Cybersecurity glossary
The cybersecurity, cloud and compliance terms your team hears every day, explained on one page in plain English.
A
Access control
Access control is the set of rules and tools that decide who can get into a system, which information they can see and what they are allowed to do. It combines identifying the person, verifying they are who they claim to be with methods such as MFA, and granting only the permissions their role requires, whether in an office or in an application.
ACL (access control list)
An ACL (access control list) is the set of rules that defines which users, devices or addresses can reach a resource and what they can do with it. Firewalls, routers, shared folders and cloud services use ACLs to allow or deny each access request.
Adware
Adware is a program that shows unwanted ads on a computer or in the browser, often installed alongside free software. Beyond the annoyance, many variants track the user's browsing habits and open the door to other malicious programs.
Agentic SOC
An agentic SOC is a security operations center in which AI agents triage alerts, correlate them and start the investigation of each incident, while human analysts supervise and make the critical decisions. Unlike traditional automation, which follows fixed scripts, the agent reads the context of each case and decides the next step.
API and API security
An API (application programming interface) is the set of rules that lets two systems talk to each other and exchange data, like when your online store checks a payment with the bank. API security protects those connections with authentication, encryption and usage limits, because a poorly configured API can expose internal information.
APT (advanced persistent threat)
An APT (advanced persistent threat) is a targeted attack in which a well-resourced group gets into an organization's network and stays hidden for weeks or months to steal information or set up a larger strike. Unlike an opportunistic attack, an APT picks its victim and moves slowly, changing tactics to avoid detection.
Attack surface
A company's attack surface is everything an intruder can reach, from outside or inside, to try to get in: every server exposed to the internet, every application, every user account, every connected laptop or phone, every cloud service and every vendor with access to your systems. The more pieces there are and the less you know about them, the more gaps go unwatched, which is why the work starts with an inventory and closing what isn't needed.
Attack vector
An attack vector is the path or method an attacker uses to get into a system, such as a phishing email, a stolen password, an unpatched vulnerability or an infected USB drive. All the possible vectors together make up the attack surface, and reducing them is one of the core jobs of cybersecurity.
Authentication vs. authorization
Authentication confirms that you are who you say you are (a password, a fingerprint, a verification code); authorization decides what you can do once you're in (view, edit, approve). A secure system needs both: signing in with a verified identity and doing only what your role allows.
B
Backdoor
A backdoor is a hidden way into a system that skips normal authentication. An attacker can leave one behind after an intrusion, or it can come hidden inside legitimate software, and it's used to get back into the system at will.
Backup
A backup is a copy of your company's data and systems stored somewhere else so you can restore them if the original is lost, damaged or encrypted by ransomware. A good practice is the 3-2-1 rule: three copies, on two different types of media, with one of them offsite or in the cloud.
BitLocker (disk encryption)
BitLocker is the Windows tool that encrypts a computer's entire drive, so if the device is stolen or lost no one can read its data without the recovery key. It is included in Windows Pro and Enterprise, and businesses should turn it on and store recovery keys centrally.
Botnet
A botnet is a network of infected computers that an attacker controls remotely without their owners knowing. Attackers use botnets for denial-of-service attacks, spam campaigns and cryptocurrency mining on the victims' resources.
Brute force attack
A brute force attack automatically tries thousands of username and password combinations until it finds the right one. Long passwords, lockout after several failed attempts and multi-factor authentication stop it.
BYOD (bring your own device)
BYOD (bring your own device) is a policy that lets employees use their personal phone or laptop to work with company email, files and applications. It saves on hardware, but it requires clear rules and tools such as mobile device management (MDM) to keep company data separate from personal data.
C
C-TPAT
C-TPAT (Customs Trade Partnership Against Terrorism) is the voluntary US Customs and Border Protection (CBP) program that certifies supply chain companies that meet security requirements, in exchange for faster border inspections. It includes cybersecurity criteria, which is why many importers and their suppliers work on it alongside ISO 27001.
CASB (cloud access security broker)
A CASB (cloud access security broker) is a tool that sits between your employees and the cloud applications they use, such as Microsoft 365 or Google Drive, to show which services are in use and enforce security rules. It helps uncover shadow IT, prevent data leaks and control who shares what.
CDN (content delivery network)
A CDN (content delivery network) is a network of servers spread across different cities that stores copies of a website and serves them from the point closest to each visitor. It makes the site load faster and protects it from traffic spikes and DDoS attacks.
CIA triad (confidentiality, integrity and availability)
The CIA triad is the model that sums up the three goals of information security: confidentiality (only the right people get access), integrity (information isn't altered without authorization) and availability (it's ready when needed). Every security control, from a backup to encryption, protects at least one of the three.
CISO (chief information security officer)
The CISO (chief information security officer) is the executive responsible for a company's information security strategy: they set priorities, budget and policies and answer to leadership for cyber risk. Companies that do not need a full-time CISO can hire a virtual CISO, or vCISO.
Cloud computing
Cloud computing is the use of servers, storage and applications that a provider runs in its own data centers and that your company accesses over the internet, paying for what it uses. Instead of buying and maintaining your own hardware, you rent the capacity you need from services such as Microsoft Azure or AWS.
Cloud security
Cloud security is the set of policies, configurations and tools that protect the data, applications and identities your company keeps in services such as Microsoft 365, Azure or AWS. The provider secures its infrastructure, but configuring access, encryption and backups for your data is still your company's responsibility.
CMDB and IT asset management
A CMDB (configuration management database) is the central inventory of a company's IT assets, such as devices, servers, licenses and applications, along with how they relate to each other. Knowing what you have and who owns each asset is the first step to protecting it and fixing failures faster.
Computer virus
A computer virus is a type of malware that attaches itself to a legitimate file or program and copies itself to other files when someone opens it. Like a biological virus, it needs a host to spread, and it can delete data, damage the system or open the door to other threats.
Computer worm
A worm is a malicious program that copies itself and spreads from one computer to another across the network without anyone opening a file. Unlike a virus, it doesn't need a host program, and it can saturate entire networks within hours.
Cryptojacking
Cryptojacking is the unauthorized use of a company's computers or servers to mine cryptocurrency for someone else. It does not steal data, but it eats up processing power and electricity, slows devices down and is often a sign that someone already has access to the company network or cloud.
CSP (cloud service provider)
A CSP (cloud service provider) is a company that offers infrastructure, platforms or software over the internet on demand, such as Microsoft Azure, Amazon Web Services or Google Cloud. In the Microsoft ecosystem, CSP also names the authorized partner that sells and manages those subscriptions for the customer.
CSPM (cloud security posture management)
CSPM (cloud security posture management) is a tool that continuously reviews the configuration of your Azure, AWS or other cloud accounts and alerts you to mistakes that leave data exposed, such as public storage or excessive permissions. It compares your settings against best practices and standards and suggests how to fix them.
Cyber kill chain
The cyber kill chain is a model created by Lockheed Martin that splits a cyberattack into seven stages: reconnaissance, weaponization, delivery, exploitation, installation, command and control, and actions on objectives. It helps you see where an attack stands and break the chain as early as possible.
Cyberattack
A cyberattack is any deliberate attempt to break into devices, networks or systems without permission to steal information, disrupt operations or demand payment. It can arrive as a phishing email, malware, a stolen password or a flood of traffic, and it often combines several techniques across different stages.
Cybersecurity
Cybersecurity is the combination of technology, processes and people that protects an organization's devices, networks, applications and data from unauthorized access, theft and disruption. It covers preventing incidents, detecting them early, responding when they happen and restoring operations with the least possible impact.
Cybersecurity audit
A cybersecurity audit is an independent, documented review of a company's controls, policies and configurations to check whether they protect its information and meet standards such as ISO 27001 or PCI DSS. The result is a report with findings, risk levels and prioritized recommendations.
D
Dark web and deep web
The deep web is every part of the internet that search engines do not index, such as your email inbox, online banking or your company's internal systems. The dark web is a small part of the deep web that can only be reached with special browsers like Tor, and it is where stolen credentials and databases are bought and sold.
Data breach
A data breach is an incident in which confidential information, such as customer data, credentials or records, is exposed or ends up in unauthorized hands. It can result from an attack, a configuration error or simple carelessness, and it usually requires the company to investigate, contain the damage and notify the people affected.
Data center
A data center is a facility designed to house servers, storage and network equipment with backup power, cooling, redundant connectivity and physical security. It can be company-owned, rented space in a shared facility (colocation) or run by a cloud provider such as Azure or AWS.
Data classification
Data classification is the process of labeling a company's data by sensitivity, for example public, internal, confidential and restricted, so each level gets the right protection. It tells you what to encrypt, who can see it and what must never leave the organization.
Data exfiltration
Data exfiltration is the unauthorized transfer of information from an organization's network to a destination the attacker controls. It's usually the last stage of an intrusion and is disguised as normal traffic (email, cloud, DNS) to go unnoticed; catching it in time is what keeps an intrusion from becoming a breach.
Data governance
Data governance is the set of policies, roles and processes that define who is responsible for each piece of data in a company, how it is classified, who can use it and how long it is kept. It makes information reliable, secure and compliant, and it is the foundation for analytics and AI projects.
Data privacy
Data privacy is the set of legal obligations and technical measures that ensure people's information is collected, used and stored only for legitimate purposes and with their knowledge. Laws such as GDPR in Europe and state privacy laws in the US, like the CCPA in California, require notices, consent and security controls.
DDoS (distributed denial of service)
A DDoS attack floods a website or service with traffic sent from thousands of devices at once until it goes offline. Its goal is to disrupt operations, and attackers often demand a payment to stop it.
Deepfake
A deepfake is a video, audio clip or image generated with artificial intelligence that imitates a real person's face or voice so realistically it's hard to tell apart. In business it's used for impersonation fraud, such as a call in the CEO's voice asking for an urgent wire transfer.
Defense in depth
Defense in depth is a strategy that protects a company with several independent layers of security, so if one fails another stops the attack. It combines, for example, firewall, MFA, antivirus, network segmentation, backups and monitoring, the same way a castle combines walls, a moat and guards.
DevSecOps
DevSecOps is the practice of building security into every stage of software development and operations instead of checking it only at the end. It combines development (dev), security (sec) and operations (ops) with automated code testing, dependency checks and cloud controls, so flaws get fixed while they are still cheap to fix.
Digital footprint
A digital footprint is the trail of information a person or company leaves online: posts, records, metadata and leaked data. Attackers use it to prepare targeted social engineering campaigns.
Digital forensics
Digital forensics is the technical investigation of an incident to reconstruct what happened: how the attackers got in, what they touched and when. It preserves evidence so it holds up in an audit, an insurance claim or a legal process.
Digital signature
A digital signature is a cryptographic mechanism that guarantees an electronic document was issued by whoever claims to have issued it and wasn't modified after it was signed. It's the basis of advanced electronic signatures, and in many jurisdictions it carries the same legal weight as a handwritten signature when it meets the applicable requirements.
Disaster recovery plan (DRP)
A disaster recovery plan, or DRP, is the document that defines how a company restores its IT systems, data and operations after a serious event, such as ransomware, a fire or a data center outage. It sets owners, priorities, procedures and recovery time targets (RTO and RPO).
DLP (data loss prevention)
DLP (data loss prevention) is the set of tools and rules that keeps sensitive information from leaving the company by email, USB drives, the cloud or messaging apps without authorization. It classifies data and spots leak attempts, then blocks or logs them.
DMZ (demilitarized zone)
A DMZ (demilitarized zone) is a network segment kept separate from the internal network, where companies place the servers that must be reachable from the internet, such as the website or the mail server. If one of those servers is compromised, the firewall stops the attacker from moving straight into internal devices and data.
DNS (Domain Name System)
DNS (Domain Name System) is the service that translates names people remember, such as tecnetone.com, into the numeric IP addresses computers use to find each other. It works like the internet's contact list: if DNS fails or is tampered with, users do not reach the right website.
Domain controller (Active Directory)
A domain controller is the server that manages the accounts, passwords and permissions of every user and device on a Windows network through Active Directory. It's the most sensitive asset in a company, because whoever controls it controls every account and every computer on the domain.
Doxxing
Doxxing is the deliberate publication of someone's personal data, such as a home address, phone number or workplace, gathered from public or leaked sources to intimidate or expose them. For companies, it's a direct risk to executives and spokespeople.
Drive-by download
A drive-by download is a malware download that happens just by visiting a compromised web page, without the user clicking or accepting anything. It exploits vulnerabilities in the browser or its plugins, which is why keeping software up to date is the main defense.
E
EDR (endpoint detection and response)
An EDR (endpoint detection and response) is an agent installed on computers and servers that watches how each program behaves to spot suspicious activity, and it can isolate a device from the network. It goes beyond antivirus because it records what happened and lets analysts investigate it.
Encryption
Encryption is the process of turning information into unreadable code that only someone with the right key can read. If a laptop with an encrypted drive is stolen or an encrypted file is intercepted, the thief only sees meaningless characters, which is why encryption is the foundation for protecting data at rest and in transit.
Endpoint
An endpoint is any device that connects to your company network and is used to work or process data: laptops, desktops, phones, tablets and servers. Every endpoint is a possible way in, which is why each one is protected with antivirus, EDR and management policies.
Exploit
An exploit is a program or sequence of instructions that takes advantage of a specific software vulnerability to run code or take control of a system. It's the bridge between a known flaw and a real attack.
F
G
GDPR (General Data Protection Regulation)
The GDPR (General Data Protection Regulation) is the European Union law that governs how personal data of people in the EU is collected, used and protected. It also applies to US companies that offer goods or services to people in Europe or track their behavior, with fines of up to 4% of global annual revenue.
GRC (governance, risk and compliance)
GRC (governance, risk and compliance) is a way to manage three areas together that are often handled separately: who decides and under which policies, which risks the business faces and which laws and standards it must meet. Integrating them avoids duplicate controls and makes it easier to answer audits, clients and regulators.
H
Hash
A hash is a fixed-length fingerprint calculated from any piece of data (a file, a password, a message) with a one-way mathematical function: the original data can't be recovered from the hash. It's used to store passwords without keeping them in plain text and to check that a file wasn't altered.
