Clicky

mobile btn
Saturday, September 19th, 2026

Guidance will help detect, disrupt malicious activity on networks

© Shutterstock

New guidance from the Cybersecurity and Infrastructure Security Agency (CISA) aims to help critical infrastructure owners and operators implement realistic decoy systems and information assets that can quickly detect and disrupt malicious activity occurring in their networks.

The ability to detect adversaries who use legitimate credentials, native tools and living-off-the-land techniques to conduct discovery, move laterally and access data is a challenge faced by many organizations. CISA encourages incorporating cyber decoy capabilities alongside existing Zero Trust models.

“Cyber decoys used in a proactive cyber defense strategy help make critical infrastructure networks unfriendly places for adversaries and enhance resilience to compromise, even against living-off-the-land techniques,” Chris Butera, CISA acting executive assistant director for cybersecurity, said. “With this guide, CISA is raising awareness of cyber decoy techniques and enabling any defensive team regardless of skill level to understand the value and steps to implementing decoy operations. CISA encourages critical infrastructure organizations to review this guide and implement a cyber decoy strategy.”

The decoy operates on the expectation that malicious actors may eventually gain some level of access. Having a decoy in place allows organizations to detect adversaries early, reduce the time to detection by generating high-fidelity alerts, allocate defensive resources more effectively, and
gather and analyze information taken from intrusions and attempted intrusions.