Knowledge Hub

Cybersecurity Glossary

One hundred and seventeen security terms explained in plain language, with what to do about each one.

Security has more jargon than almost any other part of technology, and most of it is written for people who already understand it. This glossary is written the other way round. Every entry says what the term means, why it matters if you run a small business or a nonprofit, and three things you can actually do about it.

  • Account TakeoverThreats and attacksWhen an attacker gains full control of a legitimate account and uses it as the real owner would
  • Advanced Persistent ThreatThreats and attacksA well resourced attacker who gets in quietly and stays for a long time
  • Air GapDefences and controlsKeeping a system or a backup physically disconnected from any network
  • Attack SurfaceGovernance and complianceEverything about your organisation that an attacker could try to reach
  • Attack VectorCore conceptsThe route an attacker uses to get in
  • Audit LogGovernance and complianceThe record of who did what and when, kept so that questions can be answered later
  • BackupDefences and controlsA separate copy of your data that you can restore when the original is lost, corrupted or encrypted
  • BotnetThreats and attacksA network of compromised machines controlled remotely and rented out for attacks
  • Breach NotificationGovernance and complianceThe legal duty to tell regulators and affected people when personal data has been exposed
  • Break Glass AccountIdentity and accessAn emergency administrator login kept aside for the day normal access fails
  • Brute Force AttackThreats and attacksGuessing a password by trying enormous numbers of combinations until one works
  • Business ContinuityDefences and controlsHow the organisation keeps operating while the technology is unavailable
  • Business Email CompromiseThreats and attacksFraud in which an attacker uses, or convincingly imitates, a real business mailbox to redirect a payment
  • CIA TriadGovernance and complianceThe three properties security exists to protect: confidentiality, integrity and availability
  • CISAGovernance and complianceThe United States Cybersecurity and Infrastructure Security Agency, and its free guidance and services
  • Cloud SecurityCore conceptsSecuring the part of the cloud that is your responsibility rather than the provider's
  • Conditional AccessIdentity and accessRules that decide whether to allow a sign in based on the circumstances, not just the password
  • Credential StuffingThreats and attacksAutomated testing of passwords stolen from one service against accounts on many others
  • Cross Site ScriptingThreats and attacksA flaw that lets an attacker run their own script inside your website, in your visitor's browser
  • CryptojackingThreats and attacksUsing your computers or cloud account to mine cryptocurrency without your knowledge
  • Cyber InsuranceGovernance and complianceInsurance covering the costs of an incident, subject to conditions you must already meet
  • Dark Web MonitoringCore conceptsWatching criminal marketplaces and breach dumps for your own credentials and data
  • Data BreachCore conceptsAn event in which personal or confidential information is exposed, taken or altered without authorisation
  • Data ClassificationGovernance and complianceSorting information into a few levels so that handling rules can follow the level
  • Data ExfiltrationCore conceptsThe act of moving stolen data out of your environment
  • Data Loss PreventionDefences and controlsRules that spot sensitive information leaving the organisation and either warn, block or record it
  • Data RetentionGovernance and complianceDeciding how long you keep information, and deleting it when that period ends
  • DeepfakeThreats and attacksA synthetic video, image or audio clip that convincingly imitates a real person
  • Defence in DepthDefences and controlsLayering controls so that no single failure results in a breach
  • Disaster RecoveryDefences and controlsThe plan and the capability to restore technical services after a serious failure
  • Distributed Denial of ServiceThreats and attacksAn attack that floods your website or network with traffic until legitimate visitors cannot get through
  • DNS FilteringDefences and controlsBlocking connections to known malicious domains at the moment the name is looked up
  • Drive by DownloadThreats and attacksMalware installed simply by visiting a compromised web page
  • Email AuthenticationDefences and controlsThe records that let receiving mail servers verify that a message really came from your domain
  • EncryptionDefences and controlsConverting data so that only someone with the right key can read it
  • Encryption at RestDefences and controlsProtecting stored data so that a stolen disk or database file is unreadable
  • Encryption in TransitDefences and controlsProtecting data while it moves across a network so it cannot be read or altered on the way
