• Services
  • Support

What Norway’s DDoS Attack Reveals About Availability

Table of Contents

Summary

A DDoS attack on Norway’s shared government digital infrastructure, affecting services from Digdir and Vivicta between August 24-26, disrupted public logins, digital mail, and data exchange services without breaching any systems or compromising personal data. The incident illustrates why availability, not just data protection, is a core part of cybersecurity, and why organizations need layered, automated DDoS defenses to maintain business continuity during an attack.

A significant DDoS attack against Norway’s shared government digital infrastructure is a timely reminder that cybersecurity is not only about protecting data. It is also about protecting availability, continuity and trust.

Beginning on 24 August, the attack affected infrastructure supporting services operated by Norway’s Digitalisation Agency, Digdir, and its operational provider, Vivicta.

Public-service logins, electronic identities, secure digital mail, government forms and data exchange services were among those affected. Some were completely unavailable for short periods, while others experienced slower response times and login problems.

Digdir reported that the attack stopped on 26 August. Except for short periods, its shared services remained available throughout, demonstrating both the seriousness of the attack and the value of effective resilience measures.

Importantly, Digdir found no indication that systems had been breached or personal data compromised.

That distinction matters.

An Attack Doesn’t Need to Steal Data to Cause Damage

Cybersecurity discussions often focus on breaches, ransomware, stolen credentials and exposed records.

Those threats remain critical, but availability is equally important.

If citizens cannot access public services, customers cannot complete transactions or employees cannot reach critical applications, the consequences are immediate. Revenue can stop, service commitments can be missed, operations can be disrupted and trust can quickly erode.

For governments and critical infrastructure providers, the implications extend further. Availability directly affects essential services and citizens’ ability to interact with the state.

The Norway incident also highlights the risks created by shared digital infrastructure. Disruption affecting one provider or platform can quickly reach many dependent organisations and services.

DDoS Is a Business Continuity Issue

DDoS is often treated primarily as a network-security problem.

But when an attack prevents people from accessing essential services, it becomes a business-continuity problem and potentially a matter of national resilience.

Organisations should therefore ask two fundamental questions:

  1. Can an attacker make our services unavailable?
  2. If so, how quickly can we detect and mitigate the attack?

Speed matters. The longer an attack remains visible to users, the greater the operational, financial and reputational impact.

Resilience Requires a Layered Defense

Cloud-based scrubbing provides essential capacity when an attack threatens to overwhelm available bandwidth. But capacity alone does not address every scenario.

Smaller, shorter-duration and more targeted attacks can disrupt applications before traffic diversion is completed. Protecting against both ends of the threat spectrum requires a layered approach combining:

  • Automated detection and mitigation close to the protected infrastructure
  • Additional capacity for attacks that could saturate network links
  • Visibility before, during and after an incident
  • Minimal dependence on manual intervention
  • Continued access for legitimate users during an attack

A layered approach provides a strong foundation for service availability: attacks can be detected and mitigated close to the protected infrastructure within seconds, while cloud-based scrubbing provides additional capacity when traffic threatens to overwhelm upstream connectivity. Corero is designed to provide the real-time mitigation layer within this type of hybrid architecture.

Availability Is Part of Cybersecurity

The lesson from Norway is straightforward: an organisation cannot claim to be resilient solely because its data remains secure. Its services must remain available too.

DDoS protection therefore belongs within business-continuity and resilience planning, not at the edge of the cybersecurity conversation.

Because the ultimate objective is not simply to protect the network.

It is to keep the business and the services people depend on running.

Picture of Sean Newman

Sean Newman

Vice President, Product Management

FAQ

What happened in the Norway DDoS attack?

Beginning on August 24, a DDoS attack affected infrastructure supporting services operated by Norway’s Digitalisation Agency, Digdir, and its operational provider, Vivicta. Public-service logins, electronic identities, secure digital mail, government forms, and data exchange services were affected, with some completely unavailable for short periods and others experiencing slower response times and login problems.

Was any data breached during the attack?

No. Digdir found no indication that systems had been breached or personal data compromised. The attack disrupted availability rather than confidentiality.

How long did the Norway DDoS attack last?

Digdir reported that the attack stopped on August 26. Except for short periods, its shared services remained available throughout the incident.

Why does availability matter as much as data protection in cybersecurity?

If citizens cannot access public services, customers cannot complete transactions, or employees cannot reach critical applications, the consequences are immediate: revenue can stop, service commitments can be missed, operations can be disrupted, and trust can quickly erode. For governments and critical infrastructure providers, availability directly affects essential services and citizens’ ability to interact with the state.

What does a layered approach to DDoS protection look like?

A layered approach combines automated detection and mitigation close to the protected infrastructure, additional capacity for attacks that could saturate network links, visibility before, during, and after an incident, minimal dependence on manual intervention, and continued access for legitimate users during an attack.

Share the Post: