CISA has released new guidance encouraging defensive teams to deploy cyber decoys, including fake systems, accounts, credentials and data, to detect and disrupt attackers already inside their networks.
The guidance targets a growing detection problem in which attackers use legitimate credentials, built-in tools and “living off the land” techniques to move through networks without triggering traditional security defenses.
Decoys such as honeypots, honeytokens, breadcrumbs and tripwires are designed to look legitimate but generate high-confidence alerts when an unauthorized user interacts with them. CISA says organizations can begin deploying decoys without major infrastructure changes or significant new spending, including by using existing endpoint detection, identity and access management, and data loss prevention tools.
The agency recommends incorporating decoys into Zero Trust and “assume compromise” strategies to identify attackers earlier, collect threat intelligence and reduce the time between an intrusion and its detection.
Donald McFarlane, Board Member, Xcape Inc.:
“I have advocated deception for decades because it can be one of the highest-ROI controls in cybersecurity.
“Most security monitoring tries to distinguish malicious activity from an enormous volume of legitimate activity. Well-designed deceptive controls turn that problem on its head: nobody conducting legitimate business should be touching certain combinations of decoy accounts, identities, credentials, servers, systems or data. When someone does, the signal can be extraordinarily high confidence.
“Deception also changes the economics for the attacker. The attacker has to distinguish the real from the fake every time. The defender only needs them to touch the wrong thing once.
“CISA is right to push this as part of an assume-compromise strategy. More broadly, cybersecurity has much to learn from military doctrine. Effective defense is not simply building higher castle walls and trying to defend every point equally. Cyber defenders should be employing deception and manoeuvre; shaping the battlespace; channeling adversaries toward ground of the defenders’ choosing; and creating opportunities to detect and disrupt them.”
John Strand, Owner, Black Hills Information Security:
“This is one of the coolest bits of security news I’ve seen in a long time. I’ve been pushing cyber deception for years, teaching it at Black Hat and through Anti-Siphon Security Training, and I love the recognition that this does not have to be expensive. You don’t need some massive commercial product to get started. You can create accounts in Active Directory that should never be used and trigger an alert the second somebody tries to authenticate with them. You can deploy simple honey tokens for free. Yes, there are great commercial offerings too, but cost should not be the reason you aren’t doing deception.
“The bigger issue is that too many security teams treat cyber deception as something you deploy after you get everything else right. I completely disagree. Deception should go in immediately, right alongside your other security controls. It gives you something incredibly valuable. An attacker touching something that no legitimate user should ever touch. That is a signal worth paying attention to. This is nothing but good news for defenders.”
This is cool and scary at the same time. I say that because that shifts the responsibility for law enforcement outside law enforcement. We will have to see if that works out well, or goes horribly bad.
Related
This entry was posted on September 17, 2026 at 4:21 pm and is filed under Commentary with tags CISA. You can follow any responses to this entry through the RSS 2.0 feed.
You can leave a response, or trackback from your own site.
The CISA tells organizations to use fake systems and data to catch hackers
CISA has released new guidance encouraging defensive teams to deploy cyber decoys, including fake systems, accounts, credentials and data, to detect and disrupt attackers already inside their networks.
The guidance targets a growing detection problem in which attackers use legitimate credentials, built-in tools and “living off the land” techniques to move through networks without triggering traditional security defenses.
Decoys such as honeypots, honeytokens, breadcrumbs and tripwires are designed to look legitimate but generate high-confidence alerts when an unauthorized user interacts with them. CISA says organizations can begin deploying decoys without major infrastructure changes or significant new spending, including by using existing endpoint detection, identity and access management, and data loss prevention tools.
The agency recommends incorporating decoys into Zero Trust and “assume compromise” strategies to identify attackers earlier, collect threat intelligence and reduce the time between an intrusion and its detection.
Donald McFarlane, Board Member, Xcape Inc.:
“I have advocated deception for decades because it can be one of the highest-ROI controls in cybersecurity.
“Most security monitoring tries to distinguish malicious activity from an enormous volume of legitimate activity. Well-designed deceptive controls turn that problem on its head: nobody conducting legitimate business should be touching certain combinations of decoy accounts, identities, credentials, servers, systems or data. When someone does, the signal can be extraordinarily high confidence.
“Deception also changes the economics for the attacker. The attacker has to distinguish the real from the fake every time. The defender only needs them to touch the wrong thing once.
“CISA is right to push this as part of an assume-compromise strategy. More broadly, cybersecurity has much to learn from military doctrine. Effective defense is not simply building higher castle walls and trying to defend every point equally. Cyber defenders should be employing deception and manoeuvre; shaping the battlespace; channeling adversaries toward ground of the defenders’ choosing; and creating opportunities to detect and disrupt them.”
John Strand, Owner, Black Hills Information Security:
“This is one of the coolest bits of security news I’ve seen in a long time. I’ve been pushing cyber deception for years, teaching it at Black Hat and through Anti-Siphon Security Training, and I love the recognition that this does not have to be expensive. You don’t need some massive commercial product to get started. You can create accounts in Active Directory that should never be used and trigger an alert the second somebody tries to authenticate with them. You can deploy simple honey tokens for free. Yes, there are great commercial offerings too, but cost should not be the reason you aren’t doing deception.
“The bigger issue is that too many security teams treat cyber deception as something you deploy after you get everything else right. I completely disagree. Deception should go in immediately, right alongside your other security controls. It gives you something incredibly valuable. An attacker touching something that no legitimate user should ever touch. That is a signal worth paying attention to. This is nothing but good news for defenders.”
This is cool and scary at the same time. I say that because that shifts the responsibility for law enforcement outside law enforcement. We will have to see if that works out well, or goes horribly bad.
Share this:
Like this:
Related
This entry was posted on September 17, 2026 at 4:21 pm and is filed under Commentary with tags CISA. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.