Short, plain-language explanations of terms you often meet in information security, cyber security and compliance. Search for a term, filter by topic or browse by letter.

A

Attacks

Account Takeover (ATO)

Gaining control of someone else’s account, typically with stolen or guessed credentials.

Malware

Adware

Software that shows unwanted ads, often bundled with free programs and sometimes tracking behaviour.

Network, cloud and technology

AI (Artificial Intelligence)

Systems that perform tasks such as detection, classification or prediction; used by both defenders and attackers.

Defence and detection

Allowlist (Whitelisting)

A list of approved items that are the only ones permitted; everything else is blocked.

Social engineering

Angler Phishing

Phishing through fake customer-support accounts on social media that lure users into sharing credentials.

Defence and detection

Anti-Malware Software

Software that detects, blocks and removes malicious programs using signatures and behaviour analysis.

Defence and detection

Antivirus

Software that scans files and processes to find and remove known viruses and other malware.

Governance and risk

Asset

Anything of value to the organisation: data, systems, people, applications or reputation.

Defence and detection

Attack Signature

A recognisable pattern of a known attack that security tools use to detect it.

Governance and risk

Attack Surface

The sum of all points through which an attacker could try to enter or extract data.

B

Defence and detection

Backporting

Applying a fix from a newer software version to an older, still-supported version.

Social engineering

Baiting

A social engineering trick that offers something tempting, such as an infected USB drive, to make victims act.

Malware

Beacon

A periodic signal from malware to its controller that confirms it is alive and asks for instructions.

Social engineering

BEC (Business Email Compromise)

Fraud in which attackers impersonate executives or suppliers by e-mail to trigger payments or data disclosure.

Governance and risk

BIA (Business Impact Analysis)

An analysis showing which processes a disruption would affect, how quickly and how badly; it underpins RTO and RPO.

Network, cloud and technology

Big Data

Very large and fast-growing datasets that need special tools to store and analyse.

Attacks

Blended Threat

An attack that combines several techniques, such as malware, phishing and exploits, at once.

Network, cloud and technology

Blockchain

A distributed ledger where records are linked cryptographically and are hard to alter.

Defence and detection

Blocklist (Blacklist)

A list of addresses, files or senders that are denied access.

Malware

Botnet

A network of infected devices controlled remotely, used for DDoS, spam or credential attacks.

Attacks

Brute-Force Attack

Trying many passwords or keys until the right one is found.

C

Network, cloud and technology

Caching

Storing copies of data close to the user to speed up access; misconfigured caches can leak data.

Defence and detection

CAPTCHA

A challenge that tells humans from automated bots.

Network, cloud and technology

CASB

Cloud Access Security Broker: a control point between users and cloud services that enforces security policy.

Social engineering

CEO Fraud

A form of BEC where the attacker poses as a senior executive to request urgent payments.

Governance and risk

CERT

Computer Emergency Response Team: a group that coordinates responses to security incidents.

Network, cloud and technology

Ciphertext

Data after encryption, unreadable without the key.

Attacks

Clickjacking

Tricking users into clicking something different from what they see, using hidden or overlaid page elements.

Social engineering

Clone Phishing

Resending a legitimate e-mail with a malicious link or attachment swapped in.

Network, cloud and technology

Cloud Computing

Delivering computing resources over the internet on demand instead of owning hardware.

Defence and detection

Cloud Firewall

A firewall delivered as a cloud service that filters traffic to and from cloud resources.

Defence and detection

CNAPP

Cloud-native application protection platform combining cloud posture, workload and code checks.

Defence and detection

Continuous Monitoring

Ongoing, automated observation of systems and controls to detect issues as they appear.

Network, cloud and technology

CORS

Cross-Origin Resource Sharing: a browser mechanism that controls which sites may request resources from another origin.

Attacks

Credential Stuffing

Automatically trying leaked username and password pairs on many services.

Attacks

Cross-Site Scripting (XSS)

Injecting malicious scripts into pages that other users then run in their browsers.

Network, cloud and technology

CRUD

Create, read, update, delete: the four basic data operations; each needs proper authorisation.

Network, cloud and technology

Cryptocurrency

Digital currency secured by cryptography, often used for ransom payments.

Malware

Cryptojacking

Malware that secretly uses a victim’s computing power to mine cryptocurrency.

Governance and risk

CSIRT

Computer Security Incident Response Team responsible for handling incidents.

Defence and detection

CSP (Content Security Policy)

A browser control that limits which sources a page may load scripts and content from.

Attacks

CSRF

Cross-site request forgery: forcing a logged-in user’s browser to send an unwanted request.

Governance and risk

CTEM

Continuous Threat Exposure Management: a cycle of scoping, discovering, prioritising and validating exposures.

Governance and risk

CVE

A public catalogue that gives known vulnerabilities unique identifiers.

Governance and risk

CVSS

Common Vulnerability Scoring System: a 0-10 score for the severity of a vulnerability.

Attacks

Cyber Attack

A deliberate attempt to steal, damage or disrupt systems or data.

Attacks

Cyber Espionage

Covertly stealing confidential information, often for state or competitive advantage.

Governance and risk

Cyber Security

Protecting systems, networks and data from digital attacks.

Governance and risk

Cyber Security Incident

An event that compromises or threatens the confidentiality, integrity or availability of information.

Defence and detection

Cyber Security Mesh

A flexible architecture that lets separate security tools work together around each identity or asset.

D

Network, cloud and technology

Dark Web / Deep Web

Parts of the internet not indexed by search engines; the dark web is often used for illegal trade.

Defence and detection

Dark Web Monitoring

Watching underground markets and forums for leaked credentials or data of an organisation.

Attacks

Data Breach

Unauthorised access to or disclosure of confidential data.

Attacks

Data Exfiltration

Unauthorised transfer of data out of an organisation.

Network, cloud and technology

Data Mining

Finding patterns in large datasets; privacy rules apply when personal data is involved.

Attacks

DDoS

Distributed denial of service: flooding a service with traffic from many sources to make it unavailable.

Social engineering

Deepfake

AI-generated audio, image or video that imitates a real person, used for fraud and disinformation.

Attacks

Dictionary Attack

Guessing passwords from lists of common words and known passwords.

Governance and risk

Digital Forensics

Collecting and analysing digital evidence to understand what happened, preserving it for legal use.

Network, cloud and technology

DNS

Domain Name System: translates names like example.com into IP addresses.

Attacks

DNS Amplification Attack

A DDoS technique that abuses open DNS servers to multiply attack traffic.

Attacks

DNS Tunneling

Hiding data or commands inside DNS queries to bypass controls.

Attacks

DoS

Denial of service: making a service unavailable to legitimate users.

Social engineering

Doxxing

Publishing someone’s private information online to harass or threaten them.

Attacks

Drive-by Attack

Infection that happens just by visiting a compromised website, without clicking anything.

Social engineering

Dumpster Diving

Searching discarded material for information useful to an attacker.

Governance and risk

Dwell Time

The time an attacker stays undetected in an environment before being found.

E

Defence and detection

EDR

Endpoint detection and response: records endpoint activity to detect, investigate and contain threats.

Social engineering

Email Phishing

Fraudulent e-mails that imitate trusted senders to obtain credentials or deliver malware.

Network, cloud and technology

Endpoint

Any device that connects to the network: laptop, server, phone or virtual machine.

Defence and detection

Endpoint Protection

Security software and policies that protect endpoints from malware and misuse.

Attacks

Enumeration

Collecting details such as users, services and shares from a target to plan an attack.

Defence and detection

EPP

Endpoint protection platform: preventive security for endpoints such as antivirus and device control.

Defence and detection

Event Log / Error Log

Records of what happened on a system; essential for troubleshooting and investigation.

Attacks

Evil Twin Attack

A rogue Wi-Fi access point that imitates a legitimate one to capture traffic.

Attacks

Exploit

Code or technique that takes advantage of a vulnerability.

F

Malware

Fileless Malware

Malware that runs in memory or through legitimate tools, leaving few files to detect.

Defence and detection

FIM (File Integrity Monitoring)

Alerts when critical files or configurations change unexpectedly.

Defence and detection

Firewall

A control that allows or blocks network traffic based on rules.

Attacks

Flooding

Overwhelming a target with a large volume of requests or packets.

Attacks

Fork Bomb

A process that keeps creating copies of itself until system resources are exhausted.

H

Attacks

Hacker

A person with deep technical skill; may be malicious (black hat), authorised (white hat) or in between.

Attacks

Hacktivism

Attacks carried out to promote a political or social cause.

Network, cloud and technology

Hash

A fixed-length fingerprint of data produced by a one-way function; used to check integrity and store passwords.

