We run a wholesale distribution business in Chicago with 35 employees. Our local office has a file server an on-prem accounting database, and a VPN setup for our remote sales reps. A third-party cybersecurity consultant reviewing our network recommended setting up 'honeypots'—trap systems—inside our internal network.
The quote he gave us is $3,200 for setup and $450/month for monitoring. We're still trying to get basic employee password complexity and email security training off the ground. Is this kind of 'decoy' system really a critical need for a small business with just a few servers?
I want to understand what this tech actually does, what it gives us in practice, and if it's worth the budget. Or is this consultant just trying to sell us an enterprise-grade luxury toy?