Prevention
Firewalls, AV, EDR, MFA
From the laptop on someone’s desk to the sensors and machinery running your physical operations — even where there’s no connection to the internet at all — a single deception layer that learns, adapts, and catches attackers in real time.
It takes an attacker as little as 29 minutes to get in. On average, it's 247 days before anyone notices — and the longer that stretches past 200 days, the breach costs 33% more. Your entire security stack is already working hard to close that gap. Treacle adds a new layer on top of it — one that makes everything else you run sharper, faster, and far harder for an attacker to slip past.
The attacker moves. The noose gets tighter.
A checkbox feature, maybe a lone trap quietly switched on and forgotten — and almost always confined to IT. OT has been left almost untouched, leaving a big door ajar. It’s not a checkbox feature.
Typically true of this categoryCloud-only deception add-ons stop at the edge of on-prem and OT networks.
True of i-MirageComprehensive protection layer — active decoys across IT, OT/ICS, and air-gapped environments alike.
Typically true of this categoryDeception bundled inside a single platform means buying the whole suite to get it.
True of i-MirageStands alone — integrates with the SIEM, SOAR, and EDR you already run.
Typically true of this categoryTraffic-visibility and anomaly-detection tools infer that something looks wrong.
True of i-MirageZero noise — an attacker has to touch a decoy to trigger an alert. Proof, not inference.
Typically true of this categoryAI anomaly detection trades precision for coverage — more alerts to chase.
True of i-MirageImproving SOC, SIEM, SOAR productivity — near-zero false positives, by architecture, not tuning.
Firewalls, AV, EDR, MFA
SIEM, XDR, threat intel
Deception, decoys, honeytokens; i-Mirage lives here
SOC, IR, SOAR
Backups, DR
SIEM and EDR alert floods are exactly what attackers count on — the real signal drowns in the queue. Every i-Mirage alert is a confirmed attacker touch, so there's nothing to miss.
Antivirus and EDR only flag malware they already recognise. i-Mirage's decoys lured in 35+ zero-day strains absent from every AV database — the exact blind spot AI-written malware is built to exploit.
Industrial ransomware hit roughly 3,300 organisations in 2025 (Dragos). Sites with strong detection contain it in 5 days — without it, 42. i-Mirage is one of the most comprehensive platforms natively covering OT/ICS in the UK/EU.
Every decoy interaction builds a live picture of attacker IPs, infrastructure and tactics — feeding your SOC and threat-intel programme, not just tripping a wire.
In one live incident, a Treacle decoy deployed inside a major financial institution — with a large, regulated, always-on security operations function — intercepted a live malware delivery attempt arriving through an exposed database service, traced to attacker infrastructure operating overseas. What followed was methodical: dynamic-library injection to gain command execution, a 33MB payload download, and an execution attempt built to blend into the environment. It never ran. The decoy was built to catch exactly this — the malware was captured whole, and nothing ever touched a real system.
Highlight: a dropped file used polyglot obfuscation — text that reads as garbled, meaningless noise on the surface, with fully functional hidden commands underneath, visible only under deeper analysis. It’s the kind of technique built specifically to slip past both automated scanners and a tired analyst at 9pm. It didn’t get past a decoy with no legitimate reason to ever be touched.
MITRE ATT&CK tactics mapped
Times the payload executed
State-linked groups named as candidate attribution
Highly sophisticated malware. Never allowed to run.
Across every environment below, i-Mirage is doing the same job: turning attacker movement into a confirmed, actionable alert before it becomes an incident — in national-scale banking infrastructure, government cyber-crime operations, critical transport, industrial engineering, and telecom networks carrying hundreds of millions of subscribers. The organisations below can’t be named under their own disclosure terms, so we’ve described them instead by what they run and how they’re regulated.
Live decoys standing watch across Data Centre, Disaster Recovery, and Cyber Security Centre of Excellence environments around the clock. Deployed at one of the largest public-sector banks in the world by branch count, under a multi-year enterprise contract.
Decoys operating inside a public-sector, law-enforcement-grade network — proof the same technology holds up well outside commercial IT. Deployed at a state-level cyber-crime division covering a jurisdiction of over 120 million people.
A single deception layer covering both OT/ICS and standard corporate IT side by side. Deployed at a multi-billion-dollar engineering, construction, and technology group spanning defence, energy, and infrastructure.
Added with zero downtime and no change to live systems — the only acceptable bar for an environment where continuity can't be interrupted. Deployed across a major international airport operator's infrastructure.
A 29-day live proof of concept surfaced 547,000+ enriched attacker events and harvested 49,884 confirmed toll-fraud numbers before they could connect — intelligence fed straight back into fraud and network defences. Run for one of the largest mobile operators in its market, serving hundreds of millions of subscribers.
Already on your regulator’s checklist.
DORA Article 26 — the EU's Digital Operational Resilience Act — requires threat-led penetration testing (TLPT). NIS2, the EU's network-and-information-security directive, and the NCSC's Cyber Assessment Framework (CAF) require demonstrable detection. Every i-Mirage alert is exactly that evidence, ready before the assessor asks.
Insurers are aligning cyber underwriting to DORA programme maturity — a completed ICT register, tested response plan, active detection. A documented deception layer is now on that checklist.
NIS2 and DORA cap penalties at 2% of global turnover or €10M, mirrored in the UK by the FCA's Operational Resilience regime (PS21/3) and the PRA's equivalent rules (SS1/21) — the same detection expectation, held across every UK/EU regulator.
The FCA (Financial Conduct Authority) and PRA (Prudential Regulation Authority) fined TSB £48.65M in 2022 for operational resilience failings, plus £32.7M in customer redress — a public marker of what this category of control is worth getting right.
i-Mirage doesn’t run one generic decoy everywhere and hope it’s convincing. It deploys domain-native decoys — servers and honeytokens for IT, Modbus/MQTT/FTP/SMB devices for OT/ICS, SIP and signalling endpoints for telecom — because an attacker working a SCADA network will never touch an IT file-share, and one working toll fraud will never touch a PLC. Every decoy, in every domain, feeds the same core AI engine: it deploys traps dynamically as an attacker moves, scores intent the instant they touch one, maps it to the attacker lifecycle, and hands your SOC a confirmed, ready-to-action alert. No rip-and-replace. No added headcount.
Servers, endpoints, databases, AD accounts & honeytokens — indistinguishable from the real estate.
Live decoys inside plant-floor and industrial networks — zero production downtime, agentless.
Dashed = on the roadmap, not yet live.
The protocols industrial and IoT devices actually speak — not IT traffic dressed up to look like it.
Signalling-native decoys that catch toll fraud, SIM-box and core-network probing before it lands.
Dashed = on the roadmap, not yet live.
The signalling layers behind calls, texts, and account data — where telecom fraud actually happens.
One brain across every domain — real-time decoy orchestration & attacker-intent scoring.
Decoys spawn and reposition in real time along the attacker's actual path — not a static trap laid once and forgotten.
Every touch is scored — attacker IP, infrastructure, protocol, payload — confirmed activity, not an inference.
Every alert mapped automatically to MITRE ATT&CK — full TTP context with zero manual enrichment.
A confirmed, ready-to-action alert pushed straight into the SIEM, SOAR and EDR you already run.
A daily, board-ready snapshot of security posture and exposure — generated automatically, not assembled by hand.
A scoped pilot: live decoys in your environment, real attacker interactions, a board-ready read-out at the end. No agents, no commitment beyond the pilot.