Decoy surface areaHigh-fidelity decoys — documents, SaaS endpoints, kubeconfigs — are laid on the same telemetry plane as production, so a single verdict can call them by name. verdict attribution ≤ 1 touch | 2 articles §164.308(a)(1)(ii)(A) Risk analysis — conduct accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI. §164.312(e)(1) Transmission security — implement security measures to guard against unauthorized access to ePHI in transit; a poisoned decoy channel surfaces the actor before any real data leaves the boundary.
| 3 articles Req. 6.4 Public-facing web applications are protected by application-layer controls; the decoy surface is a control surface that learns from touch. Req. 11.4 Use of techniques to detect and alert on unauthorized wireless encryption protocols and rogue wireless devices. Req. A3.4.1 Sensitive authentication data (SAD) is not stored after authorization; the decoy fakes SAD that triggers containment rather than authorization.
| 3 articles SI-4 System monitoring Monitor the system to detect attacks, indicators of potential attacks, and unauthorized activity; the decoy surface sits inside continuous monitoring as a runnable workload. RA-3 Risk assessment Conduct a risk assessment including likelihood and magnitude of harm; a touch on a decoy is a measurable risk signal. CA-7 Continuous monitoring Develop a continuous monitoring strategy and implement continuous monitoring programs; decoys + watchdogs are the ConMon engines.
| 2 articles Art. 18(1) Resilience testing Establish and maintain a digital operational resilience testing programme; decoy surface is a live test under realistic conditions. Art. 5 ICT risk framework Maintain an effective and comprehensive ICT risk management framework as part of the overall risk management system; the touch is recorded as a risk signal.
| 2 articles Art. 21(2)(f) Vulnerability handling Procedures for vulnerability handling and disclosure; a touch on a decoy is a vulnerability signal before it surfaces on a real surface. Art. 21(2)(e) Supply chain security Supply-chain security including security-related aspects of supplier relationships; decoy surfaces map the lateral pathways the actor explored.
|
Hash-chained evidence packetA sealed evidence packet lands on the analyst desk. Actor confidence, toolchain map, and regulatory framing bound to the framework the customer reports under. replayable without re-running | 3 articles §164.308(a)(6)(ii) Response and reporting — identify, respond to, and document security incidents; the playbook packet is the reportable record. §164.316(b)(1) Documentation retention — maintain written policies/procedures and documentation of actions/activities for six years; the hash chain is the tamper-evident form. §164.312(c)(1) Integrity — implement policies and procedures to protect ePHI from improper alteration or destruction; the chain seals the verdict trail end-to-end.
| 3 articles Req. 10.2 Audit logs record all required events with required content — actor, timestamp, event type, success/failure, origination, affected component. Req. 12.10 Document and implement an incident response plan — the playbook packet is the on-call form the analyst attests to. Req. 10.5 Audit log files are protected from unauthorized modification and retained for at least 12 months with the most recent three months immediately available.
| 3 articles AU-2 Event logging Identify the types of events that the system is capable of logging and select for ongoing collection; the packet is the corpus the AO attests to. AU-9 Protection of audit information Protect audit information and audit tools from unauthorized access, modification, and deletion; the hash chain is the tamper-evident form. AU-6 Audit review, analysis, and reporting Review and analyze information system audit records for indications of inappropriate or unusual activity; the packet is the analyst deliverable.
| 3 articles Art. 17 Incident reporting Initial, intermediate, and final notifications on major ICT-related incidents and voluntary notification of significant cyber threats. Art. 19 Operational resilience testing outcomes Capture findings of digital operational resilience testing and ensure follow-up action; the packet is the capture-of-record. Art. 28 Contractual arrangements Contractual terms with ICT third-party service providers must include exit strategies, audit rights, and incident cooperation; the chain is the audit trail.
| 3 articles Art. 23 Reporting obligations Early warning within 24 hours of becoming aware of an incident, incident notification within 72 hours, and final report within one month. Art. 21(2)(b) Incident handling Incident handling procedures; the hash-chained packet is the on-call form the analyst attests to. Art. 24 Crisis management Member States ensure essential and important entities have designated crisis-management authorities; the packet is the cross-border delegation surface.
