This article is part of our Opinions section, where we invite industry professionals to share their views on the most pressing technology questions of our time.
Why rising internet baselines are changing how we think about DDoS, capacity and resilience
Every World Cup generates predictions of record-breaking Internet traffic. This yearโs tournament has been no different. Yet as operators prepare for another surge in demand, I find myself wondering whether we are looking at the phenomenon the wrong way. The interesting question may no longer be how high the peaks are becoming, but whether off-peak traffic still exists at all.
Record traffic is no longer news
The World Cup remains one of the largest events on the global digital calendar. Streaming providers prepare for record audiences. Online gaming and entertainment platforms brace for increased demand. Network operators revisit capacity plans and ensure critical infrastructure is ready for the inevitable surge.
In conversations with operators supporting online entertainment and gaming platforms, Iโve been surprised by how early some of these traffic surges are appearing. Several have already reported legitimate traffic levels reaching three to five times their normal baseline during the group stages alone. Not the knockout rounds. Not the semi-finals. Not the final. The group stages.
A decade ago, numbers like that would have immediately triggered discussions about whether infrastructure could cope. Today, most mature operators know how to buy more bandwidth. They know how to add capacity. They know how to scale. None of this is new. While nobody has infinite resources, capacity itself is often not the most interesting part of the conversation anymore.
What caught my attention was something else. If operators are already seeing traffic levels several times above normal before the tournament has even reached its later stages, what does that tell us about the state of Internet demand today?
When peak traffic was actually peak traffic
For much of the Internetโs history, traffic followed relatively predictable patterns. Networks experienced busy periods and quiet periods. There were clear distinctions between weekdays and weekends, business hours and after-hours usage, ordinary days and extraordinary events.
Capacity planning reflected this reality. Operators studied traffic patterns, identified peak periods, and designed infrastructure accordingly. Major events such as the World Cup, the Olympics, Black Friday, or New Yearโs Eve stood out because they created obvious spikes above normal operating conditions.
The relationship between baseline traffic and peak traffic was clear. Most of the time, networks operated comfortably below their maximum capacity. Peaks were temporary events that required preparation but were relatively easy to identify.
Traffic behaved much like roads. There were rush hours, and there were quiet stretches in between.
The internet no longer sleeps
Over the past two decades, that model has steadily eroded.
Streaming platforms operate around the clock. Online gaming has evolved from a niche activity into mainstream entertainment consumed by hundreds of millions of users worldwide. Social media platforms generate constant engagement across every time zone. Live commerce, esports tournaments, influencer broadcasts, video streaming and cloud applications create a continuous stream of demand that rarely subsides.
When Asia winds down, Europe begins its day. When Europe signs off, North America takes over. At any given moment, somewhere in the world millions of users are watching content, participating in online games, engaging with social platforms, consuming digital services, or interacting with cloud applications.
The Internet no longer experiences the kind of downtime it once did. More importantly, neither does demand.
What was once considered peak behaviour has quietly become part of everyday life.
The disappearing traffic valley
This is where the World Cup observation becomes particularly interesting.
The World Cup is still capable of generating enormous traffic spikes. Nobody is suggesting otherwise. What has changed is the relationship between those spikes and the baseline beneath them.
Historically, network traffic resembled a mountain range. Peaks stood clearly above deep valleys. Major events were easy to identify because they towered over ordinary demand.
Today, the mountains remain, but the valleys are gradually disappearing.
Streaming, gaming, social media, cloud applications and always-connected mobile devices have steadily raised the baseline. Major events still push traffic higher, but the difference between an ordinary day and an extraordinary day is becoming less dramatic than it once was.
Peak traffic still exists. What is disappearing is the contrast.
Why this matters for DDoS and resilience
This shift has implications that extend beyond capacity planning.
Traditionally, abnormal traffic was easier to identify because it stood apart from the baseline. Large spikes often drew immediate attention. Whether the cause was a flash crowd, a major event, or a DDoS attack, unusual activity was easier to spot when normal traffic levels were comparatively low.
As baselines rise, the problem becomes more complicated.
Security teams, network operators and service providers increasingly find themselves operating in environments where high traffic volumes are no longer unusual. During major events, legitimate demand can rise dramatically within a short period of time. Distinguishing between genuine user activity, automated traffic, malicious activity and attack traffic becomes more difficult when all of them are occurring against an already elevated baseline.
Having enough capacity still matters. The difference is that capacity alone no longer tells you very much about what is happening on your network. A sudden surge could be millions of football fans tuning in to watch a match. It could be a successful marketing campaign. It could be a bot-driven scraping operation. It could be a DDoS attack. Increasingly, it may be a combination of all of them.
The challenge is no longer simply surviving large traffic volumes. It is understanding them.
This is also changing how operators think about growth. Traditional capacity planning focused heavily on preparing for occasional surges. Today, many operators are planning for sustained levels of demand that would once have been considered exceptional. The question is gradually shifting from โCan we survive the next peak?โ to โWhat should we consider normal?โ
That distinction may seem subtle, but it fundamentally changes how infrastructure is designed, monitored and protected.
The new traffic problem
Viewed through this lens, the World Cup serves as more than just a sporting event. It acts as a reminder of how profoundly the Internet has evolved.
The fact that operators can absorb traffic increases of several times their normal baseline during the early stages of a global tournament is a testament to decades of investment in networks, cloud platforms and infrastructure. Yet that is not what stood out to me this year.
What stood out was how high the baseline has already become before we have even reached the knockout stages.
Peak traffic has not disappeared, nor is it likely to. The World Cup reminds us of that every four years. What appears to be fading is the notion of a true off-peak period. Streaming, gaming, social media, cloud services and now AI are all contributing to a world where demand continues to accumulate rather than replace what came before.
For network operators, service providers and security teams, the next challenge may not be preparing for the next big peak. It may be adapting to a world where normal increasingly looks like what we once considered peak.
Read our latest interviews