Cybersecurity glossary
The cybersecurity, cloud and compliance terms your team hears every day, explained on one page in plain English.
A
ACL (access control list)
An ACL (access control list) is the set of rules that defines which users, devices or addresses can reach a resource and what they can do with it. Firewalls, routers, shared folders and cloud services use ACLs to allow or deny each access request.
Adware
Adware is a program that shows unwanted ads on a computer or in the browser, often installed alongside free software. Beyond the annoyance, many variants track the user's browsing habits and open the door to other malicious programs.
APT (advanced persistent threat)
An APT (advanced persistent threat) is a targeted attack in which a well-resourced group gets into an organization's network and stays hidden for weeks or months to steal information or set up a larger strike. Unlike an opportunistic attack, an APT picks its victim and moves slowly, changing tactics to avoid detection.
Attack surface
A company's attack surface is everything an intruder can reach, from outside or inside, to try to get in: every server exposed to the internet, every application, every user account, every connected laptop or phone, every cloud service and every vendor with access to your systems. The more pieces there are and the less you know about them, the more gaps go unwatched, which is why the work starts with an inventory and closing what isn't needed.
Authentication vs. authorization
Authentication confirms that you are who you say you are (a password, a fingerprint, a verification code); authorization decides what you can do once you're in (view, edit, approve). A secure system needs both: signing in with a verified identity and doing only what your role allows.
B
Backdoor
A backdoor is a hidden way into a system that skips normal authentication. An attacker can leave one behind after an intrusion, or it can come hidden inside legitimate software, and it's used to get back into the system at will.
Botnet
A botnet is a network of infected computers that an attacker controls remotely without their owners knowing. Attackers use botnets for denial-of-service attacks, spam campaigns and cryptocurrency mining on the victims' resources.
Brute force attack
A brute force attack automatically tries thousands of username and password combinations until it finds the right one. Long passwords, lockout after several failed attempts and multi-factor authentication stop it.
C
CIA triad (confidentiality, integrity and availability)
The CIA triad is the model that sums up the three goals of information security: confidentiality (only the right people get access), integrity (information isn't altered without authorization) and availability (it's ready when needed). Every security control, from a backup to encryption, protects at least one of the three.
Computer worm
A worm is a malicious program that copies itself and spreads from one computer to another across the network without anyone opening a file. Unlike a virus, it doesn't need a host program, and it can saturate entire networks within hours.
CSP (cloud service provider)
A CSP (cloud service provider) is a company that offers infrastructure, platforms or software over the internet on demand, such as Microsoft Azure, Amazon Web Services or Google Cloud. In the Microsoft ecosystem, CSP also names the authorized partner that sells and manages those subscriptions for the customer.
D
Data exfiltration
Data exfiltration is the unauthorized transfer of information from an organization's network to a destination the attacker controls. It's usually the last stage of an intrusion and is disguised as normal traffic (email, cloud, DNS) to go unnoticed; catching it in time is what keeps an intrusion from becoming a breach.
DDoS (distributed denial of service)
A DDoS attack floods a website or service with traffic sent from thousands of devices at once until it goes offline. Its goal is to disrupt operations, and attackers often demand a payment to stop it.
Deepfake
A deepfake is a video, audio clip or image generated with artificial intelligence that imitates a real person's face or voice so realistically it's hard to tell apart. In business it's used for impersonation fraud, such as a call in the CEO's voice asking for an urgent wire transfer.
Digital footprint
A digital footprint is the trail of information a person or company leaves online: posts, records, metadata and leaked data. Attackers use it to prepare targeted social engineering campaigns.
Digital forensics
Digital forensics is the technical investigation of an incident to reconstruct what happened: how the attackers got in, what they touched and when. It preserves evidence so it holds up in an audit, an insurance claim or a legal process.
Digital signature
A digital signature is a cryptographic mechanism that guarantees an electronic document was issued by whoever claims to have issued it and wasn't modified after it was signed. It's the basis of advanced electronic signatures, and in many jurisdictions it carries the same legal weight as a handwritten signature when it meets the applicable requirements.
DLP (data loss prevention)
DLP (data loss prevention) is the set of tools and rules that keeps sensitive information from leaving the company by email, USB drives, the cloud or messaging apps without authorization. It classifies data and spots leak attempts, then blocks or logs them.
Domain controller (Active Directory)
A domain controller is the server that manages the accounts, passwords and permissions of every user and device on a Windows network through Active Directory. It's the most sensitive asset in a company, because whoever controls it controls every account and every computer on the domain.
