CASE STUDY BY LABYRINTH: USING THE DECEPTION SOLUTION FOR GALNAFTOGAZ
Our partners, companies Labyrinth and IT Specialist recently published an informative case study on the use of the Deception platform in the implementation of the SOC for Galnaftogaz.
The Concern Galnaftogaz, the OKKO filling station chain, is one of the leaders in the Ukrainian industry with a market share of over 18% in the sale of light petroleum products. With more than 400 OKKO-branded filling stations, the company also has the largest network of roadside restaurants in Ukraine.
Customer’s Challenge
Galnaftogaz that operates a network of petrol stations in Ukraine, is committed to providing uninterrupted customer service in this area, so ensuring 100% security of their IT infrastructure is crucial.
Labyrithm has previously implemented a number of cybersecurity measures for Galnaftogaz, including the creation of a cybersecurity operations centre (SOC) and other cybersecurity tools. During routine penetration tests using attack simulations (red/blue commands), the need for additional protection of the internal network was identified. It became apparent that in the event of a hack, hackers could remain undetected in the system for a long time before the attack was launched.
Deception solutions for protection
Deception is a sophisticated class of cybersecurity tools aimed at proactively identifying potential threats and alerting organisations to risk at the earliest stages of intruder infiltration into an internal network. Often referred to as a maze, this system creates a network of traps or simulated targets that mimic real assets in an information system. This technology not only helps to identify attackers at the initial stages of network infiltration, but also allows you to neutralise potential threats before they cause real damage.
The effectiveness of Deception technologies lies in creating the illusion of easy prey. This involves hackers interacting with a controlled environment containing simulated resources, such as fictitious user accounts or databases. It is important to note that these resources remain inaccessible and isolated from the real network under normal conditions. Therefore, any attempt to interact with them becomes highly suspicious and effectively serves as a clear indicator of intrusion.


A significant feature of the project implementation was deep integration with existing monitoring systems, in particular with the SIEM system. This made it possible to create a two-way communication channel between the system Deception and security analysis tools. This interaction helped to detect attacks in a simulated environment and analyse activity on real hostsenhancing the ability to detect and neutralise threats.
“Deception is a very promising area. Such solutions create conditions where the advantage during attacks remains on the side of the cybersecurity team. This changes the rules of the game, leaving no room for error for attackers, and IT professionals only need to react and stop the attack. This product was developed based on real needs and daily tasks. For us, this case serves as a portfolio, a recommendation and an example for other customers,” said Yuriy Gatupov, Head of iIT Distribution.