forumNew topic

Are honeypot trap systems actually worth it on a small company server?

MMustafa Ç***Member
Job title
Clinic manager
Sector
Glass
Organization type
two-branch business
Joined
Oct 2022
Message
49
#1

We're a 12-person logistics and customs software company based in Lyon. We run two virtual servers with an infrastructure cost of around 450 euro a month. While checking our server logs last week, we noticed tens of thousands of failed login attempts per day hitting our ssh and database ports.

An outside consultant suggested we set up a honeypot system, claiming we could observe attacker methods and take preventive action. Honestly, we're a small team with no full-time cybersecurity specialist on staff.

Do these honeypot systems provide tangible protection for a small setup like ours, or will they just create an extra maintenance and analysis headache?

HHilal D***MemberCommunity member
Joined
Dec 2024
Message
166
Most Helpful#2

Short answer: For a small business, setting up a honeypot on its own doesn't provide a direct protective shield; it's simply a decoy that logs the tools and techniques attackers use. Deploying a honeypot before taking basic server hardening measures is a waste of time for a small team, and if not properly isolated, it actually creates a new security risk.

Honeypots fall into two main types. Low-interaction ones simply listen on specific ports and return fake responses to log attack attempts; they consume few resources, but their value is limited if no one is reviewing the log pile and acting on it. High-interaction honeypots simulate a real operating system, letting you observe attacker behavior in depth, but unless completely isolated from your primary network, they can easily become a jumping-off point into your production servers.

In your situation, the proper sequence is: 1) Close standard management ports to the public internet and restrict access strictly to internal static IPs or a VPN, 2) Disable password-based authentication completely and switch exclusively to SSH keys, 3) Deploy IP-banning tools to block automated brute-force attacks. Chasing honeypots before doing these three things is like putting a camera in the backyard of a shop without locking the front door.

GGamze K***Member
Job title
QA Tester
Sector
Printing
Organization type
sole proprietorship
Joined
Jan 2025
Message
178
#3

Seeing tens of thousands of requests a day is entirely normal; it's just automated internet-wide scanning bots. Even if you set up a honeypot, these bots will hit it and tell you what you already know: bots exist on the internet. Even for a low-interaction trap, you can't leave it on the same VLAN as your production network; you'd need a separate subnet and strict firewall rules.

Edit: asked below, I wrote the answer in the second message.

UUfuk B***Member
Job title
Field sales representative
Sector
Paper
Organization type
chain store
Joined
Nov 2024
Message
2
#4

Shelve the consultant's advice for now. Changing default ports, disabling password logins in favor of key files, and setting up a basic security tool to temporarily ban failed attempts will eliminate almost all of those daily scans immediately. You can fix this in two hours at zero cost.

MMelis K***Expert
Job title
Marketing director
Sector
Real estate
Organization type
family business
Joined
Mar 2022
Message
205
#5

Out of curiosity last year, we spun up an open-source ssh honeypot on a spare server. In three days, it collected over 140k login attempts and 800 different username variations. One of our devs wasted 4 hours a week combing through useless noise. We shut it down completely after a month because it didn't give us a single actionable insight.

GGamze K***Member
Job title
Accounting Manager
Sector
Textile
Organization type
300-person organization
Joined
Jul 2024
Message
350

Doki · E-commerce infrastructure · 2026

#6

Did the consultant mention who's going to monitor the logs after setting up this honeypot? Do you have a security operations center to manage alerts, or are you just going to set it up and forget it? What's the point of setting a trap if you haven't budgeted for analyzing reports on a weekly basis?

YYasemin T***New memberCommunity member
Joined
Aug 2026
Message
68
#7

totally unnecessary man... that consultant is probably just trying to sell you a template from big enterprise projects. close the ssh port to the outside world or put it behind a vpn and thats enough. you dont have enough lifetimes to read through all those logs.

ZZehra E***ExpertCommunity member
Joined
Aug 2023
Message
220
#8

A honeypot is not a defense tool it is a threat intelligence and research tool. Companies with hundreds of employees that have their own security teams use it to detect new attack vectors early on. A 12-person software company simply doesn't have the operational luxury to study attacker profiles.

KKemal T***Member
Job title
Site Manager
Sector
Agriculture
Organization type
20-person company
Joined
Mar 2025
Message
191

Doki · Brand identity · 2025

#9

The matter is quite clear. A honeypot doesn't prevent an attack, it merely documents it. What you need isn't to analyze logs, but to lock the doors. The moment you close the ports to the outside and switch to key-based authentication, all these question marks will disappear.

KKemal U***VeteranCommunity member
Joined
Nov 2025
Message
1
#10

My questions are cleared up, thanks. Processes without records never improve, because you don't know what to fix.

Forgotten test environments are more often the entry point than live systems. Good luck with that.

FFeyza S***Member
Job title
Front office accounting
Sector
Furniture manufacturing
Organization type
sole proprietorship
Joined
Dec 2023
Message
414
#11

If I understood correctly, you're saying: The real issue isn't the number, but what it's based on.

SSinan Ç***Member
Job title
Administrative manager
Sector
Security services
Organization type
20-person company
Joined
Jan 2025
Message
159
#12

My perspective changed after experiencing that. anyway trying to do this alone is the most expensive way.

Trying to do this alone is the most expensive way.

FFatma N***Member
Job title
Data Engineer
Organization type
sole proprietorship
Joined
Apr 2024
Message
142
#13

Let me speak from the other side; I'm on the supplier side. An automated scan report is not the same as a penetration test.

Good luck with that.

NNevinMember
Job title
Language school
Joined
Apr 2024
Message
92
#14

I'll try it.

ÖÖzgür Y***MemberCommunity member
Joined
Mar 2022
Message
385
#15

I didn't know that.

İİbrahim S***MemberCommunity member
Joined
Apr 2026
Message
106
#16

don't miss this: An untested bacup is not a backup.

when maaking a decision first look at what data you have on hand... if you post the result here it will help others too.

KKoray C***MemberCommunity member
Joined
Oct 2022
Message
180
#17

There is something to watch out for. Start with a small trial; don't commit to everything at once.

Just leaving this note, it might be useful.

NNuri Y***ExpertCommunity member
Joined
Oct 2023
Message
246
#18

Let me summarize what's been said so far. If the notification path is long, notifications don't arrive; missing notifications mean delayed incident detection.

Good luck with that.

EEsmaNew member
Job title
Small business owner
Organization type
two-branch business
Joined
Oct 2024
Message
40

Doki · SEO consulting · 2025

#19

We need to take it step by step. The biggest time-waster for us was not knowing who had the final say.

Just leaving this note, it might be useful.

VVildan Y***Member
Job title
Content Editor
Sector
Retail
Organization type
20-person company
Joined
Nov 2024
Message
70
#20

I'll argue the opposite, don't get mad. Just because everyone does it doesn't mean it's right.

Good luck with that.

Reply