TMT
A distributed denial of service (DDoS) attack is a cyberattack designed to make a website, online service or network unavailable by flooding it with malicious traffic from multiple sources. Unlike a denial-of-service (DoS) attack from a single source, DDoS attacks use numerous devices (often harnessing tens to hundreds of thousands of attacking systems) to overwhelm targets with traffic volumes that the connecting infrastructure and systems cannot handle. When successful, these attacks prevent genuine users from accessing internet-based services, causing business disruption and potential financial losses.
Attackers typically use exploitable systems – legitimate internet services that can be tricked into participating, or botnets (networks of infected computers, IoT devices and servers) to generate attack traffic. In the case of botnets, these ‘zombie’ devices are compromised without their owners’ knowledge through malware infections. The attacker controls these devices remotely, instructing them to simultaneously send requests to a target or victim. The ensuing volume of traffic overwhelms the target’s resources, or connection to the target, causing service degradation or complete failure.
DDoS attacks can be categorised based on which open system interconnection (OSI) network layer they target:
Layer 3/4 (network/transport) attacks target network infrastructure by exhausting bandwidth or connection capabilities. For example:
Layer 7 (application) attacks target web applications and are typically more sophisticated.
The scale and frequency of DDoS attacks have increased dramatically in recent years. According to industry data, attacks doubled between 2022 and 2024, with some estimates suggesting global attacks exceeded 100m in 2024 alone. This growth is driven by:
Exhibit 1: Number of DDoS attacks worldwide from Q123–Q424
![]() |
Source: Statista
While any online service can be targeted, certain sectors face higher risks:
Attacks are often motivated by financial extortion, political activism, competitive disruption or simply as diversionary tactics for more sophisticated breaches. Recent changes to the geopolitical landscape have resulted in a marked increase in state-sponsored attacks, which typically target critical IT infrastructure to maximise broader social and economic impact.
Cloud DDoS protection typically uses so-called scrubbing services:
While effective, this approach has limitations:
Exhibit 2: Leading DDoS protection providers

Source: Edison Investment Research
Modern DDoS protection uses more sophisticated techniques:
The most effective defences combine multiple approaches in a layered security strategy, with solutions that can adapt to evolving attack methods.
As organisations increasingly rely on online services, DDoS protection has become a critical component of cybersecurity strategy. The impact of successful attacks extends beyond immediate service disruption to include:
With attack volumes increasing rapidly in recent years, for example up by more than 50% in 2024, organisations must ensure their DDoS mitigation capabilities evolve to match the growing threat landscape.
Industrials | thematic
Consumer | thematic
thematic
Industrials | thematic
Consumer | thematic
thematic
Financials
O Banco Angolano de Investimentos S.A. (BAI) é o maior banco angolano em termos de activos. Trata-se de um banco de centro monetário, centrado em instituições, com elevadas receitas de investimento e de transacções, financiadas por uma base de depósitos diversificada. A sua forte base de capital e solvência posicionam-no para o crescimento numa retoma económica angolana. O baixo rácio de empréstimos e depósitos do BAI oferece a possibilidade de aumentar a rendibilidade dos activos e dos capitais próprios. O crédito começou a ser concedido mais fortemente durante o ano de 2024, uma tendência que se manteve no 1.º sem. de 2025.