The other pattern for the past week is orgs with on prem systems, either just directly internet exposed or - more likely - behind BIG-IP.
Having a big link and DDoS scrubbing doesn't work on prem if you allow inbound web requests unfiltered - NoName just send valid HTTP requests from 20k systems at the same time 24/7 to search pages.
Orgs need cloud WAFs.
Another thought - somebody like the NCSC needs to provide a managed, central WAF service to councils. They can't deal with this stuff.