1.1 Information Security Fundamentals, Threat Landscapes, and Attack Vectors

Key Takeaways

  • The CIA triad forms the core of incident handling, but tactical containment often requires deliberately sacrificing system availability to preserve data confidentiality and system integrity.

  • An event is any observable system occurrence, an alert is an automated notification triggered by predefined criteria, and an incident is a confirmed violation or imminent threat against security policies or operational integrity.

  • Advanced Persistent Threats (APTs) execute prolonged espionage campaigns leveraging living-off-the-land (LotL) techniques, while Ransomware-as-a-Service (RaaS) syndicates enforce payment through multi-extortion models.

  • Modern attack vectors exploit supply chains, web vulnerabilities, spear phishing, credential abuse, and zero-day vulnerabilities, bypassing traditional perimeter defenses.

  • Defense-in-depth requires layered controls—from physical isolation and network microsegmentation to endpoint telemetry and identity governance—underpinned by Zero Trust architecture.

Last updated: October 2026

Information Security Fundamentals, Threat Landscapes, and Attack Vectors

Incident handling and response operates at the critical junction between preventative security engineering and enterprise business survival. When preventative controls fail, incident responders must make rapid, consequential decisions to contain adversaries, protect organizational assets, and preserve legal evidence. Mastering modern incident response requires a rigorous understanding of information security fundamentals, operational tradeoffs in crisis triage, the threat landscape, and multi-layered defensive architectures designed to halt intrusions.

The CIA Triad and Incident Response Tradeoffs

The foundational model of information security centers on the CIA Triad: Confidentiality, Integrity, and Availability. During an active security incident, the CIA triad transforms into an urgent series of operational tradeoffs:

  • Confidentiality: Preserving authorized restrictions on information access and disclosure. A breach occurs when an adversary accesses or exfiltrates restricted data, such as customer records, trade secrets, or financial files.
  • Integrity: Guarding against improper information modification or destruction. Violations include unauthorized database alterations, manipulating audit logs to conceal adversary presence, or deploying ransomware to encrypt production volumes.
  • Availability: Ensuring timely, reliable access to critical systems and data. Availability is degraded through distributed denial-of-service (DDoS) attacks, wiper malware, or destructive system commands.

Two vital extensions reinforce this triad: Authenticity (ensuring an entity or payload is genuine and originates from its stated source) and Non-Repudiation (the inability of an actor to dispute an action, secured through cryptographic signatures and immutable audit logging).

In live incident handling, responders frequently confront the Availability vs. Containment Dilemma. When an adversary gains administrative privileges on an Active Directory domain controller or stages data on an ERP database, the swiftest containment action is immediate network isolation. Isolating the asset can stop lateral movement and protect confidentiality and integrity, but it may degrade or eliminate availability for dependent operations. Handlers must weigh operational downtime against catastrophic corporate compromise, collaborating closely with business stakeholders.

Responders must also balance Forensic Preservation and Business Continuity. Standard IT operations prioritize restoring services rapidly by rebooting servers, reimaging virtual machines, or wiping disks. Abrupt power loss destroys volatile RAM, including processes, sockets, and ephemeral keys. When safety, active harm, authority, and available time permit, handlers preserve valuable volatile evidence before destructive recovery; when containment must take priority, they document that tradeoff.

Classifying Telemetry: Events, Alerts, and Incidents

Enterprise environments generate immense volumes of telemetry. Distinguishing between routine background signals and confirmed threats requires a disciplined classification methodology:

  • Event: Any observable occurrence within a computer system or network. Examples include user authentication, firewall packet drops, file reads, or DNS queries. Large enterprises generate hundreds of millions of events daily, the vast majority representing benign baseline activity.
  • Alert: A formal notification generated by security monitoring tools (such as SIEM, IDS/IPS, or EDR) signaling that an event has matched a detection signature, exceeded an anomaly threshold, or violated a correlation rule. Alerts carry high false-positive rates requiring human analyst triage.
  • Incident: An adverse event, or series of coordinated events, that actually or imminently jeopardizes system confidentiality, integrity, or availability, or constitutes a violation of security policies or regulatory standards.

This progression forms the Triage Funnel. Millions of raw events are evaluated by automated security controls; a subset triggers alerts for Tier 1 Security Operations Center (SOC) review; verified anomalies escalate to Tier 2 analysts; and confirmed breaches are declared security incidents that mobilize the Computer Security Incident Response Team (CSIRT).

