Cyber Security — Deception

Know when they are
already inside.

Plant lifelike decoys inside your network. Nobody touches them in day-to-day work, so the moment one is touched you are almost certainly looking at an intruder — a second layer of defense, sitting outside the perimeter you have already hardened.

In 30 seconds

Without a single piece of jargon

01

Not blocking. Noticing.

This is not a product that stops 100% of intrusions. It is a way to find an intruder early and act before the damage spreads.

02

A safe that holds nothing

We place fake servers and fake confidential files inside your network. No employee has a business reason to touch them, so a single touch becomes an event worth investigating.

03

Nothing you already own gets replaced

Your antivirus and firewall stay exactly where they are. This plays a different role, so it is added on top rather than swapped in.

Why now

A guard cannot tell
a stolen key from a real one.

Most security spending buys a lock and a guard at the front door. Against someone trying to force their way in, that works.

But a great many of today’s intrusions arrive with a stolen ID and password and walk in “as an employee.” Suppliers, contractors and group companies are used as stepping stones. To the guard at the door, it simply looks like staff arriving for work.

Cases in Japan and abroad have seen weeks or months pass between the intrusion and its discovery. For an attacker, that unwatched stretch of time is the most valuable asset there is.

How an attack unfolds

Ransomware does not fire the moment they get in.

An attacker does not encrypt everything the moment they arrive. They survey the network, take over privileges, move toward the systems that matter — and only then pull the trigger. That preparation window is the one chance you have to move first.

  1. 01
    Initial access

    A mail attachment, a stolen credential, an unpatched VPN appliance, a compromised supplier. The stage everyone wants to seal shut — and the one nobody seals completely.

  2. 02
    Discovery — this is where you catch them

    The attacker maps the place: shared folders, server lists, administrator accounts. This is when a decoy is most likely to be touched.

  3. 03
    Privilege escalation and credential theft — this is where you catch them

    They harvest saved passwords and connection history and climb to administrator rights. Plant a fake credential and the moment it is used, you know.

  4. 04
    Lateral movement — this is where you catch them

    From the first machine to the next PC, the file server, the core systems. This is the line between one infected laptop and a company-wide incident.

  5. 05
    Impact — encryption and exfiltration

    Data is stolen, then encrypted, then ransomed. By this point the only decisions left are recovery and disclosure.

Deception owns stages 02 to 04 — the stretch where the attacker is still feeling around inside your network.

How it works

Place it. Wait. Catch them.

Deception is a defensive technique that misleads an attacker into somewhere that is not real. Because it makes no difficult judgement calls, the mechanism itself is remarkably simple.

01

Place

Fake servers, fake PCs, fake cameras and fake control devices are woven into the network. These are the decoys. Your real production systems are not modified.

02

Wait

On real endpoints we leave fake saved passwords and fake network shortcuts — the breadcrumbs. Nobody uses them in normal work, so in quiet periods the alert count is zero.

03

Catch

The moment an attacker picks up a breadcrumb and connects to a decoy, the alert fires — with a record of who, from which machine, using what tooling, and what they were after.

The core idea

No judgement call
to get wrong.

Conventional detection has to separate an employee’s actions from an attacker’s. Because the two look alike, it can only work in probabilities — and that produces a flood of alerts. Analysts going numb to those alerts is the single most common failure in the field.

Deception throws that judgement away. A decoy has no business purpose, so no legitimate user has any reason to reach it. “It was touched” therefore equals “something is wrong” — a fact, not a probability.

Being straight with you
It is not a silver bullet. An attack that reaches its goal without ever touching a decoy will not be caught. That is exactly why it belongs in a layered defense alongside perimeter and endpoint controls. Be wary of any vendor who tells you one product is enough.

Where it fits

It fills an empty slot rather than replacing one.

Every security product watches a different place. Start by laying out what you already have and where the gap is.

Control What it watches What it tells you
Firewall / IPSThe perimeterWhether inbound traffic was blocked
Antivirus / EDREach individual endpointWhether something suspicious ran on that machine
SIEM / log monitoringThe records every device leavesWhether a signal is buried in the noise
Vulnerability assessment / penetration testingYour own weak pointsWhere an attacker could get in
DeceptionInside the networkWhether an intruder is moving through it right now

Factories and critical infrastructure

You cannot install
agents on a line that never stops.

The domain that runs production lines, power, water and building systems is called OT — operational technology. It carries constraints that IT simply does not have.

  • It cannot be stopped

    A planned outage for a reboot or a patch may be available only a few times a year.

  • Legacy operating systems are still in service

    Equipment lives 10 to 20 years. Unsupported operating systems still running production is not unusual.

