Founder and CEO at CYFIRMA, overseeing the business strategy, product roadmap, growth & expansion plan, and investor relationship.

For nearly two decades, honeypots were the closest thing the security industry had to a window into attacker behavior.

I have spent much of my career watching honeypots work. I began at a premier intelligence agency, where I served as head of cyber threat intelligence, building and operating national-scale deception capability. I later carried that discipline into my present work, deploying deception environments to generate firsthand, zero-day intelligence on live adversaries.

Over those years, I've seen it time and time again: The moment an attacker suspects they are being watched, they disengage, and the intelligence stops. Honeypots, for all their promise, routinely gave the game away.

The reason is that a honeypot tries to imitate a system, but a modern adversary is not fooled by a system. Instead, they are fooled, or not fooled, by an environment.