Modern Threat Landscapes: APTs, Cybercrime, and RaaS

The adversary ecosystem has evolved into well-funded threat entities operating under distinct models:

  • Advanced Persistent Threats (APTs): State-sponsored or heavily resourced groups pursuing long-term strategic or political objectives. APTs exhibit extreme operational discipline and extended dwell time. Rather than relying on noisy malware, modern APTs utilize Living-off-the-Land (LotL) techniques, repurposing native operating system binaries (such as PowerShell, WMI, PsExec, and certutil) to execute commands and move laterally without triggering signature-based antivirus tools.
  • Cybercrime Syndicates: Financially motivated groups operating corporate structures, featuring specialized developers, access brokers, and money laundering infrastructure.
  • Ransomware-as-a-Service (RaaS): A franchised cybercrime model where core developers author encryption malware and negotiation portals, leasing them to independent "affiliates" who execute intrusions. Affiliates deploy multi-tiered extortion strategies:
    • Single Extortion: Encrypting victim files and demanding cryptocurrency ransoms for decryption keys.
    • Double Extortion: Exfiltrating sensitive corporate records prior to encryption, threatening public release on leak sites if payment is withheld.
    • Triple Extortion: Adding secondary pressure vectors, such as DDoS attacks against company infrastructure or directly harassing the victim's clients and regulators.

Critical Attack Vectors

Adversaries gain entry through diverse attack vectors, each requiring targeted incident detection techniques:

  • Supply Chain Compromise: Infiltrating trusted third-party software vendors, open-source repositories, or Managed Service Providers (MSPs) to deliver trojanized updates to downstream victims simultaneously.
  • Web Application Exploitation: Targeting internet-facing portals through SQL injection (SQLi), Cross-Site Scripting (XSS), Server-Side Request Forgery (SSRF), and broken API authorization to extract backend data or pivot internally.
  • Email and Social Engineering: Spear phishing, executive whaling, and Business Email Compromise (BEC), leveraging forged credentials and social manipulation to redirect funds or harvest session tokens.
  • Identity and Credential Abuse: Credential stuffing, password spraying, Adversary-in-the-Middle (AiTM) phishing to bypass MFA, and Active Directory token manipulation such as Kerberoasting and DCSync attacks.
  • Zero-Day Vulnerabilities: Exploiting previously undisclosed software flaws before vendor patches exist, requiring behavioral heuristics and anomaly telemetry rather than static signatures.

Defense-in-Depth and Zero Trust Architecture

To withstand modern attack vectors, organizations employ Defense-in-Depth—deploying layered, concentric defensive controls across perimeter security (firewalls, WAFs), network segmentation (microsegmentation, internal firewalls), endpoint telemetry (EDR/XDR), application hardening, and immutable backups. If a single defensive perimeter fails, subsequent layers impede lateral progress.

This philosophy is formalized in Zero Trust Architecture (ZTA), which replaces the perimeter model. Governed by the core tenet "never trust, always verify," Zero Trust assumes the internal network is already compromised. It enforces continuous identity verification, device health validation, least-privilege access, and behavioral telemetry evaluation across every transaction, drastically constraining adversary maneuverability.

Loading diagram...
Event-to-Incident Classification Funnel
Test Your Knowledge

During an active ransomware attack, an incident handler isolates a database server containing critical intellectual property from the network, temporarily halting manufacturing operations. Which component of the CIA triad did the handler deliberately compromise to protect data confidentiality and integrity?

A

Availability

B

Non-repudiation

C

Authenticity

D

Confidentiality

Test Your Knowledge

A security information and event management (SIEM) system flags five consecutive failed login attempts on a domain controller within 30 seconds, followed by a successful login. How is this occurrence properly categorized before human analysis confirms whether malicious activity occurred?

A

A confirmed security incident requiring immediate public disclosure

B

A security alert generated by automated correlation rules

C

A security vulnerability requiring an immediate kernel rebuild

D

A post-incident activity artifact ready for archive

Test Your Knowledge

A cybercrime syndicate compromises a corporate network, exfiltrates sensitive customer records, encrypts the primary virtual machine clusters, and subsequently launches a distributed denial-of-service (DDoS) attack against the victim's customer support portal to force payment. Which extortion model is this organization deploying?

A

Single extortion

B

Living-off-the-land extortion

C

Triple extortion

D

Supply chain extortion

Sections you finish are checked off in the contents.