Government Advisory

CISA Guidance: Using Decoys to Catch Hackers Hiding in Plain Sight

CISA · 16 Sept 2026
Key Takeaway Consider placing a few realistic decoy accounts or files in your network; any interaction with them is a strong, low-noise signal that an intruder is present.

CISA has published new guidance encouraging organisations to use cyber decoys, fake systems, accounts, or data designed to lure and expose attackers, as part of their detection and response strategy. The advisory targets a growing challenge: attackers who use stolen but legitimate credentials and built-in system tools (known as living off the land techniques) to explore networks and steal data without triggering typical security alerts.

Decoys such as tripwires, breadcrumbs, and honeytokens act as bait. If a decoy is touched, it generates a high-confidence alert since no legitimate user should ever interact with it. CISA notes this approach complements Zero Trust security models, which assume attackers may already have some access to a network, by adding another layer of visibility. The guidance draws on the MITRE Engage and MITRE ATT&CK frameworks to offer practical, low-complexity steps organisations of any maturity level can use to plan and refine decoy strategies.

For small businesses, this means fewer false alarms and clearer warning signs when something is genuinely wrong, without requiring expensive new infrastructure.

CISA threat detection zero trust decoys SMB security

Summarised by CISO AI from CISA. We link back to every original so you can read it yourself.