Back to Glossary

Entry · Business

Denial Service Attack Dos

A denial of service attack is a deliberate attempt to make a website, payment system or network unusable by flooding it with more traffic or requests than it can handle. Genuine customers and staff are then unable to log in, pay or place orders.

For businesses it is both a security risk and a direct financial risk.

From the Money Master HQ dictionary, founded by Shihan Sheriff (FCMA, VP of Finance at Nomod, CFO at Esanjo Ventures). How these definitions are written.

What it means

In a normal day, a company's servers answer thousands of small requests from real users. In a DoS attack, an attacker sends an overwhelming volume of junk requests, or requests designed to use up memory and processing power, until the system slows to a crawl or stops.

The attacker does not need to steal anything for the damage to be real. A common variant is the distributed denial of service attack, or DDoS, where the flood comes from thousands of hijacked computers at once.

This makes it much harder to block because the traffic appears to come from many different places. Attackers sometimes demand a payment to stop, which is a form of extortion.

For finance professionals, the cost shows up in several places. Lost sales during the outage, staff time spent on recovery, emergency fees for security specialists and possible service credits owed to customers all hit the profit and loss account.

Reputation damage can also reduce future revenue, although that is harder to measure. Businesses manage the risk through protective services that filter traffic, spare network capacity, response plans and cyber insurance.

Finance leaders are often asked to approve these budgets, so it helps to compare the cost of protection with the expected cost of downtime. Some insurance policies cover business interruption from cyber events, but the terms and waiting periods vary.

A key nuance is that DoS attacks are sometimes used as a smokescreen. While the technical team is busy restoring the website, attackers may try to break into other systems, so recovery plans should include checks on payment and data systems as well.

In practice

Real-world examples.

1

Example

An online ticketing company is hit by a flood of requests minutes after a popular concert goes on sale. Genuine fans cannot complete purchases for three hours, and the finance team estimates the lost sales and refunds as a six-figure cost.

2

Example

A small regional bank sees its online banking portal slow to a halt on a Monday morning. The bank activates its response plan, moves traffic through a filtering service and tells customers to use the mobile app and branches while it recovers.

3

Example

A software-as-a-service company with a monthly subscription model suffers a two-hour outage during a DDoS attack. Its contracts promise 99.9% availability, so the finance team calculates service credits owed to customers and accrues them in the month's accounts.

Formula

Calculation

Expected loss from downtime = Hours of outage x Revenue per hour x Share of revenue lost Suppose an online retailer earns $1,200,000 a month from its website, running every day of a 30-day month. Revenue per hour is $1,200,000 / (30 x 24) = $1,200,000 / 720 = $1,666.67 per hour. If an attack takes the site down for 9 hours and 90% of sales are lost with no later catch-up, the direct loss is 9 x $1,666.67 x 0.90 = $13,500. Adding $4,000 of emergency specialist fees brings the total cost of the incident to $17,500.

Case study

Seen in the real world.

Brightwater Supplies is a fictional online stationery business that takes about $40,000 in orders each week. In this illustrative story, a competitor-linked group floods its website with traffic on the Friday before a major back-to-school promotion.

The owner has no protection plan, so the site stays down for 14 hours and sales are lost. Afterwards the finance manager compares the roughly $9,000 in lost revenue with the $250 monthly cost of a traffic filtering service. The company signs up for the service the same week, adds a cyber insurance policy and writes a one-page response plan so the team knows who to call next time.

Watch out

Common mistakes.

  • Assuming only large companies are targeted. Small businesses are often easier targets because they have fewer defences.
  • Counting only lost sales as the cost. Recovery fees, staff time, customer credits and lost trust all add to the bill.
  • Assuming a standard insurance policy covers it. Many cyber and business interruption covers have exclusions, waiting periods or limits that need to be read carefully.

Questions

People also ask.

What is the difference between DoS and DDoS?

A DoS attack comes from one source, while a DDoS attack comes from many sources at once. The distributed version is harder to block and is more common in serious incidents.

Does a DoS attack mean data was stolen?

Not necessarily, since the aim is to disrupt service rather than take information. However, it can be used as a distraction, so security checks should follow any major outage.

Should a company pay if attackers demand money to stop?

Security advisers generally warn against paying because it does not guarantee the attack will end and may invite repeat demands. Businesses are better off using traffic filtering and calling their security provider and, where relevant, law enforcement.

Was this explanation helpful?

From the founder's library

Accounting Fundamentals: A Non-Finance Manager's Guide to Finance and Accounting, by Shihan Sheriff

Take it further with the book.

Build your financial confidence beyond this definition. Shihan's full-length guide, Accounting Fundamentals, takes the same plain-English approach and turns it into a complete, practical playbook for non-finance managers, business owners and students - with chapter-end quiz answers and presentation slides included.

US$2.24US$2.99

25% off with code MMHQ25, applied at checkout. Priced in USD - checkout may show the equivalent in your local currency.

View the book and save 25%
Last updated · October 8, 2026
Browse all terms →

Disclaimer

The information provided in this finance dictionary is for educational and informational purposes only. It should not be construed as financial, investment, legal, or tax advice. Always consult with a qualified professional before making any financial decisions. Money Master HQ makes no representations or warranties about the accuracy, completeness, or suitability of this information. Use of this content is at your own risk.