NETSCOUT will double the DDoS mitigation capacity of its Arbor Cloud to 33 terabits per second by the end of August 2026, a move designed to keep critical digital services online during increasingly large and AI-driven attacks. The expansion responds to a market where multi-vector assaults, carpet bombing, and mega-botnets like Aisuru and Kimwolf have pushed attack volumes near or past 30 Tbps, forcing operations teams to close response gaps fast.
What's driving the capacity push
The DDoS protection market continues to grow as attackers combine more vectors, launch simultaneous strikes, and execute quick hit-and-run raids. According to Markets and Markets, cloud adoption and attack sophistication are the main accelerants. NETSCOUT's investment adds 16 global scrubbing centers and fully owned infrastructure, giving the company end-to-end control over the mitigation pipeline. That control means faster scaling and fewer dependencies on third-party bandwidth alone.
"With the increased use of AI, threat actors are targeting organizations whose defenses are vulnerable to the new, more complex DDoS attacks designed to take down critical infrastructure," said Carlos Morales, SVP and general manager of Arbor Cloud. "As enterprises increasingly rely on AI-powered applications and cloud-native services, while at the same time, attack size and complexity continue to rise, implementing automated and proactive defenses for uninterrupted availability has become a business risk imperative."
How Arbor Cloud distributes defense
Rather than simply adding more bandwidth, Arbor Cloud ties global mitigation capacity to NETSCOUT's threat intelligence, drawn from visibility into live internet attack activity. The hybrid design combines on-premises defense with cloud scrubbing, using automated cloud signaling to stop attacks close to the source and absorb volumetric floods in the cloud. A 24x7 Security Operations Center staffed by NETSCOUT experts backs the service.
The increased capacity delivers several operational advantages:
- Intelligent mitigation - absorbs and blocks larger volumetric and multi-vector attacks without losing effectiveness.
- Multiple threat handling - manages concurrent targets, such as carpet bombing attacks, or multiple vectors at once.
- Consistent performance - prevents capacity from becoming a bottleneck as attack size and frequency climb.
- Faster stabilization - limits collateral damage that persists long after the actual attack subsides.
- Operational confidence - gives mission-critical sectors like financial services, hospitals, retail, and the public sector assurance that protection holds when legitimate traffic surges and cyberattacks hit simultaneously.
Why this matters for operations
Operations professionals bear the direct consequences of DDoS-induced downtime: revenue loss, degraded customer trust, and recovery fire drills that drain resources. The 33 Tbps capacity figure is not just a larger number-it means fewer scenarios where attack volume overwhelms the mitigation pipe. For teams managing always-on digital services, the hybrid architecture integrates with existing on-premises gear and cuts the time between detection and cloud scrubbing. That reduces the window where a service is exposed and shortens the post-attack stabilization period, a factor often overlooked until the first spike hits.
Your membership also unlocks: