Skip to main content
CybersecurityHacking

CISA Deploys Cyber Decoys to Disrupt Attackers

Rows of computer servers and networking equipment with interspersed brightly-lit decoy systems in a secure server room.
“We’ve been looking at it for a while, and we believe that decoys can be both a very low-cost but actually high-fidelity way to detect an adversary who’s already gained access to networks,” Chris Butera, acting executive director of CISA’s cybersecurity division, told CyberScoop at Google Cloud’s Cyber Defense Summit 26.

CISA’s new guidance on cyber decoys

The Cybersecurity and Infrastructure Security Agency (CISA) has published formal guidance titled “Using Cyber Decoys to Strengthen Detection and Response,” urging owners and operators of critical infrastructure to deploy phony systems, accounts, and data to distract, detect, and expose intruders. CISA’s recommendation follows internal work from the agency’s threat hunters and penetration testers, who concluded decoys can be an effective defensive tool.

Honeytokens and other decoy types explained

The 22-page guidance defines several kinds of decoys and explains how to use them. One specific example the guidance gives is the honeytoken: “Data elements or logical objects with no legitimate business use (e.g., fake records, credentials, or files) planted to detect unauthorized access or exfiltration. Any interaction strongly suggests malicious or otherwise unauthorized activity.” The manual pairs definitions with practical scenarios for deployment.

Why CISA says decoys are worth considering

According to CISA, decoys are complementary to architectural approaches such as zero-trust (treating no user or device as trustworthy by default) and assume-compromise (operating under the assumption an attacker already has network access). Chris Butera framed decoys as particularly valuable where personnel and funding are limited: “This could be something to prioritize as a lower cost solution,” he said, adding that “you can create your own honey tokens yourself.”

What the 22-page guide covers for implementers

CISA’s manual lays out decoy principles and goals, types of decoys, and scenarios for deployment. The agency presents decoy operations as a way to make networks “unfriendly places for adversaries” and to “enhance resilience to compromise, even against living-off-the-land techniques,” Butera said in a CISA news release. The guidance is described as accessible to defensive teams “regardless of skill level,” suggesting a low barrier for basic adoption while allowing for more sophisticated operations where resources permit.

What this means for technologists, critical infrastructure owners, and adversaries

  • Technologists and security teams: The guidance provides a structured set of definitions and scenarios they can adopt or adapt. Because CISA frames decoys as complementary to zero-trust and assume-compromise strategies, teams already pursuing those approaches may find decoys a practical addition to detection tooling.
  • Critical infrastructure owners and operators: CISA explicitly positions decoys as a lower-cost option for sectors with constrained budgets or staff. The agency “encourages critical infrastructure organizations to review this guide and implement a cyber decoy strategy,” signaling an official nudge toward wider adoption.
  • Adversaries and threat actors: By increasing the use of fake systems, credentials, and data, defenders aim to distract attackers and increase the likelihood of discovery. CISA’s framing emphasizes disrupting attackers’ ability to operate undetected, including against “living-off-the-land techniques.”

CISA’s push elevates deception techniques from niche exercises to an advised component of defensive planning for critical infrastructure. The agency’s guidance couples practical definitions and scenarios with a policy message: decoys can be effective even when budgets and headcount are thin, and they fit alongside prevailing defensive doctrines like zero-trust and assume-compromise. CISA’s next concrete step for organizations is clear in its own language — review the guide and implement a cyber decoy strategy — but how quickly and widely operators will adopt decoys remains an open question for those managing constrained cyber programs.

Original CyberScoop story