High availability
High availability is the design of systems, networks and applications so they keep running even if one component fails, with minimal downtime. It is achieved by duplicating devices, links or servers so one takes over for another automatically, and it is usually measured as a percentage of uptime, such as 99.9%.
I
IaaS, PaaS and SaaS
IaaS, PaaS and SaaS are the three cloud service models. IaaS delivers infrastructure (servers, network and storage) that you manage. PaaS delivers the platform to deploy applications without managing servers. SaaS delivers finished software, ready to use by subscription.
IAM (identity and access management)
IAM (identity and access management) is the set of processes and tools that controls who each user is, what they can access and with which permissions, from the day they join the company to the day they leave. It covers onboarding and offboarding, roles, multi-factor authentication and periodic access reviews.
Incident response
Incident response is the organized process a company uses to detect, contain, eliminate and recover from an attack or security failure, so it limits the damage and gets back to normal operations quickly. It follows defined phases: preparation, identification, containment, eradication, recovery and lessons learned.
Information security
Information security is the discipline that protects an organization's information, in any format, so it stays confidential, accurate and available. It goes beyond cybersecurity to include paper documents, conversations and processes, and it is organized through policies, controls and standards such as ISO 27001.
Information security policy
An information security policy is the document approved by leadership that defines how the company protects its information: who is responsible, what is allowed, what is prohibited and how incidents are handled. Specific rules come from it, such as password use, remote work or data classification.
Insider threat
An insider threat is a risk that comes from people who already have legitimate access to company systems, such as employees, former employees or vendors. It can be intentional, like copying a customer database before resigning, or accidental, like sending a confidential file to the wrong person.
IoT (internet of things)
IoT (internet of things) is the set of network-connected devices that aren't traditional computers: cameras, sensors, printers, plant controllers, medical equipment or appliances. They often ship with default passwords and get few updates, so they widen a company's attack surface unless they're isolated and monitored.
IP address
An IP address is the number that identifies every device connected to a network, such as a laptop, a server or a phone, so data reaches the right place. It can be public, the one the internet sees, or private, the one used inside your company network, and it comes in two versions: IPv4 and IPv6.
ISMS (information security management system)
An ISMS (information security management system) is the set of policies, processes, roles and controls an organization uses to protect its information in an orderly way that improves over time. It's what the ISO/IEC 27001 standard certifies.
ISO 27001
ISO 27001 is the international standard that defines how to build, run and improve an information security management system (ISMS). It requires a risk assessment, a set of controls chosen from its Annex A and audits that prove it works, so a certified company can show clients and partners it protects information with a verifiable method.
ISO 27002
ISO 27002 is the international standard that explains how to apply the information security controls required by ISO 27001. Its 2022 version describes 93 controls grouped into four themes: organizational, people, physical and technological, with practical guidance for implementing each one.
ITIL
ITIL is the most widely used best-practice framework for managing IT services: it describes how to plan, deliver, support and improve services through processes such as incident, problem, change and service level management. It is not a certifiable standard for companies but a guide each organization adapts.
ITSM and help desk
ITSM (IT service management) is the way IT organizes how it delivers and supports its services, with clear processes to log incidents, handle requests and manage changes. The help desk is the single point of contact where users report problems and get follow-up through tickets.
J
K
L
LAN and WAN
A LAN (local area network) connects the devices in one location, such as an office or a plant, and a WAN (wide area network) links several LANs separated by distance, for example a company's branches with each other and the cloud. The LAN is usually company-owned and fast; the WAN relies on links contracted from carriers.
Latency and bandwidth
Latency is the time it takes data to travel from one point of the network to another, and bandwidth is how much data a connection can carry at once. If the network were a highway, bandwidth would be the lanes and latency the travel time; together they explain why a video call drops or a system feels slow.
Lateral movement
Lateral movement is the stage of an attack in which the intruder, after getting into one device, jumps to other devices and servers on the same network looking for accounts with more privileges or valuable information. Detecting it early makes it possible to contain the incident before it reaches critical systems.
Logic bomb
A logic bomb is a piece of malicious code that stays dormant until a condition is met, such as a date, a deleted user account or a number of runs. When it triggers, it deletes, encrypts or alters data on the system.
Logs (event logs)
Logs, or event logs, are the files where systems, applications and network devices automatically record what happens: sign-ins, errors, configuration changes or connections. In cybersecurity they are the evidence used to detect attacks and investigate incidents, which is why they are centralized in a SIEM and kept for a defined period.
M
Malvertising
Malvertising (malicious advertising) is the use of online ads to spread malware or lead the victim to a fraudulent site. The ads run through legitimate ad networks, so they can appear on news portals or well-known sites without the site knowing.
