Skip to content
The Three Rules Every Valuable Must Obey
BusinessContinuity dataprivacy onlinesafety

The Three Rules Every Valuable Must Obey

Jude Adiefe
Jude Adiefe
The Three Rules Every Valuable Must Obey
4:17

A Safe Is Not Enough On Its Own

You have installed a safe in your house to protect your valuables, the gold bars, the jewellery, the home ownership documents. That is a start. But now ask yourself three questions. Can only the right people open it? Is everything inside exactly as you deposited it, nothing added, nothing removed, nothing swapped? And when you urgently need your valuables, can you actually get to them?

If the answer to any of those is that you are not sure, you have a cybersecurity problem, even if the safe is brand new and looks impenetrable. These three questions map directly to the foundational framework of cybersecurity: the CIA Triad.

Confidentiality: Only the Right People See It

Confidentiality means that sensitive information is accessible only to those who are authorised to see it. Think of it as the combination to your safe. The valuables may be locked away, but if everyone in the building knows the combination, the safe is theatre, not security.

In practice, confidentiality is achieved through encryption, which scrambles data so only authorised parties can read it, access controls, which limit who can view which files, and classification, which marks which information is sensitive in the first place.

Not everything deserves the same level of confidentiality. Your company newsletter is public. Your customer payment details are highly confidential. Knowing the difference, and enforcing it, is the first act of practical cybersecurity.

Integrity: The Valuables Must Be Genuine

Integrity means that data has not been altered, corrupted or tampered with, whether by an attacker or by accident. Imagine opening your safe and finding that someone has swapped your gold bars for lead ones, or replaced your home ownership documents with expert forgeries. They look the same. The weight feels right; the paper looks official. But they are not what you deposited.

Digital tampering can be far subtler. A financial record with a changed digit. A medical file with an altered dosage. A software update secretly modified before delivery. In each case, the data exists, but it can no longer be trusted.

Integrity is protected through checksums, mathematical fingerprints that detect changes, audit logs, records of who changed what and when, and version controls, the ability to restore a known-good state.

Availability: You Must Be Able to Use It

The most secure safe in the world is worthless if the door is jammed shut when you need to access your valuables, whether that is gold to sell, jewellery to wear, or ownership documents to present. Availability means that information and systems are accessible when legitimate users need them.

Availability threats include ransomware, which locks you out of your own data and demands payment for the key, denial-of-service attacks, which flood a system until it collapses, and even poor infrastructure design, a single server with no backup that fails at a critical moment.

For a bank, unavailability of its internet banking platform is not just an inconvenience. It is a direct revenue and reputational loss. Availability is the dimension of the CIA Triad that businesses feel most immediately.

The Triad in Balance

Here is the nuance that makes cybersecurity genuinely interesting: the three properties sometimes pull against each other. Making a system highly confidential, accessible only to a few, can reduce its availability. Making data highly available, fast, open, everywhere, can compromise confidentiality. Security professionals must calibrate the triad based on the value and nature of each asset.

“A financial system needs high confidentiality, high integrity and high availability. An employee benefits form may need high integrity but only moderate confidentiality. The calibration is the craft.”

In the next article, we go deeper on a prerequisite that most organisations skip: you cannot protect what you have not yet found. Before the CIA Triad can be applied to anything, you must know what your digital assets actually are.

Next in the series: You Cannot Protect What You Cannot See. Learn more at www.cybervergent.com, or get started at cloud.cybervergent.com.

Share this post