CYBERSECURITY GLOSSARY Malware and viruses CYBERSECURITY GLOSSARY Attacks and techniques CYBERSECURITY GLOSSARY Detection and response CYBERSECURITY GLOSSARY Identity and access CYBERSECURITY GLOSSARY Cloud and infrastructure CYBERSECURITY GLOSSARY Compliance and management CYBERSECURITY GLOSSARY Continuity and metrics CYBERSECURITY GLOSSARY Privacy and OSINT CYBERSECURITY GLOSSARY Cybersecurity
Resource center

Cybersecurity glossary

The cybersecurity, cloud and compliance terms your team hears every day, explained in plain English with examples by the TecnetOne security team.

212 terms

A

Access control

Access control is the set of rules and tools that decide who can get into a system, which information they can see and what they are allowed to do. It combines identifying the person, verifying they are who they claim to be with methods such as MFA, and granting only the permissions their role requires, whether in an office or in an application.

View term →

ACL (access control list)

An ACL (access control list) is the set of rules that defines which users, devices or addresses can reach a resource and what they can do with it. Firewalls, routers, shared folders and cloud services use ACLs to allow or deny each access request.

View term →

Adware

Adware is a program that shows unwanted ads on a computer or in the browser, often installed alongside free software. Beyond the annoyance, many variants track the user's browsing habits and open the door to other malicious programs.

View term →

Agentic SOC

An agentic SOC is a security operations center in which AI agents triage alerts, correlate them and start the investigation of each incident, while human analysts supervise and make the critical decisions. Unlike traditional automation, which follows fixed scripts, the agent reads the context of each case and decides the next step.

View term →

API and API security

An API (application programming interface) is the set of rules that lets two systems talk to each other and exchange data, like when your online store checks a payment with the bank. API security protects those connections with authentication, encryption and usage limits, because a poorly configured API can expose internal information.

View term →

APT (advanced persistent threat)

An APT (advanced persistent threat) is a targeted attack in which a well-resourced group gets into an organization's network and stays hidden for weeks or months to steal information or stage a larger attack. Unlike an opportunistic attack, an APT picks its victim and moves slowly, changing tactics to avoid detection.

View term →

Attack surface

A company's attack surface is everything an intruder can reach, from outside or inside, to try to get in: every server exposed to the internet, every application, every user account, every connected laptop or phone, every cloud service and every vendor with access to your systems. The more pieces there are and the less you know about them, the more gaps go unwatched, which is why the work starts with an inventory and closing what isn't needed.

View term →

Attack vector

An attack vector is the path or method an attacker uses to get into a system, such as a phishing email, a stolen password, an unpatched vulnerability or an infected USB drive. All the possible vectors together make up the attack surface, and reducing them is one of the core jobs of cybersecurity.

View term →

Authentication vs. authorization

Authentication confirms that you are who you say you are (a password, a fingerprint, a verification code); authorization decides what you can do once you're in (view, edit, approve). A secure system needs both: signing in with a verified identity and doing only what your role allows.

View term →

B

Backdoor

A backdoor is a hidden way into a system that skips normal authentication. An attacker can leave one behind after an intrusion, or it can come hidden inside legitimate software, and it's used to get back into the system at will.

View term →

Backup

A backup is a copy of your company's data and systems stored somewhere else so you can restore them if the original is lost, damaged or encrypted by ransomware. A good practice is the 3-2-1 rule: three copies, on two different types of media, with one of them offsite or in the cloud.

View term →

BEC (business email compromise)

A BEC (business email compromise) attack is a scam in which someone impersonates an executive, vendor or customer by email to trick employees into wiring money or sharing sensitive data. It usually carries no malware or links, so it often slips past email filters; it is prevented with verification processes and training.

View term →

BIA (business impact analysis)

A BIA (business impact analysis) is the analysis that identifies which processes are critical to a company and how much damage a disruption of hours or days would cause. It is used to set recovery objectives, such as RTO (how long a process can be down) and RPO (how much data the company can afford to lose), and the priorities of the continuity plan.

View term →

BitLocker (disk encryption)

BitLocker is the built-in Windows feature that encrypts a computer's entire drive, so if the device is stolen or lost no one can read its data without the recovery key. It is included in Windows Pro and Enterprise, and businesses should turn it on and store recovery keys centrally.

View term →

Botnet

A botnet is a network of infected computers that an attacker controls remotely without their owners knowing. Attackers use botnets for denial-of-service attacks, spam campaigns and cryptocurrency mining on the victims' resources.

View term →

Brute force attack

A brute force attack automatically tries thousands of username and password combinations until it finds the right one. Long passwords, lockout after several failed attempts and multi-factor authentication stop it.

View term →

Building a SOC

Building a SOC means setting up an in-house security operations center: the analysts, processes and technology, such as SIEM, EDR and SOAR, needed to monitor, detect and respond to threats around the clock. It requires hiring and retaining enough people to cover every shift, licensing and tuning tools, and writing playbooks, which is why many companies weigh it against contracting SOC as a Service.

View term →

Business continuity plan (BCP)

A business continuity plan, or BCP, defines how a company keeps its critical operations running during and after a serious disruption, such as a cyberattack, an earthquake or a power failure. It covers people, processes, vendors and technology; the IT disaster recovery plan (DRP) is only one part of it.

View term →

BYOD (bring your own device)

BYOD (bring your own device) is a policy that lets employees use their personal phone or laptop to work with company email, files and applications. It saves on hardware, but it requires clear rules and tools such as mobile device management (MDM) to keep company data separate from personal data.

View term →

C

C-TPAT

C-TPAT (Customs Trade Partnership Against Terrorism) is the voluntary US Customs and Border Protection (CBP) program that certifies supply chain companies that meet security requirements, in exchange for benefits such as fewer and faster border inspections. It includes cybersecurity criteria, which is why many importers and their suppliers work on it alongside ISO 27001.

View term →

C2 (command and control)

C2 (command and control) is the infrastructure an attacker uses to communicate with devices it has already infected: from an external server it sends commands, receives stolen data and pushes additional malware. Detecting and blocking those outbound connections cuts off the attacker's control even if the malware is still inside the network.

