Table of Contents

Cyber Security Glossary: Essential Terms for Modern Businesses

Reviewed & Written by:

|

Published:

|

Updated:

September 27, 2026
Glossary
Table of Contents
Cybersecurity moves fast. This cyber security glossary is a practical, business-focused reference curated by Cyphere for all organisations that need to cut through the jargon and speak the same language across technical teams, leadership, and external partners. This glossary is designed for security leaders, IT professionals, and non-technical stakeholders who need to understand and communicate about cyber security
 
New threats, regulations, and tools emerge every quarter, and the language used to describe them can be just as overwhelming as the risks themselves. Whether you are preparing for a penetration test, working toward ISO 27001 certification, or explaining risk to your board, you will find plain-English definitions here for the cyber security terms that matter most.  

This glossary is aligned with common UK/EU frameworks and regulations including Cyber Essentials, NIS2, DORA, ISO 27001, and NIST CSF, and reflects Cyphere’s consulting and penetration testing experience since 2020. It is current as of late 2026, and Cyphere regularly updates terms as cyber threats and regulations evolve.

How We Chose and Explained the Cyber Security Terms

Rather than listing every possible acronym, we selected terms based on real-world relevance across hundreds of engagements. Our criteria for inclusion:

  • Relevance to UK/EU businesses undergoing security validation such as penetration testing, or compliance challenges arund Cyber Essentials, ISO 27001, PCI DSS, and NIS2/DORA preparations.

  • Direct link to cyber risk, incident response, or day-to-day IT and security operations (e.g. EDR, SIEM, NAC, identity and access management, micro-segmentation).

  • Coverage of both technical concepts (e.g. CVE, CVSS, XSS, YAML) and governance/compliance language (e.g. GRC, CAF, risk tolerance, operational resilience).

  • Inclusion of modern cloud computing and DevOps concepts that drive posture management (e.g. CSPM, CWPP, IaC, drift, CTEM, ODM).

  • Balance between attacker terminology (e.g. kill chain, lateral movement, C2 servers, pass-the-hash) and defender terminology (e.g. safe remediation, policy validation, security controls optimisation).

Each entry stays concise and avoids vendor-specific language.

Why understanding cyber security terminology matters?

A shared understanding of cyber security terms is essential for effective risk management, compliance, and incident response. This creates a positive culture of innovation, ensuring cyber security is an enabler for entire organisations’ success and not just security team’s motive.

Cyphere’s Top Cyber Security Terms to Learn First

This section highlights the most important concepts to understand before diving into the full A–Z glossary below.

1. Cybersecurity

Cybersecurity is the practice of protecting information systems, computer networks, cloud services, and operational technology from cyber attacks, misuse, and disruption. It spans technology, people, and processes and underpins every service Cyphere delivers, from penetration testing to managed security. The CIA Triad, consisting of Confidentiality, Integrity, and Availability, forms the foundation of information security and is the lens through which every security decision should be evaluated. Cybersecurity is the umbrella concept for every other entry in this glossary.

2. Cyber Attack

A cyber attack is any deliberate attempt to compromise confidentiality, integrity, or availability of systems or data. Examples include ransomware that encrypts files and demands payment, DDoS floods that exhaust system resources, phishing campaigns designed to trick users into surrendering credentials, injection attacks that insert malicious code into applications, and lateral movement using pass-the-hash techniques. Understanding attack paths and kill chains helps structure penetration tests and incident response playbooks so defenders can disrupt adversaries at every stage.

cyber kill chain

3. Vulnerability

A vulnerability is a weakness in a computer system, process, or people that can be exploited by a threat actor. An exploit takes advantage of a vulnerability to cause unintended behaviour, while an un-patchable vulnerability is a flaw that cannot be fixed by vendor patches (e.g. legacy OT, unsupported operating system). The CVE catalogue assigns unique IDs to known security vulnerabilities, and CVSS provides a standardised severity score from 0.0 to 10.0. Cyphere’s vulnerability assessment and penetration testing services identify exploitable weaknesses and support safe remediation so organisations can close gaps before attackers find them. Penetration testing identifies vulnerabilities in systems through controlled, authorised simulations.

4. Risk Assessment

Risk assessment is a structured process to identify, analyse, and prioritise cyber risks, including mapping the attack surface and estimating likelihood and impact. Risk is the potential for loss due to a threat exploiting a vulnerability. Risk assessment underpins governance, risk and compliance (GRC), Cyber Essentials, ISO 27001, and operational resilience decisions. It also establishes the relationship between risk tolerance and acceptable risk, giving business leaders the information they need to make informed investment and remediation decisions. Learn more in Cyphere’s guide on how to perform a cyber security risk assessment.

