The Third Word in the Definition of Security
The CIA triad defines security as confidentiality, integrity and availability. The industry sells the first two and forgets the one that closes businesses.
Decades ago, in the first security course I ever sat, an instructor wrote three words on a whiteboard: confidentiality, integrity, availability. The CIA triad - every security qualification since has opened with it, and the formal definitions still do. NIST’s glossary defines information security as protecting systems “in order to provide confidentiality, integrity, and availability” (NIST CSRC, 2026). Three words, equal billing.
Then I spent a lot of my career watching the industry quietly drop the third one.
Two words get all the money
Confidentiality is where the products live. Encryption, access control, data loss prevention, the entire breach-headline economy - secrets, and the fear of losing them. Integrity gets the auditors: is the data correct, has anything been tampered with, can you prove it. Both legs matter, and both have an industry attached, because both can be sold to enterprises with compliance obligations and reputations to insure.
Availability - NIST's words: "ensuring timely and reliable access to and use of information" (NIST CSRC, 2026) - has no such lobby at the small end of town. There's no breach notification for a flooded office. No headline for a business that spent four days locked out of its own accounting package. Nobody markets a deadbolt for "the internet was down and we couldn't take payments". So the third word fell off the whiteboard somewhere between the textbook and the sales deck.
For a small business, the third word is the business
Here's what those years taught me about which leg actually breaks first. Enterprises genuinely do face espionage, tampering and targeted theft; their obsession with the first two words is rational. But walk through the worst weeks I've seen small businesses have, and the pattern inverts.
The laptop that died with the only copy of everything. The office that flooded. The owner locked out of an account that the whole operation ran through. The phone - holding every authenticator code - gone. The internet connection that stayed down past the third day. In none of these was anything stolen or altered. The information was perfectly confidential and perfectly intact. It just wasn't there when the business needed it, and a business that can't reach its own information is closed - politely, invisibly, with no attacker required.
The cleanup looks different too. A confidentiality breach is partly other people's pain - your customers', your insurer's, your lawyer's. An availability failure is all yours: the payroll that can't run, the job that can't be quoted, the Friday takings that never happened.
I'd put it more bluntly: in my time consulting to owner-operators, availability failures have closed more small-business days than confidentiality failures have, by a wide margin - and yet every dollar of the security budget gravitates to the secrets. We've inherited the enterprise's priorities without inheriting its risks.
What availability actually asks of you
The good news is that the neglected leg is also the cheapest one to fix, because availability work is mostly unglamorous physical-world common sense. A backup that you have actually restored from, not merely configured. A second path to the internet. A spare machine. Recovery codes that don't live on the device they're meant to recover. A written list of your suppliers and accounts so a bad morning becomes a sequence of phone calls instead of an archaeology dig. None of it needs a vendor; most of it needs an afternoon.
You'll notice none of that sounds like "cyber". That's partly the point. The triad never said security was about hackers - it said security is the state where your information stays private, stays correct, and stays reachable. A flood is an availability incident. A stolen phone is an availability incident. The basics I keep coming back to - the configuration-level fixes our June 2026 posture research shows most businesses haven't done - protect the first two words. The next few pieces I write will work through the third: backups you've tested, run books, second connections, spare equipment, and what happens when the phone holding your MFA dies.
The next time someone offers your business "security", ask which words they mean. If the answer doesn't include the one that keeps you trading through a flooded pit, a dead laptop and a locked account, you're being sold a two-legged stool. How long do you plan to balance without the third leg?
Sources
- NIST Computer Security Resource Center, Glossary: information security - retrieved 13 June 2026
- NIST Computer Security Resource Center, Glossary: availability - retrieved 13 June 2026
- Red Bridge Cyber, SMB Posture Baseline, June 2026