October 2, 2026
30 Days of Cybersecurity | Day 2 | The CIA Triad: The Three Principles Behind Cybersecurity
On Day 1 of my 30 Days of Cybersecurity challenge, I set a simple goal for October: learn, practice, document, and reflect every day.

By Shamita
4 min read
Today, I am starting with one of the most fundamental concepts in cybersecurity:
The CIA Triad.
No, this has nothing to do with the Central Intelligence Agency.
In cybersecurity, CIA stands for:
Confidentiality Integrity Availability
These three principles form a simple framework for thinking about what security is actually trying to protect.
Almost every security control, vulnerability, attack, or incident can be connected to one or more of these three properties.
What Is the CIA Triad?
Imagine that you are using an online banking application.
You would expect your financial information to remain private.
You would expect your account balance and transaction history to remain accurate.
And you would expect the application to be accessible when you need it.
These expectations correspond directly to the three components of the CIA Triad.
Confidentiality: Only authorized people should be able to access information.
Integrity: Information should remain accurate, complete, and trustworthy.
Availability: Authorized users should be able to access systems and information when they need them.
Together, they provide a basic way to evaluate whether information and systems are being adequately protected.
1. Confidentiality
Confidentiality is about preventing unauthorized disclosure of information.
Consider a university database containing student records.
Students may be authorized to view their own information, while administrators may have broader access. An unrelated person should not be able to access the database simply because they discovered where it was hosted.
That is a confidentiality problem.
Security mechanisms that help protect confidentiality include:
- Authentication
- Authorization
- Encryption
- Access controls
- Network segmentation
- Data classification
Phishing is another common example.
If an attacker convinces someone to reveal their password, the attacker may gain access to information that was supposed to remain private.
The important point is that confidentiality is not simply about keeping information "secret."
It is about ensuring that information is accessible only to entities that are authorized to access it.
2. Integrity
Integrity is about maintaining the accuracy and trustworthiness of information.
Consider the same banking application.
Suppose your account contains ₹50,000.
If an unauthorized person modifies the database so that your balance becomes ₹5,000, the problem is not primarily that the information was exposed.
The problem is that the information was changed without authorization.
That is an integrity failure.
Integrity can be protected through mechanisms such as:
- Hashing
- Digital signatures
- Access controls
- File integrity monitoring
- Version control
- Checksums
- Audit logs
Integrity is especially important in environments where decisions depend on the accuracy of data.
Think about medical records, financial transactions, software updates, examination results, or security logs.
If the information cannot be trusted, the system cannot reliably be trusted either.
3. Availability
Availability means that authorized users should be able to access systems and information when required.
Imagine that your university's examination portal works perfectly from Monday to Thursday.
On Friday, thousands of students attempt to access it simultaneously, but the service becomes unavailable.
The data may still be confidential.
It may still be completely accurate.
But if legitimate users cannot access the system, availability has been compromised.
Availability can be affected by many things:
- Distributed denial-of-service attacks
- Hardware failures
- Power outages
- Network failures
- Software bugs
- Ransomware
- Resource exhaustion
- Poor capacity planning
This is why cybersecurity is not only about stopping attackers from stealing information.
Keeping systems operational is also a security objective.
Seeing All Three Together
Consider a hypothetical hospital information system.
The system contains patient records, prescriptions, diagnostic reports, and billing information.
Now imagine three different incidents.
An unauthorized person accesses a patient's medical record.
Confidentiality is compromised.
An attacker modifies a patient's prescription.
Integrity is compromised.
The hospital's system becomes unavailable during an emergency.
Availability is compromised.
The same organization can therefore experience different types of security failures depending on what happened to the information or system.
Why the CIA Triad Matters
The interesting part about the CIA Triad is that cybersecurity is rarely about maximizing one property independently.
Security decisions often involve trade-offs.
For example, imagine a company wants extremely strict access controls for sensitive data.
That could improve confidentiality.
But if the controls become so restrictive that employees cannot access the information required to perform their jobs, availability and usability may suffer.
Similarly, encrypting sensitive data can improve confidentiality, but organizations still need appropriate key management and access mechanisms to ensure legitimate users can use that data.
Security is therefore not simply about adding more controls.
It is about applying appropriate controls while considering the requirements and risks of the system.
The CIA Triad in Real Cyberattacks
The model also becomes useful when looking at actual security incidents.
A data breach generally raises questions about confidentiality.
A malicious modification of records or software raises questions about integrity.
A ransomware attack that prevents users from accessing their files raises questions about availability.
Some incidents affect all three.
For example, consider a compromised server.
An attacker could steal sensitive information, modify files, and disrupt the service.
In that situation, confidentiality, integrity, and availability could all be affected.
This makes the CIA Triad useful not only for learning cybersecurity concepts, but also for analyzing incidents.
A Simple Way to Remember It
I find it useful to think about the three principles as three questions:
Confidentiality: "Who is allowed to see this?"
Integrity: "Can I trust that this has not been improperly changed?"
Availability: "Can an authorized user access this when they need it?"
If you can answer these three questions for a system, you already have a basic framework for thinking about its security.
My Takeaway From Day 2
The CIA Triad looks simple.
That is precisely what makes it useful.
Cybersecurity can quickly become overwhelming because it includes networks, operating systems, applications, cloud infrastructure, cryptography, malware, identity management, incident response, and many other areas.
The CIA Triad provides a common foundation underneath all of them.
Before asking how to secure a system, it helps to first ask:
What are we protecting?
What could go wrong?
Which security property would be affected?
From there, we can start thinking about appropriate controls and defenses.
For me, the biggest takeaway from today is that cybersecurity is not just about preventing unauthorized access.
It is about protecting information and systems from being exposed, improperly changed, or made unavailable.
And those three ideas will appear repeatedly throughout the rest of this 30-day journey.
Day 2/30 complete.
Tomorrow, I am moving from protecting systems to something every security system depends on:
Authentication.
Passwords, multi-factor authentication, passkeys, and the question behind all of them:
How do you prove that you are actually you?