View term →

CAPTCHA

A CAPTCHA is a test a website uses to tell a person from an automated program, such as typing distorted letters, picking images or simply checking a box. It protects sign-up, login and checkout forms against bots that try stolen passwords or generate spam.

View term →

CASB (cloud access security broker)

A CASB (cloud access security broker) is a tool that sits between your employees and the cloud applications they use, such as Microsoft 365 or Google Drive, to show which services are in use and enforce security rules. It helps uncover shadow IT, prevent data leaks and control who shares what.

View term →

CDN (content delivery network)

A CDN (content delivery network) is a network of servers spread across different cities that stores copies of a website and serves them from the point closest to each visitor. It makes the site load faster and helps it absorb traffic spikes and DDoS attacks.

View term →

CIA triad (confidentiality, integrity and availability)

The CIA triad is the model that sums up the three goals of information security: confidentiality (only the right people get access), integrity (information isn't altered without authorization) and availability (it's ready when needed). Every security control, from a backup to encryption, protects at least one of the three.

View term →

CISO (chief information security officer)

The CISO (chief information security officer) is the executive responsible for a company's information security strategy: they set priorities, budget and policies and are accountable to leadership and the board for cyber risk. Companies that do not need a full-time CISO can hire a virtual CISO, or vCISO.

View term →

Cloud computing

Cloud computing is the use of servers, storage and applications that a provider runs in its own data centers and that your company accesses over the internet, paying for what it uses. Instead of buying and maintaining your own hardware, you rent the capacity you need from services such as Microsoft Azure or AWS.

View term →

Cloud migration

Cloud migration is the process of moving a company's servers, applications and data from on-premises infrastructure to cloud platforms such as Microsoft Azure or AWS. It can be done by moving workloads as they are (lift and shift), by adapting the applications (replatforming) or by redesigning them (refactoring), and it requires planning security, costs and continuity so operations are not interrupted.

View term →

Cloud security

Cloud security is the set of policies, configurations and tools that protect the data, applications and identities your company keeps in services such as Microsoft 365, Azure or AWS. The provider secures its infrastructure, but configuring access, encryption and backups for your data is still your company's responsibility.

View term →

CMDB and IT asset management

A CMDB (configuration management database) is the central inventory of a company's IT assets, such as devices, servers, licenses and applications, along with how they relate to each other. Knowing what you have and who owns each asset is the first step to protecting it and fixing failures faster.

View term →

COBIT

COBIT is ISACA's framework for the governance and management of enterprise information technology. It helps align IT with business goals, define responsibilities and controls, and measure performance, and it is widely used by auditors, boards and compliance teams.

View term →

Computer virus

A computer virus is a type of malware that attaches itself to a legitimate file or program and copies itself to other files when someone opens it. Like a biological virus, it needs a host to spread, and it can delete data, damage the system or open the door to other threats.

View term →

Computer worm

A worm is a malicious program that copies itself and spreads from one computer to another across the network without anyone opening a file. Unlike a virus, it doesn't need a host program, and it can saturate entire networks within hours.

View term →

Conditional access

Conditional access is the Microsoft Entra ID feature that decides whether to allow, block or require an extra step at sign-in based on context: who the user is, what device they are on, where they are signing in from and how risky the sign-in looks. For example, it can require MFA outside the office or block devices the company does not manage.

View term →

Containers (Docker and Kubernetes)

A container is a lightweight package that includes an application with everything it needs to run, so it behaves the same on any server or cloud. Docker is a widely used tool to build them and Kubernetes orchestrates them at scale, and their security depends on trusted images, least privilege and monitoring.

View term →

Credential stuffing

Credential stuffing is an automated attack that tries usernames and passwords leaked from other services across many sites, taking advantage of people reusing their passwords. Unlike brute force, it does not guess passwords: it replays real ones. It is countered with unique passwords, MFA, bot detection and monitoring for mass login attempts or sign-ins from unusual locations.

View term →

Cryptojacking

Cryptojacking is the unauthorized use of a company's computers or servers to mine cryptocurrency for someone else. It usually does not steal data, but it eats up processing power and electricity, slows devices down and is often a sign that someone already has access to the company network or cloud.

View term →

CSP (cloud service provider)

A CSP (cloud service provider) is a company that offers infrastructure, platforms or software over the internet on demand, such as Microsoft Azure, Amazon Web Services or Google Cloud. In the Microsoft ecosystem, CSP also stands for Cloud Solution Provider, the authorized partner that sells and manages those subscriptions for the customer.

View term →

CSPM (cloud security posture management)

CSPM (cloud security posture management) is a tool that continuously reviews the configuration of your Azure, AWS or other cloud accounts and alerts you to mistakes that leave data exposed, such as public storage or excessive permissions. It compares your settings against best practices and standards and suggests how to fix them.

View term →

CTEM (continuous threat exposure management)

CTEM (continuous threat exposure management) is a program, defined by Gartner, that continuously assesses what a company exposes to attackers, prioritizes what is truly exploitable and validates that fixes work. It follows five stages: scoping, discovery, prioritization, validation and mobilization.

View term →

Cyber kill chain

The cyber kill chain is a model created by Lockheed Martin that splits a cyberattack into seven stages: reconnaissance, weaponization, delivery, exploitation, installation, command and control, and actions on objectives. It helps you see where an attack stands and break the chain as early as possible.

View term →

Cyber threat

A cyber threat is any person, event or circumstance that can harm a company's systems or information, such as a cybercriminal, malware, human error or a power failure. Risk arises when a threat can exploit an existing vulnerability.

View term →

Cyberattack

A cyberattack is any deliberate attempt to break into devices, networks or systems without permission to steal information, disrupt operations or demand payment. It can arrive as a phishing email, malware, a stolen password or a flood of traffic, and it often combines several techniques across different stages.

View term →

Cybercrime

Cybercrime is any illegal activity that uses computers, networks or the internet as a tool or a target, such as unauthorized access to systems, data theft, online fraud, ransomware extortion or identity theft. In the US it is prosecuted under laws such as the Computer Fraud and Abuse Act (CFAA) and state laws.

View term →

Cybersecurity

Cybersecurity is the combination of technology, processes and people that protects an organization's devices, networks, applications and data from unauthorized access, theft and disruption. It covers preventing incidents, detecting them early, responding when they happen and restoring operations with the least possible impact.

View term →

Cybersecurity audit

A cybersecurity audit is an independent, documented review of a company's controls, policies and configurations to check whether they protect its information and meet standards such as ISO 27001 or PCI DSS. The result is a report with findings, risk levels and prioritized recommendations.

View term →

D

Dark web and deep web

The deep web is every part of the internet that search engines do not index, such as your email inbox, online banking or your company's internal systems. The dark web is a small part of the deep web that can only be reached with special browsers like Tor, and it is where stolen credentials and databases are bought and sold.

View term →

Dark web monitoring

Dark web monitoring is the continuous search of underground forums, markets and channels for a company's stolen information, such as employee credentials, databases or network access up for sale. Catching it early lets you reset passwords and revoke access before it is used in an attack.

View term →

Data breach

A data breach is an incident in which confidential information, such as customer data, credentials or records, is exposed or ends up in unauthorized hands. It can result from an attack, a configuration error or simple carelessness, and it usually requires the company to investigate, contain the damage and notify the people affected.

View term →

Data breach notification

Data breach notification is the legal obligation to inform affected people, and in some cases regulators, when their personal data is exposed in a security incident. The notice must explain what happened, which data was affected and what steps to take, within the deadlines set by each applicable law, such as US state breach notification laws, HIPAA or GDPR.

View term →

Data center

A data center is a facility designed to house servers, storage and network equipment with backup power, cooling, redundant connectivity and physical security. It can be company-owned, rented space in a shared facility (colocation) or run by a cloud provider such as Azure or AWS.

View term →

Data classification

Data classification is the process of labeling a company's data by sensitivity, for example public, internal, confidential and restricted, so each level gets the right protection. It tells you what to encrypt, who can see it and what must never leave the organization.

View term →

Data exfiltration

Data exfiltration is the unauthorized transfer of information from an organization's network to a destination the attacker controls. It's usually the last stage of an intrusion and is disguised as normal traffic (email, cloud, DNS) to go unnoticed; catching it in time is what keeps an intrusion from becoming a breach.

View term →

Data governance

Data governance is the set of policies, roles and processes that define who is responsible for each piece of data in a company, how it is classified, who can use it and how long it is kept. It makes information reliable, secure and compliant, and it is the foundation for analytics and AI projects.

View term →

Data privacy

Data privacy is the set of legal obligations and technical measures that ensure people's information is collected, used and stored only for legitimate purposes and with their knowledge. Laws such as GDPR in Europe and state privacy laws in the US, like the CCPA in California, require notices, consent and security controls.

View term →

DDoS (distributed denial of service)

A DDoS attack floods a website or service with traffic sent from thousands of devices at once until it goes offline. Its goal is to disrupt operations, and some attackers demand a payment to stop it.

View term →

Deepfake

A deepfake is a video, audio clip or image generated with artificial intelligence that imitates a real person's face or voice so realistically it's hard to tell from the real thing. In business it's used for impersonation fraud, such as a call in the CEO's voice asking for an urgent wire transfer.

View term →

Defense in depth

Defense in depth is a strategy that protects a company with several independent layers of security, so if one fails another can stop the attack. It combines, for example, firewall, MFA, antivirus, network segmentation, backups and monitoring, the same way a castle combines walls, a moat and guards.

View term →

DevSecOps

DevSecOps is the practice of building security into every stage of software development and operations instead of checking it only at the end. It combines development (dev), security (sec) and operations (ops) with automated code testing, dependency checks and cloud controls, so flaws get fixed while they are still cheap to fix.

View term →

Digital footprint

A digital footprint is the trail of information a person or company leaves online: posts, records, metadata and leaked data. Attackers use it to prepare targeted social engineering campaigns.

View term →

Digital forensics

Digital forensics is the technical investigation of an incident to reconstruct what happened: how the attackers got in, what they touched and when. It preserves evidence so it holds up in an audit, an insurance claim or legal proceedings.

View term →

Digital signature

A digital signature is a cryptographic mechanism that guarantees an electronic document was issued by whoever claims to have issued it and wasn't modified after it was signed. It's the basis of legally binding e-signatures, and in many jurisdictions it carries the same legal weight as a handwritten signature when it meets the applicable requirements.

View term →

Disaster recovery plan (DRP)

A disaster recovery plan, or DRP, is the document that defines how a company restores its IT systems, data and operations after a serious event, such as ransomware, a fire or a data center outage. It sets owners, priorities, procedures and recovery targets: RTO (how quickly systems must be back) and RPO (how much data loss is acceptable).

View term →

DLP (data loss prevention)

DLP (data loss prevention) is the set of tools and rules that keeps sensitive information from leaving the company by email, USB drives, the cloud or messaging apps without authorization. It classifies data and spots leak attempts, then blocks or logs them.

View term →

DMZ (demilitarized zone)

A DMZ (demilitarized zone) is a network segment kept separate from the internal network, where companies place the servers that must be reachable from the internet, such as the website or the mail server. If one of those servers is compromised, the firewall stops the attacker from moving straight into internal devices and data.

View term →

DNS (Domain Name System)

DNS (Domain Name System) is the service that translates names people remember, such as tecnetone.com, into the numeric IP addresses computers use to find each other. It works like the internet's contact list: if DNS fails or is tampered with, users do not reach the right website.

View term →

Domain controller (Active Directory)

A domain controller is the server that manages the accounts, passwords and permissions of every user and device on a Windows network through Active Directory. It's one of the most sensitive assets in a company, because whoever controls it controls every account and every computer on the domain.

View term →

Doxxing

Doxxing is the deliberate publication of someone's personal data, such as a home address, phone number or workplace, gathered from public or leaked sources to intimidate or expose them. For companies, it's a direct risk to executives and spokespeople.

View term →

DRaaS (disaster recovery as a service)

DRaaS (disaster recovery as a service) is a service in which a provider replicates your servers to its cloud and can power them on there, often within minutes, if your main site fails because of ransomware, a power outage or a disaster. It avoids having to maintain a second data center of your own.

View term →

Drive-by download

A drive-by download is a malware download that happens just by visiting a compromised web page, without the user clicking or accepting anything. It exploits vulnerabilities in the browser or its plugins, which is why keeping software up to date is the main defense.

View term →

DRPS (digital risk protection services)

DRPS (digital risk protection services) is a service that monitors the internet, social media, app stores and the dark web for threats against a brand, such as fake websites, impersonating profiles or leaked credentials, and manages takedowns. It protects what lives outside the company's perimeter.

View term →

E

EDR (endpoint detection and response)

An EDR (endpoint detection and response) is an agent installed on computers and servers that watches how each program behaves to spot suspicious activity, and it can isolate a device from the network. It goes beyond antivirus because it records what happened and lets analysts investigate it.

View term →

Email security

Email security is the set of controls that protect a company's inboxes against phishing, malware, impersonation and data loss. It combines filters that analyze links and attachments, domain authentication with SPF, DKIM and DMARC, encryption and training, because email is still one of the most common ways attacks get in.

View term →

Encryption

Encryption is the process of turning information into unreadable code that only someone with the right key can read. If a laptop with an encrypted drive is stolen or an encrypted file is intercepted, the thief only sees meaningless characters, which is why encryption is the foundation for protecting data at rest and in transit.

View term →

Endpoint

An endpoint is any device that connects to your company network and is used to work or process data: laptops, desktops, phones, tablets and servers. Every endpoint is a possible way in, which is why each one is protected with antivirus, EDR and management policies.

View term →

Exploit

An exploit is a program or sequence of instructions that takes advantage of a specific software vulnerability to run code or take control of a system. It's the bridge between a known flaw and a real attack.

View term →

External threat monitoring (cyber patrolling)

External threat monitoring, which TecnetOne calls cyber patrolling, is the continuous monitoring of the internet, social media, forums and the dark web to catch threats against a company early, such as network access for sale, data leaks or attack plans. Unlike digital risk protection (DRPS), which focuses on brand abuse and takedowns, it looks for signs that an attack against the company is being prepared.

View term →

F

G

H

I

IaaS, PaaS and SaaS

IaaS, PaaS and SaaS are the three cloud service models. IaaS delivers infrastructure (servers, network and storage) that you manage. PaaS delivers the platform to deploy applications without managing servers. SaaS delivers ready-to-use software by subscription.

View term →

IAM (identity and access management)

IAM (identity and access management) is the set of processes and tools that controls who each user is, what they can access and with which permissions, from the day they join the company to the day they leave. It covers onboarding and offboarding, roles, multi-factor authentication and periodic access reviews.

View term →

Immutable backup

An immutable backup is a copy that, once written, cannot be changed or deleted for a defined period, not even with administrator credentials. It is one of the strongest defenses against ransomware, because attackers often target backups before encrypting the data.

View term →

Incident response

Incident response is the organized process a company uses to detect, contain, eradicate and recover from a cyberattack or security breach, to limit the damage and restore normal operations quickly. It follows defined phases: preparation, identification, containment, eradication, recovery and lessons learned.

View term →

Incident response plan

An incident response plan is the document that defines who does what, how people communicate and which steps to follow when a security incident occurs. It includes roles, contacts, escalation criteria, procedures by incident type and notification requirements, and it should be tested with drills.

View term →

Information security

Information security is the discipline that protects an organization's information, in any format, so it stays confidential, intact and available (the CIA triad). It goes beyond cybersecurity to include paper documents, conversations and processes, and it is organized through policies, controls and standards such as ISO 27001.

View term →

Information security policy

An information security policy is the document approved by leadership that defines how the company protects its information: who is responsible, what is allowed, what is prohibited and how incidents are handled. Specific rules come from it, such as password use, remote work or data classification.

View term →

Infostealer

An infostealer is a type of malware built to steal information stored on a device, especially browser passwords, session cookies, card data and crypto wallets, and send it to the attacker, often within seconds of infection. Those credentials are sold on the dark web and are a common entry point for ransomware attacks.

View term →

Insider threat

An insider threat is a risk that comes from people who already have legitimate access to company systems, such as employees, former employees or vendors. It can be intentional, like copying a customer database before resigning, or accidental, like sending a confidential file to the wrong person.

View term →

IOC (indicators of compromise)

IOCs (indicators of compromise) are the traces an attack leaves behind that let you detect or confirm it, such as a malicious IP address, a suspicious domain, the hash of a malware file or an unusual change in the Windows registry. Security teams share them and load them into their tools to find attacks in progress.

View term →

IoT (internet of things)

IoT (internet of things) is the set of network-connected devices that aren't traditional computers: cameras, sensors, printers, industrial controllers (PLCs), medical equipment or appliances. They often ship with default passwords and get few updates, so they widen a company's attack surface unless they're isolated and monitored.

View term →

IP address

An IP address is the numeric address that identifies every device connected to a network, such as a laptop, a server or a phone, so data reaches the right place. It can be public, the one the internet sees, or private, the one used inside your company network, and it comes in two versions: IPv4 and IPv6.

View term →

ISMS (information security management system)

An ISMS (information security management system) is the set of policies, processes, roles and controls an organization uses to protect its information in an orderly way that improves over time. It's what the ISO/IEC 27001 standard certifies.

View term →

ISO 27001

ISO 27001 is the international standard that defines how to build, run and improve an information security management system (ISMS). It requires a risk assessment, a set of controls chosen from its Annex A and audits that prove it works, so a certified company can show clients and partners it protects information with a verifiable method.

View term →

ISO 27002

ISO 27002 is the international standard that explains how to implement the information security controls listed in Annex A of ISO 27001. Its 2022 version describes 93 controls grouped into four themes: organizational, people, physical and technological, with practical guidance for implementing each one.