5. Security Posture

Security posture is the overall strength and maturity of an organisation’s security controls across endpoints, network, cloud, OT, and users. Maintaining and improving posture requires continuous monitoring through tools and programmes such as CTEM, CSPM, CWPP, SOC operations, and XDR. Cyphere’s continuous risk remediation and security controls optimisation services help organisations measure and strengthen posture over time rather than relying on point-in-time assessments.

6. Penetration Testing

Penetration testing is a CREST-accredited, authorised simulated attack designed to identify exploitable weaknesses across networks, applications, cloud environments, and OT. Unlike a vulnerability assessment, which scans for known issues, a pen test actively explores kill chains, lateral movement, and privilege escalation to show how an attacker could gain access and what damage they could do. Cyphere uses pen testing as a starting point for remediation and ongoing advisory, not just a report-and-run exercise. For a comparison of approaches, see Vulnerability Assessment vs Penetration Testing.

7. Incident Response

Incident response is the organised set of actions to detect, contain, eradicate, and recover from security incidents. It is a structured approach to managing cyber incidents, and effective incident response reduces recovery time and costs. Incident handling includes preparation, identification, and recovery steps, and the goal of incident response is to prevent future attacks. Incident response minimises damage from cybersecurity incidents by connecting the security operations center, SIEM, SOAR, MTTD, MTTR, and audit logs into a coordinated workflow. Having playbooks aligned to frameworks like NIST and CAF is critical for resilience and regulatory expectations under NIS2 and DORA. See Cyphere’s guide on building a cyber security incident response plan.

Here’s our modern A-Z glossary covering cyber security terms, definitions, acronyms. 

A

Access Control List (ACL)

A set of rules applied to network devices, files, or cloud security groups that permit or deny specific access to system resources. ACLs are a foundational mechanism for enforcing access control, which defines who can view or use resources in a computing environment.

Access Logging

The practice of recording each attempt to access a system, application, or resource, creating an audit trail for security analysis, compliance evidence, and forensics.

Account Takeover (ATO)

An attack where a malicious actor gains unauthorized access to a user’s account, typically through credential stuffing, phishing, or brute force attack methods, to steal data or commit fraud.

Active Directory

Microsoft’s directory service for centralised management of users, groups, computers, and policies in Windows environments, used by most enterprises to control network access and enforce security policy.

Active Directory Auditing

The process of monitoring and recording changes to Active Directory objects, permissions, and configurations to detect suspicious activity and maintain data integrity.

Active Directory Security

The discipline of hardening Active Directory against attacks such as pass-the-hash, privilege escalation, Golden Ticket attacks, and GPO abuse, which are common targets during penetration tests.

Address Resolution Protocol (ARP) Spoofing

An attack where a threat actor sends forged ARP messages on a LAN to link their MAC address to a legitimate IP address, enabling them to intercept, modify, or stop data packets in transit.

Address Space Layout Randomization (ASLR)

A memory protection technique used by the operating system to randomise the location of key data areas in memory, making it harder for attackers to exploit buffer overflow vulnerabilities.

ADFS (Active Directory Federation Services)

A Microsoft service providing single sign-on (SSO) and federated identity across organisational boundaries, allowing users to authenticate once and gain access to multiple applications.

Advanced Encryption Standard (AES)

A widely adopted symmetric cryptographic algorithm used to protect encrypted data at rest and in transit, considered the gold standard for government and enterprise encryption.

Advanced Persistent Threat (APT)

An advanced persistent threat APT is a targeted cyberattack where an intruder gains access to a network and remains undetected for an extended period, often backed by nation-state resources and motivated by espionage or strategic objectives rather than immediate financial gain.

Adversarial AI

The use of artificial intelligence techniques to evade, manipulate, or defeat security solutions, including generating polymorphic malware, bypassing detection models, and crafting convincing phishing content.

Adversary-in-the-Middle (AiTM) Attack

An attack where the adversary positions themselves between two communicating parties to intercept and potentially alter data in transit, often used to capture authentication tokens and bypass multi factor authentication.

Adware

Malicious software that displays unwanted advertisements on devices, often bundled with free applications. Adware can degrade performance and serve as a vector for more dangerous malware.

Adware Protection

Security tools and browser configurations designed to detect and block adware before it can install or display unwanted content on endpoints.

