Why this, and why now

It takes an attacker as little as 29 minutes to get in. On average, it's 247 days before anyone notices — and the longer that stretches past 200 days, the breach costs 33% more. Your entire security stack is already working hard to close that gap. Treacle adds a new layer on top of it — one that makes everything else you run sharper, faster, and far harder for an attacker to slip past.

The attacker moves. The noose gets tighter.

Sources: CrowdStrike 2026 Global Threat Report; IBM Cost of a Data Breach Report 2026.

Why this is a paradigm shift

The market treated deception as a bolt-on.

A checkbox feature, maybe a lone trap quietly switched on and forgotten — and almost always confined to IT. OT has been left almost untouched, leaving a big door ajar. It’s not a checkbox feature.

Typically true of this category

True of i-Mirage

Typically true of this categoryCloud-only deception add-ons stop at the edge of on-prem and OT networks.

True of i-MirageComprehensive protection layer — active decoys across IT, OT/ICS, and air-gapped environments alike.

Typically true of this categoryDeception bundled inside a single platform means buying the whole suite to get it.

True of i-MirageStands alone — integrates with the SIEM, SOAR, and EDR you already run.

Typically true of this categoryTraffic-visibility and anomaly-detection tools infer that something looks wrong.

True of i-MirageZero noise — an attacker has to touch a decoy to trigger an alert. Proof, not inference.

Typically true of this categoryAI anomaly detection trades precision for coverage — more alerts to chase.

True of i-MirageImproving SOC, SIEM, SOAR productivity — near-zero false positives, by architecture, not tuning.

Where this fits in your stack

One more layer, engineered to work with the rest.

Prevention

Firewalls, AV, EDR, MFA

Detection

SIEM, XDR, threat intel

Defence & Intelligence

Deception, decoys, honeytokens; i-Mirage lives here

Response

SOC, IR, SOAR

Recovery

Backups, DR

AV — antivirus · EDR — endpoint detection & response · MFA — multi-factor authentication · SIEM — security information & event management · XDR — extended detection & response · SOC — security operations centre · IR — incident response · SOAR — security orchestration, automation & response · DR — disaster recovery.

Why this works

Proof, not promises.

Near-zero

No noise to hide in

SIEM and EDR alert floods are exactly what attackers count on — the real signal drowns in the queue. Every i-Mirage alert is a confirmed attacker touch, so there's nothing to miss.

35+

Catches what antivirus has never seen

Antivirus and EDR only flag malware they already recognise. i-Mirage's decoys lured in 35+ zero-day strains absent from every AV database — the exact blind spot AI-written malware is built to exploit.

42 → 5 days

OT ransomware, contained fast

Industrial ransomware hit roughly 3,300 organisations in 2025 (Dragos). Sites with strong detection contain it in 5 days — without it, 42. i-Mirage is one of the most comprehensive platforms natively covering OT/ICS in the UK/EU.

5.4M+

Intelligence, not just alarms

Every decoy interaction builds a live picture of attacker IPs, infrastructure and tactics — feeding your SOC and threat-intel programme, not just tripping a wire.

No security layer gets you to 100% on its own. Add i-Mirage and a well-designed stack gets close — about 90%. Figures above reported by Treacle across live deployments, except where cited. Source: Dragos 2026 OT/ICS Cybersecurity Report.

Caught in the act

A live attack, caught before it touched anything real.

In one live incident, a Treacle decoy deployed inside a major financial institution — with a large, regulated, always-on security operations function — intercepted a live malware delivery attempt arriving through an exposed database service, traced to attacker infrastructure operating overseas. What followed was methodical: dynamic-library injection to gain command execution, a 33MB payload download, and an execution attempt built to blend into the environment. It never ran. The decoy was built to catch exactly this — the malware was captured whole, and nothing ever touched a real system.

Highlight: a dropped file used polyglot obfuscation — text that reads as garbled, meaningless noise on the surface, with fully functional hidden commands underneath, visible only under deeper analysis. It’s the kind of technique built specifically to slip past both automated scanners and a tired analyst at 9pm. It didn’t get past a decoy with no legitimate reason to ever be touched.

9

MITRE ATT&CK tactics mapped

0

Times the payload executed

3

State-linked groups named as candidate attribution

Highly sophisticated malware. Never allowed to run.

Proof in the field

Deployed where the stakes — and the scrutiny — are highest.

Across every environment below, i-Mirage is doing the same job: turning attacker movement into a confirmed, actionable alert before it becomes an incident — in national-scale banking infrastructure, government cyber-crime operations, critical transport, industrial engineering, and telecom networks carrying hundreds of millions of subscribers. The organisations below can’t be named under their own disclosure terms, so we’ve described them instead by what they run and how they’re regulated.

National-scale retail bank

Live decoys standing watch across Data Centre, Disaster Recovery, and Cyber Security Centre of Excellence environments around the clock. Deployed at one of the largest public-sector banks in the world by branch count, under a multi-year enterprise contract.

Government cyber-crime division

Decoys operating inside a public-sector, law-enforcement-grade network — proof the same technology holds up well outside commercial IT. Deployed at a state-level cyber-crime division covering a jurisdiction of over 120 million people.

