DDoS (Distributed Denial of Service)
DDoS Protection safeguards critical public sector services with always on threat detection, real time mitigation and resilient cloud-based defence. It keeps citizen facing platforms, healthcare systems, education services and local authority applications available during attacks, ensuring continuity, security and confidence across distributed public sector environments.
Features
- Netscout & Arbor protection embedded directly within network core
- Real time automated detection of DDoS threats
- Automatic diversion of hostile traffic away from services
- Intelligent filtering to block malicious traffic instantly
- Automatic service restoration once attacks subside
- Automated reporting for clear operational oversight
- Built in service optimisation and tuning
- Two annual service tests included as standard
- Continuous 24/7 operational support
- Transparent, predictable pricing model
Benefits
- Strengthens core infrastructure resilience for essential public services
- Identifies threats instantly to protect critical operations
- Prevents service disruption by isolating harmful traffic
- Ensures only legitimate traffic reaches public services
- Minimises downtime and restores citizen services quickly
- Provides clear oversight for governance and audit needs
- Optimises performance without additional procurement burden
- Validates readiness and strengthens organisational assurance
- Guarantees continuous protection for always on public services
- Enables predictable budgeting across public sector environments
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
7 6 0 5 3 1 6 6 9 0 6 1 2 6 5
Contact
TALKTALK BUSINESS DIRECT LIMITED
Andrew Stokes
Telephone: 07976911843
Email: andrew.stokes@talktalk.business
About your service
- Service categories
-
Systems Infrastructure Software
Security
- Cloud native application protection platform
- Security analytics
- Governance, risk and compliance
Identity and access management
- Access
Network security
- Trusted network access and protection
- Active application security
Data security
- Information protection
- Multi cloud support
- No
Service scope
- Software add-on or extension
- Yes
- What software services is the service an extension to
- DIA (Dedicated Internet Access), offering high speeds (up to 10GB) and symmetrical bandwidth for customers who upload or host a significant amount of data. Bandwidth is uncontended, so customers maintain all their bandwidth consistently, meaning there’s no slowdown in busy periods.
- Cloud deployment model
-
- Public cloud
- Private cloud
- Service constraints
- Customers must purchase the service to cover the entire bandwidth of the access service provided. For all planned notices and maintenance, the customer will be notified 10 business days in advance. Emergency maintenance is rarely required and is typically not customer-affecting. In the event emergency maintenance is required and is likely to be customer-affecting, the planning and risk assessment that we undertake will include provision to minimise the impact in terms of scope and duration. Where possible, advance notice will be given.
- System requirements
- DDoS Mitigation is only available to TTB supplied access services
User support
- Email or online ticketing support
- Yes
- Support response times
-
Support is available 24x7x365.
All questions and queries will be acknowledged immediately upon receipt and we will endeavour to respond as quickly as possible during the working day.
Our default configuration for the automated response to a DDoS attack is three minutes. This is to ensure that the response initiates quickly enough to protect against disruption, without being too sensitive to fluctuations in traffic. However, this is configurable to a customer’s individual needs.
For incident support we will respond within 1 hour.
For configuration change requests or ad-hoc reporting requests, we will respond within 2 working days. - User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 24 hours, 7 days a week
- Web chat support
- No
- Onsite support
- No
- Support levels
-
TAll questions and queries will be acknowledged immediately upon receipt by our security operations centre and we will endeavour to respond as quickly as possible during the working day.
Our default configuration for automated response to a DDoS attack is three minutes. This is to ensure that the response initiates quickly enough to protect against disruption, without being too sensitive to fluctuations in traffic. However, this is configurable to a customer’s individual needs.
For incident support we will respond within 1-hour, and regular updates will be provided every hour through to resolution. A full debrief and detailed fault report will be provided once fully resolved.
For configuration change requests or ad-hoc reporting requests we will respond within 2 working days.
All support levels detailed above and associated costs are included as standard within the Service Contract.
