What happened
CISA published (~16 September 2026) new guidance helping critical infrastructure detect, observe and impede malicious cyber activity by placing realistic decoy systems and 'honeytoken' information assets inside internal and high-value network areas to reveal post-compromise discovery, lateral movement, and data access by actors using valid credentials and native admin tools. Implementation is mapped to MITRE ATT&CK and MITRE Engage and positioned as a complement to Zero Trust.
Why it matters
High-fidelity decoy alerts expose living-off-the-land and credential-abuse activity that bypasses conventional controls — including activity attributable to AI-agent-enabled intrusions. It is the principal federal posture publication of the window and may feed sector regulator procurement/control expectations.
Action needed
Review the guidance and pilot decoy/honeytoken placement in high-value network segments; align the deployment with ATT&CK/Engage mappings and existing detection stacks.