Agent

A lightweight software component installed on an endpoint or server that collects telemetry, enforces policies, or enables remote management by security and IT platforms.

Agent vs Agentless

Agent-based security deploys software on each endpoint for deep visibility, while agentless approaches use APIs or network scanning to monitor without installing software, each offering different trade-offs in coverage and overhead.

Agentic AI Security

The emerging discipline of securing autonomous AI agents that can make decisions, execute actions, and interact with other systems, ensuring they cannot be manipulated to bypass security measures.

AI Security Specialist

A cybersecurity professional focused on securing machine learning models, AI pipelines, and related information processing services against adversarial manipulation, data poisoning, and prompt injection attacks.

Air Gap Security

A security approach where critical systems are physically isolated from unsecured networks, preventing attackers from using network-based attack vectors to gain access to sensitive or classified data.

Air Gap/Wall

The physical or logical separation between a secured network and any external connection, commonly used in industrial control systems, military environments, and systems holding sensitive information.

Air Gapping

The practice of isolating a computer system or network by ensuring it has no direct connection to the internet or other unsecured networks, used to protect distributed control systems and critical infrastructure.

Algorithm

A defined set of rules or calculations used to solve problems or process data, underpinning everything from encryption keys and hashing to machine learning models in cybersecurity.

Allowlisting

A security practice that permits only explicitly approved applications, IP addresses, or domains to run or communicate, blocking everything else by default. Sometimes called whitelisting.

AnonFiles

A formerly popular anonymous file-sharing service that was frequently abused to distribute malware, stolen credentials, and exfiltrated data before its shutdown.

Anonymizer

A tool or service, such as the Tor network, that hides a user’s identity and IP addresses online, used legitimately for privacy and by threat actors to obscure malicious intent.

Anti-Fraud System

Technology and processes designed to detect and prevent fraudulent transactions, identity theft, and financial manipulation across digital channels.

Anti-Spyware

Security software designed to detect, quarantine, and remove spyware that secretly collects user data without consent from endpoints and mobile devices.

Antivirus (AV)

Antivirus software is designed to detect and block known malware signatures, often integrated into modern EDR/XDR platforms. Its limitations against fileless malware, zero-day exploits, and advanced ransomware mean organisations should not rely on it alone.

Antivirus Affiliate Program

A marketing model where third parties promote antivirus software in exchange for commission, sometimes abused to distribute scareware or potentially unwanted applications.

API Gateway

A server that acts as a single entry point for API requests, handling authentication, rate limiting, and routing while providing a layer of network security between clients and backend services.

API Security

The practice of protecting application programming interfaces from attacks such as injection, broken authentication, and excessive data exposure, critical for modern web server architectures and mobile device applications.

App Server

A server that hosts and runs business applications, sitting between the user interface and backend databases, requiring hardening and access management to prevent exploitation.

Application Access

Policies and controls governing which users, roles, or devices can interact with specific applications, typically managed through identity and access management platforms.

Application Definition

The formal documentation of an application’s components, dependencies, data flows, and security requirements, essential for threat modelling and risk assessment.

Application Delivery Controller

A network device that optimises, secures, and manages the delivery of web applications, often providing load balancing, SSL termination, and web application firewall capabilities.

Application Exploit

A technique or payload that takes advantage of a vulnerability in application code or logic to gain unauthorized access or execute malicious code on the target system.

Application Performance Monitoring

Tools that track application speed, errors, and resource usage, which also provide observability data useful for detecting anomalies that may indicate a cyber attack.

Application Repacking

A technique where attackers decompile a legitimate mobile application, inject malicious code, and redistribute it, commonly used in mobile malware campaigns.

Application Security Engineer

A professional responsible for designing, testing, and maintaining security controls within software applications throughout the development lifecycle.

Application Security Orchestration and Correlation (ASOC)

A platform that aggregates findings from multiple application security tools (SAST, DAST, SCA), correlates results, and prioritises remediation to reduce noise.

Application Security Posture Management (ASPM)

A discipline and toolset that provides continuous visibility into the security posture of applications, tracking vulnerabilities, misconfigurations, and compliance across the software lifecycle.

Application Services

The collection of capabilities, from load balancing to WAFs, that support secure and reliable delivery of applications to end users and other systems.

Application Whitelisting

A security control that only allows pre-approved applications to execute on a system, preventing malicious software and unauthorised tools from running.

AppSec

Short for application security, the practice of finding, fixing, and preventing security vulnerabilities in software throughout its development and deployment.

