TL;DR: Sustained internet demand, higher DNS noise, and longer, more automated DDoS activity defined the end of 2025, with attackers increasingly using prolonged pressure rather than brief spikes to stress infrastructure, according to DigiCert. That shifts resilience from burst handling to continuous operations across DNS, network, and application layers.
Editorial analysis by NHI Mgmt Group, based on content published by DigiCert: “DigiCert Releases Q4 2025 RADAR Brief”.
Key questions
Q: How should security teams prepare for sustained DNS and DDoS pressure?
A: Teams should plan for prolonged pressure, not just peak traffic.
Q: Why do sustained DNS failures and NXDOMAIN noise matter to availability?
A: They matter because they show the environment is under constant pressure, not just occasional load.
Q: What are the signs that low-noise application probing is becoming a real risk?
A: Look for repeated request variation, unexpected cookie manipulation, steady automated activity, and control behaviour that changes under small input differences.
Practitioner guidance
- Harden DNS endurance testing Stress-test authoritative and recursive DNS paths under sustained query volume, repeated NXDOMAIN noise, and mixed automated traffic so the team can see when degradation starts.
- Validate multiday DDoS response coverage Exercise the full mitigation chain across scrubbing, rate limiting, escalation, and vendor coordination for attacks that last longer than a single shift.
- Tune application controls for quiet probing Review cookie handling, request variation tolerance, and anomaly thresholds so low-noise automated testing is surfaced before it becomes exploitation.
Bottom line: DigiCert's Q4 brief shows that sustained traffic growth and longer DDoS campaigns are replacing the old burst-and-recover model.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Sustained pressure is now the operating condition, not the exception: The article shows that DNS demand and malicious traffic both remained elevated for long stretches, which collapses the old assumption that teams can recover between spikes. That matters because resilience programmes built around burst handling can look healthy in calm windows while failing under continuous load. Practitioners should treat endurance as a control property, not a capacity afterthought.
A question worth separating out:
Q: When should organisations treat internet traffic growth as a resilience governance issue?
A: When demand stays elevated for weeks, the problem is no longer just capacity planning. It becomes governance over how DNS, network, and application teams coordinate under sustained pressure, because availability now depends on joined-up ownership rather than isolated controls.
👉 Read our full editorial: Q4 traffic and DDoS pressure are reshaping internet resilience