Skip to content Skip to Search
Skip navigation

The triad that secures blockchain

Confidentiality, integrity and availability are all challenges as the Middle East adopts new technology

The private funding round values Israeli cybersecurity startup Cato Networks at $3 billion Reuters/Kacper Pempel
The private funding round values Israeli cybersecurity startup Cato Networks at $3 billion

As we face growing concerns around cybersecurity, blockchain technology is seen as a critical component in combatting financial instability and eroded public trust.

It is also projected to boost global GDP by $1.76 trillion by 2030, according to PwC figures.

Blockchain is a decentralised, distributed ledger system with a structure that allows transactions to be securely recorded across multiple computers. This makes it nearly impossible to change any record retroactively.

Adoption of blockchain technology and virtual assets in the Middle East continues to grow, driven by clarity of regulations, technological awareness and innovative use cases in finance, virtual currencies and the Internet of Things.

While blockchain’s potential to revolutionise industries is exciting, it also presents new challenges and questions around three core tenets of information security.

This triad forms the foundation of most security programmes and controls: confidentiality, integrity and availability (CIA).

1. Confidentiality: The paradox of transparency and anonymity

Restricting data access to authorised individuals is a cornerstone of information security.

With its complex cryptographic techniques, blockchain ensures that only individuals with the appropriate private keys can access the transaction data.

All transactions are visible to all users of the blockchain.

However, the same transparency that underpins blockchain also poses a risk to confidentiality.

Although complex pseudonyms protect user identities, the transparency of transactions means that patterns can sometimes be traced back to individuals or businesses.

If not correctly managed this can potentially lead to an unauthorised disclosure of information.

2. Integrity: The double-edged sword of immutability

The accuracy and completeness of data must be maintained and assured over its entire life cycle.

Blockchain inherently ensures a high level of data integrity because it is decentralised and therefore immutable. Once a transaction is recorded, it cannot easily be changed, which deters potential tampering and fraud.

However, this immutability can also be a vulnerability. For instance, if a fraudulent or erroneous transaction is made, recorded data cannot be deleted, which can lead to irreversible damage.

Additionally, blockchain isn’t entirely immune to tampering. Although unlikely, a potential 51 percent attack, where an entity gains control of most of the network’s computational power, could threaten the integrity of smaller or newer blockchains.

While such attacks are challenging to execute, they’re not impossible, underscoring the need for continuous vigilance.

This is particularly the case with certain blockchains that do not have the level of decentralisation that something like Bitcoin has.

3. Availability: A balancing act

Ensuring that information is accessible to authorised users when needed is the third pillar of the CIA triad.

Blockchain’s decentralised nature means that data isn’t stored on a single server but is distributed across multiple nodes. This approach reduces the risk of data loss and increases data availability, as the entire network doesn’t fail even if individual parts do.

However, the promise of high availability can be undermined by practical issues.

Key management is one such concern. In blockchain systems, losing a private key means losing access to the associated data or assets permanently.

Moreover, scalability issues pose another potential pitfall – as a blockchain grows, transaction speed may decrease in many cases, affecting the availability of timely information from transactions processed.

Navigating this landscape

The potential of blockchain to enhance security and build trust in digital transactions is substantial, but it’s not without certain vulnerabilities.

A thorough understanding of these aspects is essential for businesses considering implementing any blockchain.

Balancing the benefits with the risks – always with an eye on maintaining confidentiality, integrity and availability – will be vital to leveraging it effectively and securely. 

Blockchain is an exciting piece of the evolving digital puzzle, and like all technologies, an informed and measured approach is the best path forward. 

Matthew White is a partner at PwC Middle East. He leads the cybersecurity and digital trust practice for the region and is a leader in virtual assets

Latest articles

Flavio Cattaneo of Enel, of which Endesa is a subsidiary, and Mohamed Jameel Al Ramahi at the signing of the deal

Masdar buys stake in Spanish utilities company Endesa

The UAE’s state-owned clean energy company Masdar has agreed to acquire a minority stake in Spanish electric utility business Endesa to partner for 2.5 gigawatts (GW) of renewable energy assets in Spain. Under the agreement, subject to regulatory approval, Masdar will invest nearly $890 million to acquire a 49.99 percent stake in Endesa, with an […]

UAE markets Hong Kong

UAE capital markets partner with Hong Kong exchange

The Hong Kong Stock Exchange (HKSE) has added the Abu Dhabi Securities Exchange (ADX) and the Dubai Financial Market (DFM) to its roster of recognised marketplaces. The move opens the door for UAE-based companies to pursue secondary listings on one of Asia’s premier financial markets. It also follows the inclusion of the Saudi Exchange (Tadawul) […]

Person, Worker, Adult

Aramco and PIF invest in Saudi-Chinese steel venture

Saudi Aramco and the Public Investment Fund have doubled their investment in a steel plate joint venture with a Chinese company to $500 million. The two Saudi companies each own 25 percent shares in the new venture in Ras Al Khair industrial city, Bloomberg reported, quoting a statement published on the Chinese stock exchange. Chinese […]

Car, Transportation, Vehicle

Dubai Taxi to pay $43m dividend despite profit drop

Dubai Taxi Company, a subsidiary of the emirate’s transport regulator, has approved a dividend payout of AED159 million ($43 million) for the first half of 2024 despite a marginal 1 percent increase in net profit. Net earnings reached AED187.4 million in the first six months of the year, compared to AED186.3 million at the same […]