Explore our Topics:

CISA urges critical infrastructure organizations to booby-trap their own networks

New federal guidance says decoy files, accounts, and credentials can catch intruders that conventional monitoring misses.
By admin
Oct 5, 2026, 10:05 AM

At a glance

CISA published a voluntary playbook on September 16 that shows critical infrastructure organizations how to deploy cyber decoys, which are fake systems, accounts and data that alert defenders when an intruder touches them. The guidance serves as a starting point for small to medium-sized organizations with no decoy experience. CISA recommends beginning with honeytokens such as fake files, dormant accounts and credentials, which it rates as low complexity. Decoys counter alert fatigue because legitimate users have no reason to touch them.

CISA wants defenders to start lying to their attackers.

On September 16, the agency published a playbook for deploying cyber decoys, fake systems, accounts, and data that defenders plant inside a network for the sole purpose of catching intruders who touch them. The document targets critical infrastructure organizations. CISA calls the approach “incremental, cost-effective, and scalable” and frames the guide as a starting point for small to medium-sized organizations and staff with no decoy experience.

Zero Trust holds that nothing on a network earns trust by default, and that defenders should plan as if a breach has already happened. CISA’s guidance takes the next step. If an attacker may eventually get inside, defenders can seed the environment with assets that give legitimate users no reason to go near them. A fake administrator credential, a decoy folder on an executive’s desktop, or a bogus network-scanning tool on a nontechnical employee’s workstation all share one property. Any interaction with them signals trouble.

Alert fatigue and stealthy intruders drive the recommendation

The agency is candid about the problems it wants decoys to solve. Security teams face high alert volumes riddled with false positives, limited analyst capacity, and resulting alert fatigue. Stealthy intruders are hard to spot when they use legitimate credentials and native tools, the living-off-the-land (LOTL) techniques that blunt signature-based detection.

Decoys invert that math, according to the guidance. Because interactions with decoy assets should be rare or nonexistent in normal operations, the alerts they produce are high fidelity almost by definition. CISA says well-implemented decoys can shorten mean time to detection, turn break-in attempts into usable threat intelligence, and help defenders put their effort where attackers actually go.

The document builds on MITRE’s ATT&CK knowledge base of adversary tactics and techniques and its Engage framework, which sorts deception into three goals. Expose detects adversaries, Affect raises the cost of their operations, and Elicit observes them in controlled settings to collect intelligence. CISA advises organizations to build Expose capabilities first and to treat Elicit as an advanced undertaking that demands isolated environments, mature monitoring, and staff equipped to handle the risks, legal ones included.

Honeytokens offer a low bar to entry

For organizations starting from scratch, the guidance points to “honeytokens,” fake data objects that nobody has a real-world reason to touch. They can take the form of files, database records, dormant accounts, credentials, email addresses, or web links. In a comparison table, CISA rates honeytokens as low complexity, requiring little security maturity, against the medium-to-high complexity of full honeypot systems.

One example in the document illustrates how little is actually required. A manager keeps monthly briefs about a sensitive project on a network share that only that manager can reach. The security team adds a few convincing fakes, a Project_Metrics.xlsx here, a Budget_Data.docx there, wires each one to raise an alarm, and warns the manager to leave them alone. From then on, any access to those files strongly suggests an intruder.

Organizations can source honeytokens through open source tools, commercial platforms, or custom development. CISA also describes a LOTL approach for defenders, who can deploy and monitor decoys with existing endpoint detection, identity management, and data loss prevention tools.

A water utility scenario shows the planning process

A later section follows a notional medium-sized water and wastewater utility deciding where decoys belong. The team maps its vulnerabilities, its defensive coverage, and its likely adversaries’ techniques against ATT&CK. Where the maps overlap and defenses are thin, decoys go in.

In the scenario, threat intelligence indicates a ransomware group targeting the sector uses techniques including phishing, password spraying, PowerShell-based commands, and network discovery. The utility finds detection gaps around phishing that users don’t report, PowerShell abuse, and data theft aimed at cloud backups. Its decoy plan includes:

  • Fake low-privilege accounts that alert on any authentication attempt
  • Listening services on decoy network ports to catch scanning
  • Seeded command tokens on workstations that fire when anyone runs them
  • Beaconing elements in public login pages that reveal when phishing campaigns use cloned copies

The guidance then calls for testing the traps through threat emulation, red teaming, or purple teaming. In the scenario, the utility brings in a third-party red team to emulate a ransomware campaign, and the decoys fire on a seeded scanning tool, then on a decoy remote service and a fake Active Directory account.

The guidance also includes operational cautions:

  • Keep documentation of decoy locations outside the production environment, where a successful intruder could otherwise find the map
  • Run planning over communication channels independent of the monitored network
  • Brief leadership on objectives while the specifics stay with the people who need them
  • Catalog expected false positives such as IT testing before the alerts start firing

The document creates no mandates, and CISA states that every action it describes is voluntary. Its argument is structural rather than regulatory, framing decoy operations as ongoing work that teams refine with each cycle, something any organization already conceding the possibility of compromise has reason to start.


Show Your Support

Subscribe

Newsletter Logo

Subscribe to our topic-centric newsletters to get the latest insights delivered to your inbox weekly.

Enter your information below

By submitting this form, you are agreeing to DHI’s Privacy Policy and Terms of Use.