Oh, and please don't come with a snooty attitude, it's not pleasant to work with.
One of the problems I imagine is size, I can still handle my couple of thousand customers and provide "good" support with enough time to investigate something that is described as a slowloris attack. I can open a dialogue with the customer and tell them that what they did was a little bit stupid and for the most part, the customer will understand and stop.
Although there was a time when I did investigate, couldn't find anything immediate (I'm spending say 5-10 minutes pruning a few TB of data here...) so the next point was to catch them in the act with a few iptables rules. Then the person who e-mailed me (and my host) pretty much turned hostile/gained a sense of entitlement and that was that. I wasn't much interesting in putting more time into it (so, didn't!). However this guy only produced a few text logs that could have been easily forged and I never heard more about it... who knows?
That also leads to another angle, how do you know who is telling the truth? The hosts are likely to side with the paying customer (well you never know with OVH) and there is little an outsider can do to prove their case in point except with easily fabricated text logs and events.
It's strange really, some of the people who I have followed up on have been very grateful (perhaps because they got their way), much in the same way going the extra mile for a customer might.
Put you in my address book in case I ever develop for a UK-audience site.