**NETSCOUT Expands DDoS Mitigation Capacity to 33 Tbps to Counter Increasingly Sophisticated Attacks**
In response to a surge in large and complex distributed denial-of-service (DDoS) attacks targeting internet-facing infrastructure, NETSCOUT is significantly enhancing its defensive capabilities. The company is doubling the mitigation capacity of its Arbor Cloud DDoS protection service to 33 Tbps (terabits per second). This expansion, which involves 16 global traffic-scrubbing centers, is scheduled for completion by the end of August 2026. The initiative is designed to safeguard critical digital services that support monitoring, maintenance, remote access, and operational data exchange across increasingly interconnected infrastructure.
These services often occupy a crucial space between enterprise IT systems and operational technology (OT) environments. Disruptions at this layer can have cascading effects, impacting access to systems used for asset oversight and industrial process coordination, even if the controllers themselves are not the direct target of an attack.
**Combining On-Premises and Cloud-Based Defenses**
A key component of NETSCOUT’s strategy is the integration of DDoS infrastructure acquired through a recent transaction, granting the company direct control over the delivery network for its mitigation services. This move reinforces the hybrid model employed by Arbor Cloud, which connects on-premises DDoS defense systems with cloud-based traffic-scrubbing services.
Automated signaling between these environments allows for intelligent traffic handling. Some attacks can be mitigated locally, close to the customer’s infrastructure, while high-volume threats are redirected to the cloud network. While on-premises controls offer visibility and can block malicious traffic near the source, they are ultimately unable to withstand saturation of upstream internet connections. Cloud-based mitigation addresses this by filtering harmful traffic before it reaches the customer’s network.
The UK National Cyber Security Centre (NCSC) has echoed this approach, noting that determined attackers can typically generate more traffic than a single organization can handle independently. This shared responsibility model is particularly relevant for utilities, transport operators, and industrial IoT deployments that rely on a blend of local operational systems and external services.
**The Expanding Threat Landscape**
The rise in DDoS activity is closely linked to the growing adoption of Internet of Things (IoT) devices. Botnets composed of compromised connected devices—such as Aisuru and Kimwolf—are increasingly being cited in attacks nearing or exceeding 30 Tbps. Cloudflare, for instance, has traced high-volume campaigns in late 2025 to the Aisuru-Kimwolf botnet, which is believed to comprise between one million and four million infected devices, primarily Android televisions.
In one notable incident, the botnet was used to launch HTTP attacks exceeding 200 million requests per second, alongside a 31.4 Tbps network-layer attack. These events highlight how compromised devices with weak credentials, exposed management interfaces, or unpatched software can be weaponized into vast, distributed networks that generate traffic from residential, enterprise, and service-provider networks globally.
For organizations running industrial environments, the consequences of these attacks extend beyond simple connectivity issues. DDoS campaigns can disrupt monitoring, identity management, scheduling, remote access, and maintenance systems—critical functions that support operational oversight and coordination.
**Conclusion**
NETSCOUT’s expansion to 33 Tbps represents a significant escalation in the industry’s response to modern DDoS threats. As attacks grow in volume and complexity—often fueled by vast IoT botnets—organizations must adopt multi-layered defenses that combine on-premises visibility with cloud-scale mitigation capacity. The transition to this enhanced capability by the end of August 2026 will strengthen resilience for enterprises and essential service providers safeguarding critical infrastructure.
### FAQ
**What is Arbor Cloud?**
Arbor Cloud is a DDoS protection service that combines on-premises detection and mitigation systems with cloud-based traffic scrubbing. It automatically routes traffic based on the type and volume of attack, ensuring both visibility and scale.
**Why is NETSCOUT expanding its mitigation capacity?**
The expansion is a response to increasingly large and complex DDoS attacks targeting internet-facing infrastructure. The 33 Tbps capacity is designed to absorb volumetric attacks that exceed the capabilities of individual organizations.
**What are hybrid DDoS defenses?**
Hybrid defenses refer to the integration of local, on-premises controls with cloud-based mitigation services. This allows organizations to stop attacks close to their source when possible and redirect high-volume traffic to the cloud for filtering.
**Which industries are most at risk from DDoS attacks?**
Utilities, transport operators, industrial IoT deployments, and other essential service providers are particularly vulnerable because they rely on interconnected IT and operational technology systems.
**How do IoT botnets contribute to DDoS threats?**
Botnets composed of compromised IoT devices can generate massive volumes of traffic from distributed sources. Their scale and distribution make them difficult to mitigate using traditional, source-based blocking methods.
### Conclusion
As DDoS attacks continue to grow in scale and sophistication, the need for robust, multi-layered mitigation strategies has never been greater. NETSCOUT’s doubling of Arbor Cloud’s capacity to 33 Tbps by 2026 marks a critical step in defending internet-facing infrastructure against evolving threats. By leveraging a hybrid approach that combines local visibility with cloud-based resilience, organizations can better protect their digital services and the operational environments they support.



