forumNew topic

Thinking of setting up a honeypot on our server — does it make sense for a small business, or is it risky?

KKübra M***Member
Job title
Accounting Manager
Sector
Consulting
Organization type
early-stage startup
Joined
Oct 2023
Message
140
#1

We're a 12-person textile e-commerce company. Our website and order tracking software run on our own rented VPS. Last month our server got hit with over 40,000 failed SSH attempts in 3 days. We set up a firewall, but our developer suggested, "Let's set up a honeypot, divert attackers there to collect logs, and get early warnings."

The honeypot idea sounds great in theory but our team only has one developer and a part-time sysadmin. What exactly is a honeypot, and does it genuinely make sense for small teams like ours?

If misconfigured, is there a risk that this decoy system could become a pivot point for attackers to breach the main network? At our scale, how much time does setup and daily monitoring take, and is it worth the effort?

YYiğit A***VeteranCommunity member
Joined
Jan 2025
Message
2
Most Helpful#2

Short answer: A honeypot is a decoy network or server resource deliberately made to look vulnerable in order to deceive attackers, understand their intentions, and keep them away from production environments. For a small business, if not properly configured, it poses more security risks and serious operational overhead than actual benefits.

There are essentially two types of honeypots: low-interaction and high-interaction. Low-interaction systems only emulate specific services (e.g., a fake SSH port) and don't allow attackers to run commands. High-interaction honeypots offer a real operating system, letting attackers move around inside; however, without total isolation, the risk of an attacker pivoting to your main server is extremely high.

In a 12-person team with a single developer, doing basic security hardening is far more rational than setting up a honeypot. Changing the SSH port to a non-standard one, disabling root login, enforcing key-based authentication only, and restricting IPs will stop nearly all of those SSH attempts.

Unless you have a dedicated security specialist to analyze hundreds of thousands of attack log lines, running a honeypot will just drain server resources and serve as a distraction. Your priority should be locking the front doors, not setting traps.

OOkan I***Member
Job title
Front office accounting
Sector
Cosmetics
Organization type
sole proprietorship
Joined
Nov 2023
Message
260
#3

A honeypot is an intelligence tool, not a defensive measure. Large enterprises deploy them to study attack techniques. At the SME level, watching random bots try to brute-force their way in brings zero commercial or technical value to your business. Spend your time on security patches and backup discipline instead.

CCaner A***Member
Job title
Technical service technician
Sector
Agriculture
Organization type
sole proprietorship
Joined
Nov 2022
Message
157
#4

Those 40k attempts are most likely simple brute-force bots randomly scanning the internet. When you aren't even dealing with a targeted attack, trying to set up a decoy and analyze logs is like starting a fire while looking for a needle in a haystack. A single network misconfiguration could turn your main server into a sitting duck.

CCaner G***MemberCommunity member
Joined
Aug 2023
Message
218
#5

Your dev is just eager to experiment, but there's really no need. Switch your SSH port from 22 to a random five-digit port, disable password logins in favor of SSH keys, and throw fail2ban on the box. Those 40k attempts will drop to zero overnight, total peace of mind.

HHavva B***MemberCommunity member
Joined
Dec 2023
Message
4
#6

We got curious last year and spun up a low-interaction honeypot on a separate IP. It logged 180k IPs in a single week. We checked it excitedly for the first three days, and after that, nobody even bothered opening the logs. It did nothing except add an extra 450 TL to our monthly server bill, so we shut it down two months later.

NNurcanNew member
Job title
Cleaning services
Joined
Nov 2024
Message
26
#7

wait, so does an attacker falling into this trap actually think they breached the server? like do you have to put fake cuustomer data in there to make it look convincing?

KKaan G***ExpertCommunity member
Joined
Jun 2023
Message
94
#8

we tried that once too and the log files bloated up filled the disk and crashed the main database in the middle of the night. imo dont bother standard security practices are plenty.

İİbrahim S***Expert
Job title
Store Manager
Sector
Printing
Organization type
20-person company
Joined
Nov 2022
Message
1
#9

If your team still insists on setting one up, you must follow these rules without exception: 1) Never host the decoy on the same local network as the main server; keep it on an entirely isolated VPS. 2) Never allow outbound connections, so your server doesn't get turned into a botnet zombie attacking others. 3) Set up daily log rotation so your disk space doesn't get eaten up.

FFiliz A***ExpertCommunity member
Joined
May 2025
Message
14
#10

Bottom line: honeypots are meant for dedicated security teams monitoring targeted attacks. For small e-commerce setups, it's just unnecessary risk and operational overhead. Changing your port and moving to key-based auth will solve your issue completely.

SSena K***Member
Job title
Accounting clerk
Sector
Media and publishing
Organization type
boutique agency
Joined
Feb 2025
Message
2
#11

The discussion got scattered, let me summarize. Start with a small trial; don't commit to everything at once.

Good luck with that.

RRamazan K***MemberCommunity member
Joined
Jan 2025
Message
33
#12

I agree.

EEmre D***MemberCommunity member
Joined
Nov 2024
Message
43
#13

My perspective changed after experiencing that... The harder it is to reverse a decision, the slower you should make it.

This is my opinion I'm not claiming it's absolute truth.

MMert D***MemberCommunity member
Joined
Feb 2023
Message
40
#14

Just a heads-up. Most incidents start with a leaked password, not a vulnerability.

This is my opinion, Im not claiming its absolute truth.

NNuri Y***Expert
Job title
Store Manager
Sector
Leather
Organization type
300-person organization
Joined
Aug 2022
Message
95
#15

I feel the same way. When making a decision first look at what data you have on hand.

Proven by experience.

FFatma Ç***Member
Job title
Production Manager
Sector
Printing
Organization type
cooperative
Joined
May 2023
Message
27
#16

My questions are cleared up, thanks.

OOnur M***Veteran
Job title
Chief Technology Officer
Sector
Electrical-electronics
Organization type
chain store
Joined
Aug 2024
Message
19

Doki · Penetration test · 2026

#17

Exactly like that. Trying to do this alone is the most expensive way.

The real issue isn't the number, but what it's based on. Good luck with that.

KKemal S***Member
Job title
Content Editor
Sector
Sports and fitness
Organization type
a company within a holding
Joined
Jul 2022
Message
1
#18

I've been down this road, let me tell you. Mistakes made on the what is a honeypot side are usually reversible but expensive.

SSenaMember
Job title
Graphic Designer
Organization type
two-branch business
Joined
Jul 2024
Message
86
#19

i've been dealing with this for a long time and when making a decision, first look at what data you have on hand.

forgotten test environments are more often the entry point than live systems.

LLeyla P***Member
Job title
Production planning
Sector
IT services
Organization type
early-stage startup
Joined
Nov 2024
Message
249
#20

I agree with this. If it's your first time start small; scaling comes later.

Hope this helps.

Reply