Immerse NYC 2026
Live Data · Cloudflare Radar · April 2025 – March 2026

The State of the
Enterprise Network
& Network Resilience

A data-driven look at the evolving DDoS threat landscape, the industries bearing the brunt of modern attacks, and why the architecture that protected your network five years ago can no longer keep up.

PresenterNetwork Protection Specialist
ProductsMagic Transit · Magic Firewall
Data SourceCloudflare Radar
Data PeriodApr 2025 – Mar 2026
Network Capacity405+ Tbps · 330+ Cities
radar.cloudflare.com 01 / 10
Immerse NYC 2026
01
Section One

The Attack Landscape
Has Changed Forever

12 months of Cloudflare Radar data on the rise in frequency, volume, and sophistication of enterprise network attacks.

radar.cloudflare.com02 / 10
Immerse NYC 2026
Section 01 — Attack Volume

Q1 2026 Produced the Highest Attack Week of the Entire Year

Weekly L3/L4 DDoS attack volume index — normalized to the annual peak. The last 8 weeks of data represent a sustained surge, not a temporary spike. March 2026 hit record levels.

+75%
Q1 2026 peak week vs. Q1 2025 peak — same normalized scale
Mar 2026 average attack volume vs. the full-year weekly average
#1
Mar 2026 produced the single highest attack week of the past 12 months
7.3Tbps
Largest single DDoS attack ever observed on Cloudflare's network
Weekly L3/L4 DDoS Attack Volume Index — Apr 2025 to Mar 2026 · Normalized to Peak (Source: Cloudflare Radar)
Cloudflare Radar · /radar/attacks/layer3/timeseries · 52w · MIN0_MAX normalization03 / 10
Immerse NYC 2026
Section 01 — Why Attacks Are Growing

Three Forces Are Driving the Surge

01

DDoS-as-a-Service Has Industrialized Attacks

For as little as $10/hour, anyone can rent a botnet capable of generating hundreds of Gbps of traffic. The barrier to entry for launching a devastating attack has effectively reached zero.

02

Botnets Are Larger and More Distributed

Modern botnets span millions of compromised IoT devices, cloud instances, and servers across 160+ countries. Geographic distribution makes traditional IP-based blocking ineffective.

03

Attacks Are Multi-Vector by Design

Attackers now launch simultaneous L3, L4, and L7 attacks — volumetric floods combined with protocol exploits and application-layer probing. Single-layer defenses are trivially bypassed.

The Consequence

The average enterprise firewall handles ~25 Gbps. The largest attacks Cloudflare sees today exceed 7,300 Gbps. That is a 292× gap. No amount of hardware investment closes it.

Attack Size vs. Enterprise Hardware Capacity — The Widening Gap (Gbps)
292×
Largest attack vs. top enterprise hardware capacity
160+
Countries attacks originated from in a single volumetric campaign
<3s
Cloudflare median time to detect and begin mitigating a new attack
Cloudflare Radar · Cloudflare DDoS Threat Reports · Industry research04 / 10
Immerse NYC 2026
02
Section Two

Who Is Being
Targeted — and Why

12 months of Cloudflare Radar data on the industries and geographies bearing the heaviest DDoS attack load.

radar.cloudflare.com05 / 10
Immerse NYC 2026
Section 02 — Industry Targeting

IT & Telecom Absorb 72% of All Attack Volume

By attack byte volume over the past 12 months (Apr 2025–Mar 2026). Two sectors dominate — but every industry in this room has skin in the game.

01IT & Technology Services
37.3%
02Telecommunications
35.2%
03Gambling & Casinos
7.0%
04Internet
6.3%
05Information Services
5.9%
06Gaming
2.8%
07Computer Software
1.8%
08Financial Services
1.1%
Why Telecom Is #2

Carriers own massive IP blocks and act as both targets and unwilling attack infrastructure. Their networks are simultaneously victimized and weaponized.

DDoS Attack Volume Share by Industry — 52 Weeks · Apr 2025–Mar 2026 (Source: Cloudflare Radar)
The Extortion Play

Gambling, Gaming, and real-time platforms are targeted because every minute of downtime is immediately measurable in lost revenue. Attackers know exactly what the pain is worth.

Cloudflare Radar · /radar/attacks/layer3/top/industry · Apr 2025–Mar 2026 · by bytes06 / 10
Immerse NYC 2026
Section 02 — Geographic Targeting

85% of Attack Volume Hits Three Countries

China, the US, and Hong Kong collectively absorbed 85% of all L3/L4 DDoS attack bytes over the past 12 months — but every global enterprise with IP infrastructure is exposed.

