THE US Cybersecurity and Infrastructure Security Agency (CISA) has urged critical infrastructure organisations to place fake files, accounts and credentials inside their networks to help detect attackers who have already bypassed perimeter defences. Its guidance, published on 16 September 2026, is the agency’s first detailed treatment of cyber decoys.
It assumes intruders may gain some access and focuses on situations where attackers use legitimate credentials and built-in tools, which can be difficult to distinguish from normal activity. CISA presents decoys as an addition to Zero Trust, not a replacement, and says the guidance contains no mandatory measures.
The document focuses on honeytokens rather than internet-facing honeypots. These are fake records, credentials or files with no legitimate business purpose; any interaction with them can indicate unauthorised activity. CISA rates honeytokens as less complex to deploy than system-level honeypots, and gives a tripwire placed on a project share as an example.
It recommends deploying high-fidelity tripwires in high-value areas, mapping coverage against adversary techniques using MITRE ATT&CK and MITRE Engage, and continuously refining the approach through threat emulation. The material is intended as an introduction for small and medium-sized organisations and defenders new to decoy operations.
The article cites research by Sysdig senior cybersecurity strategist Crystal Morin, in which a prompt injection planted in a vulnerable container instructed any large language model reading it to echo a hidden marker. Morin said every AI-driven operator tracked followed the instruction, while a human attacker recognised the bait and avoided it. She stressed that decoys must match the adversary and are not a substitute for containment.