View term →

ITIL

ITIL is a widely adopted best-practice framework for managing IT services: it describes how to plan, deliver, support and improve services through processes such as incident, problem, change and service level management. It is not a certifiable standard for companies but a guide each organization adapts.

View term →

ITSM and help desk

ITSM (IT service management) is how an IT team designs, delivers and supports its services, with clear processes to log incidents, handle requests and manage changes. The help desk is the single point of contact where users report problems and get follow-up through tickets.

View term →

J

K

L

LAN and WAN

A LAN (local area network) connects the devices in one location, such as an office or a plant, and a WAN (wide area network) links several LANs separated by distance, for example a company's branches with each other and the cloud. The LAN is usually company-owned and fast; the WAN usually runs over circuits leased from carriers.

View term →

Latency and bandwidth

Latency is the time it takes data to travel from one point of the network to another, and bandwidth is how much data a connection can carry at once. If the network were a highway, bandwidth would be the lanes and latency the travel time; together they explain why a video call drops or a system feels slow.

View term →

Lateral movement

Lateral movement is the stage of an attack in which the intruder, after getting into one device, jumps to other devices and servers on the same network looking for accounts with more privileges or valuable information. Detecting it early makes it possible to contain the incident before it reaches critical systems.

View term →

LDAP and Kerberos

LDAP (Lightweight Directory Access Protocol) is the standard protocol for querying and updating a company's directory of users, computers and groups, such as Active Directory. Kerberos is the protocol that verifies user identity with encrypted tickets so passwords do not travel across the network. Together they underpin sign-in and authentication in Windows (Active Directory) domains.

View term →

Logic bomb

A logic bomb is a piece of malicious code that stays dormant until a condition is met, such as a date, a deleted user account or a number of runs. When it triggers, it deletes, encrypts or alters data on the system.

View term →

Logs (event logs)

Logs, or event logs, are the records in which systems, applications and network devices automatically capture what happens: sign-ins, errors, configuration changes or connections. In cybersecurity they are the evidence used to detect attacks and investigate incidents, which is why they are centralized in a SIEM and retained for a set period.

View term →

M

Malvertising

Malvertising (malicious advertising) is the use of online ads to spread malware or lead the victim to a fraudulent site. The ads run through legitimate ad networks, so they can appear on news portals or well-known sites without the site knowing.

View term →

Malware

Malware is any program designed to damage a device, steal information or take control of a system without the owner's permission. The word is short for malicious software, and it includes viruses, trojans, ransomware, spyware, worms and keyloggers, which differ in how they get in and what they do once inside.

View term →

Man-in-the-middle attack

A man-in-the-middle attack happens when someone secretly places themselves between two parties that are communicating, for example between your laptop and your bank's website, to read or change what they send. It is common on unprotected public Wi-Fi and is prevented with encrypted connections such as HTTPS and VPNs.

View term →

MDR (managed detection and response)

MDR (managed detection and response) is a service in which a provider watches a company's endpoints and other telemetry around the clock and handles its alerts, from investigation to containment. It pairs EDR technology with human analysts and is usually priced per protected device.

View term →

MFA (multi-factor authentication)

Multi-factor authentication (MFA) asks for two or more proofs of identity to sign in: something you know (a password), something you have (a phone or security key) or something you are (a fingerprint). It stops most sign-ins made with stolen passwords.

View term →

Microsoft 365 backup

Microsoft 365 backup is an independent copy of a company's email, OneDrive and SharePoint files and Teams chats, stored outside Microsoft. It is needed because, under Microsoft's shared responsibility model, Microsoft keeps the service running but protecting the data is up to the customer: items deleted by mistake, removed by a former employee or encrypted by ransomware cannot be recovered once retention periods expire.

View term →

Microsoft Defender

Microsoft Defender is Microsoft's family of security products that protects devices, email, identities and cloud: Defender for Endpoint, for Office 365, for Identity and for Cloud, among others. Their alerts come together in the Microsoft Defender portal (Defender XDR), and several are included in plans such as Microsoft 365 Business Premium or E5.

View term →

Microsoft Entra ID (formerly Azure AD)

Microsoft Entra ID, formerly Azure Active Directory, is Microsoft's cloud identity service that controls who can sign in to Microsoft 365, Azure and thousands of applications. It lets you enforce MFA, conditional access and single sign-on, and it is the foundation of identity security in a Microsoft environment.

View term →

Microsoft Intune

Microsoft Intune is Microsoft's cloud service for managing and protecting a company's computers, phones and tablets from a single console. It lets you install apps, apply security settings, require encryption and remotely wipe a lost device, and it is included in plans such as Microsoft 365 Business Premium.

View term →

MITRE ATT&CK

MITRE ATT&CK is a public knowledge base that organizes the tactics and techniques real attackers use, from how they get in to how they steal information. Security teams use it as a common language to design detections, evaluate tools and measure their detection coverage.

View term →

MPLS

MPLS (multiprotocol label switching) is a technology carriers use to build private networks between a company's branches, steering traffic with labels instead of looking up the route at every hop. It offers predictable quality of service, although many companies now combine or replace it with SD-WAN.

View term →

MSSP (managed security service provider)

An MSSP (managed security service provider) is a company that runs other companies' security under contract, managing firewalls, endpoint protection, email security and monitoring with its own team and tools. It gives a business enterprise-grade security without building an in-house security team.

View term →

MTTD, MTTA and MTTR

MTTD, MTTA and MTTR are the three core incident response metrics. MTTD is the mean time to detect a problem; MTTA, the mean time until someone acknowledges it and starts working on it; MTTR, the mean time to resolve it. The lower they are, the less impact each incident has.

View term →

N

NAC (network access control)

NAC (network access control) is the technology that decides which devices can connect to a company's network and with what permissions, based on who the user is, which device they use and whether it meets security policies such as active endpoint protection and an updated operating system. An unknown or noncompliant device ends up on an isolated network or with no access.

