Different attacks, the same outcome

A few years ago, in a post-incident review, the conversation started the way it always does. What was the attack? Ransomware. Phishing. DDoS. Different vectors, different techniques. But the deeper the review went, the clearer it became that the attack method was not actually the important fact. What failed was more fundamental than the method used to fail it.

Exhibit 1

What actually breaks, in one view

Ransomware, phishing and DDoS are three different methods. Underneath, each one is trying to break one of the same three properties, and only one of those three ever changes name.

Same three failures, every time
AttackWhat it looks likeWhat actually fails
RansomwareEncrypts systemsAvailability
PhishingSteals credentialsConfidentiality and integrity
DDoSFloods infrastructureAvailability
Framed by attack type
  • Strategy is built around threat categories, tools, signatures
  • "How do we stop ransomware?"
  • A new attack name means a new playbook
Framed by CIA
  • One question asked of every incident: which property is failing
  • "How do we ensure availability cannot be easily broken?"
  • The triad does not change, so the playbook does not restart
Attacks are just methods. They keep changing. They are always trying to break the same three things.Rhinexa Perspective · Krishna Mohan Parsha
Exhibit 1. Three familiar attacks mapped to the property that actually fails, and the two ways a SOC can frame the same incident. Download it as an image for your own board pack.

The mistake most detection programmes make

Every cyber incident ultimately maps to one or more parts of the CIA triad. Confidentiality fails and data is exposed. Integrity fails and data is altered. Availability fails and systems become unusable. A ransomware attack encrypts systems, but the failure that matters is availability. A phishing attack steals credentials, but the failure is confidentiality and integrity together. A DDoS attack floods infrastructure, but the failure, again, is availability. Different attacks, the same three possible outcomes, every time.

Most detection and response programmes are built around the wrong axis. They organise around threat categories, tools, signatures and indicators, which means every new attack name, a new ransomware family, a new phishing kit, arrives looking like it needs a new strategy. The CIA triad does not change no matter how the tooling does, and a SOC that asks which part of the triad is actually failing is asking the one question that stays constant while the threat landscape does not.

The question that changes the response

The shift is in the question a SOC asks itself, and it changes what gets built. Not "how do we stop ransomware", a question about one attack type that goes stale the moment the next variant appears. Instead: "how do we ensure availability cannot be easily broken", a question about a property that can be designed around permanently. Not "how do we detect phishing", but "how do we limit the damage to confidentiality and integrity even if credentials are stolen anyway", which assumes the perimeter will eventually fail and builds the response around what happens next.

Attacks are just methods. They keep changing. But every attack is trying to break the same three things, and when they succeed, trust breaks with them.

That shift moves a programme from reactive defence, chasing the attack of the month, to resilient design, built around the three properties that were always actually at stake.

Where to begin

Take the last three incidents your SOC closed, whatever they were called in the ticket. For each one, write down which part of the CIA triad actually failed, not the attack type, the property. If two or three land on the same word, that is not a coincidence. It is where the programme's real gap is, and it will still be the gap after the next attack has a different name.

Krishna Mohan Parsha

CTO and Co-Founder, Rhinexa

Krishna works at the intersection of cyber security, infrastructure, AI and enterprise risk, with a focus on engineering trustworthy and resilient technology foundations.

Follow on LinkedIn

This perspective expands a post first published by the author on LinkedIn.