  • Nothing can be installed on the device

    Adding software to a controller can void support or change how it behaves.

Because decoys live on the network side, the production equipment itself is untouched. Decoys that impersonate controllers and IoT devices let you see someone probing the plant network without taking anything offline.

How we roll it out

We do not recommend starting company-wide.

Run a four-to-six-week trial on one important segment first, see what it actually surfaces in your environment, then widen the scope. That wastes the least money.

  1. 01
    Discovery workshop

    We map the assets that matter, the network, the sites, the current operating model and who answers an alert at 2am. Without deciding what to protect, there is no way to design decoy placement.

  2. 02
    Placement design

    Which segments, how many decoys, and what each one should look like. The design follows your real environment so the decoys read as natural from an attacker’s point of view.

  3. 03
    Trial deployment (4–6 weeks)

    We run it for real on a limited scope, validate detection against attack scenarios, and report the results in language the board can act on.

  4. 04
    Production build

    We stand up the management server, deploy the decoys, wire the alerts into your existing log platform and EDR, and train your administrators.

  5. 05
    Operations

    We build the response runbook, refresh decoy placement at regular reviews, and take first-line calls in Japanese — escalating to the developer when it is warranted.

What we provide

We do not hand over a licence and walk away.

With deception, placement design and operations decide almost everything. We take on the platform, the deployment design for Japan, and Japanese-language operational support as one package.

Layer 1

The deception platform

We supply a deception platform developed in Ukraine — a country under relentless cyberattack — with a deployment record that includes financial institutions and state bodies. It covers both IT and OT environments.

Layer 2

Deployment design for Japan

Japanese white-hat hackers with public-sector experience work with our engineers on the ground in Ukraine — from analysing the target network to decoy placement, detection rules and the response runbook.

Layer 3

Japanese-language operations

First-line response, administrator training, periodic reviews and technical escalation to the developer, all in Japanese. You never end up with an English-only support desk as your only option.

Better together

“Where could they get in?” and “what happens after they do?” are two different questions.

A penetration test follows the same path a real attacker would and tells you which holes to close. Deception makes sure that when someone still gets through, you find out. Offensive validation plus assume-breach defense — together they turn a one-off assessment into an actual security posture.

Who this is for

For organisations where an outage is a business outage

Manufacturing and plants (OT) Financial institutions Healthcare Logistics and retail (POS) Telecommunications Government and municipalities Critical infrastructure Multi-site enterprises Companies with supplier system links

“If the core system were down for three days, what would it cost?” Organisations that can answer that in figures decide faster — and run the platform better once it is in.

Glossary

The vocabulary of this field, in plain words.

These are the terms that turn up in every proposal and quotation. Use them for internal briefings and approval papers.

Terms for how attackers move

Initial Access Initial Access

The moment an attacker first gets inside: a mail attachment, a stolen credential, an unpatched VPN appliance, or a compromised supplier.

Discovery Discovery

The attacker works out what the organisation looks like — shared folders, server lists, administrator accounts. This is where deception bites hardest.

Privilege Escalation Privilege Escalation

Climbing from an ordinary user account to administrator rights. Once this happens, the blast radius widens fast.

Credential Access Credential Access

Stealing IDs, passwords and access tokens left on machines. From then on the attacker’s activity looks like a legitimate login, which is what makes it so hard to spot.

Lateral Movement Lateral Movement

Moving from the first compromised machine to the next PC, the file server, the core systems. The line between one laptop and the whole company.

Command and Control Command and Control

The channel malware uses to reach its operator and take orders — usually disguised to blend into ordinary business traffic.

Exfiltration Exfiltration

Sending designs, customer data or contracts out of the company. Modern ransomware almost always steals before it encrypts — double extortion.

Ransomware Ransomware

Encrypting data and demanding payment to release it. Days or weeks of preparation usually precede the encryption — and whether you notice in that window decides the size of the loss.

Dwell Time Dwell Time

How long an attacker sits inside before being found. The longer it runs, the further the reconnaissance, privilege theft and data theft have progressed.

Supply Chain Attack Supply Chain Attack

Hitting the real target through a less-defended supplier, contractor or subsidiary. It is why hardening only your own perimeter is not enough.

Zero-day Zero-day

An attack against a flaw with no patch available yet. “We would have been fine if we had updated” does not apply.

Insider Threat Insider Threat

Theft or sabotage by someone who legitimately holds access — staff, ex-staff or contractors. Harder to detect than an outside attack precisely because the access is genuine.

Terms for the defender’s toolkit

Firewall Firewall

Sits at the boundary and sorts traffic that may pass from traffic that may not. The gatekeeper at the front door.

