Menu
Vela Blog Cybersecurity

Why Deception Belongs in Your 90-Day Cyber Readiness Plan

The clock is ticking.

Cyber deception has been gaining momentum for years, but the conversation has changed quickly. What was once viewed by some security teams as an advanced or specialized capability is now being discussed as a practical response to AI-assisted attacks, shrinking exploit timelines, and overloaded security operations.

The expert community is pointing in the same direction. Gartner has been talking about preemptive cybersecurity, where the goal is to deny, deceive, and disrupt attackers before they can complete their objectives. MITRE Engage is built around the same active defense ideas, helping organizations think through adversary engagement, denial, and deception as part of a deliberate security strategy. 

Meanwhile, two important documents arrived in quick succession this month, and security leaders should read them as a pair.

First, the Cloud Security Alliance (CSA), SANS, [un]prompted, the OWASP Gen AI Security Project, and a long list of cybersecurity leaders released The AI Vulnerability Storm: Building a Mythos-Ready Security Program, an expedited strategy briefing created in response to Anthropic’s Claude Mythos capabilities disclosure. The briefing gives CISOs an actionable framework for responding to AI-driven vulnerability discovery and includes a clear near-term recommendation: build a deception capability within the next 90 days. That recommendation is part of a broader 11-action security program, which also calls for actions like AI agent adoption, updated risk models, continuous patching readiness, attack surface reduction, environment hardening, automated response, and a permanent VulnOps function. Deception stands out because it is one of the more concrete steps security teams can begin taking now. It is measurable, operational, and directly tied to how AI-assisted attackers are beginning to behave.

Second, Anthropic’s LLM ATT&CK Navigator report adds important context. Anthropic analyzed 832 banned accounts associated with malicious cyber activity over one year and mapped observed behavior to MITRE ATT&CK. The report shows AI use moving beyond preparation and into operational activity inside live environments. Attackers are using AI to help with account discovery, service enumeration, lateral movement, exfiltration, and multi-step orchestration.

Read together, the two documents make a complete argument: as threats move faster and deeper into the kill chain, security teams need more than the traditional sequence of detection, research, patching, and response. The fundamentals still matter, but defenders also need controls that can detect suspicious behavior when the exploit, malware, or vulnerability is unknown.

Why the Clock is Ticking

AI-assisted vulnerability discovery changes the defender timeline. If attackers can find weaknesses faster, develop exploits faster, and move from discovery to action faster, then security teams have less time to rely on the usual sequence of detection, research, patching, prioritization, and response.

Patching, asset inventory, segmentation, MFA, dependency management, and incident response remain critical. In many cases, they matter more than ever. The challenge, however, is that those controls still depend on time, awareness, and coordination. Security teams need to know what exists, understand what is vulnerable, identify what matters most, apply the right fix, and respond before the attacker moves too far.

AI compresses that timeline.

It also changes what attackers can do once they are inside. Anthropic’s ATT&CK findings suggest AI use is moving from preparation into live operations, where attackers enumerate accounts, test access, pivot across systems, and chain actions together. Those behaviors matter because they create a detection opportunity. When an attacker explores an environment, follows credentials, tests access, or investigates something that appears valuable, deception can turn that activity into a high-confidence signal.

That is why the CSA/SANS recommendation matters. Deception is attack-tool and vulnerability independent. It doesn’t need to know which model the attacker used, which CVE got them in, or which exploit path they followed. It detects what the attacker does next.

How Cyber Deception Works

See how ACE works.

The basic concept behind deception is straightforward. A deception platform creates believable-but-fake assets that appear attractive inside an environment. These can include decoys, baits, breadcrumbs, lures, honey accounts, honey tokens, fake credentials, cloud artifacts, IT assets, OT assets, and other elements placed where an attacker is likely to look.

Those elements are designed to look useful to an attacker, but they have no legitimate business purpose. Since normal users and normal business processes shouldn’t need to interact with them, the signal is cleaner. If an attacker, insider, automated process, or AI-assisted attack path engages with a deception element, the security team gets an early indication that something deserves attention.

That is what makes deception especially relevant in an AI-assisted attack environment. AI can help attackers enumerate more thoroughly, move faster, and test more paths than a human operator might explore manually. The same exhaustive behavior that makes an AI-assisted intrusion dangerous can also make it more likely to touch a decoy, follow a breadcrumb, test a honey account, or interact with an asset that should never be touched.

Deception doesn’t replace the rest of the security program. It adds an early-warning layer in the places where attackers are likely to move after preventive controls fail.

What a 90-Day Deception Effort Can Look Like

Days 1-14: Begin with the assets and pathways attackers are most likely to care about. In the first month, the priority is identifying crown-jewel systems, sensitive data stores, privileged identities, key network segments, and the paths an attacker might use to reach them. This work supports deception, but it also strengthens broader cyber readiness by clarifying what matters most and where lateral movement risk is likely to concentrate.

Days 15-45: Place an initial deception layer in areas most likely to attract attacker attention. That may include breadcrumbs where an enumerating attacker would look first, baits and honey tokens in file shares or cloud storage, decoy service accounts in the directory, and decoy assets projected into key network segments. Early coverage should focus on the paths an attacker is most likely to test first, with high-confidence detection points placed around priority assets, credentials, and lateral movement routes.

Days 46-75: Connect the signal to response. A deception alert is only useful if the right people see it quickly and know what to do next. Alert routing, escalation contacts, runbook actions, containment expectations, and approval thresholds should be defined and documented before a real incident occurs. In an AI-assisted attack environment, the time between discovery and action may be shorter than teams are used to, so the response model needs to be ready before the alert fires.

Days 76-90: Test and tune. Organizations should validate that deception elements are visible where intended, alerts route correctly, runbooks make sense, and teams understand how to investigate and respond when a deception asset is touched. They can also measure time from interaction to investigation, identify gaps in coverage, tune deception placement, and refine response procedures.

By the end of the 90 days, deception should no longer be a concept or a pilot with unclear ownership. It should be an operational capability that produces actionable intelligence, supports faster investigations, and delivers a measurable improvement in cyber readiness to leadership.

Built for This Moment

Cyber deception has existed for years, but deploying it well takes planning. The technology needs to fit the environment. The deception elements need to be believable. The alerts need to route to the right people and tools. The incident process needs to be clear before a real alert occurs. Without that operational layer, even a strong platform can become another tool that a busy security team has to learn, tune, and maintain.

Velaspan’s Active Cyber Engagement (ACE) solution was built for this exact moment. ACE is a managed cyber deception and adversary engagement service powered by Acalvio ShadowPlex and operated by Velaspan. For qualified environments, ACE can help organizations stand up a deception capability in as little as 30 days, giving security teams a practical path to act on the 90-day guidance without spending that entire window evaluating, learning, staffing, and managing a new platform on their own.

That managed approach is the difference between deploying deception technology and making deception operational. Velaspan works with customers to understand the environment, identify the right use cases, define the deployment approach, coordinate implementation, integrate alerts into existing workflows, and manage the service over time. That includes the playbooks, runbooks, escalation paths, communication procedures, reporting expectations, and ongoing tuning needed to support deception in a real environment.

The goal is to give security teams a capability that fits into the way they already operate. ACE is designed to complement the customer’s existing SOC, SIEM, SOAR, EDR, MDR, and incident response processes by adding an active defense layer that produces high-fidelity alerts, supports faster investigation, and strengthens the tools and teams already in place.

The managed model also helps customers avoid the common trap of deploying a powerful tool without the time or staff to maintain it. Deception needs to stay believable. Environments change. Attack paths change. Priorities change. ACE gives customers a partner responsible for helping tune and operate the capability as part of an ongoing service, not just a one-time deployment.

ACE can also support use cases beyond initial detection. During an attack, deception can help test hypotheses, continue engagement with an attacker in a controlled way, and enrich investigation. During an acquisition, it can support threat hunting on new networks or new segments. During a purple team exercise or penetration test, it can provide additional visibility into how simulated attackers move and which controls need improvement.

A Practical Response to a Faster Threat Environment

The recent guidance reinforces the need for security leaders to move quickly while continuing to invest in the fundamentals. Deception belongs in that plan because it is independent of the specific exploit, tool, or vulnerability an attacker uses. It creates a way to detect suspicious behavior based on interaction with assets that should never be touched.

ACE gives organizations a practical way to build that capability without starting from scratch. Acalvio provides the deception platform. Velaspan provides the implementation, integration, and managed operations layer that helps customers put it to work.

For organizations building a 90-day cyber readiness plan, the next step is making deception operational in their own environment.

Velaspan can help.


Don’t spend 90 days evaluating options. Be operational in 30 with Velaspan ACE. Get started now.

Still Here?

We're glad you stuck around...

Check This Out

Protect your organization from AI threats. Deploy ACE in 30 days.

Get started

Be empowered by a Cellular Coverage Assessment

Click for Case Study

How can we help?

We design, deploy, and manage enterprise wireless networks and cybersecurity solutions for leading businesses and brands. Which option best describes your project?

WiFi
Cellular
Cybersecurity

Let's Find Out
What Your Network Needs.

Just answer a few quick questions and receive some immediate thoughts on a plan for your wireless network. No cost or commitment, you might even learn something along the way!

Next

New or Existing Network?

Maybe your existing WiFi network needs work — or maybe you need a new network built from the ground up. In either case, Velaspan's experience and expertise ensure optimal WiFi connectivity and ROI.

Which best applies to you?

Planning for a new network
Make current network better

For You or a Client?

Velaspan works with a wide range of global businesses AND some of the best IT solution providers worldwide. Are you looking for a network for your own company — or are you a solution provider looking to partner with us to support your client?

I need WiFi for my company
I'm designing for a client

About Your Business

Your business has needs and challenges that are uniquely yours and we'll need a real conversation to address them all! However, we work with clients in virtually every industry, so a few key details can give us a solid starting point to assess your needs.

What industry best describes your business?

Enterprise
Education
Pharmaceutical
Healthcare
Retail
Sports & Entertainment
Manufacturing
Logistics
Industrial

One Facility — or More?

Scalability and size are key factors in WiFi design. A network spanning multiple buildings or facilities requires added consideration around scalability, interoperability, and consistency.

What scenario best describes your project?

Just one facility
Multiple facilities

Your Environment

Today's businesses need comprehensive networks designed for security, connectivity, and longevity — with a close eye on what's on the horizon.

Designing yours starts by understanding your space, which we realize might be vast and varied. Which best describe your physical environments?

When shaping minds, anywhere can be a classroom — if it's connected. Whether your school is inside four walls, outdoors, something else, or all of the above, we've got your wireless covered.

Which best describe your school, campus, or facility environments?

Often global and always complex, pharmaceutical operations require high-performance wireless across labs, cleanrooms, boardrooms, and more.

Delivering it starts by understanding your space. Which best describe your physical environments?

Healthcare is high-stakes, 24/7, and ever dependent on wireless — demanding a strong signal across every square inch of space.

Designing a network that stands up to your needs starts by understanding that space. Which best describe your healthcare facility's physical environments?

From in-store points of sale to e-commerce, retail is increasingly dependent on high-performance wireless for operations as well as customer experience.

A successful network starts by understanding the complexity of your space. Which best describe your company's physical environments?

From fan livestreams to broadcast signals to record-breaking crowds, venues and visitors need winning wireless.

Designing and delivering it starts by understanding your space. Which best describe your venue or facility's physical environments?

Vast, hazardous, and teeming with movement, manufacturing spaces are tough to design for — and one of our specialties.

Our work starts by better understanding your space, which often takes different forms across uses. Which best describe your physical environments?

Your business can't afford dead spots or a weak signal — but is probably ripe with them.

Designing wireless that stands up to supply chain demands starts by better understanding your starting point. Which best describe your physical environments?

Whether you're a refinery or a confectionary, you probably face connectivity hurdles — often in hazardous areas, no less. Luckily, industrial connectivity in classified zones is one of our specialties.

