CISA Urges Critical Infrastructure to Plant Decoys Inside Networks
CISA's first decoy guidance tells critical infrastructure to deploy honeytokens and tripwires inside networks, mapped via MITRE ATT&CK and Engage, to speed detection.
CISA published its first detailed cyber decoy guidance on September 16, urging critical infrastructure organizations to plant honeytokens such as fake credentials, records, and files with no legitimate business use inside their networks. The guide recommends deploying high-fidelity tripwires in high-value areas, mapping decoy coverage with MITRE ATT&CK and MITRE Engage, and continuous refinement through threat emulation. It is positioned as a complement to Zero Trust, contains no mandatory measures, and targets small and medium-sized organizations and defenders new to deception operations.