The National Cyber Security Centre is calling on organisations to submit to an evidence base on the use case and efficacy of cyber deception.
Recently, the NCSC, along with international government partners, discussed the advent of cyber deception tactics and tools in cyber defence initiatives.
Following this, the NCSC has found motivation to establish an evidence-base for use cases of cyber deception and their efficacy, on a national scale, in support of Active Cyber Defence 2.0.
The NCSC did highlight the need to define their use of the term cyber deception, to include tripwires, honeypots, and breadcrumbs, i.e., various methods for attracting and detecting threat actors often to better study their processes and methods.
So far, the NCSC has identified two primary use cases for cyber deception:
- Low-interaction solutions, including tripwires and honeytokens which alert unauthorised access
- Low-interaction and high-interaction honeypots used to collect threat intelligence
The NCSC says it is aware of wider thinking and approaches designed to produce synthetic behaviours and content, but these are outwith the organisation’s scope.
For its evidence base, the NCSC intends to collect existing evidence, while at the same time encouraging at-scale deployment within the UK.
The NCSC has specific objects to meet, as a minimum:
- 5,000 instances on the UK internet of low and high interaction solutions across IPv4 and IPv6
- 20,000 instances within internal networks of low interaction solutions
- 200,000 assets within cloud environments of low interaction solutions
- 2,000,000 tokens deployed
Recommended reading
- NCSC Warns Organisations to Prepare for Long Ukraine Conflict
- UK and France to Consult on Commercial Cyber Intrusion
- UK Gov at Risk of “Catastrophic” Ransomware Attack
Through this, the NCSC hopes to answer key questions about how cyber deception deployments can discover latent and new compromises, as well as how the known presence of these tools at a national level cause changes in observable behaviour of threat actors.
Public and private sector organisations in the UK which have deployed cyber deception solutions as described are invited to participate, with contact information found here.





