TL;DR: Multi-layered DDoS, malformed DNS activity, and continuous automation are putting internet resilience under sustained pressure, according to DigiCert’s RADAR Brief, with availability now functioning as a trust signal rather than a pure uptime metric. The operational lesson is that identity, infrastructure, and response controls have to be coordinated as one resilience system.
Editorial analysis by NHI Mgmt Group, based on content published by DigiCert: “Hard Data on DDoS, DNS, and the Race for Resilience”.
Key questions
Q: How should security teams prepare for sustained DNS and DDoS pressure?
A: Teams should plan for prolonged pressure, not just peak traffic.
Q: Why do cryptographic changes matter to IAM and NHI programmes?
A: IAM and NHI programmes rely on certificates, signing keys, and token trust to establish who or what is authenticated.
Q: What are the signs that resilience controls are failing during a DDoS event?
A: Look for delayed mitigation handoffs, inconsistent telemetry across teams, repeated DNS anomalies, and service degradation that persists even after partial filtering begins.
Practitioner guidance
- Unify DNS and DDoS runbooks Align DNS operations, DDoS mitigation, and application protection into one response workflow so teams are not making separate decisions about the same incident.
- Treat availability as a control objective Add service continuity and DNS stability to the same governance discussions that already cover identity assurance, access reliability, and customer trust.
- Instrument the DNS control plane Monitor malformed queries, unusual lookup patterns, and configuration drift as operational signals that can precede broader resilience failure.
Bottom line: DDoS and DNS pressure are no longer isolated infrastructure problems because they directly influence how digital trust is perceived and experienced.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Availability has become a trust control, not a downstream metric: The article shows that organisations now signal credibility through continuity, not just through authentication strength or certificate hygiene. When DDoS and DNS strain can interrupt service paths, digital trust becomes dependent on resilience engineering as much as identity assurance. Practitioners should treat uptime as an identity-adjacent control surface because every interruption changes how users and systems judge the environment.
A question worth separating out:
Q: Should organisations prioritise unified monitoring over separate point defenses for DNS and DDoS?
A: Yes, when attacks are multi-layered and automated. Unified monitoring shortens the time between detection and coordinated response, while separate point defenses often leave teams reacting to different symptoms of the same event.
👉 Read our full editorial: DDoS, DNS and automation are redefining digital trust