Vol. 01 · Story 06 · Domain 1

THETHREE SAFES.

The CIA Triad

Gary's Coffee Shop · 2 min read

Three safes, three properties. The combination lock, the wax seal, the water supply — and the sign-in book that answers three questions every time.

Reading Progress
00 / 22
Story 06 · Domain 1 · CIA Triad

The Three Safes.

Gary has three safes. Each protects something different. Each fails in a different way. Together, they are the foundation of every security decision.

Gary has three safes in his coffee shop. Each one protects something different. Each one has a different weakness. Lose one and you lose a different piece of what matters.

The first safe has a combination lock and a blindfold rule — you can only open it if you know the code, and nobody else can watch. Inside are the secret recipes. Only Gary and his head barista know the combination.

That's Confidentiality — keeping secrets secret. A customer sneaks behind the counter and reads the recipe book → that's a confidentiality breach. The fix? Encryption (the combination lock) and access controls (the blindfold rule).

The second safe has a tamper-evident seal — red wax with Gary's thumbprint. Inside is the accounts ledger. If anyone changes a number, the seal breaks and Gary knows.

That's Integrity — making sure data hasn't been altered. Someone changes "10 bags of beans" to "100 bags" → that's an integrity breach. The fix? Hashing (the wax seal — any change breaks it) and digital signatures (Gary's thumbprint — proves who sealed it).

Gary's thumbprint on the seal means he can't deny he approved the ledger. That's non-repudiation — the digital signature proves both identity and integrity. You can't sign and then say you didn't.

The third safe isn't really a safe — it's the water supply. It doesn't hide anything or prove anything. It just needs to flow. Every day, all day. No water, no coffee, shop shuts.

That's Availability — making sure things are there when you need them. Someone dumps a truckload of gravel into the water main → that's a DDoS (flooding the pipe with rubbish so nothing useful gets through). Ransomware padlocks the stopcock → that's an availability attack. The fix? Redundancy (a second water supply), backups (bottled water), and load balancing (two taps sharing the pressure).

Gary also has a sign-in book at the door. Three questions, every visitor, every time.

"Who are you?" → Authentication (prove your identity). "Are you allowed in the kitchen?" → Authorisation (what can you access). "What did you do while you were here?" → Accounting (logging your actions). That's AAA — the three questions every security system asks.

Ransomware padlocks the shop. That's not theft — it's an availability attack. Every security incident attacks one of three things. Know which one, and you know which safe to fix first. — Story 06 · CIA Triad
// THE LOCK-IN

Every security incident attacks one of three things: Confidentiality (the secret got out), Integrity (the data got changed), or Availability (the system went down). Identify which safe is broken, and you know what to fix.

Check Yourself · Question 06

Ransomware encrypts Gary's accounts ledger and demands £5,000. Which property of the CIA Triad does it primarily attack?

Terminology · Story 06

The Three Properties.

// Term · 01 / 05
Confidentiality
Tap to reveal
// Definition
Keeping information accessible only to those authorised to see it. Defended by: encryption, access controls, classification. The combination lock.
Domain 01
// Term · 02 / 05
Integrity
Tap to reveal
// Definition
Data has not been altered without authorisation. Defended by: hashing, digital signatures, version control. The wax seal.
Domain 01
// Term · 03 / 05
Availability
Tap to reveal
// Definition
Systems and data are accessible when needed. Defended by: redundancy, backups, load balancing, HA. The water supply.
Domain 01
// Term · 04 / 05
Non-repudiation
Tap to reveal
// Definition
You cannot deny an action you performed. Achieved via digital signatures — the private key proves you signed it. Gary's thumbprint on the ledger seal.
Domain 01
// Term · 05 / 05
AAA
Tap to reveal
// Definition
Authentication — who are you? Authorisation — what can you access? Accounting — what did you do? The sign-in book at the door.
Domain 01