CISA urges business to deploy decoys, lures, and honeypots to catch hackers
in the act
Date:
Fri, 18 Sep 2026 13:50:00 +0000
Description:
ZTNA is great, but it can be even better with a little honeypot, CISA advises.
FULL STORY ======================================================================Copy link Facebook X Whatsapp Reddit Pinterest Flipboard Threads Email Share this article 0 Join the conversation Follow us Add us as a preferred source on Google Newsletter Subscribe to our newsletter CISA urged organizations to deploy honeypots, lures, and honeytokens as cyber decoys Decoys complement Zero Trust by detecting LOTL activity and producing highfidelity alerts Guidance outlines tripwires, breadcrumbs, MITRE ATT&CK/Engage steps for scalable implementation The US Cybersecurity and Infrastructure Security Agency (CISA) is urging organizations to deploy honeypots and various lures
to better detect cyber-intrusions and keep hackers busy with spoofed materials. To that end, it recently published a new guidance to help businesses of different sizes and cybersecurity maturity implement these
cyber decoy strategies.
Many organizations struggle to detect adversaries who use legitimate credentials, native tools, and living off the land (LOTL) techniques to conduct discovery, move laterally, and access data,. CISA said in a new security advisory. Cyber decoys are assets that appear to be legitimate systems, accounts, or data, but are designed to distract adversaries, detect their presence, or facilitate collection of cyber threat intelligence (CTI). As organizations adopt Zero Trust models, they should assume that a malicious threat actor may gain some level of access to their environment and plan accordingly. Latest Videos From TechRadar Watch full video here: Tripwires, breadcrumbs, and honeytokens CISAs advisory hints that Zero Trust is the preferred way to go about securing corporate infrastructure. Zero Trust
treats no user, device, or network segment as inherently trustworthy and requires organizations to operate on the assumption that compromise is inevitable, it says. If you want to learn more, read our in-depth guide on what ZTNA is .
However, it adds that cyber decoys are consistent with this paradigm and complement ZTNA by supporting continuous monitoring and verification,
creating high-fidelity alerts for suspicious activity, reducing alert
fatigue, and helping defenders detect post-compromise activity such as adversary LOTL techniques. They are also incremental, cost-effective, and scalable, and can be introduced into the cybersecurity tech stack without major architectural changes. You may like Identity and attack paths - can you stop hackers getting from A to B? No standing still: Zero Trust and cybersecurity How to set up data breach and dark web monitoring for your business
The guidance can be found on this link (PDF). It introduces different decoy concepts such as tripwires, breadcrumbs, and honeytokens, and uses the MITRE Engage and MITRE ATT&CK frameworks to provide the steps needed to plan, implement, and refine these operations. The best antivirus for all budgets
Our top picks, based on real-world testing and comparisons
Read our full guide to the best antivirus 1. Best overall: Bitdefender Total Security 2. Best for families: Norton 360 with LifeLock 3. Best for mobile: McAfee Mobile Security Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds. Are you a pro? Subscribe to our newsletter Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed! Contact me with news and offers from other Future brands Receive email from us on behalf of our trusted partners or sponsors By submitting your information you agree to the Terms & Conditions and Privacy Policy and are aged 16 or over.
======================================================================
Link to news story:
https://www.techradar.com/pro/security/cisa-urges-business-to-deploy-decoys-lu res-and-honeypots-to-catch-hackers-in-the-act
--- Mystic BBS v1.12 A49 (Linux/64)
* Origin: tqwNet Technology News (1337:1/100)