AI DDoS Attack Post-Mortem and Hardening Plan Playbook
An e-commerce company experienced a 6-hour DDoS attack during peak shopping season, resulting in $2.3M in lost revenue. The attack peaked at 840Gbps. CDN and WAF mitigations partially worked but failed after 90 minutes. The board wants a post-mortem and a hardening plan before the next peak season.
When to use this playbook
- Use this playbook when the decision looks like the situation above: An e-commerce company experienced a 6-hour DDoS attack during peak shopping season, resulting in $2.3M in lost revenue.
- It is a fit when you have source files in hand and need a structured, reviewable analysis — not a generic chat answer about "DDoS Attack Post-Mortem and Hardening Plan".
- Do not use it as a substitute for licensed, legal, clinical, or authorized official judgment in the domain.
What you'll need
- CDN and WAF traffic logs during the 6-hour attack window
- Origin server performance metrics during the attack
- Mitigation activation timeline (what was triggered, when, by whom)
- Vendor (CDN provider) post-incident report
- Revenue loss estimate by hour and product category
Attachments: Documents (Documents)
The Prompt
You are a cybersecurity architect conducting a DDoS post-mortem and building a hardening plan for an e-commerce company. I am attaching: Work only from the attached source files. If a conclusion is not supported, say so. Produce: 1. Reconstruct the attack: vector (volumetric, protocol, application layer), peak traffic profile, and geographic distribution of attack sources. 2. Identify the specific point at which CDN/WAF mitigation failed: what traffic patterns saturated the mitigation capacity? 3. Assess the origin server exposure: was it directly reachable once the CDN mitigation failed, and was the origin IP exposed? 4. Calculate the cost of the attack (direct revenue loss + incident response cost + reputational damage estimate) and the cost of prevention measures. 5. Build the hardening plan: specific controls, vendors, configurations, and the order of implementation to be ready before next peak season. Call out where independent models are likely to disagree, and list follow-up documents a reviewer should request.
What to expect
- Attack vector and timeline reconstruction
- Mitigation failure point analysis
- Origin server exposure assessment
- Attack cost vs. prevention cost comparison
- Prioritized hardening plan with implementation timeline
Review before you act
- Validate this output against source files before relying on it: Reconstruct the attack: vector (volumetric, protocol, application layer), peak traffic profile, and geographic distribution of attack sources.
- Validate this output against source files before relying on it: Identify the specific point at which CDN/WAF mitigation failed: what traffic patterns saturated the mitigation capacity?.
- Validate this output against source files before relying on it: Assess the origin server exposure: was it directly reachable once the CDN mitigation failed, and was the origin IP exposed?.
- Validate this output against source files before relying on it: Calculate the cost of the attack (direct revenue loss + incident response cost + reputational damage estimate) and the cost of prevention measures.
- Confirm every cited figure, date, counterparty, or requirement against the attached originals — models compress and can drop a qualifier.
- Treat disagreement between models as a review item, especially on classification, materiality, and recommended next action.
- Do not authorize an operational, clinical, legal, credit, or enforcement action solely because the models agree.
Why compare models on this
For DDoS Attack Post-Mortem and Hardening Plan, running the same attachments across independent models is useful because the hard part is classification and completeness, not fluency. The workflow is already designed to surface attack vector and timeline reconstruction; mitigation failure point analysis; origin server exposure assessment; attack cost vs. prevention cost comparison. Those are comparison artifacts — they only exist if more than one model runs. Models disagree on blast radius, attribution confidence, and whether a vendor finding is theoretical or exploitable. Those disagreements mark where an analyst should slow down.
Related playbooks
See governed multi-model AI on your own prompt
Compare GPT-5, Claude, and Gemini side by side, with human review and a decision record built in.