Malware
Malware is any program designed to damage a device, steal information or take control of a system without the owner's permission. The word is short for malicious software, and it includes viruses, trojans, ransomware, spyware, worms and keyloggers, which differ in how they get in and what they do once inside.
Man-in-the-middle attack
A man-in-the-middle attack happens when someone secretly places themselves between two parties that are communicating, for example between your laptop and your bank's website, to read or change what they send. It is common on unprotected public Wi-Fi and is prevented with encrypted connections such as HTTPS and VPNs.
MDR (managed detection and response)
MDR (managed detection and response) is a service in which a provider watches a company's devices around the clock and handles its alerts, from investigation to containment. It pairs EDR technology with human analysts and is usually priced per protected device.
MFA (multi-factor authentication)
Multi-factor authentication (MFA) asks for two or more proofs of identity to sign in: something you know (a password), something you have (a phone or security key) or something you are (a fingerprint). It stops most sign-ins made with stolen passwords.
Microsoft Entra ID (formerly Azure AD)
Microsoft Entra ID, formerly Azure Active Directory, is Microsoft's cloud identity service that controls who can sign in to Microsoft 365, Azure and thousands of applications. It lets you enforce MFA, conditional access and single sign-on, and it is the foundation of identity security in a Microsoft environment.
Microsoft Intune
Microsoft Intune is Microsoft's cloud service for managing and protecting a company's computers, phones and tablets from a single console. It lets you install apps, apply security settings, require encryption and remotely wipe a lost device, and it is included in plans such as Microsoft 365 Business Premium.
MITRE ATT&CK
MITRE ATT&CK is a public knowledge base that organizes the tactics and techniques real attackers use, from how they get in to how they steal information. Security teams use it as a common language to design detections, evaluate tools and measure how well their defenses are covered.
MSSP (managed security service provider)
An MSSP (managed security service provider) is a company that runs other companies' security under contract, managing firewalls, endpoint protection, email security and monitoring with its own team and tools. It gives a business enterprise-grade security without building an in-house security team.
MTTD, MTTA and MTTR
MTTD, MTTA and MTTR are the three core incident response metrics. MTTD is the mean time to detect a problem; MTTA, the mean time until someone acknowledges it and starts working on it; MTTR, the mean time to resolve it. The lower they are, the less impact each incident has.
N
NAC (network access control)
NAC (network access control) is the technology that decides which devices can connect to a company's network and with what permissions, based on who the user is, which device they use and whether it meets security policies such as active endpoint protection and an updated operating system. An unknown or noncompliant device ends up on an isolated network or with no access.
NDR (network detection and response)
NDR (network detection and response) is a technology that continuously analyzes network traffic to detect suspicious behavior, such as lateral movement or communication with malicious servers, and respond to it. It complements EDR because it sees what happens between devices, including those that cannot run an agent.
Network security
Network security is the set of controls that protect a company's communications infrastructure and the traffic that flows through it, so only authorized users and devices reach each resource. It includes firewalls, segmentation, VPN or ZTNA, network access control, Wi-Fi protection and traffic monitoring.
Network segmentation
Network segmentation is the practice of dividing a company network into separate zones, for example users, servers, guests and production equipment, with rules that control what can talk to what. Microsegmentation takes the idea down to each server or application, so an incident in one zone does not spread to the rest.
NGFW (next-generation firewall)
An NGFW (next-generation firewall) is a firewall that, besides filtering by address and port, identifies the applications and users behind the traffic and adds intrusion prevention, web filtering and malware analysis. It allows more precise rules, such as blocking one specific application without cutting off internet access.
NIST CSF (NIST Cybersecurity Framework)
The NIST CSF (Cybersecurity Framework) is a free framework from the US National Institute of Standards and Technology that helps organize a cybersecurity program. Version 2.0 groups activities into six functions: govern, identify, protect, detect, respond and recover.
NOC (network operations center)
A NOC (network operations center) is the team that makes sure a company's network, servers and services stay available and perform well. It handles outages, congestion and hardware failures. A SOC, by contrast, watches for anyone misusing those systems.
O
OSI model
The OSI model is a reference framework that splits communication between devices into seven layers, from the physical cable (layer 1) to the application the person uses (layer 7). It helps pinpoint where a network problem happens and at which layer each security control works, such as a firewall or a WAF.
OSINT (open-source intelligence)
OSINT (open-source intelligence) is the collection and analysis of publicly available information: websites, social media, public records and leaks. Attackers use it to prepare targeted attacks, and security teams use it to measure how exposed a company is.
OT and SCADA security
OT (operational technology) is the systems that control physical processes, such as production lines, pumps or substations, and SCADA is the software that monitors and controls them remotely. Securing them is different from IT because a failure does not just expose data: it can stop a plant or put people at risk.