APT Group

A named set of threat actors, often state-sponsored, that conducts advanced persistent threat campaigns against specific industries, governments, or organisations over extended periods.

ARP Spoofing

An attack on a local area network where forged ARP packets are sent to associate the attacker’s MAC address with a legitimate network resource, enabling interception of network traffic.

Artificial Intelligence

The simulation of human intelligence by computer systems, used in cybersecurity for threat detection, behavioural analytics, automated response, and increasingly by attackers for evasion and social engineering.

Asset

Any resource of value to an organisation, including hardware, software, data, intellectual property, and people, that must be protected through security controls.

Asymmetric Algorithm

A cryptographic algorithm that uses a pair of keys, a public key and a private key, for encryption and decryption, enabling secure exchange of data and digital signatures without sharing a secret key.

Attack Vector

The specific method or pathway an attacker uses to gain network access or breach a system, such as phishing emails, exposed RDP ports, or supply chain compromise.

IT security terms

Audit Event

A recorded occurrence within a system that has security significance, such as a login attempt, configuration change, or permission modification, stored for analysis and compliance.

Audit File

A file containing recorded audit events, used for forensic investigation, compliance reporting, and continuous monitoring of system activity.

Audit Log

Time-stamped records of security-relevant events across IT systems, including logins, changes, and admin actions, essential for SIEM, forensics, and compliance evidence under ISO 27001, NIS2, and DORA.

Authentication

The process of verifying user identity before granting access to systems or data. Multi-factor authentication requires two or more verification methods, such as passwords and tokens, significantly strengthening this control.

Automated Threat Intelligence

Systems that automatically collect, analyse, and distribute threat data from multiple sources, enabling faster detection and response to emerging cyber threats.

AutoScanning

The automated, scheduled scanning of network resources, endpoints, and applications for security vulnerabilities without manual intervention.

AWS Cloud Security

The set of security tools, services, and best practices specific to Amazon Web Services, including IAM policies, security groups, encryption, and logging for protecting cloud workloads and computing resources.

B

Backdoor Attack

An attack that exploits a hidden method of bypassing normal authentication to gain remote, unauthorised access to a computer system, often installed by malware or left by developers.

Backup

Copies of data stored separately for recovery after data loss, corruption, or ransomware. Backups are a critical component of any business continuity plan and disaster recovery plan.

BAT File

A batch file containing a sequence of commands executed by the Windows command interpreter, sometimes abused by attackers to automate malicious actions on compromised systems.

Behavioral Analytics

Analysis of user and entity behaviour patterns to identify anomalies that may indicate insider threats, compromised accounts, or malicious intent, closely related to UBA/UEBA.

Big Game Hunting

A ransomware strategy where attackers specifically target large, high-revenue organisations to demand substantial ransom payments, often using sophisticated techniques to maximise leverage.

Binary Code

The machine-readable representation of software as sequences of 0s and 1s, analysed during malware reverse engineering and forensic investigation.

Black Hat

A malicious hacker who breaks into computer networks and systems for criminal or personal gain, operating without authorisation and often with malicious intent.

Blackholing

A network defence technique where malicious or unwanted network traffic is silently dropped, often used as an emergency DDoS mitigation measure by upstream providers.

Blockchain Security Expert

A cybersecurity professional specialising in securing blockchain networks, smart contracts, and cryptocurrency platforms against exploits and fraud.

Blocklist

A list of entities such as IP addresses, domains, or applications that are explicitly denied access or execution, used in firewalls, email gateways, and endpoint protection.

Blue Screen of Death (BSOD)

A Windows stop error screen indicating a critical system failure. While often caused by driver or hardware faults, frequent BSODs can be symptoms of malware or rootkit activity.

Blue Team

The defensive security team responsible for monitoring, detecting, and responding to security threats, maintaining security posture, and implementing security measures within an organisation.

Bluejacking

Sending unsolicited messages to nearby Bluetooth-enabled devices, generally a low-risk nuisance but can be a precursor to more serious Bluetooth attacks.

Bluesnarfing

Gaining unauthorized access to data on a Bluetooth-enabled mobile device, including contacts, emails, and messages, by exploiting Bluetooth protocol vulnerabilities.

Boot Sector

The area of a storage device that contains code executed during system startup, targeted by bootkits and certain viruses to gain persistence before the operating system loads.

Bootkit

A type of rootkit that infects the boot sector or firmware to execute malicious code before the operating system starts, making it extremely difficult to detect and remove.

