Special Interview | You Bought DDoS Protection. But Do You Know If It Works?
MazeBolt CEO Matthew Andriani says organizations are relying on security policies they have never truly tested, creating a dangerous gap as AI makes DDoS campaigns faster, more adaptive, and harder to predict
DDoS attacks remained one of the most disruptive cyber threats in the first quarter of 2026, targeting organizations across government, critical infrastructure, transportation, finance, media, gaming, and cloud services, according to an analysis by cybersecurity company MazeBolt.
The company identified geopolitical hacktivism as a major driver behind many of the most visible campaigns during the period, with groups such as the pro-Russian NoName057 targeting public-sector agencies, defense organizations, telecom providers, banks, rail operators, and other critical infrastructure across Europe and the Middle East.
But according to Matthew Andriani, CEO of MazeBolt, the bigger challenge is not only stopping attacks in real time. It is knowing beforehand whether existing defenses are actually configured to withstand the techniques attackers are likely to use.
"The biggest problem is that organizations don’t really know how their defenses are configured against the attacks that can bypass them," he says in an interview with Cybertech.
Andriani founded MazeBolt in 2013 after leadership roles at Radware and Check Point. He says the company was born from a pattern he repeatedly saw while responding to large-scale attacks: organizations had invested in DDoS protection, yet attackers were still finding ways around those defenses.
"In hundreds of real-time attacks, we saw attackers bypass protections we had sold. Once we understood how they did it, we always had a solution — but we had no way of getting that information before the attack happened."
Where DDoS defenses often fail
According to Andriani, one of the biggest misconceptions among security leaders is that deploying a DDoS protection solution automatically means an organization is secure.
"The assumption is: I bought protection, therefore I’m protected. But when you really look at what you bought, you realize the vendor puts a lot of the configuration responsibility back on the customer."
The challenge becomes even more complex at large enterprises, which operate thousands of services across on-premise environments, cloud platforms, APIs, and customer-facing applications. Each may require different protection policies and configurations.
"Theoretically, every time you change something in your production environment, your DDoS mitigation policies should be updated. But that process does not happen. And even if you make a change, you often don’t know whether it actually worked."
As a result, many organizations only discover weaknesses once an attack is already underway.
"They are effectively waiting for damage to happen and then triggering an SLA. But the analysis and preparation could have happened beforehand."
AI Is accelerating the DDoS arms race
The rise of artificial intelligence has made this gap more urgent. While attackers have relied on automation for years, AI allows them to adapt known attack techniques faster and with less manual effort.
"AI-orchestrated attacks mean taking known attack vectors and using them much more effectively against an organization. Instead of an attacker manually changing tactics, it can happen much faster."
According to Andriani, defenders are still facing the same fundamental challenge: they lack visibility into how their environments will respond to new attack techniques.
"Defense has not moved at the same speed. The problem remains that organizations do not have enough data about what can bypass their defenses."
MazeBolt’s approach is based on continuously testing DDoS defenses through simulated attacks, allowing organizations to identify weaknesses before they are exploited. Its Radar platform tests existing protections against known attack techniques, while its newer Vector AI product focuses on emerging AI-generated attack scenarios.
Rather than testing only against existing attack patterns, Vector AI creates new variations based on known attack families and evaluates whether defenses can detect and block them.
"An AI model is only as good as the data it was trained on. We are providing the data needed to help security systems recognize and respond to new attack patterns."
The surprising failures hiding inside major organizations
Despite working primarily with large enterprises, financial institutions, and government organizations, Andriani says the most surprising failures are often not sophisticated vulnerabilities, but basic assumptions that turn out to be wrong.
"We have seen cases where companies thought their traffic was going through providers like Akamai, Radware, or Cloudflare, but when we checked, it wasn’t. That meant they were exposed."
Another recurring issue is that identical security policies do not always provide identical protection.
"You can have the same policy applied to five targets. An attack is blocked on four of them, but on the fifth one it is not. The customer assumes something is wrong with the product, but the reality is that the fifth target needed a different configuration."
For Andriani, the lesson is that resilience cannot be measured by the tools an organization has deployed, but by how those tools perform under real attack conditions.
Having a DDoS mitigation provider remains essential, he says, but it is only the starting point. As DDoS campaigns become faster and more adaptive, continuous validation is becoming as important as prevention itself.