Teams should place decoys near remote access termination points and at the IT and OT interface, because those locations are common entry paths for attacks. Devices that support USB use should also be shadowed with decoys. That placement strategy gives defenders earlier detection, better context on attacker movement, and coverage around the areas most often probed first.
Why OT deception placement should follow attacker entry paths
Deception only works well in OT when it sits where an intruder is most likely to look first. Remote access termination points and the IT/OT boundary are high-value because they reflect how real attackers usually enter, validate access, and start mapping the environment. Decoys there are more likely to be touched early, which shortens detection time and gives defenders a cleaner signal than scattered deception deeper in the plant.
That placement also fits the way OT environments are usually segmented. The goal is not to hide every asset, but to position believable tripwires at points where trust changes, especially where enterprise credentials, remote support, or integration traffic crosses into operational space. A well-placed decoy can reveal both the initial foothold and the attacker’s first pivot attempt.
USB-exposed assets deserve the same treatment because removable media remains a common bridge into OT. Shadowing those endpoints with decoys gives defenders coverage where portable media, local maintenance, and technician workflows can bypass normal network monitoring. In practice, the best placements are the ones that mirror how the environment is actually used, not just how it is documented.
Which OT zones deserve decoys first?
The first priority is the remote access path, including jump servers, remote support gateways, and any externally reachable maintenance channel. Those paths often concentrate privileged activity and are attractive because they promise rapid reach into engineering and control networks. A decoy in that zone can tell you whether someone is enumerating sessions, testing credentials, or probing for higher-value systems.
The second priority is the IT and OT interface, where segmentation is supposed to constrain movement but often still allows some operational visibility or management traffic. That makes it a natural reconnaissance point. Decoys here can surface discovery behavior, lateral movement attempts, and the earliest signs that an attacker is trying to map which side of the boundary contains what.
Third, place decoys near USB-dependent devices and adjacent maintenance workflows. That includes stations or assets that are likely to interact with portable media, vendor laptops, or local engineering tools. The value is not just detection, but context: a hit on a USB-adjacent decoy often suggests hands-on access or an on-site stage of the intrusion rather than a purely remote one.
How should teams judge whether a decoy is in the right place?
Good OT deception placement is judged by realism and by how early it catches attacker curiosity. If a decoy is too isolated from actual workflow, it may never be touched. If it is too generic, it may be ignored by anyone who has already enumerated the network. The best decoys resemble systems an intruder would expect to find while still being instrumented enough to alert clearly when touched.
Placement should also follow the attacker’s decision points. A decoy is most useful where an adversary is trying to decide whether the environment is worth deeper effort, such as after initial access, after crossing a trust boundary, or after discovering removable-media handling. Those moments matter because they often precede credential harvesting, privilege discovery, or pivoting into control segments.
For OT teams, that means the question is not “where can we hide a decoy?” but “where would a realistic attacker expect to find the next useful system?” The answer usually points to boundary zones, shared services, and maintenance paths rather than isolated production controllers.
Risk and Threat Considerations
OT deception placed in the wrong part of the environment can create noise without improving detection. If decoys are hidden too deep or too far from common entry paths, they may only attract benign scanning long after an attacker has already moved on, which weakens their value as an early warning control.
Failure mechanism: Attackers tend to test the easiest trust boundaries first, so deception that is not aligned to remote access, segmentation boundaries, or USB-adjacent workflows can miss the initial reconnaissance and expose defenders to delayed detection.
Impact: Missed early contact reduces context on attacker intent and movement, making it harder to distinguish a fleeting probe from an active intrusion path and giving the attacker more time to pivot toward operational assets.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 and NIST CSF 2.0 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | CA-8 — Penetration Testing | Deception placement benefits from validating likely attacker paths at boundaries. |
| Recommendation — Use CA-8 to test whether decoys are placed where real intrusion paths are most likely to touch them. | ||
| NIST CSF 2.0 | DE.CM-01 — Anomalies and Events Are Detected | OT deception is meant to create detectable events at likely entry points. |
| PR.AA-05 — Network Access Is Managed Through Authentication and Authorization | Remote access termination points are central to OT entry-path control. | |
| Recommendation — Use DE.CM-01 to monitor decoy hits at remote access and IT/OT boundary points. Use PR.AA-05 to control and verify access at remote termination points before deploying deception there. | ||
| ISO/IEC 27001:2022 | A.8.20 — Network security | OT deception placement depends on segmented network boundaries and trusted pathways. |
| A.7.4 — Physical security monitoring | USB-adjacent deception relates to physical maintenance and removable-media touchpoints. | |
| Recommendation — Use A.8.20 to align deception with network segmentation and boundary monitoring. Use A.7.4 to cover physical touchpoints where removable media or local access can bypass network controls. | ||
Practitioner Guidance
What to prioritise: Place the first decoys where access changes hands, not where assets are merely valuable. Remote access gateways, IT/OT boundary systems, and USB-supported maintenance zones should be the default starting points because they are the most likely points of first contact.
What to verify: Confirm that each decoy matches the look and role of the zone it is meant to protect, including naming, protocol exposure, and surrounding network context. A decoy that does not fit the local workflow is easy to dismiss, both by attackers and by internal testers.
Common mistake: Teams often spread deception evenly across the plant instead of concentrating it at likely approach paths. That produces weaker signal quality and less useful attacker context than a smaller number of well-placed decoys.
Practitioner takeaway: OT deception should be deployed where an intruder is most likely to touch the environment first, because early boundary contact is what gives defenders the best chance to detect movement before it reaches control assets.
Related resources from NHI Mgmt Group
- How should security teams place deception controls in Active Directory?
- How should security teams validate ransomware controls against Clop-style attack paths?
- How should security teams reduce attack paths into legacy and OT systems without disrupting operations?
- How should security teams use exposure validation to prioritise the controls and attack paths that matter most?