Abstract
The maritime sector—an essential service under the NIS 2 Directive and a linchpin of global commerce—has emerged as a primary target for sophisticated cyber operations conducted by state-aligned threat collectives and their proxies. Traditional, reactive threat-intelligence paradigms struggle to anticipate the tactics and motivations of persistent human adversaries: static indicators of compromise capture what happens, but rarely why. This paper proposes a proactive cyber-deception
framework that addresses this intelligence gap by extending conventional
honeypot architectures with a psychologically resonant lure layer informed by Lacanian psychoanalytic theory. Our central claim is that designing the deception environment not merely as a technical trap but as a structured lack—conceptualised through the notion of objet petit a—can encourage sustained adversary engagement beyond purely instrumental objectives. Through a multiphased methodology—OSINT-driven ecosystem mapping, covert infiltration via a purpose-built digital persona, and deployment of a psychologically augmented high-interaction honeypot simulating a
maritime-logistics operator—we present a proof-of-concept based on a single, controlled case study. The deployment generated 135,311 Wazuh security events. Against that baseline, three high-severity human-driven sessions showed extended dwell time and repeated attempts on opaque, narrative-shaped artefacts. Chat-discourse evidence—a leader directive to “keep trying” a corrupted archive—is consistent with an account in terms of Desire, though curiosity, sunk cost, and hierarchical tasking fit the same three sessions. We report this as a single case study. The findings generate hypotheses; they do not test them. The study introduces an interdisciplinary model of cyber deception and offers hypothesis-generating insights for the protection of Critical Information Infrastructures.
framework that addresses this intelligence gap by extending conventional
honeypot architectures with a psychologically resonant lure layer informed by Lacanian psychoanalytic theory. Our central claim is that designing the deception environment not merely as a technical trap but as a structured lack—conceptualised through the notion of objet petit a—can encourage sustained adversary engagement beyond purely instrumental objectives. Through a multiphased methodology—OSINT-driven ecosystem mapping, covert infiltration via a purpose-built digital persona, and deployment of a psychologically augmented high-interaction honeypot simulating a
maritime-logistics operator—we present a proof-of-concept based on a single, controlled case study. The deployment generated 135,311 Wazuh security events. Against that baseline, three high-severity human-driven sessions showed extended dwell time and repeated attempts on opaque, narrative-shaped artefacts. Chat-discourse evidence—a leader directive to “keep trying” a corrupted archive—is consistent with an account in terms of Desire, though curiosity, sunk cost, and hierarchical tasking fit the same three sessions. We report this as a single case study. The findings generate hypotheses; they do not test them. The study introduces an interdisciplinary model of cyber deception and offers hypothesis-generating insights for the protection of Critical Information Infrastructures.
| Original language | English |
|---|---|
| Publication status | Accepted/In press - 20 Jun 2026 |
| Event | 21st International Conference on Critical Information Infrastructures Security - Cyprus, Nicosia, Cyprus Duration: 28 Sept 2026 → 30 Sept 2026 https://critis2026.com/ |
Conference
| Conference | 21st International Conference on Critical Information Infrastructures Security |
|---|---|
| Abbreviated title | CRITIS 2026 |
| Country/Territory | Cyprus |
| City | Nicosia |
| Period | 28/09/26 → 30/09/26 |
| Internet address |
Keywords
- security
- psychology
- rationality
- maritime
- threat intelligence
- Lacan, Jacques
Cite this
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver