What’s happening: On September 16, 2026, the Cybersecurity and Infrastructure Security Agency published Using Cyber Decoys to Strengthen Detection and Response, its first guide dedicated to the defensive decoy process. The new CISA cyber decoy guidance tells critical infrastructure operators, federal agencies, and enterprises to plant decoy systems, accounts, and data inside their networks as a core part of a Zero Trust strategy.
Where we fit in: CISA is describing the discipline CounterCraft has practiced since 2015: assume the adversary is already inside, give them something they cannot safely touch, and turn every interaction into intelligence. Our deception environments are running today in banks, defense ministries, energy operators, and Fortune 500 networks on exactly the principles the guidance lays out.
Read on to find out what CISA said, why it matters, and how to act on it.
What the CISA cyber decoys guidance says
The guidance opens with the problem every SOC recognizes. Attackers who arrive with valid credentials and use native tools to conduct discovery, move laterally, and reach data are hard to separate from legitimate users. Signature-based tools have nothing to match. Behavioral analytics drown in noise. CISA calls this living off the land (LOTL, which we wrote a whole blog about), and it names LOTL detection as the gap decoys close.
CISA defines cyber decoys as assets that look like real systems, accounts, or data but exist to distract adversaries, detect their presence, or collect cyber threat intelligence. The document introduces three building blocks:
- Tripwires: monitored assets or actions that fire an alert on any interaction
- Breadcrumbs: planted clues, such as saved credentials or mapped drives, that lead an adversary toward a decoy
- Honeytokens: data objects with no legitimate business use, such as fake records, credentials, or files, where any access signals unauthorized activity
The guidance then lays out a ten-step adversary engagement lifecycle grouped into three phases: Prepare, Operate, and Understand. The steps run from assessing likely adversaries and defining objectives, through choosing what the adversary should perceive and how it will be presented, to execution, turning raw data into intelligence, and feeding that intelligence back into the next operation. The whole cycle is mapped to the MITRE Engage framework and the MITRE ATT&CK knowledge base, so teams plan decoy placement around the specific adversary tactics they expect. CISA also includes honeypots, full decoy systems built to attract and observe an adversary, as the fourth decoy type. The document is written for organizations at varying maturity levels and stresses that decoys can be deployed without major architectural change.
In the accompanying press release, CISA’s acting executive assistant director for cybersecurity, Chris Butera, said decoys help make critical infrastructure networks unfriendly places for adversaries. Speaking to CyberScoop, he added that the agency’s own threat hunters and penetration testers pushed for the guidance because decoys are a cheap, high-fidelity way to find an adversary who has already gained access.
Why this matters
Three things make this guidance a turning point for deception technology.
Deception is now official Zero Trust doctrine. CISA lists four ways decoys complement Zero Trust: supporting continuous monitoring and verification, creating high-fidelity alerts, reducing alert fatigue, and detecting post-compromise activity including LOTL. Every organization following CISA’s Zero Trust Maturity Model now has a documented reason to put decoys on the roadmap.
Read about how deception works, step by step, against zero trust principles in our whitepaper >
The assume-breach argument is settled. The guidance states plainly that organizations should plan for an adversary gaining some level of access. Once you accept that premise, the question shifts from “how do we keep them out” to “how fast do we know they are in.” Decoys answer that question because nobody legitimate touches a decoy. Any interaction is a real event, which is why CISA links decoys directly to lower mean time to detection.
It is the second major endorsement in a month. In August, OpenAI’s Black Hat presentation on the Hugging Face incident listed honeytokens and deception among the countermeasures for autonomous AI attackers, on the grounds that uncertainty slows an agent down. We covered that in Deception Made OpenAI’s List of Countermeasures. Within weeks, the US government’s cyber defense agency has reached the same conclusion from the critical infrastructure side. When the frontier AI lab and the national cyber agency converge on the same control, the category conversation is over.