🇨🇳China
41.9%
🇺🇸United States
24.2%
🇭🇰Hong Kong
19.2%
🇧🇷Brazil
6.6%
🇩🇪Germany
3.0%
🇬🇧United Kingdom
0.8%
🇰🇷South Korea
0.7%
🇮🇳India
0.6%
Attack Volume by Target Country — Top 8 · Apr 2025–Mar 2026 (Source: Cloudflare Radar)
The Global Enterprise Reality

If your organization has infrastructure in APAC, the Americas, or Europe — you are in a high-risk geography. Distributing your infrastructure does not distribute your risk. It multiplies your attack surface.

Cloudflare Radar · /radar/attacks/layer3/top/locations/target · Apr 2025–Mar 2026 · by bytes07 / 10
Immerse NYC 2026
03
Section Three

Why Legacy Tools
Can't Win This Fight

On-premise hardware was built for a threat landscape that no longer exists. Here is exactly why — and what you need instead.

radar.cloudflare.com08 / 10
Immerse NYC 2026
Section 03 — The Architecture Problem

Hardware Has Three Unsolvable Problems

01

The ISP Choke Point — Hardware Loses Before It Starts

Your appliance sits downstream of your ISP link. A volumetric attack saturates that link first. Your hardware never fires a packet. The network is offline before the defense activates.

02

The Capacity Ceiling — You Can't Buy Enough Hardware

Top enterprise appliance: ~25 Gbps. Largest observed attack: 7,300 Gbps. To match that with hardware you need 292 appliances — at every location you operate. The math doesn't work.

03

The Refresh Trap — Manual Patching, Forced Upgrades

Threat intelligence updates require manual patching. Hardware refreshes happen every 3–5 years. Every upgrade window is a window of exposure. The threat actors don't take a maintenance window.

The Magic Transit Difference

Magic Transit moves the defensive perimeter from your data center to Cloudflare's global edge — 405+ Tbps of scrubbing capacity across 330+ cities. Attacks are absorbed upstream of your ISP link. Clean traffic reaches you. Always on. Zero hardware. Predictable OpEx.

Capability Hardware Appliance Magic Transit
Max DDoS Capacity~25 Gbps405+ Tbps
Upstream of ISP Link✗ No✓ Yes — global edge
Protection ActivationManualAlways-on, automatic
Detection SpeedMinutes<3 seconds
Threat IntelligenceManual patchingReal-time, automatic
High AvailabilityBuy 2× hardwareBuilt-in anycast
Latency ImpactNegative (bottleneck)None to negative
Firewall / IDSSeparate applianceMagic Firewall built-in
Zero Trust Integration✗ Separate stack✓ Native CF One
Cost ModelHigh CapEx + OpExPredictable OpEx
Refresh CycleEvery 3–5 yearsNever — cloud-native
Cloudflare Magic Transit · developers.cloudflare.com/magic-transit09 / 10
Immerse NYC 2026
Section 03 — The Path Forward

The Network Is the Business.
Protect It at Cloudflare Scale.

Three Things to Take Away

1. Attack volumes are at record highs and accelerating. Q1 2026 produced the highest attack week of the past 12 months. This is not a temporary spike — it is the new baseline.

2. Your industry is in the bullseye. IT, Telecom, Gambling, Gaming, and Financial Services together absorbed 89% of all attack volume over the past year.

3. The architecture has to change. Hardware appliances were designed for a threat landscape that no longer exists. The ISP choke point problem alone makes on-premise defense structurally insufficient at modern attack scales.

What Magic Transit Gives You

405+ Tbps of always-on DDoS protection, upstream of your ISP link, across 330+ cities — with Magic Firewall deep packet filtering and IDS built in. No hardware to buy, patch, or refresh. One subscription. Your entire network, protected at Cloudflare scale.

405+Tbps
Global network scrubbing capacity
330+
Cities where attacks are stopped at the edge
<3s
Median time to detect and mitigate new attack vectors
01

Get a Custom Threat Brief

We'll show you exactly what Cloudflare can see about your network's attack surface, IP space, and ASN exposure — right now, before you buy anything.

02

Run a Proof of Concept

We can have clean traffic flowing to your data center quickly, in parallel with your existing infrastructure — no forklift migration required.

03

Talk to Your Account Team Today

Magic Transit is Enterprise-only. Your Cloudflare account team is here at Immerse. Find them today or visit cloudflare.com/magic-transit to get started.

cloudflare.com/magic-transit · Enterprise only · Data: Cloudflare Radar Apr 2025–Mar 202610 / 10
Speaker Notes