Defence and detection

HIDS / HIPS

Host-based intrusion detection and prevention systems that monitor a single machine.

Defence and detection

Honeypot

A decoy system built to attract attackers and study their behaviour.

Defence and detection

Human Firewall

Employees who are trained and alert enough to spot and stop attacks.

I

Network, cloud and technology

IaaS

Infrastructure as a service: virtual servers, storage and networks rented from a provider.

Defence and detection

IAM

Identity and access management: controls who can access what, and under which conditions.

Defence and detection

IDS / IPS / IDPS

Systems that detect (IDS) and optionally block (IPS) suspicious network or host activity.

Governance and risk

Incident Response

The organised process of detecting, containing, eradicating and recovering from a security incident.

Governance and risk

Information Security

Protecting the confidentiality, integrity and availability of information in any form.

Defence and detection

Input Validation

Checking data entered by users before processing it, to prevent injection and other attacks.

Attacks

Insider Threat

Risk from people inside the organisation who misuse access, deliberately or by mistake.

Defence and detection

IoA (Indicator of Attack)

A sign that an attack is in progress, based on behaviour and intent.

Defence and detection

IoC (Indicator of Compromise)

Evidence such as a file hash or IP address showing a system was compromised.

Network, cloud and technology

IoT

Internet of things: connected devices such as sensors and cameras, often weakly secured.

Network, cloud and technology

IP Address

A numeric address that identifies a device on a network.

Governance and risk

IRP (Incident Response Plan)

Documented roles and steps to follow when an incident occurs.

Governance and risk

ISMS

Information Security Management System: the policies, processes and controls used to protect information on a risk basis; the subject of ISO 27001.

K

Malware

Keylogger

Software or hardware that records keystrokes to steal passwords and other input.

Governance and risk

KVKK

Turkey’s Personal Data Protection Law no. 6698, which sets obligations for processing personal data and rights of data subjects.

L

Defence and detection

Log Files / Log Monitoring

Records generated by systems and the practice of reviewing them to spot problems or attacks.

Attacks

Log4Shell (Log4j)

A critical 2021 vulnerability in the Log4j logging library that allowed remote code execution.

Malware

Logic Bomb

Malicious code that stays dormant until a specific condition is met.

M

Network, cloud and technology

Machine Learning

Algorithms that learn patterns from data; used to detect anomalies and threats.

Malware

Macro Virus

Malicious macros embedded in documents such as spreadsheets that run when the file is opened.

Attacks

Malvertising

Using online ads to deliver malware or redirect users to malicious sites.

Malware

Malware

Any software designed to harm, spy on or take control of systems.

Defence and detection

Managed SIEM

A SIEM platform operated and monitored for you by a service provider.

Defence and detection

MDR

Managed detection and response: outsourced 24/7 threat monitoring and response by specialists.

Defence and detection

MFA (Multi-Factor Authentication)

Authentication that requires a second proof in addition to the password, such as an app code or hardware key.

Attacks

MITM (Man-in-the-Middle)

An attacker secretly intercepts and possibly alters communication between two parties.

Defence and detection

MITRE ATT&CK

An open knowledge base of attacker tactics and techniques; detection rules and test scenarios are mapped to it.

Governance and risk

MSSP

Managed security service provider that runs security functions for customers.

N

Governance and risk

NOC

Network operations centre: monitors availability and performance of networks.

O

Governance and risk

OWASP

An open community that publishes the most common web application risks (OWASP Top 10) and testing guides.

P

Attacks

Packet Sniffing

Capturing and inspecting network traffic, legitimately for diagnosis or maliciously to steal data.

Defence and detection

Password Manager

A tool that generates and stores strong unique passwords securely.

Attacks

Password Spraying

Trying a few common passwords against many accounts to avoid lockouts.

Defence and detection

Patching

Applying vendor updates to fix known vulnerabilities.

Governance and risk

Penetration Test

A test in which an authorised expert uses an attacker’s perspective to exploit weaknesses and demonstrate real impact.

Social engineering

Phishing

Tricking people with fake messages or sites into revealing credentials or installing malware.

Q

Network, cloud and technology

Quantum Computing

Computing based on quantum physics that could one day break today’s public-key cryptography.

R

Malware

RaaS (Ransomware as a Service)

Criminals rent ready-made ransomware and infrastructure.

Malware

Ransomware

Malware that encrypts data and demands payment for the key.

Governance and risk

Red Team

A broad attack simulation that imitates a real attacker to test an organisation’s detection and response capability.

