Let's talk about your project
DOKI / Cybersecurity

Cybersecurity · Deception and decoys

We place decoy assets in your network that look like real systems but carry no workload. Legitimate users have no reason to touch them; when someone does, you get an early, clear warning rather than a false alarm.

  • Isolated decoys
  • Alert rules
  • Response playbook
  • Scope boundaries
01 / What this service includes

Tempting for an attacker, silent for you.

01

Isolated decoys

Decoy servers, shares and accounts run in a segment isolated from your real systems. Even if compromised, there is no path from them into your production network.

02

High-confidence alerts

Every connection to a decoy is suspicious, so alerts are few and each is worth a look. The alert reaches your team with its source and the action that was attempted.

03

Response playbook

Who does what, in which order, when an alert arrives is written in advance: isolate the source, disable the account, preserve the traces. The playbook is exercised at least once a year.

02 / How it works

Layout of the decoy network

Decoys sit on the paths an attacker would take toward real assets and are wired to a single alerting point.

Decoy serverDecoy databaseDecoy admin screenDecoy DNS recordAlerting point
03 / Scope

Let's define the scope together.

We clarify the scope, deliverables and acceptance criteria together in the first meeting. The written quote lists that scope item by item; if the scope changes, the quote is updated as a new version.

Only explicitly authorized assets and agreed scope are assessed.

Deliverables

  • 01Isolated decoys
  • 02Alert rules
  • 03Response playbook
  • 04Scope boundaries
04 / Process

How we move forward, step by step.

Each step ends with something concrete in your hands; we move on with your approval.

  1. 01

    Scope

    Together we put the goal, the boundaries and the acceptance criteria in writing.

  2. 02

    Setup

    We set up tools, access and settings, document the setup and hand it over to you.

  3. 03

    Simulation

    Within the authorised scope, we run the agreed scenarios in a controlled way.

  4. 04

    Reporting

    We share what was done, the result and the next step in a plain report.

05 / Decision details

What to know before you ask for a quote.

What is included, what we need from you, timing and payment, all in one place. The exact scope and price are set in the written quote.

Included

  • Decoys placed in your network, isolated from real systems (decoy servers and decoy files).
  • An alert as soon as a decoy is touched, plus written response steps.

What we need from you

  • A signed written authorisation.
  • Approval for the network segments where decoys go.
  • Who should receive the alerts.

What sets the price

  • Number of decoys and size of the network.
  • We respond to every request within 12 hours.
  • Meetings are held in Turkish; correspondence and deliverables are handled in the language of your choice with translation support.
  • We work in person in Istanbul and remotely across Türkiye and worldwide.
06 / FAQ

The questions on your mind.

Tell us what you need; we will define the scope together.

Tell us about your project
Won't the decoys mislead our own staff?

Decoys are placed where daily work never goes, and your IT team knows which ones are decoys. Innocent touches in the first weeks are reviewed and, if needed, the decoy is moved.

Is permission needed before testing?

Yes. Only systems you are authorised for and have approved in writing are assessed.

Will testing affect my live system?

Scope, time window and methods are agreed in advance; risky steps require your separate approval.

Let's begin

Let's talk about your project.

Tell us what you need; we will define the scope together.