Cyber deception trials: what we’ve learned so far

Just over twelve months ago, the NCSC invited UK organisations to help us build a nation-scale evidence base for cyber deception. Since then, we’ve been busy running trials, speaking to users, and analysing the results. This blog post shares what we’ve learned so far, and what we’re planning next.
A quick recap
We’re exploring whether cyber deception (ie defensive strategies such as a honeypots used to lure attackers) can increase your observability and threat hunting, and even influence how attackers behave.
To do that, we’ve tested three core assumptions:
- Cyber deception can help uncover hidden compromises already inside networks.
- Cyber deception can help detect new attacks as they happen.
- Cyber deception can change how attackers behave if they know cyber deception is in play.
To test these assumptions, we ran an experiment under the Active Cyber Defence (ACD) 2.0 programme, which involved:
- 121 organisations from across the UK
- 14 commercial providers of cyber deception solutions
- 10 product trials across different environments, from cloud deployments to operational technology
Thank you to everyone who volunteered to help us with this research, and especially those who were selected for product trials. We are particularly grateful to the providers who offered our volunteers trials of cyber deception products and allowed us to observe onboarding processes. Our thanks go to Acalvio Technologies, aql, CounterCraft, Defused, DeceptIQ, FIRCY, Fortinet, GreyNoise Intelligence, Horizon3.ai, Intel, Lupovis, PentenAmio, Thinkst Canary, Tracebit, and Zscaler.
What we found
Our key findings can be grouped into 5 areas.
- 1
Cyber deception can work, but it’s not plug-and-play
When surveyed, most organisations expressed a belief that cyber deception could offer real value, particularly in detecting novel threats and enriching threat intelligence. A few highlighted its potential for identifying insider threats. However, outcome-based metrics were not readily available and require development.
As with any observability and threat hunting methods, the effectiveness of cyber deception depends on having the right data and context. We found that cyber deception can be used for visibility in many systems, including legacy or niche systems, but without a clear strategy organisations risk deploying tools that generate noise rather than insight.
- 2
Language is a barrier
There’s a surprising amount of confusion around terminology, and vocabulary across the industry is often inconsistent. This makes it harder for organisations to understand what’s on offer or even what they’re trying to achieve. We think adopting standard terminology should help and we will be standardising our cyber deception vocabulary.
- 3
Most organisations prefer to stay covert
90% of trial participants said they wouldn’t publicly announce that they use cyber deception. That’s understandable, they don’t want to tip off attackers. This is at odds with the academic research we’ve reviewed, which found that when attackers believe cyber deception is in use they are less confident in their attacks. This can impose a cost on attackers by disrupting their methods and wasting their time, to the benefit of the defenders.
- 4
There’s a gap in guidance
Many organisations told us they’re interested in cyber deception but don’t know where to start. They want impartial advice, real-world case studies, and reassurance that the tools they’re using are effective and safe. We’ve found a strong marketplace of cyber deception providers offering a wide range of products and services. However, we were told that navigating this market can be difficult, especially for beginners. This is where the NCSC can play a role by helping organisations to make informed, strategic choices.
- 5
There are risks
As with any cyber security solution, misconfiguration can introduce new vulnerabilities. If cyber deception tools aren’t properly configured, they may fail to detect threats or lead to a false sense of security, or worse, create openings for attackers. As networks evolve and new tools are introduced, keeping cyber deception tools aligned requires ongoing effort. It is important to consider regular updates and fine-tuning cyber deception solutions.
So, what's next?
We think there’s a compelling case for increasing the use of cyber deception in the UK. We want to help the UK to better understand cyber deception, so that means helping organisations to:
- understand what cyber deception is (and isn’t)
- decide whether it’s right for them
- identify strategic gaps before choosing a product
- learn from others who’ve done it well
- understand how cyber deception can impose cost on adversaries and contribute to national cyber resilience
By helping organisations to understand cyber deception and finding clear ways to measure impact, we are building a strong foundation to support the deployment of cyber deception at a national scale in the UK. We are looking at developing a new ACD service to achieve this.
Beyond detection
One of the most promising aspects of cyber deception is its potential to impose cost on adversaries. By forcing attackers to spend time and resources navigating false environments, chasing fake credentials, or second-guessing their access, cyber deception can slow down attacks and increase the likelihood of detection. This aligns with broader national resilience goals by making the UK a harder, more expensive target.
Cyber deception isn’t new, but neither is it widely used, and that’s a missed opportunity. When done well, it can provide early warning of attacks, generate high-quality intelligence, and shape how our adversaries operate. But it’s not a magic fix; it requires planning, strategy, and support. That’s where we believe the NCSC can help, by providing guidance, building confidence, and helping the UK to make the most of this powerful tool.
Cyber deception, observability and threat hunting are all part of a modern, layered defence strategy. Together, they help organisations not only detect threats, but understand and respond to them more effectively. Beyond detection and intelligence, cyber deception can also impose cost on adversaries, disrupting their operations, wasting their time, and undermining their confidence. This kind of friction is valuable at both organisational and national levels, helping to shift the economics of cyber attacks in our favour.
We’ll continue to share what we learn. In the meantime, if you’re successfully using cyber deception, or experimenting with it, we’d love to hear from you at [email protected].