  • Endpoint Detection and ResponseDefences and controlsSecurity software that watches behaviour on each device, and lets you investigate and contain remotely
  • ExploitCore conceptsThe technique or code that turns a vulnerability into an actual compromise
  • FirewallDefences and controlsA control that decides which network traffic is allowed in and out
  • GDPRGovernance and complianceThe European data protection regulation governing how personal data is handled
  • HardeningDefences and controlsReducing a system to what it actually needs, and turning off the rest
  • HIPAAGovernance and complianceThe United States rules protecting health information, and the contracts that extend them to suppliers
  • HoneypotDefences and controlsA deliberately attractive fake asset placed to detect intruders
  • Identity and Access ManagementIdentity and accessThe practice of controlling who exists in your systems and what each person may reach
  • Immutable BackupDefences and controlsA backup copy that cannot be changed or deleted for a fixed period, even by an administrator
  • Incident Response PlanGovernance and complianceThe written plan for what happens in the first hours after something goes wrong
  • Indicator of CompromiseCore conceptsEvidence suggesting that a system has already been breached
  • Insider ThreatThreats and attacksDamage caused by someone who already has legitimate access, whether deliberately or by accident
  • ISO 27001Governance and complianceThe international standard for running an information security management system, with certification available
  • Just in Time AccessIdentity and accessElevated rights that are granted for a defined window and expire on their own
  • KeyloggerThreats and attacksA tool that records every keystroke, capturing passwords as they are typed
  • Least PrivilegeIdentity and accessGiving each person and each system only the access needed for the job, and nothing more
  • Living off the LandThreats and attacksAttacks carried out with the legitimate tools already present on your systems
  • MalvertisingThreats and attacksMalicious code delivered through legitimate online advertising networks
  • MalwareThreats and attacksAny software written to do harm, from ransomware and spyware to banking trojans and cryptominers
  • Man in the MiddleThreats and attacksAn attacker positioned between you and the service you are using, reading or altering what passes
  • Managed Detection and ResponseDefences and controlsAn outside team that watches your security alerts around the clock and acts on the ones that matter
  • Mean Time to DetectCore conceptsThe average time between something bad starting and somebody noticing it
  • Mean Time to RespondCore conceptsThe average time between noticing a problem and having it contained
  • MFA FatigueIdentity and accessFlooding someone with approval prompts until they tap accept just to make it stop
  • Mobile Device ManagementDefences and controlsCentral control of the phones, tablets and laptops that reach your company data
  • Multi Factor AuthenticationIdentity and accessRequiring a second proof of identity in addition to a password
  • Network SegmentationDefences and controlsDividing the network so a problem in one part cannot reach the rest
  • NIST Cybersecurity FrameworkGovernance and complianceA widely used structure that organises security work into six functions
  • PasskeyIdentity and accessA sign in method that replaces the password with a key stored on your device
  • Password ManagerIdentity and accessAn encrypted vault that generates and stores a different password for every account
  • Patch ManagementDefences and controlsThe routine of applying security updates promptly and confirming that they applied
  • PayloadCore conceptsThe part of an attack that actually does the damage
  • PCI DSSGovernance and complianceThe card industry's security requirements for anyone handling payment card data
  • Penetration TestingDefences and controlsA person, not a tool, attempting to break into your systems with permission
  • PhishingThreats and attacksA fraudulent message designed to make you hand over a password, approve a payment or open a malicious file
  • Privileged Access ManagementIdentity and accessControlling, recording and time limiting the accounts that can change everything
  • Prompt InjectionThreats and attacksHidden instructions placed inside content so that an AI assistant reading it follows the attacker instead of you
  • QuishingThreats and attacksPhishing that hides the malicious link inside a QR code, so no address is visible before you scan
  • RansomwareThreats and attacksMalicious software that encrypts your files and demands payment, usually while also threatening to publish the data
  • Recovery Time ObjectiveGovernance and complianceThe maximum time a system may stay down before the consequences become unacceptable
  • Risk AssessmentGovernance and complianceWorking out what could go wrong, how likely it is and what it would cost you
  • Risk RegisterGovernance and complianceThe living list of your known risks, their owners and what is being done about each
  • RootkitThreats and attacksMalware that hides itself deep in the operating system so that it survives and stays invisible
  • SandboxCore conceptsAn isolated environment where suspicious files can run without touching anything real
  • Secrets ManagementDefences and controlsStoring passwords, keys and tokens used by software in one protected place rather than in files and code
  • Security AwarenessCore conceptsThe habits and knowledge that let your team recognise and report an attack
  • Security Operations CentreDefences and controlsA team that watches your alerts and responds, whether in house or bought as a service
  • Security PolicyGovernance and complianceThe short written rules that say how your organisation handles technology and data
  • Separation of DutiesCore conceptsSplitting a sensitive process so that no single person can complete it alone
  • Service AccountIdentity and accessA login used by software rather than a person, often with wide rights and a password nobody has changed
  • Session HijackingThreats and attacksStealing the token that keeps you logged in, so the attacker skips the password and the second factor entirely
  • Shadow ITCore conceptsTools and services staff adopt for work without anyone approving or securing them
  • SIEMDefences and controlsA system that collects logs from everywhere and raises alerts on suspicious patterns
  • SIM SwappingThreats and attacksFraud in which an attacker moves your phone number onto a device they control, and receives your codes
  • Single Sign OnIdentity and accessSigning in once with one account to reach many applications
  • SmishingThreats and attacksPhishing delivered by text message
  • SOC 2Governance and complianceAn audit report on how a service provider handles security and related commitments
  • Social EngineeringThreats and attacksManipulating a person into granting access or breaking a rule, rather than defeating a technical control
  • Software Bill of MaterialsGovernance and complianceA list of the components inside a piece of software, so you can tell whether a new flaw affects you
  • Spear PhishingThreats and attacksA phishing attack aimed at one named person, written with details that make it convincing
  • SpywareThreats and attacksSoftware that watches what you do and reports it back, usually without any visible sign
  • SQL InjectionThreats and attacksAn attack that smuggles database commands into an ordinary web form or web address
  • Supply Chain AttackThreats and attacksCompromising a supplier, a plugin or an update in order to reach that supplier's customers
  • Tabletop ExerciseGovernance and complianceA discussion based rehearsal of an incident, without touching any systems
  • Third Party RiskCore conceptsThe risk you inherit from suppliers, contractors and platforms with access to your systems or data
  • Threat ActorCore conceptsThe person or group behind an attack, and their motive
  • Threat ModellingCore conceptsThinking through how something could be attacked, before it is built or deployed
  • TLS CertificateDefences and controlsThe credential that proves a website is who it claims to be and enables the encrypted connection
  • TrojanThreats and attacksMalicious software disguised as something legitimate that the user installs willingly
  • TyposquattingThreats and attacksRegistering domain names that look almost like yours in order to catch mistakes and mislead readers
  • Vendor Due DiligenceGovernance and complianceChecking what a supplier does with your data and systems before you sign, and again later
  • Virtual Private NetworkDefences and controlsAn encrypted tunnel between a device and a network, used for remote access
  • VishingThreats and attacksPhishing by telephone, increasingly using cloned voices
  • VulnerabilityCore conceptsA weakness that could be used to compromise a system
  • Vulnerability ScanningDefences and controlsAutomated checking of your systems for known weaknesses
  • Watering Hole AttackThreats and attacksAn attack that compromises a website your team already visits, and waits for them to come to it
  • Web Application FirewallDefences and controlsA filter in front of your website that blocks malicious requests before they reach it
  • WormThreats and attacksMalware that spreads by itself from machine to machine without anyone opening anything
  • Zero DayThreats and attacksA vulnerability being exploited before the vendor has released a fix
  • Zero TrustIdentity and accessTreating no request as trustworthy purely because it comes from inside your network

Want a plain answer about your own setup?

We review what you have against the basics that stop most incidents, and give you a ranked list with effort and cost. Useful whether or not you decide to work with us.