- Job title
- Accounting Manager
- Sector
- Consulting
- Organization type
- early-stage startup
- Joined
- Oct 2023
- Message
- 140
We're a 12-person textile e-commerce company. Our website and order tracking software run on our own rented VPS. Last month our server got hit with over 40,000 failed SSH attempts in 3 days. We set up a firewall, but our developer suggested, "Let's set up a honeypot, divert attackers there to collect logs, and get early warnings."
The honeypot idea sounds great in theory but our team only has one developer and a part-time sysadmin. What exactly is a honeypot, and does it genuinely make sense for small teams like ours?
If misconfigured, is there a risk that this decoy system could become a pivot point for attackers to breach the main network? At our scale, how much time does setup and daily monitoring take, and is it worth the effort?