---
title: "Explanation of the Cybersecurity CIA Triad"
description: "Master the Cybersecurity CIA Triad and its counter, DAD, with this explanation covering encryption, hashing, and availability strategies."
lang: en
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "Person",
      "@id": "https://christianespinosa.com/#person",
      "name": "Christian Espinosa",
      "url": "https://christianespinosa.com/",
      "image": "https://christianespinosa.com/__l5e/assets-v1/de07e44b-a8e0-4bcc-bcb0-13aec15421f1/headshot-front.jpg",
      "sameAs": [
        "https://www.facebook.com/christian.espinosa.official",
        "https://x.com/Ironracer",
        "https://www.instagram.com/christian.espinosa.official/",
        "https://www.youtube.com/@ChristianEspinosaOfficial",
        "https://www.linkedin.com/in/christianespinosa/"
      ],
      "jobTitle": "Bestselling Author, Keynote Speaker, Entrepreneur",
      "worksFor": {
        "@type": "Organization",
        "name": "Blue Goat Cyber",
        "url": "https://bluegoatcyber.com/"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "@id": "https://christianespinosa.com/#website",
      "name": "Christian Espinosa",
      "url": "https://christianespinosa.com/",
      "publisher": {
        "@id": "https://christianespinosa.com/#organization"
      },
      "inLanguage": "en-US"
    },
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "@id": "https://christianespinosa.com/#organization",
      "name": "Christian Espinosa",
      "url": "https://christianespinosa.com/",
      "logo": {
        "@type": "ImageObject",
        "url": "https://christianespinosa.com/logo.svg"
      },
      "founder": {
        "@id": "https://christianespinosa.com/#person"
      },
      "sameAs": [
        "https://www.facebook.com/christian.espinosa.official",
        "https://x.com/Ironracer",
        "https://www.instagram.com/christian.espinosa.official/",
        "https://www.youtube.com/@ChristianEspinosaOfficial",
        "https://www.linkedin.com/in/christianespinosa/"
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "Article",
      "headline": "Explanation of the Cybersecurity CIA Triad - Christian Espinosa",
      "description": "Master the Cybersecurity CIA Triad and its counter, DAD, with this explanation covering encryption, hashing, and availability strategies.",
      "image": "https://christianespinosa.com/__l5e/assets-v1/0a6404bd-28be-422a-8fd2-4f49945215ea/explanation-of-the-cybersecurity-cia-triad-card.png",
      "datePublished": "2021-08-29T22:27:20+00:00",
      "dateModified": "2026-06-26T05:34:01.993Z",
      "mainEntityOfPage": {
        "@type": "WebPage",
        "@id": "https://christianespinosa.com/blog/explanation-of-the-cybersecurity-cia-triad"
      },
      "author": {
        "@type": "Person",
        "name": "Christian Espinosa",
        "url": "https://christianespinosa.com/about"
      },
      "publisher": {
        "@type": "Organization",
        "name": "Christian Espinosa",
        "logo": {
          "@type": "ImageObject",
          "url": "https://christianespinosa.com/logo.svg"
        }
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "FAQPage",
      "mainEntity": [
        {
          "@type": "Question",
          "name": "What is the core idea behind \"Explanation of the Cybersecurity CIA Triad - Christian Espinosa\"?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "This post is a transcript of Christian Espinosa's explanation of the cybersecurity CIA triad including the opposite, DAD."
          }
        },
        {
          "@type": "Question",
          "name": "Who is this post for?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Honestly, security leaders, medical device teams, and technical operators who want the honest version, not the vendor version. If you want a listicle, this is not that. If you want the honest version of what I have actually lived and worked through, keep reading."
          }
        },
        {
          "@type": "Question",
          "name": "How do I actually apply this, not just nod along?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Pick the single line in the post that made you flinch or look away, and change one thing in your week because of it. One choice this week beats a whole framework you never touch."
          }
        }
      ]
    }
  ]
---

[Skip to content](#main)

[](/)

[About](/about)[Speaking](/speaking)[Cybersecurity](/cybersecurity)[Programs](/programs)[Books](/books)[Media](/media)

Writing

Search Ctrl K[Connect](/connect)

[Cybersecurity](/blog/category/cybersecurity)

# Explanation of the Cybersecurity CIA Triad

August 29, 2021 3 min read 589 words 

I talk about the Cybersecurity CIA Triad and its opposite, DAD.