Global engineering conglomerate

A single deception layer covering both OT/ICS and standard corporate IT side by side. Deployed at a multi-billion-dollar engineering, construction, and technology group spanning defence, energy, and infrastructure.

Major airport operator

Added with zero downtime and no change to live systems — the only acceptable bar for an environment where continuity can't be interrupted. Deployed across a major international airport operator's infrastructure.

Tier-1 mobile network operator

A 29-day live proof of concept surfaced 547,000+ enriched attacker events and harvested 49,884 confirmed toll-fraud numbers before they could connect — intelligence fed straight back into fraud and network defences. Run for one of the largest mobile operators in its market, serving hundreds of millions of subscribers.

Banking, government, industrial, transport, telecom — these are the same sectors covered by DORA, NIS2, the CAF, and the Telecoms Security Act in the UK and EU. The environments differ. What regulators now expect from each of them is the same: prove you can detect an attacker, not just block one.

The compliance dividend

It pays off in regulator dividends, too.

Already on your regulator’s checklist.

TLPT-ready

Evidence your next audit already needs

DORA Article 26 — the EU's Digital Operational Resilience Act — requires threat-led penetration testing (TLPT). NIS2, the EU's network-and-information-security directive, and the NCSC's Cyber Assessment Framework (CAF) require demonstrable detection. Every i-Mirage alert is exactly that evidence, ready before the assessor asks.

Smoother renewal

What underwriters now ask for

Insurers are aligning cyber underwriting to DORA programme maturity — a completed ICT register, tested response plan, active detection. A documented deception layer is now on that checklist.

2%

The standard now in force

NIS2 and DORA cap penalties at 2% of global turnover or €10M, mirrored in the UK by the FCA's Operational Resilience regime (PS21/3) and the PRA's equivalent rules (SS1/21) — the same detection expectation, held across every UK/EU regulator.

£81M

The precedent the market already has

The FCA (Financial Conduct Authority) and PRA (Prudential Regulation Authority) fined TSB £48.65M in 2022 for operational resilience failings, plus £32.7M in customer redress — a public marker of what this category of control is worth getting right.

Sources: NIS2 Directive (EU 2022/2555); DORA — Digital Operational Resilience Act (EU 2022/2554); FCA — Financial Conduct Authority — Operational Resilience Policy Statement PS21/3; PRA — Prudential Regulation Authority — SS1/21; FCA/PRA final notices to TSB Bank plc (Dec 2022); WTW, ‘DORA vs. NYDFS: cyber insurance for financial institutions’ (2025).

How i-Mirage works

One engine. Every domain it protects speaks its own language.

i-Mirage doesn’t run one generic decoy everywhere and hope it’s convincing. It deploys domain-native decoys — servers and honeytokens for IT, Modbus/MQTT/FTP/SMB devices for OT/ICS, SIP and signalling endpoints for telecom — because an attacker working a SCADA network will never touch an IT file-share, and one working toll fraud will never touch a PLC. Every decoy, in every domain, feeds the same core AI engine: it deploys traps dynamically as an attacker moves, scores intent the instant they touch one, maps it to the attacker lifecycle, and hands your SOC a confirmed, ready-to-action alert. No rip-and-replace. No added headcount.

IT

Servers, endpoints, databases, AD accounts & honeytokens — indistinguishable from the real estate.

ServersEndpointsDatabasesAD accountsHoneytokens

OT / ICS & air-gapped

Live decoys inside plant-floor and industrial networks — zero production downtime, agentless.

ModbusMQTTFTPSMBPLC / SCADA HMI

Dashed = on the roadmap, not yet live.

The protocols industrial and IoT devices actually speak — not IT traffic dressed up to look like it.

Telecom

Signalling-native decoys that catch toll fraud, SIM-box and core-network probing before it lands.

SIP / VoIPDiameterSMSCSS7

Dashed = on the roadmap, not yet live.

The signalling layers behind calls, texts, and account data — where telecom fraud actually happens.

Core AI Engine

One brain across every domain — real-time decoy orchestration & attacker-intent scoring.

1

Dynamic deployment

Decoys spawn and reposition in real time along the attacker's actual path — not a static trap laid once and forgotten.

2

Malice & intent scoring

Every touch is scored — attacker IP, infrastructure, protocol, payload — confirmed activity, not an inference.

3

Attacker lifecycle mapping

Every alert mapped automatically to MITRE ATT&CK — full TTP context with zero manual enrichment.

4

Action to your SOC

A confirmed, ready-to-action alert pushed straight into the SIEM, SOAR and EDR you already run.

5

Daily executive reporting

A daily, board-ready snapshot of security posture and exposure — generated automatically, not assembled by hand.

No rip-and-replaceNo added headcountNo production downtimeNear-zero false positives, by architecture

Self-healing after every interaction — decoys reset from a clean snapshot, so the trap stays convincing.

See it work in your environment.

A scoped pilot: live decoys in your environment, real attacker interactions, a board-ready read-out at the end. No agents, no commitment beyond the pilot.