Q1: What type of DDoS? There are many ...
Q2: How do you fight this when everybody want's cheaper, the resources to fight/mitigate costs money?
Q3: How do you stop people running to cheaper (with lesser protection) if all the nice to mitigate most DDoSs stuff is implemented.
Q4: Why does a user have to pay when it's somebody else's attitude of CCAF about securing his DNS servers, it's not hurting him?
The tech is there, but it's not cheap.
/not associated with CI nor their client. But they have my sympathy.