CISA Guidance: Using Decoys to Catch Hackers Hiding in Plain Sight
CISA has published new guidance encouraging organisations to use cyber decoys, fake systems, accounts, or data designed to lure and expose attackers, as part of their detection and response strategy. The advisory targets a growing challenge: attackers who use stolen but legitimate credentials and built-in system tools (known as living off the land techniques) to explore networks and steal data without triggering typical security alerts.
Decoys such as tripwires, breadcrumbs, and honeytokens act as bait. If a decoy is touched, it generates a high-confidence alert since no legitimate user should ever interact with it. CISA notes this approach complements Zero Trust security models, which assume attackers may already have some access to a network, by adding another layer of visibility. The guidance draws on the MITRE Engage and MITRE ATT&CK frameworks to offer practical, low-complexity steps organisations of any maturity level can use to plan and refine decoy strategies.
For small businesses, this means fewer false alarms and clearer warning signs when something is genuinely wrong, without requiring expensive new infrastructure.