CISA wrote its guidance with human operators in mind, and the argument only gets stronger against AI. An autonomous agent has no way to check what is real. It pattern-matches on plausibility and it consumes enormous amounts of information every minute, so every decoy credential, share, and document you plant becomes part of the picture its orchestration layer works from. Human attackers can smell a trap and test before committing. AI agents push forward on what they half-suspect, which is the behavior a decoy is built to catch. The same decoys CISA recommends for living-off-the-land intrusions let a defender control the attacker’s reality when the attacker is a machine.
Expose, affect, elicit: how CISA structures decoy operations
CISA borrows three goals from MITRE Engage and organizes the guidance around them. This is the most useful part of the document for anyone designing a program.
Expose. Detect the adversary quickly and unambiguously. CISA’s examples are fake admin credentials, decoy shares, and decoy tools. The guidance notes that interaction with a decoy should be rare in normal operations. Ie: NO FALSE POSITIVE PROBLEM.
Affect. Raise the attacker’s cost and slow them down with misleading accounts, fake data, and decoy services. This is the same argument OpenAI made about uncertainty and autonomous agents covers humans, too.
Elicit. Observe adversary behavior safely inside a controlled environment, from a single decoy network to a full isolated segment, and collect the tradecraft.
On our platform, each goal maps to a capability.. Every deception host, service, credential, and breadcrumb acts as a the so-called tripwires, which covers Expose. Realistic environments that mirror your organization divert attacker effort away from production, which covers Affect. Full adversary engagement, with telemetry mapped to ATT&CK and turned into incident reports, covers Elicit. CISA’s lifecycle phases follow the same lines: Campaign creation is Prepare, activation and telemetry collection are Operate, and incidents, TTP mapping, and reporting are Understand.
What it means for CISOs and SOC leaders
If you run security for a bank, a utility, a manufacturer, or a government body, the practical consequences are these:
- Budget conversations get easier. Deception used to require an internal champion to justify. Now the justification is a CISA publication with “Zero Trust” in the related topics.
- Auditors and regulators will start asking. CISA guidance has a way of appearing in assessment frameworks within a year or two. Being able to show a decoy strategy mapped to MITRE Engage will soon be a differentiator, and later a baseline.
- Alert fatigue has an official remedy. CISA names alert reduction as a benefit. A decoy alert carries no ambiguity, so it belongs at the top of the queue, and it lets a small team act with confidence.
- Critical infrastructure gets a low-cost path. Butera was explicit that the guidance is aimed at sectors short on people and money. Decoys deliver detection without a rip-and-replace.
How to implement the CISA cyber decoys guidance
The guidance is deliberately practical. Here is how we would translate it into a first campaign.
- Start with the adversary, using ATT&CK. Pick the two or three techniques you most need to see: credential access, discovery, lateral movement. Your decoy placement follows from that list. CISA’s Best Practices for MITRE ATT&CK Mapping is a useful primer.
- Plant breadcrumbs where attackers look first. Cached credentials on workstations, saved RDP sessions, entries in password managers, and shares that appear in discovery output. These are the LOTL touchpoints CISA highlights.
- Seed deception decoys in high-value areas. Fake service accounts in Active Directory, fake API keys in repositories, fake customer records in databases. Inexpensive to maintain.
- Route alerts as confirmed intent. Wire decoy telemetry into the SIEM or SOAR as a top-priority source. Treat these differently, because they are inherently better intel.
- Close the loop with intelligence. The third phase of CISA’s cycle is understanding. Every interaction with a decoy reveals tooling, targets, and tradecraft. Feed that back into detection rules, hardening priorities, and threat hunting.
- Scale with realism. Adversaries who find one decoy and then hit a flat, obviously fake environment learn to avoid the rest. Full deception environments that mirror your organization, with believable users, systems, and data, keep attackers engaged long enough to collect real intelligence. That is the difference between a tripwire and a source of threat intel.