P
Packet sniffing
Packet sniffing is capturing the traffic that crosses a network to read its contents: passwords, emails, sessions or files sent without encryption. An attacker does it with a packet analyzer connected to the network, for example on public Wi-Fi or an internal segment they've already accessed.
PAM (privileged access management)
PAM (privileged access management) is the practice and the tools that control accounts with elevated permissions, such as server or Microsoft 365 administrators. It keeps their passwords in a vault, grants access only when needed and records what is done, because those accounts are the most sought after in an attack.
Passkeys and security keys (FIDO2)
A passkey is a way to sign in without a password: your device stores a cryptographic key that you unlock with your fingerprint, face or a PIN. It is based on the FIDO2 standard, like physical security keys such as YubiKey, and it resists phishing because the key only works on the legitimate site.
Password manager
A password manager is an application that stores all your passwords encrypted and fills them in for you, so you only need to remember one master password. It makes it easy to use a long, unique password for every service, and in a business it lets teams share access in a controlled way and revoke it when someone leaves.
Payload
The payload is the part of an attack that carries out the harmful action once the malware or exploit gets in, such as encrypting files or stealing credentials. The entry vector (an email, an attachment, a vulnerability) only delivers it; the payload is what does the damage.
PCI DSS
PCI DSS (Payment Card Industry Data Security Standard) is the security standard every business that processes, stores or transmits credit or debit card data must follow. It is set by the major card brands and includes requirements for firewalls, encryption, access control, monitoring and regular testing.
Penetration testing (pentest)
A penetration test, or pentest, is a controlled and authorized attack on a company's systems to find and prove its vulnerabilities before a real attacker does. It ends with a report of prioritized findings and how to fix them.
Personal data and sensitive data
Personal data is any information that identifies or can identify a person, such as a name, email address, phone number or Social Security number; in the US it is often called personally identifiable information (PII). Sensitive data is the subset that can cause serious harm if misused, such as health, financial or biometric information, and privacy laws require stronger protection for it.
Pharming
Pharming is an attack that sends people to a fake website even when they type the correct address of the real one, by tampering with DNS or the device's settings. Unlike phishing, it does not need the victim to click a deceptive link, which makes it harder to notice.
Phishing
Phishing is a message, almost always an email, that impersonates a trusted company or person so the victim hands over credentials or opens a malicious file. It's the entry point for most incidents in companies.
PKI and digital certificates
PKI (public key infrastructure) is the set of rules, authorities and keys that issues and validates digital certificates. A digital certificate is a file that works like an official ID on the internet: it confirms that a website, server or person is who they claim to be and allows communication to be encrypted, as with the HTTPS padlock.
Principle of least privilege
The principle of least privilege states that every person, application or account should have only the permissions it needs to do its job, and nothing more. If an accounting account can only see financial data, an attacker who steals it cannot reach the servers or HR records.
Public, private and hybrid cloud
A public cloud is infrastructure from a provider such as Azure or AWS that many customers share; a private cloud is dedicated to a single organization, in its own data center or a third party's. A hybrid cloud combines both, and multicloud uses services from more than one provider to get the best of each.
Q
R
Ransomware
Ransomware is malicious software that encrypts a company's files and systems and demands a payment to restore access. Current variants also steal the data before encrypting it, to add pressure by threatening to publish it. Recovery depends on immutable backups and a tested recovery plan.
RAT (remote access trojan)
A RAT (remote access trojan) is a trojan that gives the attacker full remote control of the infected computer, from the screen and camera to files and programs. It usually arrives disguised as a legitimate document or installer.
RBAC (role-based access control)
RBAC (role-based access control) is the model that assigns permissions to roles (accountant, salesperson, administrator) and has each user inherit the permissions of their role. Onboarding a new hire or moving someone to a new position means changing their role, without handing out permissions one by one.
RCE (remote code execution)
RCE (remote code execution) is a type of vulnerability that lets an attacker run their own commands on a server or device from a distance, without physical access or credentials. It is among the most serious flaws because it usually gives full control of the system, which is why patches that fix it should be applied right away.
RDP (Remote Desktop Protocol)
RDP (Remote Desktop Protocol) is the Microsoft protocol that lets you control a Windows computer or server from a distance, seeing its desktop as if you were sitting in front of it. It is very useful for support and remote work, and it should be protected with a VPN, MFA and strong passwords instead of being left open to the internet.
Red team, blue team and purple team
The red team simulates real attacks against an organization to find its weak points; the blue team defends, detects and responds. The purple team brings both together so every simulated attack immediately turns into a concrete improvement to the defenses.
Regulatory compliance
Regulatory compliance is a company's ability to show that it operates according to the laws, standards and contracts that apply to it, such as HIPAA, PCI DSS or SOC 2. In cybersecurity it means having policies, controls and evidence ready for audits, clients and regulators.
