A clean DDoS test can tell you your protection works and still leave you blind to how it holds up against the attacks actually hitting the market right now. Those aren't the same thing, and the gap between them is widening.
Most organisations that test their DDoS resilience do it with synthetic traffic. A tool fires a controlled volume of requests from a defined set of sources, the mitigation stack responds, the test passes, everyone moves on.
That's a fair place to start. It's just worth being clear about what synthetic testing actually tells you, and what it leaves out.
What Synthetic Testing Is Designed To Do
Synthetic DDoS testing exists to confirm that your mitigation controls are configured correctly and behave the way you expect. It checks that policies are active, that thresholds fire when they should, and that the system reacts when traffic volumes climb.
For that purpose, it works.
The catch is that real attacks often look nothing like the conditions a synthetic test is set up to recreate.
Amazon Web Services makes this point about its own firedrill testing: synthetic tests don't generate real volumetric traffic, so you won't see the logs and operational data a live attack would throw off.
A clean synthetic test proves your protection is deployed and working. It doesn't prove how your infrastructure holds up against the kind of attacks landing in the real world right now. Related questions, but not the same one.
How Attacks Have Changed
The distance between synthetic testing and real attack conditions has grown a lot in the past few years.
In December 2025, a single botnet pushed out a 31.4 Tbps attack, a new record and a clear sign of how much firepower modern attack infrastructure can muster. Total DDoS events doubled between 2024 and 2025. Cloudflare says it now mitigates more than 5,000 attacks an hour.
Volume is only half of it.
Akamai Technologies' latest State of the Internet Security report found APAC absorbed 52% of all global application-layer DDoS attacks against financial services in 2025, the most targeted region for the fourth year running. Banking took 44% of those attacks, fintech 38%.
The same research flagged a 147% rise in advanced bot activity in late 2025, with botnets that can imitate real browser behaviour and slip past traditional detection.
That shift is the part that matters. When malicious traffic looks obviously malicious, mitigation systems can usually make easy calls. When it starts to behave like a real customer, those calls get much harder. The job is no longer spotting big spikes in traffic. It's telling genuine users apart from very convincing copies of them.
The Residential IP Problem
A growing share of DDoS activity now comes from networks of compromised home devices. Smartphones, routers, consumer IoT kit, all of it gives attackers a large pool of endpoints scattered across the map that look a lot like ordinary users.
That traffic tends to carry the markers of legitimate activity: consumer ISP addresses, spread across multiple countries, with behaviour that's hard to separate from the real thing.
This is a different problem from the older model, where attack traffic came from recognisable data centres or cloud platforms. A mitigation platform might handle one scenario well and behave completely differently against the other. Testing with synthetic traffic validates the first set of conditions. It says little about the second.
What Regulators Mean By Realistic Conditions
Regulators are starting to reflect that distinction in what they expect.
Bank Negara Malaysia's updated Risk Management in Technology policy, issued in November 2025, requires financial institutions to run realistic attack simulations against their infrastructure at least once every three years, and sets a Maximum Tolerable Downtime of 120 minutes for critical systems.
GCC regulators are moving the same way, leaning harder on operational resilience and evidence-based validation instead of accepting documentation that controls exist.
The principle holds across jurisdictions. Supervisors care less about whether a control exists on paper and more about whether you can show it performs under realistic conditions. That calls for a different kind of evidence.
Where This Leaves Security Teams
None of this means synthetic testing is pointless. It's still a solid way to validate basic configuration, confirm controls are live, and catch certain implementation issues.
The trouble starts when synthetic testing gets treated as enough on its own.
Teams that push their testing past synthetic traffic often turn up problems that never showed during traditional exercises. Their controls weren't broken. The two approaches were simply answering different questions.
Synthetic testing tells you whether your mitigation stack responds to traffic it recognises. Advanced simulation tells you whether your infrastructure keeps performing when the traffic resembles the attacks you're actually likely to face.
And as attacks keep getting more sophisticated, the gap between those two questions is only going to widen.
If you're responsible for resilience testing at a financial institution, the question worth asking is simple: when did you last test against conditions that look like a real attack, not just one your tools were built to recognise?
Nader Salem is the regional partner for Obsidio in the Middle East and Southeast Asia.
← Back to Insights