![](/__l5e/assets-v1/be4ae1a7-d388-41cf-83dd-8151b166a6ae/0b058f6e8a8d.jpg)

The takeaways

1.  01 
    
    For each, I go into the technologies I use.
    
    What to do next Run a 20-minute tabletop with your team this month using technologies as the scenario.
    
2.  02 
    
    DAD, the opposite, stands for Disclosure, Alteration, and Destruction/Denial.
    
    What to do next Ask your security lead this week for the one-page view of opposite in your environment, and read it end to end.
    
3.  03 
    
    Today’s topic is on CIA, not the Central Intelligence Agency, but confidentiality, integrity and availability.
    
    What to do next Add today to the next leadership review as a standing item, not a one-time slide.
    
4.  04 
    
    These three things are what we try to achieve with cybersecurity.
    
    What to do next Ask your security lead this week for the one-page view of three in your environment, and read it end to end.
    

I talk about the Cybersecurity CIA Triad and its opposite, DAD. Here's what I cover:

CIA stands for Confidentiality, Integrity, and Availability. For each, I go into the technologies I use. Confidentiality means encryption. Integrity means hashing. Availability means load-balancers and hot sites. DAD, the opposite, stands for Disclosure, Alteration, and Destruction/Denial.

You can check out my latest book, [https://christianespinosa.com/books/the-smartest-person-in-the-room/](https://christianespinosa.com/books/the-smartest-person-in-the-room/).

In Dec 2020, Alpine Security was acquired by Cerberus Sentinel ( [https://www.cerberussentinel.com/](https://www.cerberussentinel.com/))

Need cybersecurity help? Connect with me: [https://christianespinosa.com/cerberus-sentinel/](https://christianespinosa.com/cerberus-sentinel/)

![thumbnail-image](/__l5e/assets-v1/876cb215-511b-4b5e-9dab-2c5f0a72d07f/0bb305a51375.jpg) 

## Complete Cybersecurity CIA Triad Explanation Video Transcript

Hey everybody. This is Christian Espinosa with Alpine Security. Today’s topic is on CIA, not the Central Intelligence Agency, but confidentiality, integrity and availability. These three things are what we try to achieve with cybersecurity.

With confidentiality, we’re trying to prevent unauthorized disclosure of our data. The technology we typically use with confidentiality is encryption. So I want to encrypt my data in transit and at rest. So if I’m sending some data to Amazon, such as my credit card number, and somebody intercepts it, they can’t read the data unless they have the encryption key. It’s kept secret. If somebody steals my hard drive and I’ve encrypted my hard drive, my data is not disclosed to them unless they can decrypt the hard drive. So confidentiality, the technology we use is encryption.

Integrity is to make sure our data is not altered, either intentionally or unintentionally. That technology we use for integrity is [hashing](https://christianespinosa.com/blog/explanation-of-cybersecurity-hashing-and-collisions/). So if we use a hashing algorithm, such as MD5, SHA1, SHA512, if we use any of those, we take the data, we run it through this hash algorithm, it spits out what’s called the message digest, that if I send you the data, you run the data you received from me through the same hash algorithm, you get a message digest. If your message digest matches, sorry, my message digest, then the data has not been altered. So that’s hashing and that’s used to prevent alteration or to see if data has been altered.

The a stands for availability. If the data is not available, it’s kind of useless. With availability, we typically use things like load balancers, backup sites, hot sites, mirrored sites, et cetera for availability.

The opposite of CIA, is DAD. That stands for disclosure, alteration and destruction. With disclosure, it’s the opposite of confidentiality. So if your data is disclose to me or to a hacker, you have no longer achieved the objective of confidentiality. With the A, alteration, if your data is supposed to have integrity, but I’m able to alter it. Let’s say I go to your shopping cart and I can change the price of your thousand dollar item to $1 then I’ve altered your data and that is not achieving integrity. The other D stands for destruction or denial of service. So if I’m able to destroy your system, like your server, or do it the of service on your server, then I have removed the availability of your system to your users. So that’s DAD, disclosure, alteration and destruction.

I hope you enjoyed this. Quick tutorial on CIA and DAD. If you have any questions or comments leave them beneath the video. Please subscribe to our channel. Thanks. I’ll talk to you later.

[![Check Out The Smartest Person in The Room](/__l5e/assets-v1/2a4e60fb-7657-43f3-8e9b-9e4346105f2b/ba7fccb1c1f2.png) ](https://cta-redirect.hubspot.com/cta/redirect/7462611/94f60ee8-4fbe-483b-8a0f-ad83ab12a665)

Frequently asked

### What is the core idea behind "Explanation of the Cybersecurity CIA Triad - Christian Espinosa"?

### Who is this post for?

### How do I actually apply this, not just nod along?

### Work with me

I help founders and cybersecurity leaders build teams that ship, not teams that stall. If that's the problem you're trying to solve, let's talk.

[Start a conversation](/contact)

Share this essay

[X ](https://twitter.com/intent/tweet?url=https%3A%2F%2Fchristianespinosa.com%2Fblog%2Fexplanation-of-the-cybersecurity-cia-triad&text=Explanation%20of%20the%20Cybersecurity%20CIA%20Triad) [LinkedIn](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fchristianespinosa.com%2Fblog%2Fexplanation-of-the-cybersecurity-cia-triad) [Facebook](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fchristianespinosa.com%2Fblog%2Fexplanation-of-the-cybersecurity-cia-triad) [Email](mailto:?subject=Explanation%20of%20the%20Cybersecurity%20CIA%20Triad&body=https%3A%2F%2Fchristianespinosa.com%2Fblog%2Fexplanation-of-the-cybersecurity-cia-triad)Copy link 

![Christian Espinosa, headshot](/__l5e/assets-v1/de07e44b-a8e0-4bcc-bcb0-13aec15421f1/headshot-front.jpg)

About the author

[Christian Espinosa](/about) · Founder & CEO, Blue Goat Cyber

Christian is the founder and CEO of Blue Goat Cyber, a medical device cybersecurity firm. He's an Air Force Academy graduate, 24x Ironman, climber of two of the Seven Summits, and the author of The Smartest Person in the Room and The In-Between: Life in the Micro.

Keep reading

-   [
    
    ### Explanation of Cybersecurity Hashing and Collisions - Christian Espinosa
    
    Same thread: cybersecurity.
    
    Read essay → ](/blog/explanation-of-cybersecurity-hashing-and-collisions)
-   [
    
    ### Gray Box Penetration Testing Explained - Christian Espinosa
    
    Same thread: cybersecurity.
    
    Read essay → ](/blog/gray-box-penetration-testing-explained)
-   [
    
    ### Black Box Penetration Testing Explained - Christian Espinosa
    
    Same thread: cybersecurity.
    
    Read essay → ](/blog/black-box-penetration-testing-explained)

[← Previous essay 

Black Box Penetration Testing Explained - Christian Espinosa

](/blog/black-box-penetration-testing-explained)[Next essay → 

Explanation of Cybersecurity Hashing and Collisions - Christian Espinosa

](/blog/explanation-of-cybersecurity-hashing-and-collisions)

Related, Cybersecurity

### Need medical-device or offensive security expertise?

Blue Goat Cyber, Christian's firm, runs FDA-aligned premarket submissions, penetration testing, and SBOM/SOUP analysis for medtech and high-stakes industries.

[Explore Blue Goat Cyber](/cybersecurity)

Christian Espinosa

Bestselling author, keynote speaker, and Founding CEO of [Blue Goat Cyber](https://bluegoatcyber.com/). Helping technical leaders develop the soft skills that turn brilliance into impact.

[](https://www.linkedin.com/in/christianespinosa/)[](https://x.com/Ironracer)[](https://www.instagram.com/christian.espinosa.official/)[](https://www.youtube.com/@ChristianEspinosaOfficial)[](https://www.facebook.com/christian.espinosa.official)

Explore

-   [About](/about)
-   [Timeline](/timeline)
-   [Speaking](/speaking)
-   [Cybersecurity](/cybersecurity)
-   [Programs](/programs)

Read

-   [Books](/books)
-   [Guides](/guides)
-   [Blog](/blog)
-   [Media](/media)
-   [Podcast Interviews](/podcasts)
-   [Success Stories](/success-stories)

Connect

-   [Contact Christian](/connect)
-   [LinkedIn ↗](https://www.linkedin.com/in/christianespinosa/)
-   [Blue Goat Cyber ↗](https://bluegoatcyber.com/)
-   [Resources](/resources)

© 2026 Christian Espinosa. All rights reserved.

[Privacy](/privacy-policy)[Terms](/terms-of-use)