Some useless information (for many, I'm sure)...
I see that Taylor Otwell (Laravel creator) has said that
he is going to move everything over to Digital Ocean.
DigitalOcean dont do DDOS mitigation, they will null the IP getting DDOS'd and if it continues they will after some effort move you to a new IP after some time has passed, and if it continues they will Null the new IP, give you a IP to move your data off and be done with you. This is from experience. We have been the target of DDOS attacks in the past.
As with many web hosting companies, CPANEL is used to host the websites. Cpanel has NO clustering service other than DNS.
Cpanel have feature requests to introduce redundant failover of all hosting services, being Apache, FTP, Email and Mysql, but this is far from ready. This is why its hard on hosting companies to be resilient against DDOS attacks.
Proper DDOS hardened hosting is expensive, customers who want to pay the lowest possible price expect 100% uptime with the best service. The very great hosting companies will give you the very best service at any price you pay for it, but DDOS protection is not something you can contend with. I have personally been to Afrihost during a DDOS attack on one of our servers, which they turned off (not even Nulled, they pulled the plug) and you know what they told me ? "The only thing you can do during a DDOS attack is to hide, you have to take the target offline and wait for the attack to stop". Which is true when you have zero DDOS migitation hardware in place and no experienced engineers with DDOS hardware skills to deal with these things. Case and point, I know of very few DDOS hardened data centers in the world. Blacklotus and Limestone to name two of the largest. OVH also comes to mind.
Now someone is going to ask "what on earth are you hosting that irritated someone enough to be DDOSed", the answer is simple. Anything from a Church website that posted a blog about Muhammad , to a competitive B&B who wants to keep your website down over easter weekend can order a DDOS online, there are cheap services online you can use to get a server switched off or nulled in South Africa. (which I wont mention here)
None of the information I posted here is thumb sucking, sadly this is from experience.
I quote here words from a network security tech that works for us, "A online security company can never state that its unhackable, as that only invites hackers to prove you wrong. You can only make the effort as much as possible and hope to make it more effort than the hack is worth"
Customers who have data that needs to be online all the time, should host at several different companies, use CDN, use DNS failover in the event a site goes down, and look at using cron jobs to make sure all the sites you host at contains the most recent data possible.
The larger the site the more likely it is that you will have dataloss. Its a bit of a migraine but with good planning your website will remain online during a DDOS attack. Hosting at several places at once means you factor out server failure, IP being targeted by a DDOS attack, even Cloudflare going down (and yes, I can tell you from experience that even CloudFlare doesnt have 100% up time)
Its a jungle out there, keep safe.
Happy new year to everyone !