
Cyber Security — Deception
Know when they are
already inside.
Plant lifelike decoys inside your network. Nobody touches them in day-to-day work, so the moment one is touched you are almost certainly looking at an intruder — a second layer of defense, sitting outside the perimeter you have already hardened.
In 30 seconds
Without a single piece of jargon
Not blocking. Noticing.
This is not a product that stops 100% of intrusions. It is a way to find an intruder early and act before the damage spreads.
A safe that holds nothing
We place fake servers and fake confidential files inside your network. No employee has a business reason to touch them, so a single touch becomes an event worth investigating.
Nothing you already own gets replaced
Your antivirus and firewall stay exactly where they are. This plays a different role, so it is added on top rather than swapped in.
Why now
A guard cannot tell
a stolen key from a real one.
Most security spending buys a lock and a guard at the front door. Against someone trying to force their way in, that works.
But a great many of today’s intrusions arrive with a stolen ID and password and walk in “as an employee.” Suppliers, contractors and group companies are used as stepping stones. To the guard at the door, it simply looks like staff arriving for work.
Cases in Japan and abroad have seen weeks or months pass between the intrusion and its discovery. For an attacker, that unwatched stretch of time is the most valuable asset there is.


How an attack unfolds
Ransomware does not fire the moment they get in.
An attacker does not encrypt everything the moment they arrive. They survey the network, take over privileges, move toward the systems that matter — and only then pull the trigger. That preparation window is the one chance you have to move first.
- 01Initial access
A mail attachment, a stolen credential, an unpatched VPN appliance, a compromised supplier. The stage everyone wants to seal shut — and the one nobody seals completely.
- 02Discovery — this is where you catch them
The attacker maps the place: shared folders, server lists, administrator accounts. This is when a decoy is most likely to be touched.
- 03Privilege escalation and credential theft — this is where you catch them
They harvest saved passwords and connection history and climb to administrator rights. Plant a fake credential and the moment it is used, you know.
- 04Lateral movement — this is where you catch them
From the first machine to the next PC, the file server, the core systems. This is the line between one infected laptop and a company-wide incident.
- 05Impact — encryption and exfiltration
Data is stolen, then encrypted, then ransomed. By this point the only decisions left are recovery and disclosure.
Deception owns stages 02 to 04 — the stretch where the attacker is still feeling around inside your network.
How it works
Place it. Wait. Catch them.
Deception is a defensive technique that misleads an attacker into somewhere that is not real. Because it makes no difficult judgement calls, the mechanism itself is remarkably simple.
Place
Fake servers, fake PCs, fake cameras and fake control devices are woven into the network. These are the decoys. Your real production systems are not modified.
Wait
On real endpoints we leave fake saved passwords and fake network shortcuts — the breadcrumbs. Nobody uses them in normal work, so in quiet periods the alert count is zero.
Catch
The moment an attacker picks up a breadcrumb and connects to a decoy, the alert fires — with a record of who, from which machine, using what tooling, and what they were after.

The core idea
No judgement call
to get wrong.
Conventional detection has to separate an employee’s actions from an attacker’s. Because the two look alike, it can only work in probabilities — and that produces a flood of alerts. Analysts going numb to those alerts is the single most common failure in the field.
Deception throws that judgement away. A decoy has no business purpose, so no legitimate user has any reason to reach it. “It was touched” therefore equals “something is wrong” — a fact, not a probability.
It is not a silver bullet. An attack that reaches its goal without ever touching a decoy will not be caught. That is exactly why it belongs in a layered defense alongside perimeter and endpoint controls. Be wary of any vendor who tells you one product is enough.
Where it fits
It fills an empty slot rather than replacing one.
Every security product watches a different place. Start by laying out what you already have and where the gap is.
| Control | What it watches | What it tells you |
|---|---|---|
| Firewall / IPS | The perimeter | Whether inbound traffic was blocked |
| Antivirus / EDR | Each individual endpoint | Whether something suspicious ran on that machine |
| SIEM / log monitoring | The records every device leaves | Whether a signal is buried in the noise |
| Vulnerability assessment / penetration testing | Your own weak points | Where an attacker could get in |
| Deception | Inside the network | Whether an intruder is moving through it right now |

Factories and critical infrastructure
You cannot install
agents on a line that never stops.
The domain that runs production lines, power, water and building systems is called OT — operational technology. It carries constraints that IT simply does not have.
- ◆It cannot be stopped
A planned outage for a reboot or a patch may be available only a few times a year.
- ◆Legacy operating systems are still in service
Equipment lives 10 to 20 years. Unsupported operating systems still running production is not unusual.
- ◆Nothing can be installed on the device
Adding software to a controller can void support or change how it behaves.
Because decoys live on the network side, the production equipment itself is untouched. Decoys that impersonate controllers and IoT devices let you see someone probing the plant network without taking anything offline.

