Short, plain-language explanations of terms you often meet in information security, cyber security and compliance. Search for a term, filter by topic or browse by letter.
A
Account Takeover (ATO)
Gaining control of someone else’s account, typically with stolen or guessed credentials.
Adware
Software that shows unwanted ads, often bundled with free programs and sometimes tracking behaviour.
AI (Artificial Intelligence)
Systems that perform tasks such as detection, classification or prediction; used by both defenders and attackers.
Allowlist (Whitelisting)
A list of approved items that are the only ones permitted; everything else is blocked.
Angler Phishing
Phishing through fake customer-support accounts on social media that lure users into sharing credentials.
Anti-Malware Software
Software that detects, blocks and removes malicious programs using signatures and behaviour analysis.
Antivirus
Software that scans files and processes to find and remove known viruses and other malware.
Asset
Anything of value to the organisation: data, systems, people, applications or reputation.
Attack Signature
A recognisable pattern of a known attack that security tools use to detect it.
Attack Surface
The sum of all points through which an attacker could try to enter or extract data.
B
Backporting
Applying a fix from a newer software version to an older, still-supported version.
Baiting
A social engineering trick that offers something tempting, such as an infected USB drive, to make victims act.
Beacon
A periodic signal from malware to its controller that confirms it is alive and asks for instructions.
BEC (Business Email Compromise)
Fraud in which attackers impersonate executives or suppliers by e-mail to trigger payments or data disclosure.
BIA (Business Impact Analysis)
An analysis showing which processes a disruption would affect, how quickly and how badly; it underpins RTO and RPO.
Big Data
Very large and fast-growing datasets that need special tools to store and analyse.
Blended Threat
An attack that combines several techniques, such as malware, phishing and exploits, at once.
Blockchain
A distributed ledger where records are linked cryptographically and are hard to alter.
Blocklist (Blacklist)
A list of addresses, files or senders that are denied access.
Botnet
A network of infected devices controlled remotely, used for DDoS, spam or credential attacks.
Brute-Force Attack
Trying many passwords or keys until the right one is found.
C
Caching
Storing copies of data close to the user to speed up access; misconfigured caches can leak data.
CAPTCHA
A challenge that tells humans from automated bots.
CASB
Cloud Access Security Broker: a control point between users and cloud services that enforces security policy.
CEO Fraud
A form of BEC where the attacker poses as a senior executive to request urgent payments.
CERT
Computer Emergency Response Team: a group that coordinates responses to security incidents.
Ciphertext
Data after encryption, unreadable without the key.
Clickjacking
Tricking users into clicking something different from what they see, using hidden or overlaid page elements.
Clone Phishing
Resending a legitimate e-mail with a malicious link or attachment swapped in.
Cloud Computing
Delivering computing resources over the internet on demand instead of owning hardware.
Cloud Firewall
A firewall delivered as a cloud service that filters traffic to and from cloud resources.
CNAPP
Cloud-native application protection platform combining cloud posture, workload and code checks.
Continuous Monitoring
Ongoing, automated observation of systems and controls to detect issues as they appear.
CORS
Cross-Origin Resource Sharing: a browser mechanism that controls which sites may request resources from another origin.
Credential Stuffing
Automatically trying leaked username and password pairs on many services.
Cross-Site Scripting (XSS)
Injecting malicious scripts into pages that other users then run in their browsers.
CRUD
Create, read, update, delete: the four basic data operations; each needs proper authorisation.
Cryptocurrency
Digital currency secured by cryptography, often used for ransom payments.
Cryptojacking
Malware that secretly uses a victim’s computing power to mine cryptocurrency.
CSIRT
Computer Security Incident Response Team responsible for handling incidents.
CSP (Content Security Policy)
A browser control that limits which sources a page may load scripts and content from.
CSRF
Cross-site request forgery: forcing a logged-in user’s browser to send an unwanted request.
CTEM
Continuous Threat Exposure Management: a cycle of scoping, discovering, prioritising and validating exposures.
CVE
A public catalogue that gives known vulnerabilities unique identifiers.
CVSS
Common Vulnerability Scoring System: a 0-10 score for the severity of a vulnerability.
Cyber Attack
A deliberate attempt to steal, damage or disrupt systems or data.
Cyber Espionage
Covertly stealing confidential information, often for state or competitive advantage.
Cyber Security
Protecting systems, networks and data from digital attacks.
Cyber Security Incident
An event that compromises or threatens the confidentiality, integrity or availability of information.
Cyber Security Mesh
A flexible architecture that lets separate security tools work together around each identity or asset.
D
Dark Web / Deep Web
Parts of the internet not indexed by search engines; the dark web is often used for illegal trade.
Dark Web Monitoring
Watching underground markets and forums for leaked credentials or data of an organisation.
Data Breach
Unauthorised access to or disclosure of confidential data.
Data Exfiltration
Unauthorised transfer of data out of an organisation.
