Unfortunately, all of these "Best Practices" are "spend more money," which effectively means the attacker wins. They're forcing you to spend more money, even if they're not attacking you now/recently. Would love to see more things that reference open source mitigation software and such like that, e.g. tossing a hardened nginx in front of your Tomcat server, stuff like that.
Granted, at some point, you're going to have to spend money to mitigate the attack no matter what, but if mitigation of DDoSs becomes entirely focused on "Go with a big centralized provider" or "Spend lots of money to mitigate the attacks," we end up in a much different Internet.