Network design starts by understanding your space, which we realize might take different forms across uses. Which best describe your company's physical environments?

Select all that apply:

Next

Existing or Proposed Space?

Is this WiFi network being designed for an existing facility/space, or one that's in the works? It's never too early to get us involved. Whether your network is going into an operational space, you're adjusting for a remodel, or if the ink is still fresh on the blueprints — we can work with you.

Existing building
Remodeling or repurposing
New construction

What Problem Are You Facing?

Looking to make your network better? Great, that's what we do! Which of the following best describe your current challenges?

Select all that apply:

Poor coverage
Unstable connections
Outdated equipment
New requirements
Next

How Old Is Your Network?

A network's age tells us a lot about its lifecycle needs. When was your current network installed?

It's brand new
1-3 years ago
4+ years ago
Not sure

Hardware Vendor

Velaspan is vendor agnostic and we don't sell hardware. It means your network's success is our only focus, i.e. no sales agenda!

We work with all major hardware vendors and can choose the best one for your network if you haven't already. Who do you work with — or are you still deciding?

Cisco
Meraki
HP/Aruba
Extreme Networks
Juniper/Mist
Haven't decided yet
Other

Your Contact Information

Thanks for sharing, we have a good understanding of your project and are ready to recommend relevant services. Of course, this is just the start of the process. Enter your contact information below and one of our WiFi experts will reach out to help.

One Step Closer to Better WiFi!

Based on your answers, we'd likely kick off with the following services:

Some other services that would likely apply:

We'll be in touch! Explore our cybersecurity solutions in more detail here.

Let's Determine Your Cellular Needs.

Just answer a few quick questions and receive some immediate thoughts on a plan for your cellular network. No cost or commitment!

Next

Does Your Cellular Project Involve Carrier Coverage or Your Own Private Network?

Cellular projects can vary based on whether you're focused on improving existing carrier signals or exploring a private network solution for your operations.

Which of these best describes your current focus?

Establishing a private network for our operations
Improving or assessing coverage from existing carriers

Do You Have a Developed Use Case for Your Private Network?

Some businesses come to us with a clear idea of how they want to use a private network (like for autonomous vehicles or real-time tracking), while others are still figuring out the best way to leverage this technology. Where are you in the process?

We have a clear use case
We're still in the planning stage and exploring our options

Have You Identified the Current State of Your Cellular Signal?

Understanding the state of your cellular coverage can be tricky. You might be looking for a full assessment to understand your signal quality, or you might already know there are areas that need improvement. Where do you stand?

We are looking to understand our current signal quality
We already know there are areas with poor coverage that need fixing

What Industry Best Describes Your Business?

Understanding the environment in which your cellular network operates helps us tailor the solution to your specific needs. Whether you're in manufacturing, healthcare, or education, each industry has unique challenges that require a customized approach.

Which industry best describes your business?

Warehousing
Manufacturing
Education
Healthcare
Construction
Mining
Retail
Chemical, Gas, and Oil
Ports and Maritime
Other

Your Use Cases

In warehousing, efficiency and connectivity are crucial for operations like inventory management, automation, and logistics. A private cellular network ensures seamless mobility for devices like AGVs, handheld scanners, and yard management systems. Which of these use cases best fits your needs? And if you're not sure, that's okay too!

In manufacturing, reliable communication and automation are key to maintaining productivity. Private cellular networks support connected systems like robotics, IoT infrastructure, and real-time monitoring, enabling more efficient production and safety. Which use case best aligns with your needs? Not sure? That's perfectly fine too!

Education environments require reliable connectivity for student devices, smart building systems, and security. A private cellular network ensures seamless connectivity across campus, supporting everything from surveillance systems to IoT-enabled learning tools. Which of these use cases fits your needs? If you're not sure, don't worry; we've got you covered.

In healthcare, secure and consistent connectivity is essential for managing patient data, communications, and medical devices. Private cellular networks enable real-time monitoring, mobile access, and secure communications across large hospital environments. Which of these use cases best fits your needs? And if you're unsure, no problem!

