Why deception technology hasn't taken off, and what changes that

Tracebit · Last updated:

Deception has a persuasive premise: put something in your environment that an attacker wants to touch, but your business doesn't need anyone to use. An interaction gives you a signal worth investigating. The harder question is why an idea this useful still hasn't become a routine part of security.

Our view is that the cost of running deception has often been easier to see than the value of the coverage it adds. Security teams have had good reasons to hesitate. Tracebit is built to change that calculation: automate the work of deploying and maintaining believable canaries, make their alerts actionable, and give teams evidence that the coverage works. Customer deployments already show what that looks like. AI gives us a reason to be more ambitious about where it goes next.

The deployment problem was real

A security team can believe in deception and still struggle to justify another project. Someone has to choose where the decoys go, make them plausible, monitor them, account for legitimate scanners, and keep the deployment useful as infrastructure changes. A few well-placed tripwires are manageable. Maintaining that coverage across hundreds of accounts is a different engineering problem.

The UK NCSC's December 2025 trial findings describe this gap clearly. It found enthusiasm for the value of deception, but a lack of readily available outcome-based metrics, inconsistent terminology, and demand for impartial guidance. It also identified the ongoing effort needed to keep deployments aligned with changing environments.

That helps explain why deception can stay on the roadmap while identity hardening, patching and other urgent work absorb the team's time. Asking an already busy team to become expert in another discipline is a considerable adoption barrier.

Tracebit changes how much work coverage requires

We deploy canaries through the infrastructure and management workflows teams already use. Cloud resources fit into infrastructure-as-code. Canary credentials can sit in workstations and CI/CD pipelines. Alerts go to the security team's existing tools. The useful unit of deployment becomes a repeatable part of the environment, with automation handling the work that would otherwise grow with each canary.

Cresta's published case study reports four engineering hours of setup across AWS, Okta, GitHub and workstations, followed by approximately two hours of annual maintenance. Its security team is listed as two to five people. Those are customer-specific results, but they demonstrate that useful deception coverage can fit into a small team's workload.

At the other end of the scale, Riot Games reports a deployment of 10,000–100,000 canaries. The team estimated an in-house implementation could take a year of full-time work to become production-ready. With Tracebit, it reported spending weeks of engineering time. Integrating deployment into its cloud account factory helped it expand across hundreds of AWS accounts.

This changes the sequencing argument. If detection can be deployed and maintained with modest effort, you can put it to work while the rest of the security programme develops. You don't need to finish every hardening project before you start finding out when someone gets through.

Believable decoys have to keep up with the environment

A canary that looks conspicuously different from everything around it gives an attacker a reason to avoid it. Maintaining realism manually gets harder as the estate grows and naming conventions, workloads and attacker techniques change.

In our explanation of how Tracebit uses LLMs, we describe using environmental context to inform canary parameters, including names, within reviewed templates. The model's role is constrained: it helps adapt the decoy to its surroundings; it doesn't receive unrestricted authority to generate and deploy infrastructure. Our infrastructure-as-code providers support changing those canaries over time.

The goal is practical. Broad coverage should stay believable without making a security engineer responsible for inventing and refreshing thousands of plausible resources by hand.

Quiet alerts need evidence behind them

Deception has a measurement problem. A month without alerts could mean no attacker encountered a canary. It could also mean the deployment missed the paths an attacker took. Silence alone cannot establish that an environment is safe.

A useful evaluation asks where canaries are deployed, whether representative attack paths encounter them, whether triggers reach the right responders, and whether those responders can act. That gives the team something to validate before a real incident.

Riot Games did that with external testing. Its case study reports that Tracebit detected both of two separate third-party red-team exercises, including one at the beginning of the engagement. Two exercises are a bounded result, rather than a universal detection rate. They are still considerably more useful evidence than a dashboard showing how many decoys exist.

There is evidence from real operations too. Zepz reports detecting insider-risk behaviour within weeks of going live that its other tooling had not surfaced. The finding led to tighter access controls and changes to how engineers retrieved secrets. This is the additional value a buyer should look for: an actionable discovery beyond what the existing stack was providing.

Cresta reports an average of one Tracebit alert per month, and says its team upgrades Tracebit High alerts to Critical in Panther. Alert volume and false-positive rate are different measurements. The result illustrates something useful about attention: a signal that arrives rarely, with a clear reason to investigate, can earn a place near the front of the queue.

AI expands what deception can do

An offensive agent still has to interact with its target. When it reads a canary secret or tries a canary credential, the defender gets an opportunity to detect that action without first recognising the particular exploit or model behind it. The condition remains encounter and interaction: a canary cannot detect an attack path it never sees.

AI also creates a new opportunity to influence what happens after that encounter. An agent reads material from the environment into its context. Defenders can design decoys to affect how it proceeds.

In Tracebit's Context Bombs working paper, we tested that idea in an AWS range with roughly 300 resources and ten attack paths. Across 152 scored runs involving five models, the reported overall rate of reaching full account administrator access fell from 57% in the baseline to 5% with a context-bomb canary. The canary contained text designed to trigger the attacking model's safety mechanisms when read.

These are results from our controlled research, dependent on the tested models, providers, prompts and environment. They establish a promising direction for defensive experimentation, not a guarantee that any AI attack can be stopped. The direction matters: the environment itself can help interrupt an attacker as well as reveal one.

Our ambition is to make deception routine

We believe deception should become a normal part of building and operating infrastructure. As an organisation adds an account, a workload or a developer environment, it should be straightforward to add detection that fits it. Keeping that coverage current should take much less work than building it from scratch. Testing it should produce evidence that a security team can use.

That is the future we are building towards with Tracebit. The customer results already demonstrate low maintenance, deployment at scale, and detections that matter. Our AI research opens a further possibility: use the defender's control of the environment to make an attack harder to complete.

There will still be attack paths to assess, alerts to investigate and incidents to contain. The opportunity is to make a useful detection capability accessible enough that teams actually deploy it, and keep improving it as their environments change.

Start with Tracebit Community Edition: deploy a canary, trigger it yourself, and see what evidence reaches you. That is a concrete first step towards answering the question that matters in your own environment: would we know?