Most people hear “cybersecurity” and picture a hoodie-wearing hacker in a dark room. That image isn’t useful. Security isn’t about hackers. It’s about three things you already care about, whether you know it or not: keeping your stuff private, keeping your stuff accurate, and being able to get to your stuff when you need it.

That’s the CIA Triad. Confidentiality. Integrity. Availability. Three letters that drive every decision a security team makes, and three ideas that apply just as cleanly to your phone, your bank account, and your front door.

Before we get into it, two rules worth remembering:

  • Security is everyone’s job. Not just IT’s.
  • People are the weakest link. Almost every breach you read about traces back to a person, not a broken machine.

Why people? Because tricking someone is faster than breaking a firewall. An attacker sends a fake email pretending to be IT. The employee clicks the link, types in their password, and the attacker walks right in. Nothing was “hacked” in the Hollywood sense. Someone got fooled. That’s it. Or someone props open a side door for a guy carrying boxes who’s “just dropping off a package.” Now he’s inside. No alarm tripped. No system failed.

Keep that in mind as we go.

Confidentiality: Keep Private Things Private

Confidentiality means only the people who should see something can see it.

You text your spouse. Only your spouse should read it. Your doctor pulls up your chart. Only your doctor and her staff should see it. Your tax return goes to the IRS. Nobody else needs a copy.

When confidentiality breaks, it’s usually because someone got into a place they didn’t belong. Sometimes that’s a stranger across the world. Sometimes that’s the nosy coworker reading over your shoulder. The damage is the same: information ends up in the wrong hands.

A perfect example of this, was the Equifax breach in 2017 which exposed personal and financial data on about 147 million Americans. A security flaw in a web application-builder gave hackers a window into the company’s data stores, and Equifax admitted to knowing about the security issue two months before the hack. They knew. They didn’t fix it. The company eventually settled for up to $425 million with the FTC, the CFPB, and all 50 states.

A few years earlier, hackers broke into Anthem and released the personal data of approximately 78 million people, including names, birthdays, Social Security numbers, email addresses, and employment and income information. Anthem paid $115 million to settle the class action, which was the biggest data breach settlement in the country at the time.

What this looks like in your own life:

  • Reusing the same password for multiple sites. One breach, and every account is open.
  • Sending a Social Security number over plain email or text.
  • Leaving your laptop unlocked at a coffee shop while you grab a refill.
  • Posting a photo of your new debit card on Instagram. People do this. Please don’t.

Integrity: Keep Information Accurate

Integrity means the data hasn’t been changed by anyone who shouldn’t be changing it.

You write a contract. The version your client signs better be the version you wrote. Your bank statement shows a $500 deposit. That number better still say $500 tomorrow. Your medical record says you’re allergic to penicillin. That allergy better still be there when the ER doctor pulls it up.

Integrity attacks are sneakier than confidentiality attacks. When someone steals data, you eventually notice. When someone quietly changes data, you might never notice, and you’ll keep making decisions based on bad information.

In 2017, electronic health records vendor eClinicalWorks agreed to a $155 million settlement tied to data integrity problems. The lawsuit alleged the company falsely claimed it met certification requirements that include accurately recording user actions, such as orders for diagnostic tests conducted during a patient’s treatment. If the audit log can’t be trusted to record what really happened, the whole chart is suspect. Doctors making treatment calls off that data are flying blind.

Another one worth mentioning: In 2015, FDA permanently debarred a clinical trial study coordinator who was convicted and sentenced to three years in prison for submitting false statements concerning a clinical trial. He created 15-20 fictitious patients and reported false test results by substituting his own blood, stool and EKG results. One person, faking records, and a drug trial gets corrupted. That’s an integrity failure with criminal consequences.

On a personal level, someone can change the routing number on an emailed invoice and you pay the wrong account, this is called Business Email Compromise, tracked by the FBI and responsible for billions in losses each year. A scammer edits the shipping address on your Amazon order, or someone gains access to your email and quietly forwards every message from your accountant to themselves. You wouldn’t catch any of these right away. That’s the point.

Availability: Be Able to Get to Your Stuff

Availability means you can actually use what you’re supposed to be able to use, when you’re supposed to be able to use it.

If your email’s down for a day, that’s an availability problem. If a hospital can’t pull up patient charts because ransomware locked their systems, that’s an availability problem with people’s lives on the line. If a power grid goes down because someone hit the controls with malware, that’s an availability problem that affects an entire city.

The case everyone remembers:

On May 7, 2021, Colonial Pipeline suffered a ransomware attack that hit the systems running the pipeline. The company halted all pipeline operations to contain it and ended up paying 75 bitcoin or $4.4 million to the hackers. The attackers got in through a compromised password for an inactive VPN account that didn’t have multi-factor authentication enabled.

One password. One forgotten account. And gas stations across the southeast ran dry for almost a week.

A class action followed, blaming “unlawfully deficient data security” for infrastructure that runs from Houston across the Southeast and into New Jersey before reaching New York Harbor, covering nearly half of the East Coast’s fuel supply. The Department of Transportation also issued a Notice of Probable Violation with proposed civil penalties of nearly $1 million.

This could happen to your personal stuff:

  • Ransomware locking your family photos because you clicked the wrong attachment.
  • Losing access to your email because you didn’t set up account recovery and the password’s gone.
  • A dead phone with no backup right when you need the boarding pass.

How the Three Connect

The triad isn’t three separate things sitting in three corners. They overlap, and trade-offs between them are constant.

Encrypt everything with a password only you know, and you’ve maxed out confidentiality. Forget the password, and you’ve destroyed availability. Make a system so easy to access that anyone can fix anything, and you’ve gutted integrity. Lock the system down so tight that nobody can touch it, and nobody can do their job.

Good security is balance. Not paranoia. Not convenience. Balance.

You don’t need a security degree to protect yourself. A few habits cover most of it:

Least privilege. Give people, apps, and accounts only the access they actually need. Your kid’s tablet doesn’t need admin rights. The contractor doing your bookkeeping doesn’t need access to your medical files. New employee handling one folder doesn’t need keys to the whole system.

Defense in depth. Don’t rely on one lock. Use a password manager, turn on multi-factor authentication, keep your software updated, and back up your data somewhere the ransomware can’t reach. If one layer fails, the next one holds.

Know what you have. You can’t protect what you don’t know exists. Take ten minutes and list the accounts that matter: email, banking, retirement, primary social media, your phone provider. Those are the crown jewels. Protect those first.

Never trust, always verify. That email from “your bank” asking you to log in? Open a new tab and type the bank’s address yourself. The text from “your boss” asking for gift cards? Call the boss. Five seconds of verification beats five months of cleanup.

The point I am trying to make is this: The CIA Triad isn’t an IT problem. It’s a life problem.

Every time you decide who can see your stuff, who can change your stuff, and whether you’ll still have access to your stuff tomorrow, you’re making a CIA Triad decision. The companies that got it wrong paid hundreds of millions in settlements. Pipelines shut down. Hospitals went dark. Records got faked.

The good news is, most of this comes down to basic habits, not expensive technology. Protect privacy. Trust your data. Keep access working.

That’s it. That’s the whole job.


Hope you find this post helpful and informative. Thanks for stopping by!

Leave a Reply

Discover more from root@cybercasta:~$

Subscribe now to keep reading and get access to the full archive.

Continue reading