Doxxing
Doxxing is the deliberate publication of someone's personal data, such as a home address, phone number or workplace, gathered from public or leaked sources to intimidate or expose them. For companies, it's a direct risk to executives and spokespeople.
Drive-by download
A drive-by download is a malware download that happens just by visiting a compromised web page, without the user clicking or accepting anything. It exploits vulnerabilities in the browser or its plugins, which is why keeping software up to date is the main defense.
E
EDR (endpoint detection and response)
An EDR (endpoint detection and response) is an agent installed on computers and servers that watches how each program behaves to spot suspicious activity, and it can isolate a device from the network. It goes beyond antivirus because it records what happened and lets analysts investigate it.
Exploit
An exploit is a program or sequence of instructions that takes advantage of a specific software vulnerability to run code or take control of a system. It's the bridge between a known flaw and a real attack.
F
G
H
I
IaaS, PaaS and SaaS
IaaS, PaaS and SaaS are the three cloud service models. IaaS delivers infrastructure (servers, network and storage) that you manage. PaaS delivers the platform to deploy applications without managing servers. SaaS delivers finished software, ready to use by subscription.
IAM (identity and access management)
IAM (identity and access management) is the set of processes and tools that controls who each user is, what they can access and with which permissions, from the day they join the company to the day they leave. It covers onboarding and offboarding, roles, multi-factor authentication and periodic access reviews.
IoT (internet of things)
IoT (internet of things) is the set of network-connected devices that aren't traditional computers: cameras, sensors, printers, plant controllers, medical equipment or appliances. They often ship with default passwords and get few updates, so they widen a company's attack surface unless they're isolated and monitored.
ISMS (information security management system)
An ISMS (information security management system) is the set of policies, processes, roles and controls an organization uses to protect its information in an orderly way that improves over time. It's what the ISO/IEC 27001 standard certifies.
J
K
L
M
Malvertising
Malvertising (malicious advertising) is the use of online ads to spread malware or lead the victim to a fraudulent site. The ads run through legitimate ad networks, so they can appear on news portals or well-known sites without the site knowing.
MDR (managed detection and response)
MDR (managed detection and response) is a service in which a provider watches a company's devices around the clock and handles its alerts, from investigation to containment. It pairs EDR technology with human analysts and is usually priced per protected device.
MFA (multi-factor authentication)
Multi-factor authentication (MFA) asks for two or more proofs of identity to sign in: something you know (a password), something you have (a phone or security key) or something you are (a fingerprint). It stops most sign-ins made with stolen passwords.
MSSP (managed security service provider)
An MSSP (managed security service provider) is a company that runs other companies' security under contract, managing firewalls, endpoint protection, email security and monitoring with its own team and tools. It gives a business enterprise-grade security without building an in-house security team.
MTTD, MTTA and MTTR
MTTD, MTTA and MTTR are the three core incident response metrics. MTTD is the mean time to detect a problem; MTTA, the mean time until someone acknowledges it and starts working on it; MTTR, the mean time to resolve it. The lower they are, the less impact each incident has.
N
NAC (network access control)
NAC (network access control) is the technology that decides which devices can connect to a company's network and with what permissions, based on who the user is, which device they use and whether it meets security policies such as active endpoint protection and an updated operating system. An unknown or noncompliant device ends up on an isolated network or with no access.
NOC (network operations center)
A NOC (network operations center) is the team that makes sure a company's network, servers and services stay available and perform well. It handles outages, congestion and hardware failures. A SOC, by contrast, watches for anyone misusing those systems.
O
P
Packet sniffing
Packet sniffing is capturing the traffic that crosses a network to read its contents: passwords, emails, sessions or files sent without encryption. An attacker does it with a packet analyzer connected to the network, for example on public Wi-Fi or an internal segment they've already accessed.
Payload
The payload is the part of an attack that carries out the harmful action once the malware or exploit gets in, such as encrypting files or stealing credentials. The entry vector (an email, an attachment, a vulnerability) only delivers it; the payload is what does the damage.
Penetration testing (pentest)
A penetration test, or pentest, is a controlled and authorized attack on a company's systems to find and prove its vulnerabilities before a real attacker does. It ends with a report of prioritized findings and how to fix them.
Phishing
Phishing is a message, almost always an email, that impersonates a trusted company or person so the victim hands over credentials or opens a malicious file. It's the entry point for most incidents in companies.
Q
R
Ransomware
Ransomware is malicious software that encrypts a company's files and systems and demands a payment to restore access. Current variants also steal the data before encrypting it, to add pressure by threatening to publish it. Recovery depends on immutable backups and a tested recovery plan.
RAT (remote access trojan)
A RAT (remote access trojan) is a trojan that gives the attacker full remote control of the infected computer, from the screen and camera to files and programs. It usually arrives disguised as a legitimate document or installer.
RBAC (role-based access control)
RBAC (role-based access control) is the model that assigns permissions to roles (accountant, salesperson, administrator) and has each user inherit the permissions of their role. Onboarding a new hire or moving someone to a new position means changing their role, without handing out permissions one by one.
Risk model
A risk model is the method an organization uses to identify its assets, the threats that affect them, how likely they are and the impact they would have, so it can decide what to protect first and how much to invest. It's the starting point of standards such as ISO 27001 and of the risk assessment an ISMS requires.
Rootkit
A rootkit is a set of tools that hides in the deepest layers of the operating system to conceal other malware and keep the attacker's access. It's hard to detect with conventional antivirus.
RTO and RPO
RTO and RPO are the two numbers that define a recovery plan. RTO (recovery time objective) is the maximum time a system can be down before it hurts the business. RPO (recovery point objective) is the maximum amount of data you accept losing, measured in time since the last copy.
S
Security patch
A security patch is an update a vendor releases to fix a vulnerability in its software. Applying it on time closes the gap before an exploit appears, and patch management is the process of doing that in an orderly way across every device.
Shared responsibility model
The shared responsibility model defines what the cloud provider protects and what the customer must protect. The provider secures the physical infrastructure, the network and the platform; the customer is responsible for its data, access, service configuration and backups. Having your data in Azure or AWS doesn't mean they back it up or manage your permissions.
SIEM (security information and event management)
A SIEM (security information and event management) is the platform that collects the logs from every system in a company and correlates them, raising an alert when a sequence matches the way an attack behaves. It's the central screen of a SOC.
SOC (security operations center)
A SOC (security operations center) is the team of analysts, processes and tools that watches a company's systems around the clock and handles every alert, from investigation to containment. As a service (SOCaaS), an outside provider runs it under a subscription.
Social engineering
Social engineering is the set of techniques used to trick a person into handing over information, approving a payment or granting access. It exploits trust, urgency or authority instead of a technical flaw, and phishing is its most common form.
SPF, DKIM and DMARC
SPF, DKIM and DMARC are three records configured on an email domain to stop anyone from sending messages that impersonate your company. SPF lists the servers allowed to send on your behalf, DKIM signs each message to prove it wasn't altered and DMARC defines what to do with email that fails both checks. Together they protect your brand and improve delivery of your legitimate email.
Spoofing
Spoofing is the technique of faking a digital identity (an email address, a phone number, an IP address or a website) so the victim believes they're dealing with someone trusted. It's the basis of many email and phone scams, because the message appears to come from an executive, a bank or a real vendor.
Spyware
Spyware is a program that installs itself without permission to collect a user's information, such as browsing habits, credentials, messages or location, and send it to a third party. It often arrives with free software or in an attachment.
SSL/TLS
TLS (Transport Layer Security) is the protocol that encrypts communication between a browser or app and a server, so no one along the way can read or alter it; SSL is its older, obsolete version, though the name is still used. It's what turns on the padlock and https on a website.
System hardening
System hardening is the process of reducing a system's attack surface. It means removing the services and ports that aren't needed and applying secure configurations with the minimum permissions. It's the foundation every other security control builds on.
T
Threat hunting
Threat hunting is the proactive search for attackers who are already inside the network and weren't caught by automated alerts. An analyst starts from a hypothesis and reviews logs and behavior to confirm or rule out an intrusion.
Trojan
A trojan is a malicious program that poses as something useful or harmless, such as an installer, an invoice or an update, so the user runs it. Once inside, it opens the way for other malware or for remote control of the computer.
U
V
W
X
Y
Z
Zero trust
Zero trust is a security model in which no user, device or connection is trusted just for being inside the network. Every access is explicitly verified and granted with the least privilege needed, and it's checked again continuously.
Zero-day
A zero-day is a vulnerability the software vendor doesn't know about yet or hasn't fixed, so there's no patch to close it. The name comes from the zero days of warning your IT team gets: an attacker can exploit it before an official fix exists.
We couldn’t find that term. We’ll add it in the next update.
Ready to put this into practice in your operation?
Tell us what you need and a TecnetOne engineer will get back to you.
Talk to an engineer