forumNew topic

Our consultant suggested setting up a honeypot on our network: What is this trap, and do we really need it?

SSonerMember
Job title
Metal manufacturing
Organization type
chain store
Joined
Dec 2023
Message
76

Doki · Corporate website · 2025

#1

We are an 18-person international logistics and customs consultancy based in Moscow. At our headquarters, we have two local servers hosting our accounting and customs records, alongside a cloud-based business app our staff connects to. The outsourced IT contractor managing our infrastructure security recommended setting up a "honeypot" to detect cyberattacks and suspicious internal network activity early on.

They're asking for a 130,000 ruble setup fee, plus 25,000 rubles a month for log monitoring. From what I’ve read, it’s basically a decoy server or trap service designed to mislead attackers. What exactly is a honeypot for an SMB on a tight budget like ours? Does it genuinely provide a security shield, or would it be a luxury expense when we should be putting resources toward basic security gaps instead?

BBurak O***Member
Job title
Store Manager
Sector
Catering
Organization type
40-person manufacturing company
Joined
Oct 2023
Message
18

Doki · E-commerce infrastructure · 2026

#2

Technically speaking, a honeypot is a decoy server on your network with deliberate fake vulnerabilities that carries zero legitimate business traffic. A normal employee would never connect to it; therefore, any packet hitting it is an immediate indicator of an attack or malware.

BBurak O***Member
Job title
Operations manager
Sector
Jewelry
Organization type
early-stage startup
Joined
Feb 2023
Message
192
Most Helpful#3

Short answer: A honeypot is an intentionally vulnerable decoy system with zero legitimate function, set up to trick attackers or malware that have penetrated your IT network. It's very effective for generating early warnings, but it's not a priority for an 18-person company that hasn't nailed down basic security measures yet.

A honeypot doesn't actively defend; it merely sounds the alarm. In other words, it won't block an incoming attack—it just logs that an attacker stepped into the trap. If you don't have a 24/7 security specialist on hand to analyze and respond to those alerts instantly, that 25,000 rubles a month is essentially being spent on reading retrospective post-mortem reports.

Putting your budget toward these basic security steps will give you far more realistic protection than a decoy trap: 1) Enforce mandatory multi-factor authentication (MFA) on all server and email logins, 2) Create daily backups of accounting and customs data to physically isolated, offline backup units disconnected from the internet, 3) Completely strip local admin privileges from employee computers.

Setting up a honeypot before putting these three basic barriers in place and segmenting your network with VLANs is like installing an expensive alarm in the backyard while leaving all the windows wide open.

HHatice A***MemberCommunity member
Joined
Dec 2023
Message
2
#4

Sounds like your consultant is pitching what's easy to sell and ties you to a monthly subscription, not what you actually need. The priority for an 18-person logistics firm is isolated backups against ransomware, not laying traps.

ZZehra D***Veteran
Job title
Courier coordinator
Sector
Automotive aftermarket
Organization type
sole proprietorship
Joined
Jun 2023
Message
80
#5

We set one up out of curiosity at an office of similar size. It logged thousands of automated bot scans a day, but 99% of it was just general internet noise. Without an in-house expert to respond, the log files just ended up eating disk space on the server.

TTarkanMember
Job title
Retail manager
Joined
Mar 2024
Message
104
#6

Spend that 130,000 rubles on a solid hardware firewall and an automated offline backup setup. It makes far more sense to make breaking in harder in the first place than to just get an alert after an attacker is already inside.

RRamazan G***Expert
Job title
Secretary
Sector
Leather
Organization type
20-person company
Joined
Apr 2022
Message
92

Doki · Mobile app · 2025

#7

unless ur a major bank or a telecom company honeypots are pure overkill. just enforce strong passwords for staff and enable 2fa and ur good.

GGürkan K***Member
Job title
Human Resources Specialist
Sector
Catering
Organization type
120-person company
Joined
Dec 2024
Message
157
#8

I saw a similar setup at a customs firm last year. Nobody checked the decoy logs for months and the real attack started when the accountant clicked a phishing email. The trap did absolutely nothing.

AAlper C***Expert
Job title
Customer service representative
Sector
Software
Organization type
cooperative
Joined
Dec 2023
Message
74
#9

Is this planned honeypot going to be exposed to the outside web or kept strictly on the internal network? If it's internet-facing, an amateurish configuration could easily turn into a stepping stone for attackers to pivot deeper into your network.

İİsmail T***MemberCommunity member
Joined
Jan 2024
Message
418
#10

The fundamental rule of security is reinforcing the weakest link. In an 18-person business, the weakest link isn't server exploits; it's users opening fake invoice attachments. Allocate your budget to staff awareness training and proper backups.

KKoray C***MemberCommunity member
Joined
Oct 2022
Message
180
#11

I've been dealing with this for a long time. If you don't write this down from the start, it leads to arguments later.

If you post the result here, it will help others too.

MMurat K***Member
Job title
SaaS developer
Organization type
boutique agency
Joined
Mar 2024
Message
118

Doki · Log management setup · 2025

#12

I'll argue the opposite don't get mad. When making a decision, first look at what data you have on hand.

If permission and scope aren't in writing, don't start that test. anyway this is my opinion, I'm not claiming it's absolute truth.

JJülide A***MemberCommunity member
Joined
Aug 2024
Message
1
#13

We need to take it step by step. When you try to change everything at once, nothing settles.

When making decisions, write down the worst-case scenario too not just the best.

NNazlı T***Expert
Job title
Sales Manager
Sector
Insurance
Organization type
40-person manufacturing company
Joined
Jan 2025
Message
133
#14

I'd appreciate it if you shared the outcome.

HHavva M***Expert
Job title
Front office accounting
Sector
Media and publishing
Organization type
chain store
Joined
Sep 2022
Message
197
#15

Correct in theory, but it doesn't work that way in practice. Security isn't absolute; it's about making attacks not worth the effort.

Good luck with that.

GGizem Y***MemberCommunity member
Joined
Feb 2026
Message
40
#16

Let me summarize what's been said so far. An automated scan report is not the same as a penetration test.

If you post the result here, it will help others too.

DDamla K***Veteran
Job title
Graphic Designer
Sector
Consulting
Organization type
two-branch business
Joined
Jan 2022
Message
320
#17

I've been dealing with this for a long time. Mistakes made on the what is a honeypot side are usually reversible but expensive.

If 2FA is on, a stolen password alone is useless. Correct me if I'm wrong.

EErcan T***MemberCommunity member
Joined
Apr 2022
Message
138
#18

i agree.

EEsra D***MemberCommunity member
Joined
Sep 2024
Message
102
#19

I went through the same thing.

DDilara U***Member
Job title
Store associate
Sector
Energy
Organization type
8-person team
Joined
Sep 2025
Message
15
#20

you're right. like hasty decisions become decisions you have to fix six months later.

this is my opinion, Im not claiming its absolute truth.

Reply