All customers will be allocated a named Account Manager who will have a team of dedicated Technical specialists that will support on any customer requirements. - Support available to third parties
- No
Onboarding and offboarding
- Getting started
-
A short DDoS Protection Provisioning Form will be sent to the customer to complete. This will give us sufficient information to provide the DDoS Mitigation Service. It includes contact details for provisioning and authorised customer contacts for in-life service amendments, along with the IP address CIDR blocks and traffic types that need protecting, e.g. DNS, email, VOIP, VPN etc.
During the first week of service a tuning exercise will be undertaken. Following the tuning week, traffic parameters will be implemented and thresholds are agreed. This means that during service operation, traffic diversion will only happen in the event of a real attack and service reports will offer more insight and value. For all DDoS Mitigation Services, detection rates will be configured according to a default threshold. In most scenarios the default detection settings should be appropriate. If the customer is expecting to exceed these thresholds with legitimate traffic, these should be noted in the DDoS Mitigation Provisioning Form. - Service documentation
- Yes
- Documentation formats
- End-of-contract data extraction
-
At the end of a customer’s contract, TTB has a cease process in place. All cease requests must be received by email from the customer with a completed Cease Request Form, if required, this will then create a case within Salesforce.
The Customer Service Team will query the address on the Cease Form to confirm that it matches the address held on our records. Should the customer require access to data upon exit, a full inventory in the form of an ASR report will be provided to the customer, which will include an up-to-date asset list, including site addresses, post codes, services and monthly costs via the customer’s Account Manager. - End-of-contract process
-
At the end of a customer’s contract, TTB has a cease process in place. After the minimum term, the customer can end the contract or any connection forming part of a contract by giving 40 days’ notice. All cease requests must be received by email from the customer with a completed Cease Request Form, this will then create a case within Salesforce.
The Customer Service Team will query the address on the Cease Form to confirm that it matches the address held on our records. Once confirmed the cease process will begin.
The exit plan will be developed by the Account Manager with the customer 6 months prior to contract expiry to ensure a smooth handover. It will be provided by email and followed up with a phone call to answer any queries or highlight any missing information. The plan will cover:
• Options for asset acquisition by the customer
• Transfer of service/supply contracts
• Licence terms for IPR
• Data transfer
• TUPE
• Transition and handover planning
• Exit plan review and update
Provided the minimum contract term has expired and payment is up-to-date, no further charges or additional costs will be payable by the customer. - Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
- We can provide bills, contracts and letters in formats such as large print, Braille, coloured paper and audio CD on request, to ensure accessibility.
Using the service
- Web browser interface
- No
- Application to install
- No
- Designed for use on mobile devices
- No
- Service interface
- No
- User support accessibility
- None or don’t know
- API
- No
- Customisation available
- Yes
- Description of customisation
- TTB’s security platform will automatically start mitigation based on traffic exceeding pre-defined Volumetric Thresholds. These thresholds are a default value to begin with and in most scenarios the default detection settings should be appropriate. During the first week of service a tuning exercise will be undertaken with the customer. This is because we recognise that anomalous traffic patterns for one customer can be within tolerance for another. Following the tuning week, traffic parameters will be implemented and thresholds agreed, ensuring that TTB’s DDoS mitigation service is customised and optimised for each customer.
Scaling
- Independence of resources
- We leverage a multi-million-pound investment to provide best-in-class DDoS volumetric attack mitigation using a Carrier class Arbor Netscout platform deployed at multiple data centres within the core network. TTB’s platform has sufficient latent capacity and scale to ensure that demand from other users does not affect performance at any time.
Analytics
- Service usage metrics
- Yes
- Metrics types
- Our standard reporting process will be used to provide weekly and monthly reports via email to the customer, summarising the traffic that has passed through the customer’s connection and details of any incidents requiring mitigation to be enabled. These reports are useful to understand incidents and how the customer connection is being used day-to-day. Default reports will summarise traffic by IP protocol, TCP port, AS number, country and application. We are happy to make changes to reporting should customers require it.
