

# Conclusion
<a name="conclusion"></a>

 DDoS resilience isn't a one-time project but an ongoing practice of applying the right architecture, services, and operational readiness before an attack occurs. Throughout this whitepaper, AWS outlined a DDoS-resilient reference architecture, explained how infrastructure layer and application layer attacks differ, and mapped the AWS services and best practices that mitigate each. Adopting these recommendations helps you protect application availability, preserve customer trust, and avoid the unnecessary scaling costs that attacks can drive. 

 The most important takeaway is also the most actionable: AWS Shield Response Team data shows that most customers who suffer business impact from DDoS attacks had not yet implemented the guidance in this paper. Review your applications against this guidance today, close the gaps where you find them, and treat DDoS resilience as a continuous part of your security posture, so that when an attack comes, your architecture is already prepared to absorb and mitigate it. 