(Quick review first: attackers differ by motive and budget, most real incidents come from boring preventable causes, and attacks are a chain with a long gap you can catch them in.)
A tool for thinking
The CIA triad is the closest thing this field has to a universal checklist. Point it at any system and it gives you three questions worth asking. It will not give you answers, but it stops you missing whole categories of problem.
Confidentiality — can the wrong people read it?
Keeping information away from those who should not have it.
You protect confidentiality with access control (only these accounts may open this), encryption (unreadable without the key, so a stolen laptop is a lost laptop rather than a data breach), and classification (knowing which data actually matters — treating everything as top secret means nothing is).
Confidentiality fails quietly. A database copied last month leaks nothing visible today. Often the first sign is your data appearing somewhere it should not — which is why you cannot rely on noticing on your own.
Integrity — can the wrong people change it, and would you know?
Often more important than confidentiality, and consistently underrated by beginners.
Consider a hospital changing a patient's blood type, or a payroll system quietly altering account numbers. Nothing was stolen. Someone might die, or a company might pay a fraudster for a year without noticing.
You protect integrity with access control again, with logging (who changed what, when — a record you can go back to), with hashes and checksums (a fingerprint of a file; if the fingerprint changes, so did the file), and with backups you have actually tested restoring.
Integrity is where the "would we notice?" question bites hardest. Changing data is only devastating if the change goes unnoticed. File integrity monitoring — software watching important files and shouting when they change — is a direct answer, and it is a Wazuh feature you will configure in Week 9.
Availability — can the right people get to it when they need it?
The one beginners forget, because it does not feel like security. It absolutely is.
A system nobody can reach is useless, whatever caused it. Availability is attacked deliberately by ransomware (encrypt everything, demand payment) and denial-of-service (flood a service until it collapses). But it also fails on its own: a disk fills, a certificate expires, a power cut hits a server room. From a user's point of view, these are identical to an attack.
You protect availability with redundancy (more than one of the thing), backups (tested — an untested backup is a rumour), capacity planning, and monitoring that tells you the disk is at 90% before it hits 100%.
They pull against each other
This is the part that makes the triad genuinely useful rather than a slogan.
Improving one property usually costs you another. Encrypt every file and lose the key — perfect confidentiality, zero availability. Require three approvals for every change — excellent integrity, and work grinds to a halt. Make a system trivially reachable from anywhere so staff are never blocked — wonderful availability, and a much larger attack surface.
Security is not about maximising all three. It is about deciding, deliberately, which one matters most for this system and accepting what that costs.
That decision belongs to whoever owns the risk — usually the business, not the security team. Your job is to make the trade-off visible so the choice is informed rather than accidental.
Worked example
A Nigerian fintech's customer transaction database:
- Integrity: highest. Altered balances or redirected transfers destroy the business and are hard to unwind. Every change is logged, logs go somewhere the application cannot edit, and changes are reconciled daily.
- Availability: very high. Customers unable to send money leave, and regulators ask questions. Redundant servers, tested failover.
- Confidentiality: high but third. A leak is serious — reputational damage, regulatory penalty — but a wrong balance is worse, and an outage is felt immediately.
Notice the ranking is arguable. Someone might reasonably put confidentiality higher. Having the argument explicitly is the point.
Try it now
Take three systems you use — your bank app, your email, your phone's photo gallery.
For each, rank C, I and A from most to least important, and write one sentence saying why. Then, for the one you ranked lowest overall, describe what would have to happen for that ranking to be wrong.
Bring your rankings to the next session. People disagree on these, and the disagreement is the lesson.