About this interactive
The CIA Triad covers three ways a system can fail; the five-pillar model covers five, and the two new bins are where most people's classifying instincts get shakiest. Authenticity asks whether a message really came from who it claims to have come from. Non-Repudiation asks whether anyone can later prove who did what. Neither is about who can see the data, whether the data changed, or whether the system is up — which is exactly why they get mixed up with the other three.
The Confidentiality four are the familiar shape: a weak password guessed, a support contractor peeking at card numbers, a stolen unencrypted laptop, an open storage bucket. Note the first one — a guessed password is not an 'authentication' bin, because there isn't one. What matters for classification is what actually happened to the data once the attacker was in: it became visible to someone who shouldn't have seen it. That is Confidentiality, full stop, no matter how the door got opened. The Integrity four change a value after the fact — a shipping address, a financial figure, a config setting, an invoice amount — while nobody is locked out and nothing was disclosed. The Availability four keep the data exactly as accurate and exactly as private as it was, and simply make it unreachable: a botnet, a fire, ransomware, an expired certificate.
Authenticity is about origin, not content or access. A spoofed CEO email, a forged certificate on a fake banking site, an impersonated help-desk caller, a wire request that looks like it came from the CFO but didn't — in every one of these, the question is not 'did the data change' or 'who saw it,' but 'was this really from who it says it's from.' That is also what separates authenticity from authentication: authentication is proving your own identity to log in; authenticity is proving a message's identity once it arrives.
Non-Repudiation is about proof after the fact, and it fails quietly — not with an alarm, but with a shrug: 'we can't actually show that happened.' A disputed purchase with no signed approval, a safety notice with no delivery receipt, a transfer approval with no audit trail, a leak with no signed access log. Nothing was blocked, changed, or exposed at the moment of the incident — the failure only becomes visible when someone tries to hold a party accountable and finds there's no record that survives the argument.
About TechKnowSurge
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →