CISA Wants Critical Infrastructure Orgs and Smaller Security Teams to Start Using Cyber Decoys
Help Net Security, Thursday, September 17th, 2026
New CISA guidance argues honeytokens and tripwires need no new spending and catch living-off-the-land intruders.
CISA's guidance, Using Cyber Decoys to Strengthen Detection and Response, targets the problem that many organizations cannot detect adversaries using legitimate credentials, built-in admin utilities and living-off-the-land techniques.
The premise is that once you accept intruders will get a foothold, the smart move is to booby-trap the environment with tripwires, honeytokens and fake credentials no legitimate user would ever touch.
For resource-constrained teams the key message is that decoys require no major architectural change or new spending: CISA explicitly directs organizations to repurpose EDR, IAM and DLP tooling they already own, with open-source options for token generation and alerting.