2026 review

Executive summary

Main decisions for security teams.

Download MarkdownBibTeX bibliography

Executive summary

15 September 2026

Cyber deception uses decoy systems, data or signals to detect and study adversary activity. It can supplement existing visibility and help identify lateral movement, credential use or reconnaissance. Its effectiveness depends on placement, realism, maintenance and the ability to respond to alerts. The UK NCSC found operational interest, but also missing outcome measures and demand for impartial guidance.

Decisions for a security team

  1. Define the behavior to detect and the surface to cover.
  2. Choose one or two decoys with a clear hypothesis, such as a file nobody should open or a simulated internal service.
  3. Document who receives an alert, what they check and how quickly they respond.
  4. Measure useful events and operational cost as well as total alert volume.
  5. Check whether decoys remain credible as real assets change.

Reading the market

The catalog separates open software, products and services. OpenCanary and Cowrie are open tools with different purposes. Thinkst Canary and FortiDeceptor are commercial examples. Vendor pages document capabilities; comparing outcomes needs tests and further evidence.

Role of the Atlas

Every record identifies technique, environment, source and review depth. Search finds options by problem, comparison displays published data and research connects findings with tools. Coverage is growing, with gaps displayed openly.