NETSCOUT is doubling the mitigation capacity of its Arbor Cloud distributed denial-of-service protection service to 33 Tbps, citing larger and more complex attacks against internet-facing infrastructure.
The expansion covers 16 traffic-scrubbing centres worldwide and is expected to be completed by the end of August 2026. NETSCOUT said the added capacity is intended to protect digital services that increasingly support monitoring, maintenance, remote access, and operational data exchange across connected infrastructure.
Those services often sit between enterprise IT and operational technology environments. Disruption at that layer can affect access to systems used to oversee assets and coordinate industrial processes, even when controllers and other operational equipment are not directly targeted.
The company is also integrating DDoS infrastructure acquired in a recent transaction. NETSCOUT said the move gives it direct control over the network used to deliver and expand its mitigation services.
Combining local and cloud defence
Arbor Cloud connects on-premises DDoS systems with cloud-based traffic-scrubbing services. Automated signalling between the two environments allows some attacks to be handled close to customer infrastructure, while high-volume traffic can be redirected to the cloud network.
On-premises controls can detect and block malicious traffic near an operator’s environment, but they cannot maintain availability once an upstream internet connection is saturated. Cloud and service-provider mitigation filters traffic before it reaches the customer network.
The UK National Cyber Security Centre said determined attackers can usually generate more traffic than individual organisations can handle without upstream support.
This division of responsibility is relevant to utilities, transport operators, and industrial IoT deployments that rely on both local operational systems and externally connected services. On-premises controls provide visibility close to the affected environment, while cloud mitigation supplies the capacity needed to absorb large volumetric attacks.
The hybrid model protects internet-facing and supporting services, but it does not replace segmentation, access controls, endpoint security, or monitoring within operational technology environments.
IT outages can reach operations
Internet-facing and enterprise services support remote monitoring, predictive maintenance, vendor access, equipment telemetry, and the management of assets across multiple locations. These services can sit outside the control network while remaining part of operational workflows.
CISA and its international partners said in guidance published in January 2026 that OT networks are becoming more interconnected to support real-time analytics, remote monitoring, and predictive maintenance. The agencies warned that insecure connectivity can expose operators to intrusions capable of disrupting essential services or causing physical and environmental harm.
IT/OT convergence does not require industrial controllers to be directly exposed to the public internet. Operational data can pass through gateways and segmented enterprise systems before reaching cloud platforms or other external applications.
DDoS attacks overwhelm network links, systems, or applications with malicious traffic, preventing legitimate users and connected services from accessing them. CISA groups these attacks into volumetric, protocol, and application-layer activity, based on the resources being targeted.
An attack does not need to alter machinery or controller logic to affect operations. Disruption to monitoring, identity, scheduling, remote-access, or maintenance systems can reduce equipment visibility, delay work, or force staff to rely on manual procedures.
In a connected industrial environment, the loss of an IT service can therefore create an operational problem without becoming a direct attack on OT equipment. A utility can lose access to remote asset data, a transport operator can experience disruption to fleet or information systems, and an industrial site can lose access to cloud-based telemetry or vendor support tools.
The UK NCSC identifies network connectivity, computing capacity, and storage as resources that denial-of-service attacks can exhaust. Its guidance also notes that such attacks can affect industrial control systems supporting critical processes.
The operational impact depends on the affected service and the availability of alternative systems. Loss of a supporting application does not automatically stop a physical process, but it can remove functions used to oversee, maintain, or coordinate operations.
NETSCOUT said multi-vector attacks, which combine several attack methods, are now common. Attackers are also using short bursts and simultaneous campaigns against multiple systems, reducing the time available for defenders to identify and contain malicious traffic.
Carpet-bombing attacks distribute traffic across numerous IP addresses or services rather than concentrating it on a single target. This can create substantial aggregate load even when the traffic reaching each destination appears comparatively low.
IoT botnets raise attack capacity
Botnets built from compromised connected devices are contributing to the scale of these attacks. NETSCOUT cited Aisuru and Kimwolf as examples associated with attacks approaching or exceeding 30 Tbps.
Cloudflare separately attributed a series of high-volume attacks in late 2025 to the Aisuru-Kimwolf botnet. The company estimated that the botnet contained between one million and four million infected devices, primarily Android televisions.
Cloudflare said the December campaign included HTTP attacks exceeding 200 million requests per second. It had recorded a 31.4 Tbps network-layer attack associated with the same broader botnet activity several weeks earlier.
The company said the 31.4 Tbps attack lasted 35 seconds and was detected and mitigated automatically. Its figures reflect activity observed on Cloudflare’s own network, but provide an independent reference point for the attack volumes cited by NETSCOUT.
Connected devices with weak credentials, exposed management interfaces, or unpatched software can be recruited into botnets and used to generate traffic without their owners’ knowledge. Compromised devices that remain online can continue generating attack traffic until they are disconnected, cleaned, or prevented from communicating with the botnet.
IoT botnets distribute traffic across residential, enterprise, and service-provider networks rather than relying on a small number of sources. Their distribution across different networks also makes them harder to address through simple source-based blocking.
The scale of these botnets changes the capacity requirements for organisations protecting connected infrastructure. Large numbers of compromised devices can generate short, high-volume bursts that exceed the bandwidth available to individual operators before local controls can respond.
Utilities, transport operators, and other essential-service providers increasingly connect operational environments to systems used for monitoring, maintenance, and data access, according to the joint guidance published by CISA and its international partners.
Industrial IoT deployments can depend on device gateways, telemetry platforms, and cloud management services. Hybrid DDoS protection can help maintain access to those external services, while segmentation, access controls, and monitoring protect devices, control systems, and operational networks.
ENISA said hacktivist activity in its 2025 EU threat dataset was mainly driven by low-impact DDoS campaigns, with only 2% of the recorded incidents leading to service disruption. Most of the campaigns in that dataset therefore did not produce a reported service interruption.
NETSCOUT said the expanded platform will support simultaneous attacks across multiple targets and attack vectors. The company expects the capacity increase to be completed by the end of August 2026.
(Photo by Alexander Gluschenko)
See also: AI adoption in OT security outpaces governance controls

Want to learn more about the IoT from industry leaders? Check out IoT Tech Expo taking place in Amsterdam, California, and London. The comprehensive event is part of TechEx and is co-located with other leading technology events including AI & Big Data Expo and the Cyber Security Expo. Click here for more information.
IoT News is powered by TechForge Media. Explore other upcoming enterprise technology events and webinars here.
