CISA has released new guidance encouraging critical infrastructure operators to use cyber decoys, such as fake systems, accounts, and data, to detect and distract intruders already inside their networks. The 22-page guide explains how honeytokens and other decoy techniques can support zero-trust and assume-compromise defenses at low cost. #CISA #CyberDecoys #Honeytokens
Keypoints
- CISA is advising critical infrastructure owners to deploy cyber decoys.
- The guidance aims to help detect attackers after initial network access.
- Honeytokens include fake records, credentials, and files that reveal unauthorized activity.
- The approach is designed to be low-cost and effective for under-resourced teams.
- CISA says decoys complement zero-trust and assume-compromise strategies.
Read More: https://cyberscoop.com/cisa-guidance-cyber-decoys-critical-infrastructure/