- Reporting types
-
- Regular reports
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Reseller providing extra features and support
- Organisation whose services are being resold
- PlatformX Communications Limited (PXC)
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Developed Vetting (DV)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
-
- Physical access control, complying with another standard
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Data Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
- Physical Destruction / Hardware containing data is completely destroyed
Data importing and exporting
- Data export approach
- There will be no requirement for a customer to export data during this service. The only data on the service will be provided on the standard reports in life.
- Data export formats
- Other
- Other data export formats
- No requirement to export data during service
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
- Private network or public sector network
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
Availability and resilience
- Guaranteed availability
-
TTB measures performance across the Network and any services provided by any Third-Party Operator are outside the scope of this.
Internet Access Platform Matrix Target Service Level Agreements
• Network availability 99.99%
• Network roundtrip latency < 30ms
• Network packet loss < 0.1
Due to the nature of the DDoS mitigation service, no service credits are applicable. - Approach to resilience
-
We have an 800GB super core fibre network to handle the demand around London with two 400GB fibre rings around the major populated areas of the country and several 100GB rings around less populated regions, all of which has a high capacity backhaul to the core network.
The core network is highly resilient - multiple nodes and high levels of redundancy with 99.99% availability. We offer Network and Openreach (R02) resiliency options to prevent single points of failure.
The datacentres combine tier 3 high-availability with very low additional energy use in the cooling and power system, resulting in an annualised power unit efficiency (PUE) of less than 1.3 within an IL3 security environment.
The systems employed ensure that our datacentres are highly scalable, ensuring an unusually low PUE at low IT loads as well as when the facility is at its maximum capacity. This results in a carbon footprint that is nearly half the industry norm.
Based in a multi-layered security complex with multiple levels of redundancy at both a power and network level, this facility ensures service continuity for customers hosting their equipment. - Outage reporting
-
TTB has an Integrated Operation Centre (IOC) that will send the Incident Communication as per the Major Incident Communications Content & Distribution Lists document via email alerts.
TTB will prioritise the incident according to the criteria and record the appropriate value for each of the following categories:
· Service
· Incident Type
· Work Type
· Reported Source
· Product Categorisation Tier
Our Internal and/or External Communications teams will send regular updated emails on progress and also through a dedicated WhatsApp group informing all recipients of the incident in the Major Incident Communications Content & Distribution Lists document, describing:
· Impact
· Symptoms
· Manual workaround (if available)
· Instructions or additional information for customers and/or agents (if available)
· Provide a progress update
Regular updates will be provided through to full restoration.
Email alerts will be provided in the event of a major service outage (MSO).
Identity and authentication
- User authentication needed
- No
- Access restrictions in management interfaces and support channels
- The Internal Network and Security Team has access and is responsible for user access management. The level of access is based on the principle of 'least privilege' and only those members of staff who need access will be granted it. We have a formal Joiners, Movers, Leavers (JML) process with role-based access governing the majority of applications and systems. Access is removed within 24hrs of an employee leaving the business. Recertification of user access is completed bi-annually.
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Dedicated link (for example VPN)
- Username or password
Audit information for users
- Access to user activity audit information
- No audit information available
- Access to supplier activity audit information
- No audit information available
- How long system logs are stored for
- Between 6 months and 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
-
TTB has a Master Security Policy in place and operates an Information Security Management System via its Security Operations Centre (SOC) for the reporting of all potential security breaches. The system is based on industry good practice (NIST CSF, PCI DSS) and is externally certified to ISO 27001. This covers a range of policies and procedures to ensure the confidentiality, integrity and availability of information, e.g., Master Security Policy, the Privacy Policy and the GDPR Policy.
We have in place a named DPO – Adam Rogers with the responsibility for GDPR/ISO27001 policies and processes.
