Home Β· Wiki Β· Incidents & Campaigns
type: incident Β· created: 2026-09-17 Β· updated: 2026-09-17 Β· tags: [incident, government] Β· confidence: high Β· severity: medium Β· affected_sectors: [government] Β· au_impact: true

CISA has released Using Cyber Decoys to Strengthen Detection and Response, described by the agency as its first guide offering a detailed explanation of the defensive cyber decoy process. The framing is unusually candid about the detection problem it exists to solve: many organisations struggle to detect adversaries who use legitimate credentials, native tools and living-off-the-land techniques to conduct discovery, move laterally and reach data β€” the class of intrusion that leaves patching maturity intact and offers little to signature-based monitoring. CISA's answer is to place realistic decoy systems and information assets inside internal networks, "especially in high-value areas", so that defenders can detect an adversary early in the intrusion lifecycle, gather information from intrusions and attempted intrusions, allocate defensive resources based on observed adversary behaviour, and reduce mean time to detection by generating high-fidelity alerts. The guide is positioned as a complement to existing Zero Trust programmes rather than a substitute, and it assumes decoy strategies operate on the premise that a malicious actor may eventually gain some level of access β€” a departure from perimeter assumptions. CISA Acting Executive Assistant Director for Cybersecurity Chris Butera framed decoys as making critical-infrastructure networks "unfriendly places for adversaries" and as enhancing resilience to compromise even against living-off-the-land technique, and the agency states the guide is written so that any defensive team, "regardless of skill level", can understand the value of decoy operations. Defenders using it are expected to have a basic grasp of the MITRE ATT&CK matrix and common enterprise security controls, because the practical method is built on ATT&CK and the MITRE Engage framework β€” Engage being the adversary-engagement counterpart to ATT&CK's behavioural taxonomy. The operational significance is that CISA is now formalising a control that sits between detection engineering and active defence, and doing so for a threat profile that has dominated its own KEV additions this year.

Attribute Detail
Sector Government
Date 2026-09-17
Source CISA
Reliability Tier 1