How do you manage the risk of the system being taken offline maliciously, resulting in the service not being available or in the case of catastrophic failure?

The platform is hosted on auto scaling infrastructure which handles significant spikes in normal traffic usage patterns. Other information pertaining to our defences are in place but commercially sensitive.