Agree that zero trust and a tight perimeter still enables breaches to happen. It's still the "not if, but when" scenario. Most defenders are missing that the edge is the place where decoys are most effective. Internal solutions, canaries, and the like are too late.
The problem has been most edge-facing decoys stuck out, looked "off", and didn't attract any useful attention. Basically, lots of alerts and activity, but no action. Edge-based deception has been infeasible in years past, but I believe we're getting to a point where it will become part of the internet's fabric.
Full disclosure that I'm a co-founder over at Divert, and we've built something that changes how decoys are used proactively on the internet.
Divert's diversion decoys are real services and infrastructure seeded with entry points from an organization's real DNS and certificate transparency presence. Diversions lure in threats with real content and functionality, and draws them away from real assets, blocking them in real time through existing enforcement points. Deploys in minutes and blocks even sooner.
mr_hedrick•46m ago
The problem has been most edge-facing decoys stuck out, looked "off", and didn't attract any useful attention. Basically, lots of alerts and activity, but no action. Edge-based deception has been infeasible in years past, but I believe we're getting to a point where it will become part of the internet's fabric.
Full disclosure that I'm a co-founder over at Divert, and we've built something that changes how decoys are used proactively on the internet.
Divert's diversion decoys are real services and infrastructure seeded with entry points from an organization's real DNS and certificate transparency presence. Diversions lure in threats with real content and functionality, and draws them away from real assets, blocking them in real time through existing enforcement points. Deploys in minutes and blocks even sooner.
https://www.divert.cloud