View term →

NDR (network detection and response)

NDR (network detection and response) is a technology that continuously analyzes network traffic to detect suspicious behavior, such as lateral movement or communication with malicious servers, and respond to it. It complements EDR because it sees what happens between devices, including those that cannot run an agent.

View term →

Network security

Network security is the set of controls that protect a company's communications infrastructure and the traffic that flows through it, so only authorized users and devices reach each resource. It includes firewalls, segmentation, VPN or ZTNA, network access control, Wi-Fi protection and traffic monitoring.

View term →

Network segmentation

Network segmentation is the practice of dividing a company network into separate zones, for example users, servers, guests and production equipment, with rules that control what can talk to what. Microsegmentation takes the idea down to each server or application, so an incident in one zone does not spread to the rest.

View term →

NGFW (next-generation firewall)

An NGFW (next-generation firewall) is a firewall that, besides filtering by address and port, identifies the applications and users behind the traffic and adds intrusion prevention, web filtering and malware analysis. It allows more precise rules, such as blocking one specific application without cutting off internet access.

View term →

NIST CSF (NIST Cybersecurity Framework)

The NIST CSF (Cybersecurity Framework) is a free framework from the US National Institute of Standards and Technology that helps organize a cybersecurity program. Version 2.0 groups activities into six functions: govern, identify, protect, detect, respond and recover.

View term →

NOC (network operations center)

A NOC (network operations center) is the team that makes sure a company's network, servers and services stay available and perform well. It handles outages, congestion and hardware failures. A SOC, by contrast, watches for anyone misusing those systems.

View term →

O

P

Packet sniffing

Packet sniffing is capturing the traffic that crosses a network to read its contents: passwords, emails, sessions or files sent without encryption. An attacker does it with a packet analyzer connected to the network, for example on public Wi-Fi or an internal segment they've already accessed.

View term →

PAM (privileged access management)

PAM (privileged access management) is the practice and the tools that control accounts with elevated permissions, such as server or Microsoft 365 administrators. It keeps their passwords in a vault, grants access only when needed and records what is done, because those accounts are the most sought after in an attack.

View term →

Passkeys and security keys (FIDO2)

A passkey is a way to sign in without a password: your device stores a cryptographic key that you unlock with your fingerprint, face or a PIN. It is based on the FIDO2 standard, like physical security keys such as YubiKey, and it resists phishing because the key only works on the legitimate site.

View term →

Password manager

A password manager is an application that stores all your passwords encrypted and fills them in for you, so you only need to remember one master password. It makes it easy to use a long, unique password for every service, and in a business it lets teams share access in a controlled way and revoke it when someone leaves.

View term →

Payload

The payload is the part of an attack that carries out the harmful action once the malware or exploit gets in, such as encrypting files or stealing credentials. The entry vector (an email, an attachment, a vulnerability) only delivers it; the payload is what does the damage.

View term →

PCI DSS

PCI DSS (Payment Card Industry Data Security Standard) is the security standard every business that processes, stores or transmits credit or debit card data must follow. It is set by the major card brands and includes requirements for firewalls, encryption, access control, monitoring and regular testing.

View term →

Penetration testing (pentest)

A penetration test, or pentest, is a controlled and authorized attack on a company's systems to find and prove its vulnerabilities before a real attacker does. It ends with a report of prioritized findings and how to fix them.

View term →

Personal data and sensitive data

Personal data is any information that identifies or can identify a person, such as a name, email address, phone number or Social Security number; in the US it is often called personally identifiable information (PII). Sensitive data is the subset that can cause serious harm if misused, such as health, financial or biometric information, and privacy laws require stronger protection for it.

View term →

Pharming

Pharming is an attack that sends people to a fake website even when they type the correct address of the real one, by tampering with DNS or the device's settings. Unlike phishing, it does not need the victim to click a deceptive link, which makes it harder to notice.

View term →

Phishing

Phishing is a message, almost always an email, that impersonates a trusted company or person so the victim hands over credentials or opens a malicious file. It's one of the most common entry points for incidents in companies.

View term →

Phishing simulation

A phishing simulation is a controlled exercise in which a company sends employees fake emails that look like real ones to measure who clicks or hands over data, and gives those who fall for it immediate training. Repeated regularly, it tracks how human risk changes over time.

View term →

PKI and digital certificates

PKI (public key infrastructure) is the framework of policies, certificate authorities and cryptographic keys that issues and validates digital certificates. A digital certificate is a file that works like an official ID on the internet: it confirms that a website, server or person is who they claim to be and enables encrypted communication, as with the HTTPS padlock.

View term →

Port scanning

Port scanning is the technique of checking which ports on a device or server are open and which services answer on them, such as web, email or remote desktop. Attackers use it to look for entry points, and security teams use it to find services that are exposed when they should not be.

View term →

Principle of least privilege

The principle of least privilege states that every person, application or account should have only the permissions it needs to do its job, and nothing more. If an accountant's account can only access financial data, an attacker who steals it cannot reach the servers or HR records.

View term →

Privilege escalation

Privilege escalation is the technique an attacker uses to go from a limited account to higher permissions, such as administrator, by exploiting a vulnerability or a misconfiguration. It is a key step in many serious attacks, because with admin rights the attacker can disable defenses and reach critical data.

View term →

Public, private and hybrid cloud

A public cloud is infrastructure from a provider such as Azure or AWS that many customers share; a private cloud is dedicated to a single organization, in its own data center or a third party's. A hybrid cloud combines both, and multicloud uses services from more than one provider to get the best of each.

View term →

Q

R

Ransomware

Ransomware is malicious software that encrypts a company's files and systems and demands a payment to restore access. Current variants also steal the data before encrypting it, to add pressure by threatening to publish it. Recovery depends on immutable backups and a tested recovery plan.

View term →

RAT (remote access trojan)

A RAT (remote access trojan) is a trojan that gives the attacker full remote control of the infected computer, from the screen and camera to files and programs. It usually arrives disguised as a legitimate document or installer.

View term →

RBAC (role-based access control)

RBAC (role-based access control) is the model that assigns permissions to roles (accountant, salesperson, administrator) and has each user inherit the permissions of their role. Onboarding a new hire or moving someone to a new position means changing their role, without handing out permissions one by one.

