2026 review

Evaluate products and services

Compare offerings with a documented test.

Download MarkdownBibTeX bibliography

Evaluating products and services

Guide · 15 September 2026

Define the scenario

State the target environment: internal network, identity, cloud, application, OT or IoT. List the behavior to detect and the system receiving alerts. Offerings covering different surfaces should not be treated as interchangeable.

Record documented capabilities

For each solution, record decoy types, installation requirements, placement, integrations, operating effort and security controls. Link every item to a dated page, document or test. Vendor-stated features remain labeled as such. Commercial portfolios include Acalvio, Fortinet and CounterCraft.

Design a comparable test

Use the same attack scenario and observation period. Measure deployment time, alert delay, useful information, maintenance effort, decoy recognition and integration quality. Document authorized test events and the state of real assets. A vendor demo can show an interface; its outcomes do not equal independent testing.

Evaluate services

Request a concrete scope: design, deployment, tuning, ongoing operation, education and alert support. Identify who maintains decoys and who investigates alerts. Check regional and language coverage, deliverables and commercial model against public documents or verifiable proposals.

Make a decision

Compare total operational cost and measured outcome against the initial objective. Mark unknown public data rather than converting it automatically to a negative score. Keep your reasons and sources so the choice can be revisited as the offering changes.

The NCSC found this market difficult to navigate and many organizations requested impartial guidance and real cases.