forumNew topic

They're trying to sell deception tech and honeypots to our 15-person office. Is this overkill or actually useful?

GGökhan G***MemberCommunity member
Joined
Mar 2023
Message
4
#1

We are an independent financial advisory firm of 15 people based in London. Our setup consists of 15 laptops, an on-prem file server, and cloud-based accounting software. In their latest proposal, our outsourced IT support provider suggested integrating deception technology (deception tech and honeypot-based systems).

They explained that they would place decoy file servers, fake user credentials, and fake database connections onto the network, so if an attacker breaches the perimeter, we'll know the second they touch any of these decoys. They are quoting around 4,800 GBP annually for licensing and management.

What exactly does deception technology do, and is it genuinely necessary for a small office network like ours? Or would it make much more sense for a 15-person setup to spend that budget on core security layers instead?

YYiğit N***Member
Job title
Product Manager
Sector
E-commerce
Organization type
300-person organization
Joined
Sep 2024
Message
115
Most Helpful#2

Short answer: Deception technology is an advanced security method that deploys decoys and traps across a network to instantly detect an attacker's lateral movement. For a 15-person office, this is absolute overkill. Spending 4,800 GBP on this when foundational security gaps likely still exist is a total misplacement of priorities.

The logic behind these systems is straightforward: you create a dummy file share or fake credential that legitimate employees have no business touching. If an attacker breaches the network and starts scanning, they mistake the decoy for a real target, try to access it, and the system alerts the security team with virtually zero false positives. It's a fantastic approach for catching stealthy intrusions inside large enterprise networks.

But on a network with 15 laptops, attackers don't take complex paths. Most attacks on small businesses come down to phishing emails harvesting credentials or brute-forcing exposed remote desktop ports directly. You simply don't have the network depth to justify setting internal traps.

You should put that 4,800 GBP budget toward these three fundamentals instead: 1) Multi-factor authentication across every single email and cloud account without exception, 2) Immutable, automatically tested offline cloud backups, 3) Up-to-date endpoint protection on all machines and regular security awareness training for staff. Setting up a honeypot without nailing these basics is like installing an alarm sensor behind an unlocked front door.

NNazlı T***MemberCommunity member
Joined
Apr 2025
Message
217
#3

Here's how deception tech works: when an attacker enters the office network, they don't know what's hosted where, so they scan. The honeypot presents a fake server that looks like an easy mark. But in a 15-person setup, even an IT guy or an intern could accidentally click that share and trigger an alert. The overhead of managing it is just too much for a small office.

YYağmur C***VeteranCommunity member
Joined
May 2023
Message
395
#4

We paid 3,500 GBP for a similar system two years ago at our 20-person law firm in Manchester. It triggered 4 alerts all year, and all four were just our own backup software polling the local office printer. There was never an actual threat. We didn't renew when the contract ended.

NNeslihan K***Expert
Job title
IT Manager
Sector
Catering
Organization type
chain store
Joined
Jan 2023
Message
40
#5

Sounds like your IT provider just signed up as a reseller for a new vendor and is trying to hit their quota on the first client they can find. What kind of lateral depth exists in a 15-person network to even lay traps in? Turn it down flat.

TTuğrulMember
Job title
Solar energy
Joined
Feb 2024
Message
88
#6

Do not approve that 4,800 GBP spend. Ask your IT firm whether they handle centralized patch management for your machines and if your backups are isolated against ransomware. Those are your actual risks, not fake servers.

KKadir Ç***Expert
Job title
Content Editor
Sector
Agriculture
Organization type
20-person company
Joined
Apr 2025
Message
128
#7

in a room with 15 people, everyone can already see each other's screens anyway. instead of scanning for fake sevrers an intruder would get info faster just glancing at the desk next to them. total fantasy purchase.

PPerihan G***Expert
Job title
Administrative manager
Sector
Logistics
Organization type
20-person company
Joined
Feb 2026
Message
283
#8

Do the 15 laptops have centrally managed antivirus or endpoint protection? Is 2FA enforced across your email accounts? If the answer to either isn't a hard yes it makes no sense to even discuss this quote.

HHasan S***MemberCommunity member
Joined
Jan 2024
Message
114
#9

honeypots are for huge corpps with thousands of users. like who is deceiving who on a 15-pc network lol, total waste of money honestly

KKoray S***MemberCommunity member
Joined
Jul 2023
Message
201
#10

To get into the details: If you don't write this down from the start, it leads to arguments later.

Start with a small trial; don't commit to everything at once. tbh hope this helps.

SSultan K***Member
Job title
IT Manager
Sector
Automotive aftermarket
Organization type
cooperative
Joined
Mar 2023
Message
1
#11

Following.

HHakan Ş***New memberCommunity member
Joined
Aug 2026
Message
2
#12

Exactly like that. If the notification path is long, notifications don't arrive; missing notifications mean delayed incident detection.

I'm also curious if anyone does it differently.

HHakan T***MemberCommunity member
Joined
Nov 2025
Message
106
#13

the most overlooked point about what is decepion technology is this: If you don't write this down from the start, it leads to arguments later.

the biggest time-waster for us was not knnowing who had the final say.. but if I were you I'd go this route.

MMeryem S***Member
Job title
Graphic Designer
Sector
Consulting
Organization type
family business
Joined
May 2024
Message
208
#14

Great work. The harder it is to reverse a decision the slower you should make it.

If you have questions, write them; Ill answer as best I can.

ÖÖzgür K***MemberCommunity member
Joined
Nov 2023
Message
4
#15

I've been dealing with this for a long time. The answer varies greatly by industry; there is no one-size-fits-all rule.

If you post the result here, it will help others too.

FFiliz S***Member
Job title
Software developer
Sector
Printing
Organization type
early-stage startup
Joined
Apr 2026
Message
129
#16

I feel the same way. Taking measures without an inventory leaves doors you haven't seen open.

Proven by experience.

AAleyna Ş***MemberCommunity member
Joined
Apr 2024
Message
15
#17

Great work.

FFiliz Ö***Member
Job title
Operations manager
Sector
Seafood
Organization type
8-person team
Joined
Sep 2024
Message
383
#18

the discussion got scattered, let me summarize and don't hesitate to ask; those who don't ask always pay more.

İİsmail T***MemberCommunity member
Joined
Jan 2024
Message
418
#19

I think differently. Don't hesitate to ask; those who don't ask always pay more.

Of course, it varies if your situation is different.

BBurak A***Member
Job title
IT manager
Sector
E-commerce
Organization type
early-stage startup
Joined
May 2023
Message
126
#20

i agree with this. tbh taking notes for two weeks yields better results than a six-month estimate.

correct me if Im wrong.

Reply