Data Mining
Finding patterns in large datasets; privacy rules apply when personal data is involved.
DDoS
Distributed denial of service: flooding a service with traffic from many sources to make it unavailable.
Deepfake
AI-generated audio, image or video that imitates a real person, used for fraud and disinformation.
Dictionary Attack
Guessing passwords from lists of common words and known passwords.
Digital Forensics
Collecting and analysing digital evidence to understand what happened, preserving it for legal use.
DNS
Domain Name System: translates names like example.com into IP addresses.
DNS Amplification Attack
A DDoS technique that abuses open DNS servers to multiply attack traffic.
DNS Tunneling
Hiding data or commands inside DNS queries to bypass controls.
DoS
Denial of service: making a service unavailable to legitimate users.
Doxxing
Publishing someone’s private information online to harass or threaten them.
Drive-by Attack
Infection that happens just by visiting a compromised website, without clicking anything.
Dumpster Diving
Searching discarded material for information useful to an attacker.
Dwell Time
The time an attacker stays undetected in an environment before being found.
E
EDR
Endpoint detection and response: records endpoint activity to detect, investigate and contain threats.
Email Phishing
Fraudulent e-mails that imitate trusted senders to obtain credentials or deliver malware.
Endpoint
Any device that connects to the network: laptop, server, phone or virtual machine.
Endpoint Protection
Security software and policies that protect endpoints from malware and misuse.
Enumeration
Collecting details such as users, services and shares from a target to plan an attack.
EPP
Endpoint protection platform: preventive security for endpoints such as antivirus and device control.
Event Log / Error Log
Records of what happened on a system; essential for troubleshooting and investigation.
Evil Twin Attack
A rogue Wi-Fi access point that imitates a legitimate one to capture traffic.
Exploit
Code or technique that takes advantage of a vulnerability.
F
Fileless Malware
Malware that runs in memory or through legitimate tools, leaving few files to detect.
FIM (File Integrity Monitoring)
Alerts when critical files or configurations change unexpectedly.
Firewall
A control that allows or blocks network traffic based on rules.
Flooding
Overwhelming a target with a large volume of requests or packets.
Fork Bomb
A process that keeps creating copies of itself until system resources are exhausted.
H
Hacker
A person with deep technical skill; may be malicious (black hat), authorised (white hat) or in between.
Hacktivism
Attacks carried out to promote a political or social cause.
Hash
A fixed-length fingerprint of data produced by a one-way function; used to check integrity and store passwords.
HIDS / HIPS
Host-based intrusion detection and prevention systems that monitor a single machine.
Honeypot
A decoy system built to attract attackers and study their behaviour.
Human Firewall
Employees who are trained and alert enough to spot and stop attacks.
I
IaaS
Infrastructure as a service: virtual servers, storage and networks rented from a provider.
IAM
Identity and access management: controls who can access what, and under which conditions.
IDS / IPS / IDPS
Systems that detect (IDS) and optionally block (IPS) suspicious network or host activity.
Incident Response
The organised process of detecting, containing, eradicating and recovering from a security incident.
Information Security
Protecting the confidentiality, integrity and availability of information in any form.
Input Validation
Checking data entered by users before processing it, to prevent injection and other attacks.
Insider Threat
Risk from people inside the organisation who misuse access, deliberately or by mistake.
IoA (Indicator of Attack)
A sign that an attack is in progress, based on behaviour and intent.
IoC (Indicator of Compromise)
Evidence such as a file hash or IP address showing a system was compromised.
IoT
Internet of things: connected devices such as sensors and cameras, often weakly secured.
IP Address
A numeric address that identifies a device on a network.
IRP (Incident Response Plan)
Documented roles and steps to follow when an incident occurs.
ISMS
Information Security Management System: the policies, processes and controls used to protect information on a risk basis; the subject of ISO 27001.
K
Keylogger
Software or hardware that records keystrokes to steal passwords and other input.
KVKK
Turkey’s Personal Data Protection Law no. 6698, which sets obligations for processing personal data and rights of data subjects.
L
Log Files / Log Monitoring
Records generated by systems and the practice of reviewing them to spot problems or attacks.
Log4Shell (Log4j)
A critical 2021 vulnerability in the Log4j logging library that allowed remote code execution.
Logic Bomb
Malicious code that stays dormant until a specific condition is met.
M
Machine Learning
Algorithms that learn patterns from data; used to detect anomalies and threats.
Macro Virus
Malicious macros embedded in documents such as spreadsheets that run when the file is opened.
Malvertising
Using online ads to deliver malware or redirect users to malicious sites.
Malware
Any software designed to harm, spy on or take control of systems.
Managed SIEM
A SIEM platform operated and monitored for you by a service provider.
MDR
Managed detection and response: outsourced 24/7 threat monitoring and response by specialists.
MFA (Multi-Factor Authentication)
Authentication that requires a second proof in addition to the password, such as an app code or hardware key.
MITM (Man-in-the-Middle)
An attacker secretly intercepts and possibly alters communication between two parties.
MITRE ATT&CK
An open knowledge base of attacker tactics and techniques; detection rules and test scenarios are mapped to it.
MSSP
Managed security service provider that runs security functions for customers.
N
NOC
Network operations centre: monitors availability and performance of networks.
O
OWASP
An open community that publishes the most common web application risks (OWASP Top 10) and testing guides.
P
Packet Sniffing
Capturing and inspecting network traffic, legitimately for diagnosis or maliciously to steal data.
Password Manager
A tool that generates and stores strong unique passwords securely.
Password Spraying
Trying a few common passwords against many accounts to avoid lockouts.
Patching
Applying vendor updates to fix known vulnerabilities.
Penetration Test
A test in which an authorised expert uses an attacker’s perspective to exploit weaknesses and demonstrate real impact.
Phishing
Tricking people with fake messages or sites into revealing credentials or installing malware.
Q
Quantum Computing
Computing based on quantum physics that could one day break today’s public-key cryptography.
R
RaaS (Ransomware as a Service)
Criminals rent ready-made ransomware and infrastructure.
Ransomware
Malware that encrypts data and demands payment for the key.
Red Team
A broad attack simulation that imitates a real attacker to test an organisation’s detection and response capability.
Risk Assessment
Identifying threats and vulnerabilities and estimating their likelihood and impact.
Risk Management
Deciding how to treat risks: reduce, transfer, accept or avoid.
Rootkit
Malware that hides itself and other malicious activity deep in the operating system.
RPO (Recovery Point Objective)
The maximum acceptable data loss expressed as time; it drives backup frequency.
RTO (Recovery Time Objective)
The maximum target time to bring a service back after a disruption.
Runbook
A step-by-step procedure for handling a recurring task or incident.
S
SaaS
Software as a service: applications delivered over the internet by a provider.
SAST / DAST
SAST looks for vulnerabilities in source code, DAST in the running application.
Scareware
Software that frightens users with fake warnings to make them buy or install something harmful.
Script Kiddie
An unskilled attacker who relies on tools written by others.
SECaaS
Security as a service: security functions delivered by a provider as a subscription.
Security Awareness Training
Teaching staff to recognise and respond to threats such as phishing.
Security Posture
The overall strength of an organisation’s defences and its readiness to respond.
Server Monitoring
Watching servers for availability, performance and suspicious activity.
Shadow IT
Systems or apps used without the IT or security team’s knowledge or approval.
Shoulder Surfing
Watching someone’s screen or keyboard to learn passwords or data.
SIEM
Security information and event management: collects and correlates logs and raises alerts.
Smishing
Phishing carried out by text message.
SoA (Statement of Applicability)
In ISO 27001, the document showing which controls are applied or excluded with a justification.
SOC
Security operations centre: team and facility that monitor and respond to security events.
SOCaaS
SOC as a service: monitoring and response operated by a provider.
Social Engineering
Manipulating people into giving up information or performing actions.
Spam
Unsolicited bulk messages, often used to spread scams or malware.
Spear Phishing
Phishing aimed at a specific person or group, using personal details to look credible.
Spoofing
Disguising a sender, address or website as a trusted one.
Spyware
Software that secretly gathers information about a user or organisation.
SQL Injection
Inserting malicious SQL into input fields to read or alter a database.
T
Tailgating
Following an authorised person through a secured door without credentials.
Threat Actor
An individual or group that carries out or intends to carry out malicious activity.
Threat Hunting
Proactively searching for hidden threats that automated tools have missed.
Threat Intelligence
Information about attackers, their tools and methods that helps defenders prepare.
Threat Management
The ongoing process of identifying, assessing and responding to threats.
Threat Modelling
Systematically identifying how a system could be attacked and what to do about it.
TLS
Transport Layer Security: encrypts data in transit, for example HTTPS.
Trojan
Malware disguised as legitimate software to trick users into installing it.
Typosquatting
Registering look-alike domain names that exploit typing mistakes.
U
UTM
Unified threat management: several security functions such as firewall and filtering in one appliance.
V
Virus
Malware that attaches itself to files and spreads when they are run or shared.
Vishing
Phishing carried out by phone call.
Vulnerability
A weakness in a system that an attacker could exploit.
Vulnerability Assessment (VA Scan)
Systematic scanning to find, rank and report known weaknesses.
W
Whaling
Phishing aimed at senior executives.
Wi-Fi
Wireless networking; open or weakly secured networks are common attack points.
Worm
Malware that spreads by itself across networks without user action.
X
XDR
Extended detection and response: correlates data across endpoints, network, cloud and e-mail.
Z
Zero-Day
A vulnerability unknown to the vendor, with no patch available yet.
Zombie
An infected computer controlled remotely, typically as part of a botnet.
No terms match your search.
Is there a topic on your mind?
Let us look together at what these terms mean for your organisation.