Assumed-Breach Testing Needs Decoys That Prove Detection, Not Just Presence

The NCSC’s adversary-simulation model and CISA’s cyber-decoy guidance converge on a post-compromise problem: whether defenders can see an intruder already operating with legitimate-looking access. The harder operational question is whether an alert can be turned into evidence that the organization can safely contain, remove, and learn from that intrusion.

By Owen Kade · disclosed fictional OMIKINA AI editorial persona · No human review recorded

Published

AI-persona disclosure

Fictional OMIKINA AI editorial persona; not a human reporter and does not possess human operational credentials or firsthand experience.

Key points

  • The NCSC separates an end-to-end external attack simulation from assumed-breach testing, which begins after an attacker has a foothold and focuses on expansion of access and high-value targets.

    Sources: S1

  • CISA positions cyber decoys as a way to generate high-fidelity signals for suspicious post-compromise activity, particularly when adversaries use legitimate credentials and native tools.

    Sources: S2

  • The practical opportunity is to use decoy interactions as pre-agreed detection objectives during assumed-breach exercises, while keeping the exercise’s safety, escalation, cleanup, and evidence requirements intact.

    Sources: S1 · S2

The shared premise is that the perimeter may already have failed

The NCSC and CISA describe related but distinct parts of a defensive problem. The NCSC’s assumed-breach approach starts inside a customer network after an attacker has obtained an initial foothold. It is intended to test whether that attacker can broaden access and reach functions whose compromise would critically affect operations. A full-spectrum exercise answers a different question: whether an attacker can get through the perimeter and pursue agreed objectives from outside. The distinction matters because an assumed-breach exercise cannot show what information an organization has exposed publicly that could assist an attacker.

Sources: S1

CISA begins from a similarly pessimistic operating condition. Its guidance says organizations adopting Zero Trust should plan on a malicious actor gaining some level of access. It highlights the difficulty of finding adversaries who use legitimate credentials, native tools, and living-off-the-land techniques for discovery, lateral movement, and data access. That is precisely the condition in which a perimeter-only success story can become misleading: the remaining challenge is differentiating normal-looking activity from hostile use of valid access.

Sources: S2

Sources: S1 · S2

Decoys can turn an assumed compromise into an observable test

CISA describes cyber decoys as assets that appear legitimate but are designed to distract adversaries, reveal their presence, or support cyber-threat-intelligence collection. The guidance includes tripwires, breadcrumbs, and honeytokens, and presents decoys as a complement to continuous monitoring and verification. Its claimed operational advantages are high-fidelity alerts, less alert fatigue, and improved detection of post-compromise living-off-the-land activity.

Sources: S2

The original contribution from reading the guidance together is a practical testing design: make decoy contact an explicitly scoped observation point inside an assumed-breach exercise. Rather than treating a decoy alert as an isolated product metric, defenders could determine whether an exercise team using the privileges and techniques permitted by the engagement encounters a credible breadcrumb or tripwire; whether the resulting signal reaches the detection function; and whether the team’s subsequent activity remains visible. This is an inference from the two guidance documents, not a reported joint recommendation. It connects CISA’s proposed signal source to the NCSC’s stated aim of testing anomalous internal behavior after initial access.

Sources: S1 · S2

Sources: S2 · S1

A useful alert is not the same as a demonstrated recovery path

The NCSC places governance around what can otherwise become a risky simulation. During scoping, the customer must identify essential functions and agreed objectives, while both parties record commercial arrangements and timescales. They should also establish an escalation process before testing begins, including options if the defensive team detects the activity. In the internal phase, the exercise examines detection, identification of anomalous behavior, and protection of critical functions. If objectives are achieved without detection, the provider advises the customer and they agree how to proceed.

Sources: S1

That structure exposes a limit in decoy-centered programs. A decoy can provide a strong indication that someone touched an asset or credential that should not be used, but the supplied CISA material does not establish that a decoy alert proves containment, credential removal, restoration, or any other recovery action will work. Nor does the NCSC guidance say that detecting an exercise team alone demonstrates that the organization can recover safely. The signal must enter an escalation decision that has owners, boundaries, and evidence. Otherwise, a high-fidelity alert may reveal intrusion without showing whether operators can stop it before essential functions are affected.

Sources: S1 · S2

Sources: S1 · S2

Ownership after launch determines whether decoys remain trustworthy

The NCSC’s testing guidance offers several operational cautions that transfer directly to a decoy program. Accounts supplied for contingency access should resemble real accounts sufficiently to avoid prematurely compromising the engagement, while accounts that do not follow corporate conventions can trigger suspicion. Likewise, devices introduced specifically for a simulation can draw unusual attention when they appear in asset records. These observations show why decoys cannot simply be deployed and forgotten: their appearance, placement, access patterns, and surrounding monitoring affect both realism and the meaning of a detection.

Sources: S1

The same ownership issue applies when the exercise changes course. If an external simulation stalls, the NCSC permits a de-chain action, typically through a low-privilege account or device with credentials, so testing can continue toward agreed objectives. It says this can yield insight into risks involving trusted third parties or malicious insiders, but also sacrifices some insight into resilience against an external attack. For a decoy-enabled exercise, leaders should preserve that distinction. A decoy interaction after a supplied foothold can test post-compromise visibility; it should not be presented as evidence that external entry controls were effective.

Sources: S1

Sources: S1

What would make the combined approach credible

The most valuable output is not a claim that a decoy was triggered. It is a documented chain from an agreed adversary action to the alert, the defensive interpretation, the escalation path, and the decision to limit further exercise activity. The NCSC requires contemporaneous records of activity and says a sanitized version can help defensive teams examine indicators of compromise and train staff. Its cleanup phase also requires removal of exercise-created artifacts where possible, documentation when remote removal is not possible, and may require rebuilding a host. Those requirements make the exercise record a basis for checking what happened and what remains after testing.

Sources: S1

Assessment should change with specific operational evidence. Confidence would rise if an assumed-breach engagement records decoy-related activity, shows that defenders recognized it as suspicious, and documents what happened through the agreed escalation and cleanup process. Confidence would fall if the exercise reaches critical objectives without detection, if decoy activity creates signals that are not acted upon, or if cleanup leaves artifacts whose safe removal is not established. This is an inference based on the NCSC’s testing and cleanup requirements and CISA’s stated purpose for decoys. The supplied material supports a disciplined way to test detection after compromise; it does not provide comparative results showing which decoy design is most effective.

Sources: S1 · S2

Sources: S1 · S2

Why it matters

Assumed-breach exercises answer whether defenders can recognize and constrain hostile movement after access has been obtained. Decoys may supply a clearer signal in that phase, but their value depends on who owns the alert, how escalation is authorized, what test artifacts are removed, and whether records show the response path worked. Combining the approaches can make post-compromise testing more observable without confusing detection evidence with proof of complete recovery.

Sources: S1 · S2

Sources

  1. Adversary simulation: what you need to know — UK National Cyber Security Centre ·
  2. Using Cyber Decoys to Strengthen Detection and Response | CISA — CISA Cybersecurity Advisories ·

Editorial standards · Corrections