Bot Activity

Automated actions performed by software bots on networks and applications, ranging from legitimate web crawling to malicious credential stuffing and DDoS participation.

Bot Cybersecurity

The discipline of identifying and mitigating automated threats from malicious bots that target web applications, APIs, and network resources.

Bot Mitigation

Security solutions that distinguish between legitimate users and malicious bots, blocking automated threats such as credential stuffing, scraping, and denial-of-service activity.

Botnet

A botnet is a collection of compromised computers controlled remotely via C2 servers, often used for DDoS attacks, credential stuffing, spam distribution, and to steal data from targeted organisations.

Bracketing

A testing technique where boundary values are tested to identify vulnerabilities in input validation, commonly used during penetration testing of web applications.

Brandjacking

The act of assuming a company’s online identity to damage its reputation, phish customers, or commit fraud, often involving domain spoofing or social media impersonation.

Bring Your Own Device (BYOD)

The practice of employees using personal devices for work access. BYOD increases the risk of data breaches because personal devices may lack adequate security controls. Malware can spread more easily through personal devices, employees may unintentionally expose sensitive data, and BYOD policies can lead to compliance issues if not managed with MDM, NAC, and zero trust controls.

Browser Extension

A software add-on for web browsers that can extend functionality but may also introduce security risks if malicious or poorly maintained, contributing to browser misuse.

Browser Helper Object

A DLL module designed as a plugin for Internet Explorer, historically exploited by adware and spyware to monitor browsing activity and inject content.

Brute Force Attack

A brute force attack is a trial-and-error method to guess user credentials or encryption keys by systematically trying every possible combination until the correct one is found, often automated with specialised tools.

BSOD

See Blue Screen of Death.

Bug Bounty Hunter

An ethical security researcher who identifies and reports security vulnerabilities in exchange for monetary rewards through organised bug bounty programmes.

Built-in Tools

Native utilities included with an operating system, such as PowerShell or cmd, that attackers can abuse in living-off-the-land (LOTL) techniques to evade detection.

Bulletproof Hosting

Hosting services that knowingly allow malicious content, C2 servers, and criminal infrastructure to operate, ignoring takedown requests from law enforcement.

Business Compliance Regulations

Legal and industry requirements, such as GDPR, PCI DSS, and NIS2, that mandate specific data protection and security practices for organisations handling sensitive data.

Business Email Compromise (BEC)

A targeted scam where attackers impersonate a trusted figure, often a CEO or supplier, via email to trick users into transferring funds or sharing sensitive information.

C

Canaries

Decoy files, tokens, or services placed within a network to detect unauthorised access early; when an attacker interacts with a canary, it triggers an alert.

CAPTCHA

A challenge-response test used to determine whether a user is human, helping prevent automated bots from abusing login forms, registration pages, and comment sections.

Carding

The illegal practice of using stolen credit card data to make fraudulent purchases or verify card validity, often facilitated through dark web marketplaces.

Cash App Scam

Fraud schemes targeting users of mobile payment platforms through phishing, social engineering, or fake giveaway promotions to steal funds or credentials.

Centralized Logging

Aggregating log data from multiple systems into a single platform for analysis, correlation, and compliance, forming the foundation of SIEM and continuous monitoring.

Chain of Trust

A hierarchy of digital certificates where each certificate is verified by the one above it, ensuring the authenticity of encryption keys, software, and communications.

CIS Benchmarks

Secure configuration guidelines published by the Center for Internet Security for hardening operating systems, cloud platforms, databases, and network devices against known security threats.

CISO

The Chief Information Security Officer, the senior executive responsible for establishing and maintaining the organisation’s security strategy, governance, and risk management programme.

Click Fraud

The practice of generating fake clicks on pay-per-click advertisements to drain an advertiser’s budget, often carried out by bots or botnets.

ClickFake Interview

A social engineering attack where threat actors pose as recruiters conducting fake job interviews to trick victims into downloading malware or revealing credentials.

Clickjacking

An attack where a user is tricked into clicking a disguised element on a webpage, unknowingly performing an unintended action such as changing settings or authorising a transaction.

Clientless VPN

A virtual private network solution that does not require dedicated client software, typically using a web browser and SSL/TLS to provide remote access to network resources.

Closed-Source Software

Software whose source code is not publicly available, meaning security relies on the vendor’s practices and independent security testing rather than community review.

Cloud Access Security Broker (CASB)

A security policy enforcement point between cloud service users and providers that monitors activity, enforces data protection policies, and provides visibility into shadow IT.

