We're a 45-person logistics software company based in Chicago. We're currently in talks with a new security vendor for our cloud servers and internal office network. They strongly advised us to add 'deception technology' alongside our standard endpoint protection, quoting 18,000 USD for an annual license.
During the pitch I argued this is basically the same old honeypot concept we've known for years and that spinning up an empty VM to monitor network traffic would get us the same result at virtually zero cost. The sales engineer insists this isn't a static honeypot, but rather generates active deception layers and dynamic breadcrumbs.
What is the real-world difference between these two concepts in a mid-sized environment like ours? In terms of operational overhead and false positives is there any genuine return on spending budget on commercial platforms like this instead of just deploying a simple honeypot and calling it a day?