Risk assessment
A risk assessment is the process of identifying which company assets could be affected, by which threats and weaknesses, and how likely and severe each scenario would be. The result is a prioritized list that shows where to invest first in security controls, and it is a core requirement of frameworks such as ISO 27001 and NIST CSF.
Risk matrix
A risk matrix is a table that combines the likelihood of an event with the impact it would have, placing each risk at a level such as low, medium, high or critical. It lets you compare different risks with the same criteria and decide which ones to address first.
Risk model
A risk model is the method an organization uses to identify its assets, the threats that affect them, how likely they are and the impact they would have, so it can decide what to protect first and how much to invest. It's the starting point of standards such as ISO 27001 and of the risk assessment an ISMS requires.
Rootkit
A rootkit is a set of tools that hides in the deepest layers of the operating system to conceal other malware and keep the attacker's access. It's hard to detect with conventional antivirus.
RTO and RPO
RTO and RPO are the two numbers that define a recovery plan. RTO (recovery time objective) is the maximum time a system can be down before it hurts the business. RPO (recovery point objective) is the maximum amount of data you accept losing, measured in time since the last copy.
S
SAML, OAuth and OpenID Connect
SAML, OAuth and OpenID Connect are standards that let people sign in or grant permissions between applications without sharing passwords. SAML and OpenID Connect are used for single sign-on (SSO), and OAuth to authorize one application to access your data in another, like when you connect a calendar to your email.
SASE (secure access service edge)
SASE (secure access service edge) is a model that combines network connectivity (SD-WAN) and security functions such as firewall, web filtering, CASB and zero trust access into a single cloud service. Users connect securely from anywhere without routing all traffic through headquarters.
Scareware
Scareware is a scam that shows fake alerts, for example that your computer is infected, to convince you to download a program or pay for a supposed fix. The screen imitates antivirus or Windows warnings, and the program it offers is usually malware or a worthless charge.
Security incident
A security incident is any event that compromises or threatens the confidentiality, integrity or availability of a company's information or systems, such as unauthorized access, ransomware or the loss of a device with data on it. Not every alert is an incident: it becomes one when real or likely harm is confirmed.
Security patch
A security patch is an update a vendor releases to fix a vulnerability in its software. Applying it on time closes the gap before an exploit appears, and patch management is the process of doing that in an orderly way across every device.
Serverless computing
Serverless computing is a cloud model in which the provider fully manages the servers and your company only uploads code, which runs when an event happens and is billed by use. The servers still exist, but you do not have to install, scale or maintain them, as with Azure Functions or AWS Lambda.
Shadow IT
Shadow IT is the applications, cloud services or devices employees use for work without IT knowing or approving them, such as a personal storage account or a free AI tool. It usually starts with good intentions, but it leaves company data outside of IT's control.
Shared responsibility model
The shared responsibility model defines what the cloud provider protects and what the customer must protect. The provider secures the physical infrastructure, the network and the platform; the customer is responsible for its data, access, service configuration and backups. Having your data in Azure or AWS doesn't mean they back it up or manage your permissions.
SIEM (security information and event management)
A SIEM (security information and event management) is the platform that collects the logs from every system in a company and correlates them, raising an alert when a sequence matches the way an attack behaves. It's the central screen of a SOC.
SIM swapping
SIM swapping is a fraud in which a criminal persuades or tricks the phone carrier into moving your number to a SIM card they control. They then receive your calls and SMS codes and can break into your bank or work accounts, which is why authenticator apps or passkeys are safer than SMS.
SLA (service level agreement)
An SLA (service level agreement) is the part of a contract in which a provider commits to measurable targets: availability, response time, resolution time and penalties if it misses them. For example, an SLA can state that a critical incident is handled in under 15 minutes, 24 hours a day.
SNMP and NetFlow
SNMP (Simple Network Management Protocol) lets you check the status of routers, switches, servers and printers, such as CPU usage or whether an interface went down. NetFlow records who talks to whom on the network and how much traffic they send. Together they are the foundation of a NOC's network monitoring.
SOAR (security orchestration, automation and response)
SOAR (security orchestration, automation and response) is a platform that connects a company's security tools and runs automatic responses to alerts. For example, if the SIEM detects a suspicious sign-in, SOAR can lock the account, isolate the device and open a ticket in seconds, without waiting for an analyst.
SOC (security operations center)
A SOC (security operations center) is the team of analysts, processes and tools that watches a company's systems around the clock and handles every alert, from investigation to containment. As a service (SOCaaS), an outside provider runs it under a subscription.
SOC as a Service (SOCaaS)
SOC as a Service (SOCaaS) is a model in which a company hires a specialized provider to monitor, detect and respond to threats around the clock instead of building its own security operations center. It gets the technology, analysts and processes for a monthly fee, without investing in infrastructure or hiring a full team.
Social engineering
Social engineering is the set of techniques used to trick a person into handing over information, approving a payment or granting access. It exploits trust, urgency or authority instead of a technical flaw, and phishing is its most common form.
SOX (Sarbanes-Oxley Act)
The SOX (Sarbanes-Oxley) Act is a US law that requires publicly traded companies to prove their financial reporting is reliable, with internal controls that can be audited. In IT it translates into access controls, change management and logs for the systems that handle financial data.
SPF, DKIM and DMARC
SPF, DKIM and DMARC are three records configured on an email domain to stop anyone from sending messages that impersonate your company. SPF lists the servers allowed to send on your behalf, DKIM signs each message to prove it wasn't altered and DMARC defines what to do with email that fails both checks. Together they protect your brand and improve delivery of your legitimate email.
Spoofing
Spoofing is the technique of faking a digital identity (an email address, a phone number, an IP address or a website) so the victim believes they're dealing with someone trusted. It's the basis of many email and phone scams, because the message appears to come from an executive, a bank or a real vendor.
Spyware
Spyware is a program that installs itself without permission to collect a user's information, such as browsing habits, credentials, messages or location, and send it to a third party. It often arrives with free software or in an attachment.
SQL injection
SQL injection is an attack in which someone types database commands into a website form or URL so the application runs them. If the site does not validate what it receives, the attacker can read, change or delete information such as customer lists or passwords without having an authorized account.
SSL/TLS
TLS (Transport Layer Security) is the protocol that encrypts communication between a browser or app and a server, so no one along the way can read or alter it; SSL is its older, obsolete version, though the name is still used. It's what turns on the padlock and https on a website.
System hardening
System hardening is the process of reducing a system's attack surface. It means removing the services and ports that aren't needed and applying secure configurations with the minimum permissions. It's the foundation every other security control builds on.
T
Tailgating and piggybacking
Tailgating is a social engineering technique in which an unauthorized person enters a restricted area by closely following someone who has access, for example slipping in behind an employee who badges through a door. When the employee knowingly lets them in out of courtesy, it is called piggybacking.
Threat hunting
Threat hunting is the proactive search for attackers who are already inside the network and weren't caught by automated alerts. An analyst starts from a hypothesis and reviews logs and behavior to confirm or rule out an intrusion.
Threat intelligence
Threat intelligence is collected and analyzed information about who is attacking, with which techniques and against what kind of companies, so you can get ahead of attacks instead of only reacting. It includes indicators such as malicious IP addresses or domains and context on active campaigns that affect your industry or region.
Trojan
A trojan is a malicious program that poses as something useful or harmless, such as an installer, an invoice or an update, so the user runs it. Once inside, it opens the way for other malware or for remote control of the computer.
U
V
Virtualization and hypervisor
Virtualization is the technology that lets a single physical server work as several independent computers, called virtual machines, each with its own operating system. The hypervisor is the software that shares the hardware's resources among them, such as VMware or Hyper-V, and it is the foundation of the modern cloud.
VLAN (virtual local area network)
A VLAN (virtual local area network) is a way to split one physical network into several separate logical networks, configured on the switches, so groups like guests, cameras or accounting cannot see each other even though they share the same cabling. It is one of the basic tools for segmenting a company network.
Vulnerability, CVE and CVSS
A vulnerability is a flaw in software or configuration that an attacker can exploit. A CVE is the unique public identifier assigned to each known vulnerability. CVSS is the 0-to-10 scale that rates its severity and helps decide what to fix first.
W
X
XDR (extended detection and response)
XDR (extended detection and response) widens the reach of EDR: beyond devices, it correlates what happens in email, the network, identities and the cloud on a single platform. That way it detects attacks that move across several fronts, which each tool on its own would miss.
XSS (cross-site scripting)
XSS (cross-site scripting) is an attack in which someone injects malicious code into a legitimate web page, for example in a comment or a form, so it runs in other visitors' browsers. It can steal sessions, redirect people to fake sites or change what the user sees, and it is prevented by validating and sanitizing everything the site receives.
Y
Z
Zero trust
Zero trust is a security model in which no user, device or connection is trusted just for being inside the network. Every access is explicitly verified and granted with the least privilege needed, and it's checked again continuously.
Zero-day
A zero-day is a vulnerability the software vendor doesn't know about yet or hasn't fixed, so there's no patch to close it. The name comes from the zero days of warning your IT team gets: an attacker can exploit it before an official fix exists.
ZTNA (zero trust network access)
ZTNA (zero trust network access) is a way to give remote access to company applications by verifying identity, device and context on every connection, without opening up the whole network. Unlike a traditional VPN, users only see the applications they are allowed to use.
We couldn’t find that term. We’ll add it in the next update.
Ready to put this into practice in your operation?
Tell us what you need and a TecnetOne engineer will get back to you.
Talk to an engineer