← Back

Information Security · Sep 2026

Why Information Security Is More Than Passwords

Before studying information security, I mostly associated security with strong passwords, encryption, and preventing hackers from accessing a system.

I now see it as a much broader part of software engineering.

One useful concept is the CIA triad:

Confidentiality means information should only be accessible to authorised users.

Integrity means information should not be changed incorrectly or without permission.

Availability means legitimate users should be able to access the system when they need it.

This means a system can have a security problem even if no data is stolen. For example, an attacker could modify important information or make a service unavailable.

Security also affects everyday development decisions.

Developers need to think about input validation, authentication, authorisation, password storage, API access, logging, and protecting sensitive data.

The biggest change in my thinking is that security should not be something added after an application is finished.

When building software, I now try to think about two questions:

Does it work?

and

What could go wrong?

That second question is becoming an important part of how I think about software development.