"Every AI-driven operator we tracked did exactly that," Crystal Morin said, describing a simple prompt-injection decoy that exposed machine-driven attackers.
CISA's new guidance for critical infrastructure, published September 16
The Cybersecurity and Infrastructure Security Agency (CISA) has urged critical infrastructure organizations to plant fake files, accounts and credentials inside their networks to detect attackers who have already penetrated the perimeter. The guidance, published September 16, is the agency's first detailed treatment of the process and assumes intruders will eventually gain some level of access. CISA framed decoys as an addition to Zero Trust rather than a replacement, and the document contains no mandatory measures.
Focus on honeytokens inside networks, not internet-facing honeypots
Rather than the internet-facing honeypots the term often evokes, the guide narrows its scope to decoys placed inside an organization's own networks and systems. That emphasis pushes honeytokens to the fore. CISA defines honeytokens as data items with no legitimate business use — for example, fake records, credentials or files planted among real assets — where any interaction strongly suggests unauthorized activity. The agency's own comparison rates honeytokens low in complexity, while honeypots operate at system level and carry medium to high complexity and deliberate vulnerabilities.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleTripwires, MTTD, and the worked example
Tripwires are the mechanism CISA highlights. Because staff have no legitimate reason to touch a decoy, CISA says an alert from one produces far less noise than conventional tooling and expects that to cut mean time to detection (MTTD). The guide includes a worked example: a honeytoken tripwire on a project share. CISA frames this material as an introductory resource for small-to-medium-sized organizations and for defenders new to decoy operations or to MITRE Engage.
Three actions and a continuous testing loop using MITRE frameworks
CISA sets out three key actions: deploy high-fidelity tripwires in high-value areas; use MITRE ATT&CK and MITRE Engage to map adversary tactics against decoy coverage; and refine the whole program continuously through threat emulation. The guidance leans on Engage's defensive objectives — Expose (detect intruders), Affect (disrupt or delay them), and Elicit (study techniques in controlled environments) — and concentrates its practical material on Expose. The agency stresses refinement through threat emulation as part of an ongoing testing loop.
What this means for critical infrastructure organizations, small-to-medium defenders, and machine-driven attackers
- Critical infrastructure organizations: CISA explicitly urges these organizations to plant decoys — fake files, accounts and credentials — inside their networks to detect intruders who move using legitimate credentials and native tools that conventional monitoring struggles to separate from normal activity.
- Small-to-medium-sized organizations and defenders new to decoy operations: The guidance is presented as an introductory resource, with practical examples such as a honeytoken tripwire on a project share and a recommended three-step program combining high-fidelity tripwires, ATT&CK/Engage mapping, and continuous threat emulation.
- Machine-driven attackers and AI-driven operators: Sysdig senior cybersecurity strategist Crystal Morin described research in which her team planted a prompt injection in a vulnerable container. The injection instructed any large language model that read the file to echo a hidden marker; "Every AI-driven operator we tracked did exactly that," she said, suggesting a specific advantage for defenders against automated, instruction-following attackers. By contrast, Morin noted a human attacker opened the file twice, recognized the bait and stepped over it.
The facts in CISA's guidance are practical and narrow: plant interior decoys, prioritize honeytokens for low-complexity coverage, map coverage with MITRE ATT&CK and Engage, and keep refining through emulation. CISA does not mandate these steps; it positions them as an addition to Zero Trust and as tools to reduce detection noise and speed detection. As Morin's research underscores, the value depends on matching the decoy to the adversary — the right bait can expose machine-driven operators, while a human opponent may simply avoid it.
Link to original story: https://www.infosecurity-magazine.com/news/cisa-critical-infrastructure-cyber/




