What you'll learn in this blog
Why the CIA triad does not secure the truth.
When information is a weapon, everyone is at war
Digital Mis, Dis, or Malinformation (MDM) is comparable to malware in terms of threat, though the exploitations are different and increasing, accelerated by the rapid proliferation of AI-generated content. The risk this presents to human, machine learning and decision making, from individual judgment to the AI systems that increasingly inform it, is severe, particularly when conducted or sponsored at the State level.
The much-publicised ‘football match that never happened’ between West Ham and Maccabi Tel Aviv is a good example of misinformation, in this case an AI hallucination. Its acceptance and inclusion as fact in a Metropolitan Police intelligence report highlights the potential for significant real-world repercussions and the institutional vulnerability that MDM is designed to exploit.
Information Operations (InfoOps) is a well-established mechanism for malign actors to exert influence over others. The widespread dissemination of deliberately false or misleading information via predominantly digital means has been increasing since at least 2016, with increasing levels of sophistication. Conventional cyber security was designed to protect information, not interrogate it, a distinction that becomes critical when the information itself is the threat. The CIA triad, the foundational model of information security, concerned with ensuring the confidentiality, integrity and availability of data, was never designed with this problem in mind. By ensuring the confidentiality, integrity and availability of information, whether true or false, existing control measures may instead aggravate the problem.
Figure 1 – The CIA triad does not differentiate between true or false information.
MDM depends on the skilful manipulation of interpretation, both human and machine, to influence behaviours. Like malicious software code, the more subtle the manipulation, the more likely it is to go unchallenged and succeed. The effects of MDM tend to aggregate over time; the longer the situation goes undetected, the greater the degree of influence. AI-enabled MDM is recognised as a present and growing threat to democratic mechanisms.[1] This is evident in the way that some malign social platforms become echo chambers for extreme views. Similarly, if MDM is allowed to taint the Large Language Models (LLM) used to train Artificial Intelligence tools, then this can lead to a lack of objectivity and bias in decision-making with far-reaching implications.[2]
While human fact-checking remains the primary defence, for now, it is fallible, expensive and has limited capacity. The volume, velocity and increasing sophistication of disinformation is driving the requirement for automated detection. In addition to the CIA triad, a fourth control element is required – the need to ensure the veracity, or truth, of the data.
Figure 2: The CIAV framework extends the CIA triad to address the veracity of information in the age of MDM
Addressing MDM requires a fundamental rethink of information security doctrine. Just as the CIA triad became the bedrock of conventional cyber defence, veracity must be elevated to an equivalent standing in a CIAV framework (Confidentiality, Integrity, Availability, Veracity), extending the established model to ensure that information is not merely secure, but true. Yet this cannot rest on technology and doctrine alone. The battle for truth is no longer confined to journalists, governments or security professionals; it is a shared responsibility across society. As the line between authentic and manipulated information continues to blur, resilience will depend on fostering critical thinking, transparency and accountability at every level. The very systems designed to inform and protect us risk becoming unwitting amplifiers of falsehood unless veracity is embedded as a core principle in both human and machine decision-making from the outset, not bolted on as an afterthought. For information security professionals, the challenge is significant; verification generally requires two or more sources to be corroborated. That requirement will likely increase some data flows by 100% before considering any other validation overheads. However, the most significant challenge is not a technical one; it is to counter the shared assumption that the information that we strive to secure can be trusted.
____________________________
[1] RUSI (2024). The Need for a Strategic Approach to Disinformation and AI-Driven Threats | Royal United Services Institute

