Guidelines  ·  2026-09-21

CISA guidance on cyber decoys (realistic decoys) for critical infrastructure

GuidelinesMedium impactUnited States
CISA published (~16 September 2026) new guidance helping critical infrastructure detect, observe and impede malicious cyber activity by placing realistic decoy systems and 'honeytoken' information assets inside internal and high-value network areas to reveal post-compromise discovery, lateral movement, and data access by actors using valid credentials and native admin tools. Implementation is mapped to MITRE ATT&CK and MITRE Engage and positioned as a complement to Zero Trust.
High-fidelity decoy alerts expose living-off-the-land and credential-abuse activity that bypasses conventional controls — including activity attributable to AI-agent-enabled intrusions. It is the principal federal posture publication of the window and may feed sector regulator procurement/control expectations.
Review the guidance and pilot decoy/honeytoken placement in high-value network segments; align the deployment with ATT&CK/Engage mappings and existing detection stacks.
CISA news — New CISA Guidance Helps Critical Infrastructure Detect, Observe and Impede Malicious Cyber Activity
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →