A glowing three-dimensional cube floating in a dark void, each face labeled with a dimension of information security — confidentiality, integrity, availability — rendered in clean sans-serif type. The cube is semi-transparent, with interior geometric lines suggesting a grid structure. Dramatic rim lighting in blue and white. Isometric perspective. Futuristic technical illustration style, no decorative elements.
Cybersecurity Basics - Start from here!

The McCumber Cube: A Blueprint for Information Security

How a 1991 model still guides organizations in protecting everything from databases to IoT sensors.

In 1991, John McCumber proposed a three-dimensional model that remains one of the clearest frameworks for evaluating an organization’s security posture. Known as the McCumber Cube, it asks security teams to consider three overlapping dimensions simultaneously: the foundational security principles, the states that data exists in, and the countermeasures available.

Data also exists in three distinct states, each requiring different protections. Data in process is actively being used — for example, a database record being updated. Data at rest lives on hard drives, USB drives, and solid-state storage. Data in transit travels between systems over networks. A robust security strategy must address all three.

Traditional organizational data — transactional records, intellectual property, financial statements — has always required protection. The emergence of the Internet of Things has added an exponential layer of complexity. IoT connects sensors, software, and physical equipment to the internet, generating vast streams of data stored in the cloud. This “Big Data” expansion means the McCumber Cube applies to a far larger, more diffuse attack surface than its creator could have imagined in 1991.

See you on the next one 🙂