Short answer: Every security decision comes back to three principles. Confidentiality means only the right people can see your information. Integrity means that information is accurate and nobody has altered it. Availability means your systems work when your staff need them. Get all three right and you are secure. Get two right and you have a problem waiting.

Most IT companies sell you a list of things. Antivirus. Backup. A firewall. A password rule. The list looks reassuring right up until something goes wrong and you find out none of it was joined up.

Good security is simpler than that, and it comes down to three words that have been the foundation of the whole field for decades.

Confidentiality. Integrity. Availability.

Whether you run a care home, a law firm, an accountancy practice or a business with nothing more regulated than a customer database, these three words are what everything else hangs off. They are also what your regulator is measuring you against, even if nobody has ever used the term with you.

Here is what each one means in real life, and what we actually do about it.

๐Ÿ‘€ Confidentiality: only the right people can see the information

Confidentiality means the people who need to see something can see it, and nobody else can.

This is where most businesses are exposed, and it is almost never because of a hacker in a hoodie. It builds up quietly over years. Staff emailing documents from personal accounts. Records sitting on a laptop nobody has updated in two years. Someone who left last summer whose login still works. One password shared between four people.

We found exactly that at one client before they came to us. Sensitive records were moving through personal email and personal phones. No protection, no control, no way of knowing who had seen what. Nothing had gone wrong yet. It was going to.

How we protect confidentiality

  • ๐Ÿ”‘ A second check when anyone logs in, so a stolen password on its own is useless
  • ๐Ÿ“ง Proper business email and file storage, so information stops travelling through personal accounts
  • ๐Ÿšช People only get access to what their job needs
  • ๐Ÿงน Regular reviews of who can see what, because old access piles up and nobody notices
  • ๐Ÿ›ก๏ธ Blocking of dangerous websites and fake emails before anyone can click them
  • ๐Ÿ’ป Control over the devices your information sits on

At another client we locked down a system holding highly sensitive records that had almost no protection when we took it on. No incident, no report, no finding at their next inspection. That is the whole point.

โœ… Integrity: the information is right and nobody has meddled with it

This is the one everybody forgets about.

Integrity means your information is what it is supposed to be. Not changed. Not corrupted. Not quietly edited by someone who should never have been near it.

For a care provider, this is a medication record that does not match what was actually given. For an accountant, it is bank details on an invoice that are no longer your supplier’s. For a solicitor, it is a file you can no longer swear is a true record of what happened. For everyone else, it is a payment that went to the wrong account because an email looked convincing.

These attacks are quiet and profitable, which is why they are so common.

How we protect integrity

  • ๐Ÿ‘๏ธ Software watching every computer for behaviour that looks wrong, rather than waiting for a virus it already recognises
  • ๐Ÿฉน Automatic updates, because out-of-date software is how people get in and start changing things
  • ๐Ÿšฉ Checks that flag emails pretending to be from someone inside your business
  • ๐Ÿ“ฌ Monitoring for the hidden email rules attackers set up to cover their tracks
  • ๐Ÿ“ A record of who did what and when, so if anything is ever questioned you can show it

That last set of controls caught a real attempt at one of our clients. Someone posed as a supplier and tried to redirect an invoice payment to their own account. We blocked it. Not a penny left the business. ๐Ÿ’ท

โšก Availability: it works when you need it

This is the one every owner understands straight away, because they have lived it. The main system is down. Email is down. Nobody can work, nobody can bill, and in a care setting nobody can safely look after anyone.

Availability is about how fast you get back when something breaks, and whether that recovery is a plan or a panic.

How we protect availability

  • ๐Ÿ“ก Constant monitoring, so we usually know before you ring us
  • ๐Ÿ’พ Backups that we actually test, because an untested backup is a hope
  • ๐Ÿ“‹ A written recovery plan for every client, so nothing depends on someone remembering
  • โ˜Ž๏ธ Direct access to your engineer. No call centre, no queue, no ticket sitting in a pile
  • โฑ๏ธ Response times you can hold us to, written into the agreement

One client lost access to their main operational system after an outage. We had them back in an hour instead of the days a full rebuild would have taken. Staff kept working throughout.

