If you order a new VPS for a live website do you always order it from a company with DDoS protection or do you only use those companies after you have been a victim of DDoS?
I only order it once needed. If I have a server that never gets hit I'd rather save the money. If it becomes a target, DDoS protection is affordable enough to get going from most places.
I would order DDoS protection for my Customer only if needed. That is when my Customer/s demand DDoS protection (as is n.b. in our case) or if my business is DDoS prone.
That's especially as GOOD DDoS protection is quite expensive.
So what I do is subscribe to multiple DDoS protected services and have for eons. Those different companies are all in a pool of front end servers (ala CDN reverse proxy). I might spin up another IP to separate projects. Outside of that, it's a platform for whatever I shove back behind it.
I try to shove everything behind protection as attacks are way too common. Whole subculture and juvenile delinquency that seems to communicate by throwing temper tantrum and DDoS stressing things so they can enjoy their ill gotten Viagra jollies.
Nowadays I definitely order a VPS with DDoS protection, even if I probably won't be targeted, but I like to be sure, that nothing could happen with my site.
unless you are in a business that needs it It would be cheaper to get your server secured, use cloudflare or/and implement some software based DDos protection.
Up until recently I didn't bother with ddos protection. Now since everyone and their dog can launch a denial of service, I fork over the money to protect my sites.