- Job title
- Human Resources Manager
- Sector
- Media and publishing
- Organization type
- workshop
- Joined
- Oct 2022
- Message
- 2
Doki · Vulnerability scanning · 2024
We are a textile wholesaler in Bursa with 12 employees. In our office we have 1 local file server and a cloud-hosted accounting software. An external IT consultant we hired suggested planting fake files and credentials called honeypot tokens on our servers.
According to them, they place a fake password file or employee list on the server, and if someone clicks on this file from inside or outside, we immediately get an alert. They quoted a one-time setup fee of 15,000 TL, plus a monthly monitoring and reporting fee of 2,500 TL.
Honestly, more than the budget, the concept itself has me confused. Is this system really necessary for a company our size, or is it total overkill? Also, are there any legal or operational risks towards employees when planting such traps on our own server?