View term →

RCE (remote code execution)

RCE (remote code execution) is a type of vulnerability that lets an attacker run their own commands on a server or device remotely, often without physical access or valid credentials. It is among the most serious flaws because it can give the attacker full control of the system, which is why patches that fix it should be applied right away.

View term →

RDP (Remote Desktop Protocol)

RDP (Remote Desktop Protocol) is the Microsoft protocol that lets you control a Windows computer or server from a distance, seeing its desktop as if you were sitting in front of it. It is very useful for support and remote work, and it should be protected with a VPN, MFA and strong passwords instead of being left open to the internet.

View term →

Red team, blue team and purple team

The red team simulates real attacks against an organization to find its weak points; the blue team defends, detects and responds. The purple team brings both together so every simulated attack immediately turns into a concrete improvement to the defenses.

View term →

Regulatory compliance

Regulatory compliance is a company's ability to show that it operates according to the laws, standards and contracts that apply to it, such as HIPAA, PCI DSS or SOC 2. In cybersecurity it means having policies, controls and evidence ready for audits, clients and regulators.

View term →

Risk assessment

A risk assessment is the process of identifying which company assets could be affected, by which threats and weaknesses, and how likely and severe each scenario would be. The result is a prioritized list that shows where to invest first in security controls, and it is a core requirement of frameworks such as ISO 27001 and NIST CSF.

View term →

Risk matrix

A risk matrix is a table that combines the likelihood of an event with the impact it would have, placing each risk at a level such as low, medium, high or critical. It lets you compare different risks with the same criteria and decide which ones to address first.

View term →

Risk model

A risk model is the method an organization uses to identify its assets, the threats that affect them, how likely they are and the impact they would have, so it can decide what to protect first and how much to invest. It's the starting point of standards such as ISO 27001 and of the risk assessment an ISMS requires.

View term →

Rootkit

A rootkit is a set of tools that hides in the deepest layers of the operating system to conceal other malware and keep the attacker's access. It's hard to detect with conventional antivirus.

View term →

RTO and RPO

RTO and RPO are the two numbers that define a recovery plan. RTO (recovery time objective) is the maximum time a system can be down before it hurts the business. RPO (recovery point objective) is the maximum amount of data you accept losing, measured as time since the last backup.

View term →

S

SAML, OAuth and OpenID Connect

SAML, OAuth and OpenID Connect are standards that let people sign in or grant permissions between applications without sharing passwords. SAML and OpenID Connect are used for single sign-on (SSO), while OAuth authorizes one application to access your data in another, like when you connect a calendar to your email.

View term →

SASE (secure access service edge)

SASE (secure access service edge) is a model that combines network connectivity (SD-WAN) and security functions such as firewall, web filtering, CASB and zero trust access into a single cloud service. Users connect securely from anywhere without routing all traffic through headquarters.

View term →

Scareware

Scareware is a scam that shows fake alerts, for example that your computer is infected, to convince you to download a program or pay for a supposed fix. The screen imitates antivirus or Windows warnings, and the program it offers is usually malware or a worthless charge.

View term →

Secure data erasure

Secure data erasure is the removal of information from drives, phones or servers so it cannot be recovered, even with forensic tools, for example by overwriting the media, using cryptographic erase or physically destroying it, following standards such as NIST SP 800-88. It is essential before selling, recycling or returning equipment, because deleting files or formatting is not enough.

View term →

Security awareness training

Security awareness training is an ongoing program that teaches employees to recognize and avoid digital risks, such as phishing emails, weak passwords or careless handling of information. It combines short courses, simulations and metrics to turn staff into a line of defense instead of the weakest link.

View term →

Security incident

A security incident is any event that compromises or threatens the confidentiality, integrity or availability of a company's information or systems, such as unauthorized access, ransomware or the loss of a device with data on it. Not every alert is an incident: it becomes one when real or likely harm is confirmed.

View term →

Security patch

A security patch is an update a vendor releases to fix a vulnerability in its software. Applying it on time closes the gap before an exploit appears, and patch management is the process of doing that in an orderly way across every device.

View term →

Serverless computing

Serverless computing is a cloud model in which the provider fully manages the servers and your team only deploys code, which runs when an event happens and is billed by use. The servers still exist, but you do not have to install, scale or maintain them, as with Azure Functions or AWS Lambda.

View term →

Shadow IT

Shadow IT is the applications, cloud services or devices employees use for work without IT knowing or approving them, such as a personal storage account or a free AI tool. It usually starts with good intentions, but it leaves company data outside of IT's control.

View term →

Shared responsibility model

The shared responsibility model defines what the cloud provider protects and what the customer must protect. The provider secures the physical infrastructure, the network and the platform; the customer is responsible for its data, access, service configuration and backups. Having your data in Azure or AWS doesn't mean they back it up or manage your permissions.

View term →

SIEM (security information and event management)

A SIEM (security information and event management) is the platform that collects the logs from every system in a company and correlates them, raising an alert when a sequence matches the way an attack behaves. It's the central console of a SOC.

View term →

SIM swapping

SIM swapping is a fraud in which a criminal convinces or tricks a mobile carrier into moving your number to a SIM card they control. They then receive your calls and SMS codes and can break into your bank or work accounts, which is why authenticator apps or passkeys are safer than SMS.

View term →

SLA (service level agreement)

An SLA (service level agreement) is the part of a contract in which a provider commits to measurable targets: availability, response time, resolution time and penalties if it misses them. For example, an SLA can state that a critical incident is handled in under 15 minutes, 24 hours a day.

View term →

SNMP and NetFlow

SNMP (Simple Network Management Protocol) lets you monitor the status of routers, switches, servers and printers, such as CPU usage or whether an interface went down. NetFlow records who talks to whom on the network and how much traffic they send. Together they are the foundation of a NOC's network monitoring.

View term →

SOAR (security orchestration, automation and response)

SOAR (security orchestration, automation and response) is a platform that connects a company's security tools and runs automatic responses to alerts. For example, if the SIEM detects a suspicious sign-in, SOAR can lock the account, isolate the device and open a ticket in seconds, without waiting for an analyst.

View term →

SOC (security operations center)

A SOC (security operations center) is the team of analysts, processes and tools that watches a company's systems around the clock and handles every alert, from investigation to containment. As a service (SOCaaS), an outside provider runs it under a subscription.

View term →

SOC 1 and SOC 2

SOC 2 is an attestation report, defined by the AICPA and issued by an independent CPA firm, that evaluates a service provider's controls against the Trust Services Criteria: security, availability, processing integrity, confidentiality and privacy. Type I reviews their design on a given date and Type II how effectively they operate over a period, typically 6 to 12 months; SOC 1, by contrast, focuses on financial reporting controls.

View term →

SOC as a Service (SOCaaS)

SOC as a Service (SOCaaS) is a model in which a company hires a specialized provider to monitor, detect and respond to threats around the clock instead of building its own security operations center. It gets the technology, analysts and processes for a monthly fee, without investing in infrastructure or hiring a full team.

View term →

Social engineering

Social engineering is the set of techniques used to trick a person into handing over information, approving a payment or granting access. It exploits trust, urgency or authority instead of a technical flaw, and phishing is its most common form.

View term →

SOX (Sarbanes-Oxley Act)

The SOX (Sarbanes-Oxley) Act is a US law that requires publicly traded companies to prove their financial reporting is reliable, with internal controls that can be audited. In IT it translates into access controls, change management and logs for the systems that handle financial data.

View term →

SPF, DKIM and DMARC

SPF, DKIM and DMARC are three records configured on an email domain to make it much harder for anyone to send messages that impersonate your company. SPF lists the servers allowed to send on your behalf, DKIM signs each message to prove it wasn't altered and DMARC defines what to do with email that fails both checks. Together they protect your brand and improve delivery of your legitimate email.

View term →

Spoofing

Spoofing is the technique of faking a digital identity (an email address, a phone number, an IP address or a website) so the victim believes they're dealing with someone trusted. It's the basis of many email and phone scams, because the message appears to come from an executive, a bank or a real vendor.

View term →

Spyware

Spyware is a program that installs itself without permission to collect a user's information, such as browsing habits, credentials, messages or location, and send it to a third party. It often arrives with free software or in an attachment.

View term →

SQL injection

SQL injection is an attack in which someone types database commands into a website form or URL so the application runs them. If the site does not validate what it receives, the attacker can read, change or delete information such as customer lists or passwords without having an authorized account.

View term →

SSH (Secure Shell)

SSH (Secure Shell) is the protocol that lets you manage servers and network devices remotely over an encrypted connection, typing commands as if you were in front of them. It is the standard for administering Linux servers and network equipment, and it is hardened by using key-based authentication instead of passwords and by not exposing port 22 to the internet.

View term →

SSL/TLS

TLS (Transport Layer Security) is the protocol that encrypts communication between a browser or app and a server, so no one along the way can read or alter it; SSL is its older, obsolete version, though the name is still used. It's what turns on the padlock and HTTPS on a website.

View term →

SSO (single sign-on)

SSO (single sign-on) lets people access many applications with one account and one sign-in instead of a password per system. It makes work easier, cuts down on weak or reused passwords and lets you remove all of a person's access from one place when they leave the company.

View term →

Steganography

Steganography is the technique of hiding a message or file inside another one that looks harmless, such as an image, audio file or document, so no one notices it is there. Unlike encryption, which makes content unreadable, steganography hides that anything exists; attackers use it to slip in malware or sneak data out undetected.

View term →

Strong password

A strong password is long, unique to each service and hard to guess, ideally a passphrase of several words with at least 14 characters. Length matters more than mixing symbols, and it works best alongside a password manager and multi-factor authentication, because even a strong password is useless once it is reused or leaked.

View term →

Supply chain attack

A supply chain attack compromises a company through a trusted vendor, for example by infecting a software update, a code library or a managed service provider's remote access. It works because the victim trusts what comes from that vendor, which is why third-party risk must be assessed.

View term →

System hardening

System hardening is the process of reducing a system's attack surface. It means removing the services and ports that aren't needed and applying secure configurations with the minimum permissions. It's the foundation every other security control builds on.

View term →

T

Tailgating and piggybacking

Tailgating is a social engineering technique in which an unauthorized person enters a restricted area by closely following someone who has access, for example slipping in behind an employee who badges through a door. When the employee knowingly lets them in out of courtesy, it is called piggybacking.

View term →

Threat hunting

Threat hunting is the proactive search for attackers who are already inside the network and weren't caught by automated alerts. An analyst starts from a hypothesis and reviews logs and behavior to confirm or rule out an intrusion.

View term →

Threat intelligence

Threat intelligence is collected and analyzed information about who is attacking, which techniques they use and what kinds of companies they target, so you can get ahead of attacks instead of just reacting. It includes indicators such as malicious IP addresses or domains and context on active campaigns that affect your industry or region.

View term →

Trojan

A trojan is a malicious program that poses as something useful or harmless, such as an installer, an invoice or an update, so the user runs it. Once inside, it opens the way for other malware or for remote control of the computer.

View term →

TTP (tactics, techniques and procedures)

TTPs (tactics, techniques and procedures) describe how an attacker operates: the tactic is the goal at each stage, the technique is the method used to reach it and the procedure is the specific way it is carried out. Detecting TTPs works better than chasing single indicators, because an attacker can easily change IP addresses but not the way they operate.

View term →

Typosquatting and cybersquatting

Typosquatting is registering domains that look like a brand's with common typos, such as tecnet0ne.com, to trick people who mistype and send them to a fake phishing or malware site. Cybersquatting is registering a domain with a brand's exact name in bad faith, to resell it or profit from its reputation.

View term →

U

V

W

X

Y

Z

We couldn’t find that term. We’ll add it in the next update.

Ready to put this into practice in your operation?

Tell us what you need and a TecnetOne engineer will get back to you.

Talk to an engineer