The US Cybersecurity and Infrastructure Security Agency (Cisa) – a roughly equivalent body to GCHQ’s National Cyber Security Centre (NCSC) in the UK – has endorsed the use of so-called cyber decoys as a means to improve incident detection and response activities, and to harmlessly ‘detonate’ inbound threats.
The agency said it had developed the new guidance to help defensive teams plan and implement strategies for dealing with adversaries using legitimate stolen credentials, native tools, and other living-off-the-land (LOTL) techniques in their intrusions.
“Cyber decoys are assets that appear to be legitimate systems, accounts, or data, but are designed to distract adversaries, detect their presence, or facilitate collection of cyber threat intelligence (CTI),” Cisa said in a statement.
“As organisations adopt zero-trust models, they should assume that a malicious threat actor may gain some level of access to their environment and plan accordingly.”
According to Cisa, cyber decoys complement a zero-trust strategy by supporting continuous monitoring and verification, creating high-fidelity alerts for suspicious activity, easing alert fatigue for cyber teams, and helping them detect post-compromise activity.
Effective deployment should enable organisations not only to detect threat actors that have successfully hacked their environments, but also gather and analyse information derived from intrusions and attempts, allocate defensive resources more effectively, and reduce mean-time-to-detection.
The full guidance – available to download from Cisa’s website – sets out three immediate key actions that security teams can take:
- Setting up digital ‘tripwires’ around high-value assets;
- Using Mitre ATT&CK and Mitre Engage frameworks to map threat actor tactics, techniques and procedures (TTPs) and design decoy coverage;
- Implement threat emulation to continuously test and refine decoys.
NCSC: Deceptive decoys are compelling, but not without risk
While the NCSC has not formalised any guidance of its own, it has been working with British organisations to develop a national evidence base for deceptive cyber tactics such as decoys. The NCSC believes there is a “compelling case” for increasing the use of cyber deception and has been working to develop a new Active Cyber Defence (ACD) service to develop and deploy of such tactics at a national scale.
In December 2025, the agency revealed the results of a series of tests conducted with the help of 121 end-user organisations and 14 technology suppliers under the auspices of its ACD 2.0 programme.
This work tested three core assumptions: that cyber deception can help find hidden compromises inside IT environments and networks; that it can help detect attacks in progress; and that it can change how threat actors behave if they are aware it is in play.
The NCSC said that cyber deception can work but is not a plug-and-play solution. Among other things, the test group found that effective cyber deception requires accurate data and context, and without a clear strategy in place, they risk just creating more noise, rather than genuine insight. A guidance gap also exists, in that while organisations are interested in the idea of deception and decoys, there is no real body of impartial advice or real-life case studies to draw upon.
The tests also found evidence of a disconnect, in that the vast majority of participants did not want to say publicly they were using such tactics – understandably – but that objective research into cyber deception had found that when threat actors believe deceptive tactics are in play they lose confidence in themselves and may even make mistakes.
Finally there was evidence of several risks associated with cyber deception – not least the potential for misconfiguration rendering efforts ineffective or worse, creating openings for threat actors, while confusion around terminology in this emerging area of defence also appeared widespread, suggesting a need for standardised vocabulary.
Andy Smith co-founder and CEO at Tracebit, said: “We welcome Cisa’s guidance on deploying decoys, the first time it has endorsed this approach. AI has changed the game in terms of making it easier to deploy canaries at scale but most importantly, maintain them so decoy material appears fresh and relevant to an attacker.
“One benefit the Cisa report misses is the psychological impact of using decoys. Attackers generally want a ‘quick win’ but decoys waste their time and make their job harder. They also work against malicious AI agents and burn up tokens, which adds to the cost and time of an attack. Anything that adds cost and time to an attacker makes it more likely they will move on to the next target.”
Sysdig senior cyber security strategist Crystal Morin was also supportive. “Cisa is right; decoys work,” she said. “But the catch is that certain traps are only useful against one adversary class or the other, AI-driven or human, so you have to plan for both.”
Morin outlined a recent example in which Sysdig’s researchers planted a prompt injection inside a vulnerable container while looking into a series of vulnerabilities. This essentially told any large language model (LLM) reading the file to echo a hidden marker back into its output. She found that while every AI that popped up did exactly this, a human who found the decoy opened the file, recognised the bait, and “simply stepped over the tripwire.”
“Not all decoys are created equal. The right decoy in the right spot will even help reduce mean time to detect, but you have to match the decoy to the adversary class. Strong posture and hygiene still matter, as does having an assume-breach failsafe in place. Regardless of who or what is driving an attack, you must be able to detect and stop the threat in real time,” said Morin.
“Decoys can be a great distraction for adversaries, but a distraction isn’t containment,” she warned.

