We are not compromised, however our current ISP has troubles coping with the DDoS.
Note that a DDoS has nothing to do with security. Security usually involves getting inside the site to steal stuff (for example) while DDoS just means sending a lot of legitimate-looking traffic to make the site go down.
Anyway we'll be moving to a much stronger solution soon (contract already signed, waiting for setup).