www.securityweek.com 17 Sept 2026, 07:53 UTC

CISA Urges Critical Infrastructure to Deploy Cyber Decoys Against Attackers

CISA Urges Critical Infrastructure to Deploy Cyber Decoys Against Attackers

THE US Cybersecurity and Infrastructure Security Agency (CISA) has published guidance for critical infrastructure organisations on using cyber decoys to strengthen detection and response. Decoys are systems, accounts or data made to appear legitimate, but intended to distract attackers, reveal their presence or support the collection of cyber threat intelligence.

CISA says they complement Zero Trust approaches by assuming an adversary may already have some access to an environment, and describes the techniques as incremental, cost-effective and scalable without major architectural changes.

The guidance covers lures, tripwires, decoy artefacts, honeytokens and honeypots. CISA recommends placing them where legitimate users rarely interact with them and configuring high-fidelity alerts. Decoys can divert attackers towards fabricated data, distort their understanding during reconnaissance, encourage the collection of non-sensitive information and guide activity into controlled environments for observation. Deployment is described as a three-phase process: preparation, execution and understanding.

Organisations should assess their threat landscape, define goals and success measures, plan how systems will be deployed, then turn collected data into actionable and feedback intelligence while reviewing what worked and what did not. CISA says the guidance is intended for defensive teams at different levels of maturity, particularly because attackers can use legitimate credentials, native tools and living-off-the-land techniques to discover systems, move laterally and access data.

View full article

Article by CyberSIXT