← NEWS & INSIGHTS

NEWS / RESEARCH & ANALYSIS

CISA publishes guidance on cyber decoys for detection and response

New guidance explains how carefully governed decoys can reveal activity that blends into normal administration.

Source published 2026-09-16DetectionCISAIncident response
Official advisory heading: CISA publishes guidance on cyber decoys for detection and response
Original advisory heading · CISA ↗

What was published

CISA released guidance on incorporating cyber decoys into defensive planning. It discusses concepts including tripwires, breadcrumbs and honeytokens, connecting decoy operations with Zero Trust and the MITRE Engage and ATT&CK frameworks.

Why it matters

An intruder using legitimate credentials can resemble a normal user in ordinary logs. A carefully designed decoy can create an additional signal for investigation. CISA presents decoys as a complement to existing defenses, not a substitute for access controls or monitoring.

Forensic focus

If an organization uses decoys, document their ownership, placement and expected interactions. Preserve alert context and the associated identity and network records. Distinguish a real unauthorized interaction from an inventory scan or an approved test. Keep decoy activity identifiable in the evidence record so it cannot be mistaken for access to genuine business data.

Source published 16 September 2026. Briefing prepared 26 September 2026.

Read CISA's guidance.

Search the lab

NEWS / FORENSICS / FIELD GUIDES ESC