Justin Brooks, Vice President, U.K. & Ireland, Zscaler.
AI has changed the economics of cyberattacks. For years, security teams have worked on the assumption that attackers move through a familiar sequence: reconnaissance, exploitation, credential theft, privilege escalation, lateral movement and, eventually, data access or disruption. That sequence still exists, but it is no longer necessarily linear, manual or slow.
Frontier models and agentic AI systems are compressing the attack timeline. They can itemize exposed assets, test vulnerabilities, automate phishing, dump credentials, probe internal systems and chain findings together faster than defenders can investigate manually. If attackers can move from initial access to impact in minutes or hours, waiting to accumulate alerts, correlate signals and confirm intent is no longer good enough.
Why Deception Belongs At The Center Of Modern Defense
This is why deception deserves a more central role in modern cyber defense. It places realistic, instrumented assets in the paths attackers are likely to take, using their interaction with those assets as a high-confidence signal of malicious activity. In an era of machine-speed attacks, deception gives defenders deterministic evidence that an attacker is present and exploring the environment.
The principle is simple. Legitimate users and workloads should have no reason to interact with a fake credential, a decoy application or a decoy cloud workload. An attacker, however, does not know which assets are real and which are deceptive. When they harvest credentials or attempt lateral movement, they are likely to touch something that has been deliberately designed to be attractive, plausible and monitored.
That interaction cuts through alert fatigue. Security teams are inundated with signals that require interpretation and prioritization. Deception changes the confidence model. If a decoy credential is used, an application is accessed or a fake service is probed from a compromised endpoint, the act of touching the decoy is the confirmation.
Turning Attacker Automation Against Itself
This is especially powerful against agentic attacks. AI-driven adversaries can run discovery and exploitation steps in parallel, testing applications, identity stores, credentials, cloud assets, internal services and AI interfaces simultaneously. That speed is dangerous, but it creates a defender opportunity: The faster attackers explore, the faster they encounter traps embedded across the environment.
In other words, deception turns the attacker’s automation against them. A human intruder might move cautiously and avoid obvious lures. An agentic attack optimized for speed and breadth is more likely to test every route. If decoys are distributed across endpoints, applications, identity systems and cloud workloads, the attacker’s momentum increases the probability of detection.
From High-Confidence Detection To Containment
For security leaders, this reframes deception from a niche detection technique into an active defense capability. A decoy should not simply generate another alert; it should trigger containment. When a compromised user touches a deceptive application, access to production applications can be blocked. When an endpoint interacts with decoy credentials, EDR can quarantine the device. When malicious traffic reaches a decoy service, perimeter controls can be updated. With a strong enough signal, response can be automated without waiting for an analyst to review every detail.
This is critical because the goal is not just to detect attackers; it’s to track and constrain them while limiting business impact. Deception shows which credentials attackers try, which applications they probe, which resources they value and which techniques they use to evade controls or move laterally. That telemetry helps security teams understand intent earlier and respond with greater precision.
Making Complex Environments Observable
It also complements, rather than replaces, the fundamentals. Organizations still need to reduce their attack surface, move private applications behind zero-trust access, segment connectivity, inspect encrypted traffic, harden AI assets, prioritize vulnerabilities and maintain strong identity controls. But even with those measures in place, compromise remains possible. Deception provides an additional control for the moment an attacker slips past prevention and starts to explore.
The rise of AI-enabled attacks makes this layered approach more urgent. Attackers can reason across multiple steps, chain vulnerabilities, automate credential use and interact with systems at scale. Meanwhile, enterprise environments now span public cloud, private infrastructure, SaaS platforms, developer environments, AI chatbots, model endpoints and data stores. No security team can manually track every possible path through that estate in real time.
Practical Requirements For Machine-Speed Defense
The most effective deception strategies are operationally simple. Security teams do not need another complex program that takes months to tune. Deception should be easy to deploy, integrated with access, endpoint, SIEM and SOC workflows, and capable of generating immediately actionable alerts. In a world where attackers are automating faster, defenders need controls that deploy quickly and deliver clear outcomes.
That is the real promise of deception in the AI era. It does not depend on predicting every new exploit or understanding every possible attacker technique in advance. It does not require defenders to know exactly how an agentic attack will reason through an environment. Instead, it asks a more practical question: If an attacker is present, where are they likely to look, what are they likely to touch, and how can we make that contact visible?
As AI accelerates offense, defenders must respond with equal speed and greater certainty. Deception gives security teams a way to identify attackers by their behavior, track their movement through realistic lures and trigger containment before a small compromise becomes a business-impacting incident. Once seen as an advanced capability for mature teams, it should now be considered a practical requirement for organizations preparing to defend against machine-speed attacks.
Attackers are moving faster because AI allows them to explore more paths, test more assumptions and automate more. The defender response cannot be limited to more alerts and slower analysis. By placing believable decoys across the attack surface and connecting those signals to automated containment, organizations can turn attacker speed into an advantage. The faster adversaries move, the sooner they reveal themselves.
Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?