How we roll it out
We do not recommend starting company-wide.
Run a four-to-six-week trial on one important segment first, see what it actually surfaces in your environment, then widen the scope. That wastes the least money.
- 01Discovery workshop
We map the assets that matter, the network, the sites, the current operating model and who answers an alert at 2am. Without deciding what to protect, there is no way to design decoy placement.
- 02Placement design
Which segments, how many decoys, and what each one should look like. The design follows your real environment so the decoys read as natural from an attacker’s point of view.
- 03Trial deployment (4–6 weeks)
We run it for real on a limited scope, validate detection against attack scenarios, and report the results in language the board can act on.
- 04Production build
We stand up the management server, deploy the decoys, wire the alerts into your existing log platform and EDR, and train your administrators.
- 05Operations
We build the response runbook, refresh decoy placement at regular reviews, and take first-line calls in Japanese — escalating to the developer when it is warranted.
What we provide
We do not hand over a licence and walk away.
With deception, placement design and operations decide almost everything. We take on the platform, the deployment design for Japan, and Japanese-language operational support as one package.
The deception platform
We supply a deception platform developed in Ukraine — a country under relentless cyberattack — with a deployment record that includes financial institutions and state bodies. It covers both IT and OT environments.
Deployment design for Japan
Japanese white-hat hackers with public-sector experience work with our engineers on the ground in Ukraine — from analysing the target network to decoy placement, detection rules and the response runbook.
Japanese-language operations
First-line response, administrator training, periodic reviews and technical escalation to the developer, all in Japanese. You never end up with an English-only support desk as your only option.
Better together
“Where could they get in?” and “what happens after they do?” are two different questions.
A penetration test follows the same path a real attacker would and tells you which holes to close. Deception makes sure that when someone still gets through, you find out. Offensive validation plus assume-breach defense — together they turn a one-off assessment into an actual security posture.
Who this is for
For organisations where an outage is a business outage
“If the core system were down for three days, what would it cost?” Organisations that can answer that in figures decide faster — and run the platform better once it is in.
Glossary
The vocabulary of this field, in plain words.
These are the terms that turn up in every proposal and quotation. Use them for internal briefings and approval papers.
Terms for how attackers move
The moment an attacker first gets inside: a mail attachment, a stolen credential, an unpatched VPN appliance, or a compromised supplier.
The attacker works out what the organisation looks like — shared folders, server lists, administrator accounts. This is where deception bites hardest.
Climbing from an ordinary user account to administrator rights. Once this happens, the blast radius widens fast.
Stealing IDs, passwords and access tokens left on machines. From then on the attacker’s activity looks like a legitimate login, which is what makes it so hard to spot.
Moving from the first compromised machine to the next PC, the file server, the core systems. The line between one laptop and the whole company.
The channel malware uses to reach its operator and take orders — usually disguised to blend into ordinary business traffic.
Sending designs, customer data or contracts out of the company. Modern ransomware almost always steals before it encrypts — double extortion.
Encrypting data and demanding payment to release it. Days or weeks of preparation usually precede the encryption — and whether you notice in that window decides the size of the loss.
How long an attacker sits inside before being found. The longer it runs, the further the reconnaissance, privilege theft and data theft have progressed.
Hitting the real target through a less-defended supplier, contractor or subsidiary. It is why hardening only your own perimeter is not enough.
An attack against a flaw with no patch available yet. “We would have been fine if we had updated” does not apply.
Theft or sabotage by someone who legitimately holds access — staff, ex-staff or contractors. Harder to detect than an outside attack precisely because the access is genuine.
Terms for the defender’s toolkit
Sits at the boundary and sorts traffic that may pass from traffic that may not. The gatekeeper at the front door.
Installed on each PC and server to watch, record and remotely contain suspicious behaviour on that machine. It sees inside the endpoint, not across the network.
Collects logs from every device into one place and correlates them to find anomalies. The more it collects, the harder it becomes to decide what should raise an alert.
The team that watches alerts around the clock and makes the first call. Either in-house or outsourced.
A system placed deliberately to be attacked, so that the tools and techniques used can be recorded.
A fake asset that impersonates a real server, PC, IoT device or industrial controller, planted inside the network to wait for contact.
Fake saved passwords, fake network shortcuts and fake connection history left on real endpoints. The attacker treats them as a find, and follows them to a decoy.
An alert that fires when nothing is wrong. Too many, and real alerts get buried and analysts stop reacting — alert fatigue.
The traces an attack leaves — IP addresses, file hashes, domains. Distributing them to other controls lets you shut down the same attack elsewhere.
A public catalogue of the techniques attackers actually use. It gives everyone a common language for arguing about which stages you can and cannot detect.
Layering controls with different jobs — perimeter, endpoint, internal, forensic — rather than betting on one. Deception owns the internal layer.
Designing on the basis that being inside the network proves nothing, and verifying user, device and traffic every time. It assumes breach, which is why it pairs naturally with deception.
Average time to detect, and average time to respond or recover. The standard way to measure how fast a security function actually moves.
An authorised attempt to break in using the same methods a real attacker would. A vulnerability scan lists holes; this proves whether they can actually be walked through.
Terms for networks and environments
The technology that physically moves things — production lines, power, water, building systems. Unlike IT, it cannot be stopped and cannot easily be rebuilt.
The systems that control and monitor industrial equipment. Because uptime comes first, unsupported legacy operating systems often remain in service.
A way to split one physical network into several logical ones — the partitions between departments or process lines.
Dividing the network by function and criticality so that a breach in one area does not become a breach everywhere. Decoys are normally deployed segment by segment.
Networked cameras, printers, door controllers and sensors. They fall off the asset register and rarely get updated, which makes them a convenient foothold.
Devices and services connected without the IT function knowing. Nobody counts them as things to protect, which is exactly why they become entry points.
FAQ
Frequently asked questions
Do we have to replace the antivirus and firewall we already use?
Will it affect production systems or plant equipment?
Can we run this without a dedicated security specialist on staff?
How large does an organisation need to be?
What does it cost?
How long does deployment take?
Will an attacker recognise the decoys for what they are?
It is a foreign product — is support available in Japanese?
Start by telling us what you have.
Before deciding whether to deploy anything, it is worth laying out the assets that matter and the team you have today. There is no charge for the conversation or the quotation.
Contact us →