Construction sites often face connectivity challenges across large, rugged areas. Private cellular networks provide reliable, secure connections for everything from push-to-talk communications to tracking heavy machinery and IoT sensors. Which of these use cases aligns with your project? And if you're not sure, that's okay too!

Mining operations need secure, reliable connectivity in remote or underground locations. Private cellular networks ensure continuous communication and monitoring, whether it's through rugged devices, IoT sensors, or surveillance systems. Which use case best aligns with your needs? And if you're not sure, that's understandable!

In retail, reliable and fast wireless connectivity is key for transactions, inventory management, and customer experience. Private cellular networks ensure your operations run smoothly, whether it's handling POS systems or managing stock across locations. Which of these use cases best fits your needs? And if you're not certain, don't sweat it!

In the chemical, gas, and oil industries, safety and monitoring are critical. Private cellular networks provide secure, uninterrupted connectivity for field operations, IoT monitoring, and communications in hazardous environments. Which of these use cases best fits your operations? If you're not sure, no worries!

Ports and maritime operations require large-scale, seamless connectivity to manage logistics, cargo, and communications. Private cellular networks enable real-time tracking and monitoring across large areas, ensuring smooth and secure operations. Which of these use cases best describes your needs? And if you're not sure, that's perfectly okay!

Every business has unique connectivity challenges, and a private cellular network could provide the secure, reliable solution you need. Whether you're managing IoT infrastructure or improving onsite communications, we can tailor a solution to your needs. Which of these use cases best fits your business? And if you're not quite sure, that's totally fine!

Select all that apply:

Next

Your Contact Information

Thanks for sharing, we have a good understanding of your project and are ready to recommend relevant services. Of course, this is just the start of the process. Enter your contact information below and one of our cellular experts will reach out to help.

One Step Closer to Better Cellular!

Based on your answers, we'd likely kick off with the following services:

Some other services that would likely apply:

We'll be in touch! Explore our cellular solutions in more detail here.

Let's Determine your Cybersecurity Needs.

Answer a few questions to receive immediate insights into your cybersecurity needs. No cost or commitment, just actionable advice

Next

What Industry Best Describes Your Organization?

Every organization needs protection, but the specific challenges you face can depend on what kind of business you're in. Whether you're keeping customer data safe, managing critical infrastructure, or just trying to make sure no one clicks that suspicious email link (again), understanding your environment helps us offer solutions that fit your needs.

So, which industry best describes your business?

Pharmaceutical
Manufacturing
Education
Healthcare
Finance
Media/Entertainment
Retail
Enterprise
Government
Other

What's Your Cybersecurity Focus Right Now?

Cybersecurity can be a bit like juggling — sometimes it's about figuring out where you're vulnerable (and making sure everything stays in the air), and other times, it's about getting those defenses ready to catch any unexpected curveballs. Whether you're more about assessing the risks or gearing up for action, knowing your focus helps us guide you to the best solution.

Which of these feels most like your current approach?

Understanding and assessing risk
Defending and responding to potential threats

What's Your Priority?

Assessing and understanding risk can take a few different paths. Maybe it's all about the human element — making sure your team knows the difference between a legitimate email and a phishing scam. Or perhaps you're more into giving your systems a good onceover, tightening up those security bolts, and making sure everything's squeaky clean. Which of these sounds more like your current concern?

Ensuring your staff follows best practices
Evaluating and strengthening your security hygiene

What's Your Priority?

Keeping the bad guys out can take a lot of forms (and sometimes feels like fighting an army of digital ninjas). Whether you're looking to beef up your defenses, spot attackers hiding in the shadows, or make sure your security tools are quick and easy to set up, we want to know where you're focusing your efforts. Which of these sounds most like your priority?

Select all that apply:

Align Security Posture
Following CISA, NIST, MITRE, etc.
Securely and Actively Detect Attackers
Kick intruders, protect IT/IoT/OT
Deep Visibility
See what's happening right now
Add Key Skills and Capabilities
Expert support, fully integrated
Speedy and Easy Deployment
100% software, cloud/on-prem/hybrid
Rapid Response
Playbooks and support for quick action
Next

Your Standards

In the pharmaceutical industry, protecting intellectual property, patient data, and maintaining regulatory compliance are critical. The standards (HIPAA, GDPR, ISO) might sound like they're from another planet, but they matter. Which ones does your organization follow? If you're not sure, no worries!

