Join our Newsletter — 33% off our NHI Course
Home› FAQ› Cyber Security› Where should teams place OT deception controls to…
Cyber Security

Where should teams place OT deception controls to catch the most likely attack paths?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 28, 2026 Domain: Cyber Security

Teams should place decoys near remote access termination points and at the IT and OT interface, because those locations are common entry paths for attacks. Devices that support USB use should also be shadowed with decoys. That placement strategy gives defenders earlier detection, better context on attacker movement, and coverage around the areas most often probed first.

Why OT deception placement should follow attacker entry paths

Deception only works well in OT when it sits where an intruder is most likely to look first. Remote access termination points and the IT/OT boundary are high-value because they reflect how real attackers usually enter, validate access, and start mapping the environment. Decoys there are more likely to be touched early, which shortens detection time and gives defenders a cleaner signal than scattered deception deeper in the plant.

That placement also fits the way OT environments are usually segmented. The goal is not to hide every asset, but to position believable tripwires at points where trust changes, especially where enterprise credentials, remote support, or integration traffic crosses into operational space. A well-placed decoy can reveal both the initial foothold and the attacker’s first pivot attempt.

USB-exposed assets deserve the same treatment because removable media remains a common bridge into OT. Shadowing those endpoints with decoys gives defenders coverage where portable media, local maintenance, and technician workflows can bypass normal network monitoring. In practice, the best placements are the ones that mirror how the environment is actually used, not just how it is documented.

Which OT zones deserve decoys first?

The first priority is the remote access path, including jump servers, remote support gateways, and any externally reachable maintenance channel. Those paths often concentrate privileged activity and are attractive because they promise rapid reach into engineering and control networks. A decoy in that zone can tell you whether someone is enumerating sessions, testing credentials, or probing for higher-value systems.

The second priority is the IT and OT interface, where segmentation is supposed to constrain movement but often still allows some operational visibility or management traffic. That makes it a natural reconnaissance point. Decoys here can surface discovery behavior, lateral movement attempts, and the earliest signs that an attacker is trying to map which side of the boundary contains what.

Third, place decoys near USB-dependent devices and adjacent maintenance workflows. That includes stations or assets that are likely to interact with portable media, vendor laptops, or local engineering tools. The value is not just detection, but context: a hit on a USB-adjacent decoy often suggests hands-on access or an on-site stage of the intrusion rather than a purely remote one.

How should teams judge whether a decoy is in the right place?

Good OT deception placement is judged by realism and by how early it catches attacker curiosity. If a decoy is too isolated from actual workflow, it may never be touched. If it is too generic, it may be ignored by anyone who has already enumerated the network. The best decoys resemble systems an intruder would expect to find while still being instrumented enough to alert clearly when touched.

Placement should also follow the attacker’s decision points. A decoy is most useful where an adversary is trying to decide whether the environment is worth deeper effort, such as after initial access, after crossing a trust boundary, or after discovering removable-media handling. Those moments matter because they often precede credential harvesting, privilege discovery, or pivoting into control segments.

For OT teams, that means the question is not “where can we hide a decoy?” but “where would a realistic attacker expect to find the next useful system?” The answer usually points to boundary zones, shared services, and maintenance paths rather than isolated production controllers.

Risk and Threat Considerations

OT deception placed in the wrong part of the environment can create noise without improving detection. If decoys are hidden too deep or too far from common entry paths, they may only attract benign scanning long after an attacker has already moved on, which weakens their value as an early warning control.

Failure mechanism: Attackers tend to test the easiest trust boundaries first, so deception that is not aligned to remote access, segmentation boundaries, or USB-adjacent workflows can miss the initial reconnaissance and expose defenders to delayed detection.

Impact: Missed early contact reduces context on attacker intent and movement, making it harder to distinguish a fleeting probe from an active intrusion path and giving the attacker more time to pivot toward operational assets.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 and NIST CSF 2.0 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5CA-8 — Penetration TestingDeception placement benefits from validating likely attacker paths at boundaries.
Recommendation — Use CA-8 to test whether decoys are placed where real intrusion paths are most likely to touch them.
NIST CSF 2.0DE.CM-01 — Anomalies and Events Are DetectedOT deception is meant to create detectable events at likely entry points.
PR.AA-05 — Network Access Is Managed Through Authentication and AuthorizationRemote access termination points are central to OT entry-path control.
Recommendation — Use DE.CM-01 to monitor decoy hits at remote access and IT/OT boundary points. Use PR.AA-05 to control and verify access at remote termination points before deploying deception there.
ISO/IEC 27001:2022A.8.20 — Network securityOT deception placement depends on segmented network boundaries and trusted pathways.
A.7.4 — Physical security monitoringUSB-adjacent deception relates to physical maintenance and removable-media touchpoints.
Recommendation — Use A.8.20 to align deception with network segmentation and boundary monitoring. Use A.7.4 to cover physical touchpoints where removable media or local access can bypass network controls.

Practitioner Guidance

What to prioritise: Place the first decoys where access changes hands, not where assets are merely valuable. Remote access gateways, IT/OT boundary systems, and USB-supported maintenance zones should be the default starting points because they are the most likely points of first contact.

What to verify: Confirm that each decoy matches the look and role of the zone it is meant to protect, including naming, protocol exposure, and surrounding network context. A decoy that does not fit the local workflow is easy to dismiss, both by attackers and by internal testers.

Common mistake: Teams often spread deception evenly across the plant instead of concentrating it at likely approach paths. That produces weaker signal quality and less useful attacker context than a smaller number of well-placed decoys.

Practitioner takeaway: OT deception should be deployed where an intruder is most likely to touch the environment first, because early boundary contact is what gives defenders the best chance to detect movement before it reaches control assets.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 28, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org