CISA pitches cheap decoys as a tripwire for hospital intruders

New CISA guidance urges resource-stretched critical infrastructure teams, hospitals included, to plant fake accounts and credentials that catch credential-based intruders.

MedRisk Staff
By
2 Min Read

CISA has published guidance urging critical infrastructure operators, hospitals and health systems among them, to plant cyber decoys, arguing that tripwires catch the intruders conventional defenses miss.

The problem CISA targets is the adversary who logs in with valid credentials and moves with built-in administrative tools, leaving few malware signatures to detect. The agency’s document, “Using Cyber Decoys to Strengthen Detection and Response,” makes the case that once an organization accepts intruders will get a foothold, the smarter play is to seed the environment with honeytokens, fake systems, fake accounts, and credentials no legitimate user would ever touch. Any interaction trips an alarm. CISA argues the approach can also impose cost on attackers and reduce the value of their work.

The pitch is aimed at teams without large budgets. CISA says decoys need no major architectural changes and no new spending: organizations can repurpose the EDR platforms, identity and access management systems, and data loss prevention tooling they already run to deploy and monitor them. Open-source token generators are another option, with commercial and custom honeytokens for teams that have developers to spare.

For rural hospitals and small clinics the appeal is obvious. A fake clinician login or a decoy imaging server costs little and can surface an intruder long before encryption starts. The tradeoff is upkeep: decoys that nobody monitors, or that drift out of step with the real environment, quietly stop working.

Share This Article