Governance and risk

Risk Assessment

Identifying threats and vulnerabilities and estimating their likelihood and impact.

Governance and risk

Risk Management

Deciding how to treat risks: reduce, transfer, accept or avoid.

Malware

Rootkit

Malware that hides itself and other malicious activity deep in the operating system.

Governance and risk

RPO (Recovery Point Objective)

The maximum acceptable data loss expressed as time; it drives backup frequency.

Governance and risk

RTO (Recovery Time Objective)

The maximum target time to bring a service back after a disruption.

Governance and risk

Runbook

A step-by-step procedure for handling a recurring task or incident.

S

Network, cloud and technology

SaaS

Software as a service: applications delivered over the internet by a provider.

Defence and detection

SAST / DAST

SAST looks for vulnerabilities in source code, DAST in the running application.

Malware

Scareware

Software that frightens users with fake warnings to make them buy or install something harmful.

Attacks

Script Kiddie

An unskilled attacker who relies on tools written by others.

Network, cloud and technology

SECaaS

Security as a service: security functions delivered by a provider as a subscription.

Defence and detection

Security Awareness Training

Teaching staff to recognise and respond to threats such as phishing.

Governance and risk

Security Posture

The overall strength of an organisation’s defences and its readiness to respond.

Defence and detection

Server Monitoring

Watching servers for availability, performance and suspicious activity.

Governance and risk

Shadow IT

Systems or apps used without the IT or security team’s knowledge or approval.

Social engineering

Shoulder Surfing

Watching someone’s screen or keyboard to learn passwords or data.

Defence and detection

SIEM

Security information and event management: collects and correlates logs and raises alerts.

Social engineering

Smishing

Phishing carried out by text message.

Governance and risk

SoA (Statement of Applicability)

In ISO 27001, the document showing which controls are applied or excluded with a justification.

Governance and risk

SOC

Security operations centre: team and facility that monitor and respond to security events.

Governance and risk

SOCaaS

SOC as a service: monitoring and response operated by a provider.

Social engineering

Social Engineering

Manipulating people into giving up information or performing actions.

Social engineering

Spam

Unsolicited bulk messages, often used to spread scams or malware.

Social engineering

Spear Phishing

Phishing aimed at a specific person or group, using personal details to look credible.

Attacks

Spoofing

Disguising a sender, address or website as a trusted one.

Malware

Spyware

Software that secretly gathers information about a user or organisation.

Attacks

SQL Injection

Inserting malicious SQL into input fields to read or alter a database.

T

Social engineering

Tailgating

Following an authorised person through a secured door without credentials.

Attacks

Threat Actor

An individual or group that carries out or intends to carry out malicious activity.

Defence and detection

Threat Hunting

Proactively searching for hidden threats that automated tools have missed.

Defence and detection

Threat Intelligence

Information about attackers, their tools and methods that helps defenders prepare.

Governance and risk

Threat Management

The ongoing process of identifying, assessing and responding to threats.

Governance and risk

Threat Modelling

Systematically identifying how a system could be attacked and what to do about it.

Network, cloud and technology

TLS

Transport Layer Security: encrypts data in transit, for example HTTPS.

Malware

Trojan

Malware disguised as legitimate software to trick users into installing it.

Social engineering

Typosquatting

Registering look-alike domain names that exploit typing mistakes.

U

Defence and detection

UTM

Unified threat management: several security functions such as firewall and filtering in one appliance.

V

Malware

Virus

Malware that attaches itself to files and spreads when they are run or shared.

Social engineering

Vishing

Phishing carried out by phone call.

Governance and risk

Vulnerability

A weakness in a system that an attacker could exploit.

Governance and risk

Vulnerability Assessment (VA Scan)

Systematic scanning to find, rank and report known weaknesses.

W

Social engineering

Whaling

Phishing aimed at senior executives.

Network, cloud and technology

Wi-Fi

Wireless networking; open or weakly secured networks are common attack points.

Malware

Worm

Malware that spreads by itself across networks without user action.

X

Defence and detection

XDR

Extended detection and response: correlates data across endpoints, network, cloud and e-mail.

Z

Attacks

Zero-Day

A vulnerability unknown to the vendor, with no patch available yet.

Malware

Zombie

An infected computer controlled remotely, typically as part of a botnet.

Is there a topic on your mind?

Let us look together at what these terms mean for your organisation.