The Cybersecurity and Infrastructure Security Agency has a new idea for defending power plants, water utilities, and other critical infrastructure: stop trying to keep every attacker out, and start feeding the ones who get in a diet of fake data. CISA's newly issued guidance advises critical infrastructure operators to deploy cyber decoys and honeytokens, low-cost digital traps designed to detect intruders early and slow them down before they reach real systems. It's a notable shift in tone from an agency that has spent years focused almost entirely on patching, perimeter defense, and access control.
What CISA's Guidance Actually Recommends
At its core, the guidance describes two related tools. Honeytokens are fake files, credentials, database records, or secrets planted inside a network that serve no legitimate business purpose. Their only job is to sit there looking valuable. If anyone accesses or attempts to use one, that's an immediate red flag, because no authorized employee or system should ever touch it. Honeypots take the concept further, setting up entire decoy systems designed to look like real servers, workstations, or industrial control assets, luring attackers away from the actual environment and giving defenders time to observe their tactics.
CISA frames these as accessible options for organizations at any level of cybersecurity maturity, not just agencies with large security budgets. That matters for critical infrastructure operators, many of which run lean IT and security teams and can't afford enterprise-grade threat detection platforms. A honeytoken, by contrast, can be as simple as a fake credential dropped in a file share. It costs little to deploy but can generate a high-confidence alert the moment someone interacts with it.
How Decoys Work Alongside VPNs and Network Segmentation
Deception technology isn't meant to replace the tools organizations already rely on, like VPNs, firewalls, and network segmentation. It's meant to fill the gap those tools leave behind. VPNs and access controls are built to keep unauthorized users out in the first place. But attackers increasingly find ways around those defenses by exploiting compromised credentials or vulnerabilities in remote-access infrastructure itself. CISA's own advisory on Gunra ransomware targeting VPNs is a clear example: threat actors are actively probing remote-access weaknesses to get a foothold, meaning perimeter defenses alone are no longer enough.
Honeytokens and decoys operate on the assumption that determined attackers will eventually breach the perimeter, whether through a stolen VPN credential, a phishing email, or an unpatched vulnerability. Once inside, decoys act as tripwires. If an intruder moves through a segmented network looking for valuable data or systems, a honeytoken planted in the wrong place can catch them almost immediately, often before they've done meaningful damage. It's a layered approach: VPNs and segmentation slow attackers down and limit their reach, while decoys make it far harder for them to move undetected once they're inside.
Why Critical Infrastructure Operators Are the Priority Target
CISA's decision to aim this guidance squarely at critical infrastructure operators reflects where the stakes are highest. Water systems, energy providers, and other essential services often run a mix of modern IT networks and older operational technology that wasn't designed with cybersecurity in mind. That combination makes them attractive targets and difficult to defend with traditional tools alone. The recent Minnesota water cyberattack that hit more than 30 systems over just two days illustrates how quickly coordinated attacks can spread across infrastructure providers that may lack the resources of a large enterprise security team. Deception technology offers these organizations a way to punch above their weight, generating high-fidelity alerts without requiring constant monitoring or expensive detection platforms.
What This Means for Detecting Lateral Movement After a Breach
One of the hardest problems in incident response is figuring out how far an attacker has traveled inside a network after the initial breach. Attackers who gain a foothold often spend days or weeks quietly moving laterally, escalating privileges, and mapping out valuable systems before launching a ransomware payload or exfiltrating data. Traditional security tools can struggle to distinguish this quiet reconnaissance from normal network activity.
Honeytokens change that calculus. Because they have no legitimate use, any interaction with one is an almost guaranteed sign of malicious activity, cutting through the noise that normally buries early warning signs. For critical infrastructure operators trying to catch intruders before they reach operational technology or customer data, that early signal can be the difference between a contained incident and a full-blown outage.
What This Means For You
If you work in IT or security for a utility, municipal system, or other infrastructure operator, CISA's guidance is worth reading in full and treating as a low-cost addition to your existing defenses, not a replacement for them. VPNs, multi-factor authentication, and network segmentation remain essential for keeping attackers out. Decoys and honeytokens are about catching the ones who get past those defenses anyway. Even organizations without dedicated security staff can start small, planting a handful of fake credentials or files in sensitive locations and setting up alerts for any interaction with them.
For everyday users and smaller organizations, the bigger takeaway is a reminder that no single security layer is foolproof. Attackers are constantly probing remote-access tools, as seen in ongoing ransomware campaigns exploiting VPN weaknesses, which means defense in depth matters more than ever.
Key Takeaways
- CISA's guidance on cyber decoys and honeytokens gives critical infrastructure operators a low-cost way to detect intruders early.
- Decoys complement, rather than replace, VPNs, access controls, and network segmentation.
- Honeytokens are especially effective at flagging lateral movement after a breach, since legitimate users never interact with them.
- Smaller infrastructure operators with limited security budgets are a priority audience for this approach.
- Organizations should pair deception technology with strong perimeter defenses, since attackers continue to target remote-access weaknesses to gain initial footholds.