Manufacturing organizations often handle a mix of proprietary data, operational technology, and supply chain information, making them a target for various cyber threats. Of course, the security standards you need to follow can feel like a confusing alphabet soup (ISO, NIST, CMMC, anyone?). Which standards or frameworks do you currently follow in your manufacturing environment? And if you're not sure, that's okay too!

Educational institutions manage a wide array of sensitive information, from student records to financial data, making them an attractive target for cyberattacks. Security standards can help — even if they sound like an endless string of acronyms (FERPA, NIST, ISO). Which cybersecurity standards or frameworks do you adhere to within your institution? Not sure? That's perfectly fine too!

Healthcare organizations face unique challenges when it comes to securing patient information, complying with regulations, and maintaining the integrity of healthcare services. With so many standards (HIPAA, ISO, NIST — it's a lot, we know), it's crucial to keep track. Which security and compliance frameworks does your healthcare organization follow? If you're not sure, don't worry; we've got you covered.

The finance sector deals with highly sensitive financial information, making it a prime target for cybercriminals. To protect client data and ensure regulatory compliance, implementing the right standards is essential — even if they sound like a bunch of acronyms (PCI-DSS, ISO, GDPR). Which standards guide your organization's practices? And if you're unsure, no problem!

Media and entertainment companies manage everything from intellectual property to consumer data, requiring strict security measures. The standards you might follow (ISO, PCI-DSS, GDPR) can feel like a code only decipherable by cybersecurity experts. Which ones apply to your organization? And if you're not sure, that's perfectly okay!

Retail businesses handle a vast amount of customer data and payment information, requiring strict security measures to prevent breaches. The standards (PCI-DSS, GDPR, ISO) can feel like a jumble of letters, but they're crucial. Which security frameworks do you follow in your retail operations? And if you're not sure, that's okay too!

Enterprises often operate in complex environments, dealing with sensitive information across multiple systems. The alphabet soup of standards (ISO, NIST, SOC) can help guide your security strategy — but we get it, it's a lot to keep track of. Which frameworks do you follow? And if you're not certain, don't sweat it!

Government agencies manage critical and sensitive information, making them prime targets for cyber threats. Adhering to security standards (CMMC, FISMA, NIST) is essential — but sometimes, it can feel like deciphering a code. Which frameworks does your agency follow? And if you're not sure, that's understandable!

Whatever your industry, we know there's no shortage of acronyms when it comes to cybersecurity standards (ISO, NIST, GDPR, and the list goes on). Which standards or frameworks do you currently follow? And if you're not quite sure, that's totally fine!

Select all that apply:

Next

How Does Your Organization Manage Compliance with Security Standards?

Staying compliant with security standards can be a daunting task, and every organization approaches it differently. Whether you have a streamlined system or feel like you're swimming against the current, we'd love to know how you manage compliance. Pick the option that best describes your approach (no judgment here — we promise!).

Badly
(we know we should be doing more, but...)
Manually, with not enough people
(we could use a few clones)
Manually, with way too many people
(and somehow it's still chaotic)
With an automation platform
(we've got this covered...mostly)
A mix of automation and manual processes
(because, why not both?)

Your Contact Information

Thanks for sharing, we have a good understanding of your project and are ready to recommend relevant services. Of course, this is just the start of the process. Enter your contact information below and one of our cybersecurity experts will reach out to help.

One Step Closer to Better Cybersecurity!

Based on your answers, we'd likely kick off with the following services:

Some other services that would likely apply:

We'll be in touch! Explore our cybersecurity solutions in more detail here.

Slow down, let me explore
Start over
Schedule a Call

In the Next
90 Days…

CSA/SANS urges building a cyber deception capability against AI-assisted attacks

We help organizations stand up industry-leading deception capabilities in as little as 30 days without adding operational complexity.

Get Started Today
The Clock is Ticking