|
Host isolationContainment revokes credentials, tunnels out suspect interfaces, and quarantines the host in under a second of a confirmed verdict. Every action is reversibly recorded. mean time-to-contain ≤ 1s | 3 articles §164.308(a)(1)(ii)(B) Risk management — implement security measures sufficient to reduce risks and vulnerabilities to a reasonable and appropriate level. §164.308(a)(6)(i) Security incident procedures — identify and respond to suspected or known security incidents; mitigate, to the extent practicable, harmful effects. §164.310(c) Workstation use — policies and procedures specifying proper functions, manner, and environment for workstation use.
| 2 articles Req. 1.2 Network security controls — configure NSCs to restrict untrusted traffic; one-line containment revokes the tunnel interface faster than a NAT change can be made. Req. 11.5 Use of intrusion-detection and/or intrusion-prevention techniques to detect, alert on, and mitigate unauthorized network activity.
| 3 articles IR-4 Incident handling Implement an incident handling program including preparation, detection, analysis, containment, eradication, and recovery; containment is the muscle. SC-7 Boundary protection Monitor and control communications at the external boundary and key internal boundaries; one-click containment moves the host off the boundary. AC-6 Least privilege Allow only authorized accesses which are necessary to accomplish assigned organizational tasks; isolation revokes privilege the verifier no longer merits.
| 2 articles Art. 9(2) Protection Continuously monitor and control the security of ICT systems and the underlying infrastructure to preserve the integrity, availability, and confidentiality of data. Art. 12(4) Response Recovery procedures and business continuity plans are tested, reviewed, and updated; isolation is the response half of the loop.
| 2 articles Art. 21(2)(d) Business continuity Business continuity and disaster recovery plans, including a crisis management plan; isolation is the operative half of that plan under attack. Art. 21(2)(a) Risk analysis Policies on risk analysis and information system security; the containment event is the documented risk signal that policy responds to.
|
Live credential poisoningThe moment an adversary touches a decoy, the agent fingerprints the tooling and poisons the credentials it would have used — the replay fails at the IdP, not at Threxen. IdP replay rejection | 3 articles §164.308(a)(5)(ii)(D) Password management — procedures for creating, changing, and safeguarding passwords; pairs with active poisoning as a defense-in-depth layer at the IdP. §164.312(a)(2)(iii) Automatic logoff — terminate an electronic session after a predetermined time of inactivity; poisoning the credential blocks the next session renewal. §164.312(b) Audit controls — implement hardware, software, procedural mechanisms to record and examine activity in information systems containing ePHI.
| 3 articles Req. 8.4 Multi-factor authentication for all non-console admin access and all access to the cardholder data environment. Req. 8.5 Authentication credentials are managed to prevent misuse — the poison invalidates captured creds at the IdP rather than at the CDE perimeter. Req. 3.5 Primary account number (PAN) is unreadable anywhere it is stored — poisoned creds never reach the store.
| 3 articles IA-2 Identification and authentication Uniquely identify and authenticate organizational users; poisoning the captured credential blocks the next session renewal. IA-5 Authenticator management Manage authenticators including initial distribution, lost/compromised, and revocation; the poison is the fastest revocation Threxen ships. AC-2 Account management Identify and select account types, conditions for group membership, and required attributes; the packet reports what was active when the touch happened.
| 2 articles Art. 9(4) Identity ICT authentication mechanisms are robust, periodically reviewed, and aligned to a strong baseline; the poison invalidates captured creds at the IdP. Art. 25(2) Third-party concentrations Identify and document concentration risks arising from ICT third-party providers; if the poisoning was downstream of an ICT provider, the packet names it.
| 2 articles Art. 21(2)(g) Cryptography Use of cryptography and encryption — including per-tenant key envelopes — so a captured credential cannot replay under stolen key material. Art. 21(2)(c) Access control Policies on access control and asset management; the poison blocks the credential the actor believed was valid.
|