
For a low-risk brochure site, frequently yes. For anything revenue-bearing, the limits show up fast: little or no tuning, no forensic report, and a provider whose incentive during a large attack may be to null-route your address to protect other tenants. Bundled filtering also rarely covers your authoritative DNS, which is a separate failure point.
What extra charges can appear on an invoice after an attack?
Overage on clean traffic bands is the most common, followed by emergency onboarding fees if you were on an on-demand plan and not yet provisioned. Then look for per-incident support charges beyond included hours, rule change fees above an annual allowance, paid forensic report exports and DNS queries billed by volume.
How do I justify the cost of DDoS protection to finance?
Model revenue or transaction value per hour at peak, add incident staff cost and any liquidated damages you owe customers under uptime clauses, then compare one realistic outage against the annual contract value. Present it as expected loss avoided, not as a doomsday scenario, and cite any national figures you use by source and year so the number survives scrutiny in the room.