Endpoint Detection and Response Endpoint Detection and Response

Installed on each PC and server to watch, record and remotely contain suspicious behaviour on that machine. It sees inside the endpoint, not across the network.

Security Information and Event Management Security Information and Event Management

Collects logs from every device into one place and correlates them to find anomalies. The more it collects, the harder it becomes to decide what should raise an alert.

Security Operation Center Security Operation Center

The team that watches alerts around the clock and makes the first call. Either in-house or outsourced.

Honeypot Honeypot

A system placed deliberately to be attacked, so that the tools and techniques used can be recorded.

Decoy Decoy

A fake asset that impersonates a real server, PC, IoT device or industrial controller, planted inside the network to wait for contact.

Breadcrumbs Breadcrumbs

Fake saved passwords, fake network shortcuts and fake connection history left on real endpoints. The attacker treats them as a find, and follows them to a decoy.

False Positive False Positive

An alert that fires when nothing is wrong. Too many, and real alerts get buried and analysts stop reacting — alert fatigue.

Indicator of Compromise Indicator of Compromise

The traces an attack leaves — IP addresses, file hashes, domains. Distributing them to other controls lets you shut down the same attack elsewhere.

MITRE ATT&CK MITRE ATT&CK

A public catalogue of the techniques attackers actually use. It gives everyone a common language for arguing about which stages you can and cannot detect.

Defense in Depth Defense in Depth

Layering controls with different jobs — perimeter, endpoint, internal, forensic — rather than betting on one. Deception owns the internal layer.

Zero Trust Zero Trust

Designing on the basis that being inside the network proves nothing, and verifying user, device and traffic every time. It assumes breach, which is why it pairs naturally with deception.

Mean Time to Detect / Respond Mean Time to Detect / Respond

Average time to detect, and average time to respond or recover. The standard way to measure how fast a security function actually moves.

Penetration Testing Penetration Testing

An authorised attempt to break in using the same methods a real attacker would. A vulnerability scan lists holes; this proves whether they can actually be walked through.

Terms for networks and environments

Operational Technology Operational Technology

The technology that physically moves things — production lines, power, water, building systems. Unlike IT, it cannot be stopped and cannot easily be rebuilt.

Industrial Control Systems / SCADA Industrial Control Systems / SCADA

The systems that control and monitor industrial equipment. Because uptime comes first, unsupported legacy operating systems often remain in service.

Virtual LAN Virtual LAN

A way to split one physical network into several logical ones — the partitions between departments or process lines.

Network Segmentation Network Segmentation

Dividing the network by function and criticality so that a breach in one area does not become a breach everywhere. Decoys are normally deployed segment by segment.

Internet of Things Internet of Things

Networked cameras, printers, door controllers and sensors. They fall off the asset register and rarely get updated, which makes them a convenient foothold.

Shadow IT Shadow IT

Devices and services connected without the IT function knowing. Nobody counts them as things to protect, which is exactly why they become entry points.

FAQ

Frequently asked questions

Do we have to replace the antivirus and firewall we already use?
No. It plays a different role, so it is added rather than swapped in. It is designed on the assumption that you already have those controls, and fills the gap between them. Alerts can be fed into your existing log platform or EDR.
Will it affect production systems or plant equipment?
Decoys run independently of your production assets, and no software has to be installed on existing servers or controllers. Depending on the network topology some design care is still required, which is exactly what the trial phase is for.
Can we run this without a dedicated security specialist on staff?
We take first-line response in Japanese. What still has to exist internally is a decision about who does what when an alert fires — and building that runbook is part of the deployment work.
How large does an organisation need to be?
One segment worth protecting is enough. Starting with the place that hurts most when it stops — the core systems, the plant network — makes the return far easier to judge than a company-wide rollout.
What does it cost?
It varies with network size, number of sites, number of decoys and the level of support, so we do not publish a single figure. We scope it with you and issue a written quotation. A limited trial deployment is usually the sensible first step.
How long does deployment take?
A trial typically runs four to six weeks. Full deployment depends on scope and the number of sites; we give you an indicative schedule during the discovery phase.
Will an attacker recognise the decoys for what they are?
Decoys run real operating systems and services and are placed to match your actual environment, so telling them apart is not straightforward. We will not claim it is impossible, however — which is why it is designed as one layer among several, not as a standalone answer.
It is a foreign product — is support available in Japanese?
We are the point of contact. First-line support is in Japanese, escalating to the developer’s engineers when needed. We work with our Ukrainian engineers daily, so the time difference does not break the chain.

Start by telling us what you have.

Before deciding whether to deploy anything, it is worth laying out the assets that matter and the team you have today. There is no charge for the conversation or the quotation.

Contact us