
What was published
CISA released guidance on incorporating cyber decoys into defensive planning. It discusses concepts including tripwires, breadcrumbs and honeytokens, connecting decoy operations with Zero Trust and the MITRE Engage and ATT&CK frameworks.
Why it matters
An intruder using legitimate credentials can resemble a normal user in ordinary logs. A carefully designed decoy can create an additional signal for investigation. CISA presents decoys as a complement to existing defenses, not a substitute for access controls or monitoring.
Forensic focus
If an organization uses decoys, document their ownership, placement and expected interactions. Preserve alert context and the associated identity and network records. Distinguish a real unauthorized interaction from an inventory scan or an approved test. Keep decoy activity identifiable in the evidence record so it cannot be mistaken for access to genuine business data.
Source published 16 September 2026. Briefing prepared 26 September 2026.