The Cybersecurity and Infrastructure Security Agency (CISA) has published new guidance for deploying cyber decoys, aiming to help critical infrastructure organizations detect and disrupt attackers who have already gained a foothold in their networks.
The guidance frames decoys as a complement to Zero Trust architectures. Where Zero Trust continuously verifies access, decoy strategies assume an adversary may already be inside the environment and focus on catching them in the act. CISA describes decoys as assets that look like legitimate systems, accounts, or data, but exist to distract intruders, detect their presence, or support collection of cyber threat intelligence.
Why CISA Is Pushing Decoys Now
According to the agency, many organizations still struggle to spot attackers who rely on stolen but valid credentials, native operating system tools, and living-off-the-land (LOTL) techniques to explore networks, move laterally, and reach sensitive data. Because these methods mimic normal administrative activity, traditional detection tools often miss them. Decoys are designed to close that gap by creating tripwires that only an intruder, not a legitimate user, would ever touch.
CISA notes that decoy techniques can be rolled out incrementally and cost-effectively, without requiring major changes to existing network architecture, making them accessible to organizations across different levels of security maturity.
Deployment Recommendations
The guidance recommends placing decoys in locations that legitimate users rarely or never access, and configuring them to generate high-fidelity alerts when triggered. Organizations are encouraged to use decoys to:
- Divert attackers toward decoy data instead of real assets
- Feed adversaries a misleading picture of the environment during reconnaissance
- Lure attackers into exfiltrating large volumes of non-sensitive or meaningless data
- Redirect intruders into controlled environments where their behavior can be studied and threat intelligence gathered
CISA outlines a range of decoy types organizations can combine, including lures, tripwires, decoy artifacts, honeytokens, and honeypots.
A Three-Phase Process
The agency structures effective decoy deployment around three phases. In the preparation phase, teams should assess their threat landscape, define clear operational goals, anticipate how adversaries might perceive and react to the environment, establish deployment channels, and set measurable success criteria.
During execution, organizations run the decoy operation itself. Afterward, in the understanding phase, teams are expected to convert collected data into actionable intelligence, feed lessons learned back into their defenses, and evaluate what worked and what did not to refine future deployments.
The full guidance document includes benefits specific to each decoy type, deployment considerations, and example scenarios intended to help defenders of varying experience levels build practical decoy strategies into their existing detection and response programs.
