CISA Tells Critical Infrastructure to Set Traps for Hackers Already Inside the Network
The Cybersecurity and Infrastructure Security Agency (CISA) has published its first detailed guidance on using cyber decoys, assuming that intruders will eventually gain some level of access to a network regardless of other defences in place. The approach is aimed at catching attackers who use legitimate stolen credentials and normal system tools to move around undetected, activity that is often difficult to distinguish from genuine staff behaviour using conventional monitoring alone.
The guidance focuses on "honeytokens": fake data items such as records, credentials or files that have no legitimate business use. Because employees have no reason to interact with these decoys, any activity involving them is a strong signal of unauthorised access. CISA rates honeytokens as low in complexity to deploy compared to honeypots, which mimic entire vulnerable systems and require more effort to maintain. A worked example in the guidance describes a honeytoken tripwire placed on a project file share to alert defenders quickly.
CISA is positioning decoys as a complement to Zero Trust security models rather than a replacement, and the guidance is not mandatory. The agency expects that alerts triggered by decoys will be far less noisy than typical security tooling, helping organisations reduce the time it takes to detect a breach.