The reporting of any security incidents is done directly to the Security team security@talktalkplc.com via the phishing report message button in the email toolbar. All incidents logged will go into the Security Team to process and escalate into the Head of Security.
All colleagues attend mandatory annual security training, and GDPR training to ensure they meet audit standards around data handling requirements and encourage them to share the responsibility for protecting data at all times. All colleagues have set timescales for completion of all training and reported against to ensure full completion. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
-
Configuration Changes are assessed, logged and components tracked through our Service Management tool, which is managed by the Network Engineering team from the point at which we raise the initial change request until that change is closed off.
Quality comes as standard throughout the change process, with everyone involved having the requisite training. Managers of teams carrying out changes will be accountable for the quality of the work undertaken. There is zero tolerance for unauthorised changes.
Security impact will be assessed through a risk assessment and structured model to ensure all risks are captured and clearly identified. - Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
- The Network Security Team conducts security scanning of all our infrastructure on a bi-weekly basis. We also conduct weekly threat and vulnerability scanning of all our network assets via InsightVM. Critical/high risk vulnerabilities patches will be applied within 14 days. All other updates are applied as soon as possible using a monthly patching cycle. Security updates will be assessed and prioritised based on threat level, likelihood of compromise, consequences of compromise, environmental characteristics and regulatory or accreditation-based requirements. We receive information about potential threats from InsightVM from weekly scanning and we use Altiris for Patch Management.
- Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
-
TTB operates a security incident management program for the alerting of potential compromises and deploys endpoint protection technology. All potential compromises will be logged on the action plan tracker and updated with notes/associated actions to mitigate risk.
Users can report Priority level 1/level 2 incidents by telephone, and a response will be given within 1 hour. Incidents can be reported by email/web portal.
Incident reports are provided upon request. For network incidents, these reports are distributed to impacted customers via email. Reason for Outage reports for priority 1 faults are provided by email within 10 working days from root cause. - Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
-
We have a pre-defined process for common events and fault related reporting through our 24/7 Technical Support Centre (TSC).
User can report Priority level 1 and level 2 incidents by telephone (08454566541/08453103444) and by email/web portal.
Incidents, when resolved, will be notified to the customer as part of the logged ticket fault. Reports will be provided upon request for network incidents, and these reports distributed to impacted customers via email. - Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 1%
- Between £500,001 and £1,000,000
- 2%
- Between £1,000,001 and £2,500,000
- 3%
- Between £2,500,001 and £5,000,000
- 4%
- Over £5,000,001
- 5%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- ISOQAR
- ISO/IEC 27001 accreditation date
- Tuesday 27 January 2026
- What the ISO/IEC 27001 doesn’t cover
- N/A
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- Alcumus ISOQAR
- ISO 9001 accreditation date
- Monday 26 May 2025
- What the ISO 9001 doesn’t cover
-
Exclusions:
8.3 Design and Development of products and services
7.1.5.2 Measurement traceability
Location: Gateshead - Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- Yes
- Who accredited the PCI DSS certification
- Viking Cloud
- PCI DSS accreditation date
- Monday 3 November 2025
- What the PCI DSS doesn’t cover
- None - The Non PCI is not covered by our certification, all PCI is covered under this certification.
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 41015739-ac20-4a9f-a558-edbab61126e0
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- None of the criteria
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
- Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Structuring of the supply chain selection process to ensure fairness (e.g. anti-corruption) and encourages participation by a diverse range of businesses, including with regard to new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutual
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Inclusive and accessible recruitment practices, and retention-focused activities, including those provided in the Guide for line managers on recruiting, managing and developing people with a disability or health condition
- Inclusive and accessible development practices, including guidance for line managers on recruiting, managing and developing people with a disability or health condition
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Other measures to offer development opportunities for the target cohort(s) in the contract workforce
- Understanding of issues relating to entering the contract workforce
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
-