- Place decoys where AI agents travel. CISA’s examples target the paths human attackers take. Agentic attackers have their own paths, so be sure to seed those too. An agent will test a credential it finds, and the test is is a giveaway. Better still, the detection is TTP-agnostic: it fires on brand-new techniques with no signature and no precedent, at the speed the attacker moves. Machine-speed attacks call for machine-speed detection, and a decoy delivers that without a single false positive. Read more about why deception works so well against AI attackers here.
For a longer treatment of what to look for when evaluating platforms, see our Deception Technology Buyer’s Checklist.
Our take
CISA’s document reads like a description of what our customers already run. Assume breach. Plant decoys in the paths attackers take. Treat any touch as a real alert. Map the whole thing to MITRE Engage. Use the intelligence to protect the real environment.
We have been working inside this framework for years: our CEO David Barroso presented on mapping ATT&CK techniques to Engage activities at MITRE’s ATT&CKcon in 2022, four years before CISA built its guidance on the same model.
Two points deserve emphasis. First, the guidance is written for defenders at every maturity level, and that matters. Deception used to be a discipline for teams with spare headcount. Our platform builds hyper-realistic deception environments in minutes and our AI-powered organization profiling generates believable identities, org charts, and data at scale, so a two-person security team at a regional utility can run a campaign that would have taken a red team weeks to build. The platform runs in the cloud or on-premises, which matters for the defense, energy, and government environments CISA is addressing, where a hosted-only deception product is a non-starter.
Second, this is preemptive cybersecurity in the sense CISA now recognizes. Decoys stop the adversary before they reach production assets, and they do it without false positives, because the only people who interact with a decoy are people who should not be there. We call this owning the attacker’s reality. CISA calls it strengthening detection and response. Same idea. Learn how preemptive cybersecurity works.
Frequently asked questions
What is the CISA cyber decoys guidance?
A September 2026 CISA publication, Using Cyber Decoys to Strengthen Detection and Response, that explains how organizations can plan, deploy, and refine decoy systems, accounts, and data to detect adversaries already inside a network.
What is the difference between a cyber decoy and a honeypot?
A honeypot is one type of decoy, usually a full system. CISA uses “cyber decoy” as the umbrella term covering honeypots, honeytokens, breadcrumbs, and tripwires. Modern deception platforms combine all of them into a realistic environment.
How do cyber decoys support Zero Trust?
Zero Trust assumes no user or device is trusted by default and that adversaries may already have access. Decoys give defenders a way to verify that assumption continuously, with high-fidelity alerts and low noise.
Do I need a deception platform to follow the guidance?
A platform is essential for realism, scale, automation, and the intelligence-collection phase CISA describes, which is where the long-term value sits.
Does the CISA cyber decoys guidance apply to AI-driven attacks?
Yes. CISA’s core logic, that no legitimate user has a reason to touch a decoy, holds whether the intruder is a person or an autonomous agent. AI attackers add three things that favor deception: they cannot independently verify what is real, they operate continuously at machine speed, and they share whatever they find across the attacking fleet, so one poisoned credential contaminates the whole operation. CISA’s guidance also stresses that decoys work for teams at every maturity level. AI-assisted deception platforms now automate campaign design, breadcrumb placement, and threat intelligence reporting, which puts the approach within reach of smaller security teams for the first time.
See it in your environment
CISA has set the standard. We can show you what it looks like running in a network like yours. Request a demo or get in touch.
CounterCraft is a leading provider of AI-powered, deception-driven threat intelligence. As adversaries deploy AI agents that attack continuously and at machine speed, CounterCraft builds hyper-realistic deception environments in minutes, contains automated attackers before they reach real assets, and delivers full visibility into their tactics, techniques, and procedures. Their Gartner-recognized, award-winning technology has been keeping Fortune 500 companies and government agencies safe since 2015. Discover how CounterCraft is redefining cybersecurity with AI-powered deception at www.countercraftsec.com.


