Why this, and why now

It takes an attacker as little as 29 minutes to get in. On average, it's 247 days before anyone notices — and the longer that stretches past 200 days, the breach costs 33% more. Your entire security stack is already working hard to close that gap. Treacle adds a new layer on top of it — one that makes everything else you run sharper, faster, and far harder for an attacker to slip past.

The attacker moves. The noose gets tighter.

Sources: CrowdStrike 2026 Global Threat Report; IBM Cost of a Data Breach Report 2026.

Why this is a paradigm shift

The market treated deception as a bolt-on.

A checkbox feature, maybe a lone trap quietly switched on and forgotten — and almost always confined to IT. OT has been left almost untouched, leaving a big door ajar. It’s not a checkbox feature.

Typically true of this category

True of i-Mirage

Typically true of this categoryCloud-only deception add-ons stop at the edge of on-prem and OT networks.

True of i-MirageComprehensive protection layer — active decoys across IT, OT/ICS, and air-gapped environments alike.

Typically true of this categoryDeception bundled inside a single platform means buying the whole suite to get it.

True of i-MirageStands alone — integrates with the SIEM, SOAR, and EDR you already run.

Typically true of this categoryTraffic-visibility and anomaly-detection tools infer that something looks wrong.

True of i-MirageZero noise — an attacker has to touch a decoy to trigger an alert. Proof, not inference.

Typically true of this categoryAI anomaly detection trades precision for coverage — more alerts to chase.

True of i-MirageImproving SOC, SIEM, SOAR productivity — near-zero false positives, by architecture, not tuning.

Where this fits in your stack

One more layer, engineered to work with the rest.

Prevention

Firewalls, AV, EDR, MFA

Detection

SIEM, XDR, threat intel

Defence & Intelligence

Deception, decoys, honeytokens; i-Mirage lives here

Response

SOC, IR, SOAR

Recovery

Backups, DR

AV — antivirus · EDR — endpoint detection & response · MFA — multi-factor authentication · SIEM — security information & event management · XDR — extended detection & response · SOC — security operations centre · IR — incident response · SOAR — security orchestration, automation & response · DR — disaster recovery.

Why this works

Proof, not promises.

Near-zero

No noise to hide in

SIEM and EDR alert floods are exactly what attackers count on — the real signal drowns in the queue. Every i-Mirage alert is a confirmed attacker touch, so there's nothing to miss.

35+

Catches what antivirus has never seen

Antivirus and EDR only flag malware they already recognise. i-Mirage's decoys lured in 35+ zero-day strains absent from every AV database — the exact blind spot AI-written malware is built to exploit.

42 → 5 days

OT ransomware, contained fast

Industrial ransomware hit roughly 3,300 organisations in 2025 (Dragos). Sites with strong detection contain it in 5 days — without it, 42. i-Mirage is one of the most comprehensive platforms natively covering OT/ICS in the UK/EU.

5.4M+

Intelligence, not just alarms

Every decoy interaction builds a live picture of attacker IPs, infrastructure and tactics — feeding your SOC and threat-intel programme, not just tripping a wire.

No security layer gets you to 100% on its own. Add i-Mirage and a well-designed stack gets close — about 90%. Figures above reported by Treacle across live deployments, except where cited. Source: Dragos 2026 OT/ICS Cybersecurity Report.

The compliance dividend

It pays off in regulator dividends, too.

Already on your regulator’s checklist.

TLPT-ready

Evidence your next audit already needs

DORA Article 26 — the EU's Digital Operational Resilience Act — requires threat-led penetration testing (TLPT). NIS2, the EU's network-and-information-security directive, and the NCSC's Cyber Assessment Framework (CAF) require demonstrable detection. Every i-Mirage alert is exactly that evidence, ready before the assessor asks.

Smoother renewal

What underwriters now ask for

Insurers are aligning cyber underwriting to DORA programme maturity — a completed ICT register, tested response plan, active detection. A documented deception layer is now on that checklist.

2%

The standard now in force

NIS2 and DORA cap penalties at 2% of global turnover or €10M, mirrored in the UK by the FCA's Operational Resilience regime (PS21/3) and the PRA's equivalent rules (SS1/21) — the same detection expectation, held across every UK/EU regulator.

£81M

The precedent the market already has

The FCA (Financial Conduct Authority) and PRA (Prudential Regulation Authority) fined TSB £48.65M in 2022 for operational resilience failings, plus £32.7M in customer redress — a public marker of what this category of control is worth getting right.

Sources: NIS2 Directive (EU 2022/2555); DORA — Digital Operational Resilience Act (EU 2022/2554); FCA — Financial Conduct Authority — Operational Resilience Policy Statement PS21/3; PRA — Prudential Regulation Authority — SS1/21; FCA/PRA final notices to TSB Bank plc (Dec 2022); WTW, ‘DORA vs. NYDFS: cyber insurance for financial institutions’ (2025).

How i-Mirage works

One engine. Every domain it protects speaks its own language.

i-Mirage doesn’t run one generic decoy everywhere and hope it’s convincing. It deploys domain-native decoys — servers and honeytokens for IT, Modbus/MQTT/FTP/SMB devices for OT/ICS, SIP and signalling endpoints for telecom — because an attacker working a SCADA network will never touch an IT file-share, and one working toll fraud will never touch a PLC. Every decoy, in every domain, feeds the same core AI engine: it deploys traps dynamically as an attacker moves, scores intent the instant they touch one, maps it to the attacker lifecycle, and hands your SOC a confirmed, ready-to-action alert. No rip-and-replace. No added headcount.

IT

Servers, endpoints, databases, AD accounts & honeytokens — indistinguishable from the real estate.

ServersEndpointsDatabasesAD accountsHoneytokens

OT / ICS & air-gapped

Live decoys inside plant-floor and industrial networks — zero production downtime, agentless.

ModbusMQTTFTPSMBPLC / SCADA HMI

Dashed = on the roadmap, not yet live.

The protocols industrial and IoT devices actually speak — not IT traffic dressed up to look like it.

Telecom

Signalling-native decoys that catch toll fraud, SIM-box and core-network probing before it lands.

SIP / VoIPDiameterSMSCSS7

Dashed = on the roadmap, not yet live.

The signalling layers behind calls, texts, and account data — where telecom fraud actually happens.

Core AI Engine

One brain across every domain — real-time decoy orchestration & attacker-intent scoring.

1

Dynamic deployment

Decoys spawn and reposition in real time along the attacker's actual path — not a static trap laid once and forgotten.

2

Malice & intent scoring

Every touch is scored — attacker IP, infrastructure, protocol, payload — confirmed activity, not an inference.

3

Attacker lifecycle mapping

Every alert mapped automatically to MITRE ATT&CK — full TTP context with zero manual enrichment.

4

Action to your SOC

A confirmed, ready-to-action alert pushed straight into the SIEM, SOAR and EDR you already run.

5

Daily executive reporting

A daily, board-ready snapshot of security posture and exposure — generated automatically, not assembled by hand.

No rip-and-replaceNo added headcountNo production downtimeNear-zero false positives, by architecture

Self-healing after every interaction — decoys reset from a clean snapshot, so the trap stays convincing.

See it work in your environment.

A scoped 6–8 week pilot: live decoys in your environment, real attacker interactions, a board-ready read-out at the end. No agents, no commitment beyond the pilot.