We also moved a growing business off personal email accounts onto proper business systems with zero downtime and nothing lost. Nobody stopped working for a minute. ๐Ÿ‘Œ

๐ŸŽฏ The three only work if they work together

This is the bit that matters.

Push any one of them too hard and you break another.

Lock everything down and your staff cannot get what they need at 3am, so they invent their own workarounds and you lose confidentiality anyway. Chase availability on its own and you end up with everything open to everyone. Back up all your data with no protection on the backup, and the backup becomes the breach.

Good security is the balance. That is why we do not sell off a list. We look at what information you hold, what your regulator expects, how your team really works, and we build around that.

๐Ÿข What the three principles look like in your sector

Care and healthcare. Your DSPT submission asks you to state that personal information is handled safely. A CQC inspector asks you to prove it. Resident records, medication charts and rostering all have to be private, accurate and available at 3am. We have taken more than ten care providers through DSPT to Standards Met.

Legal. Client confidentiality is the whole business. A leaked matter file is a regulatory problem before it is anything else, and a day of downtime is a day of billing you never get back.

Accountancy. You hold client financial data and you work to fixed filing deadlines. Invoice fraud and email compromise target you specifically, and an outage in January is not an inconvenience.

Financial services. Operational resilience and client data protection are watched closely. You are expected to show you have thought about all three principles, not just bought antivirus.

Everyone else. Construction, property, agencies, manufacturers. You may not have a regulator breathing down your neck, but you have GDPR duties, customer data, and a business that stops earning the moment your systems stop working.

๐Ÿ“ What this means when someone asks you to prove it

Regulators do not accept intentions. They ask for evidence.

At one client we showed the evidence at inspection and they passed. The evidence existed because the protections existed, so there was no scramble the night before. ๐Ÿ˜Œ

We are Cyber Essentials certified ourselves. That is the difference between a company that talks about compliance and one that has sat in the room and done it. ๐Ÿ…

โ“ Common questions about data security

What is the CIA triad in data security?

The CIA triad is the standard model for information security. It stands for confidentiality, integrity and availability. Confidentiality keeps information private. Integrity keeps it accurate. Availability keeps it accessible when needed. Every serious security control exists to support at least one of the three.

Why is integrity the one businesses miss?

Confidentiality and availability are obvious. You notice a leak and you notice an outage. Integrity failures are silent. An invoice with the wrong bank details or a quietly altered record can sit unnoticed for months, which is exactly why attackers favour them.

What does DSPT require from a care provider’s IT?

The Data Security and Protection Toolkit asks you to assert that personal information is handled safely. In practice that means access controls and a second check at login, protected devices, up to date software, tested backups, staff training, and a record of who can see what.

Does my business need Cyber Essentials?

It is mandatory for some government contracts and increasingly expected by insurers, commissioners and larger clients. Beyond that, it is the clearest independent proof that your basic protections are in place, and it takes days rather than months.

What happens if my business has a data breach?

Depending on the data involved you may have to report it to the Information Commissioner’s Office within 72 hours and notify the people affected. Regulated businesses will also answer for it at their next inspection or audit. The reputational cost with clients is usually the part that hurts longest.

How much does managed IT and security cost?

It depends on your headcount and how much security and compliance support you need. What matters more is what is included. A cheap contract that leaves gaps on confidentiality or integrity costs far more the day something goes wrong.

๐Ÿš€ Where to start

If you are not sure whether your setup holds up on all three, the honest answer is usually that it is fine on availability and has gaps on the other two. That is what we find most of the time.

We will look at your systems, tell you plainly where the gaps are, and show you what it takes to close them and prove it to whoever asks.

Guard IQ provides managed IT, security and compliance support to businesses across North West London, Greater London and the Home Counties.

Guard IQ. IT and Security Managed For You. ๐Ÿ”’

Book a security and compliance review