Cloud Application Security

The practice of securing applications deployed in cloud computing environments through configuration management, access control, encryption, and continuous monitoring.

Cloud Based

Refers to services, storage, or computing resources delivered over the internet rather than on local hardware, with shared-responsibility security models between provider and customer.

Cloud Compliance Solutions

Tools and services that help organisations meet regulatory requirements such as GDPR, PCI DSS, and NIS2 within their cloud computing environments.

Cloud Compromise Assessment

An evaluation of cloud environments to identify indicators of compromise, misconfigurations, and evidence of past or ongoing breaches.

Cloud Computing

Cloud computing is the on-demand delivery of computing resources including servers, storage, databases, and applications over the internet, provided by platforms such as AWS, Azure, and GCP.

Cloud Data Security

The protection of data stored in cloud environments through encryption, access management, data loss prevention, and compliance controls.

Cloud Governance

The framework of policies, roles, and processes that ensure cloud resources are used securely, cost-effectively, and in compliance with organisational and regulatory requirements.

Cloud Incident Response

The adapted practice of incident response for cloud environments, accounting for shared responsibility, provider APIs, ephemeral resources, and multi-tenant architectures.

Cloud Native

Applications designed from the ground up to run in cloud environments, leveraging containers, microservices, and serverless architectures, each with distinct security considerations.

Cloud Networking

The infrastructure and services that connect cloud-based resources, including virtual networks, load balancers, and DNS, requiring proper segmentation and data protection.

Cloud Security Architecture

The design of security controls within cloud environments, covering identity, network segmentation, encryption, logging, and incident detection across IaaS, PaaS, and SaaS.

Cloud Security Best Practices

Proven approaches for securing cloud infrastructure, including least privilege IAM, encryption of data at rest and data in transit, CSPM, and infrastructure as code security scanning.

Cloud Security Frameworks

Structured guidelines such as CSA Cloud Controls Matrix, NIST, and ISO 27017 that help organisations assess and improve cloud security posture.

Cloud Workload Protection (CWP)

Solutions that protect running workloads, including virtual machines, containers, and serverless functions, from runtime threats, vulnerability exploitation, and malicious software.

Code Security

The practice of identifying and remediating security vulnerabilities within application source code through static analysis, peer review, and secure coding standards.

Cold Storage

Data or cryptographic material stored offline, physically isolated from the network to protect it from cyber attacks and unauthorized access.

Command and Control Center

Infrastructure used by attackers to remotely direct compromised systems, send commands, and exfiltrate data, often detected through analysis of network traffic anomalies.

Common Cash App Scams

Recurring fraud patterns on mobile payment platforms, including fake customer support, refund scams, and phishing links designed to steal data.

Compiler Security

The practice of using compiler-level security features, such as stack canaries and ASLR, to harden compiled software against memory corruption exploits.

Compliance Analyst

A professional responsible for assessing and ensuring an organisation’s adherence to regulatory and industry security requirements such as ISO 27001, PCI DSS, and NIS2.

Computer Virus

A virus is a type of malicious software that attaches itself to a legitimate program and replicates when executed, spreading to other systems. Modern malware campaigns often go far beyond simple viruses.

Computer Worm

Worms replicate themselves to spread across computer networks without requiring user interaction, often exploiting security vulnerabilities in operating systems or services.

Conditional Access

Policy-based access control that evaluates conditions such as user identity, device compliance, location, and risk level before granting access to resources.

Configuration Management Tools

Software that automates the provisioning, configuration, and management of IT systems, helping maintain security baselines and detect drift across infrastructure.

ConsentFix

A solution focused on managing consent and privacy preferences to help organisations comply with data privacy regulations like GDPR.

Container

A lightweight, isolated runtime environment, such as a Docker container or Kubernetes pod, used in modern DevOps to package and run applications consistently across environments.

Container Security

The practice of securing container images, runtime environments, orchestration platforms, and secrets management against vulnerabilities, misconfiguration, and malicious code injection.

Containerization

The process of packaging applications with their dependencies into containers, which introduces specific security challenges including image hardening, drift detection, and IaC scanning.

Conti Ransomware

A high-profile ransomware-as-a-service operation that targeted organisations globally before its infrastructure was disrupted, known for double-extortion tactics and rapid encryption.

Continuous Monitoring

The ongoing, automated observation of IT systems, networks, and security controls to detect security threats, policy violations, and configuration changes in real time.

Cookie

A small data file stored by a web browser that tracks user sessions and preferences; cookies can be hijacked through XSS or session fixation attacks to gain unauthorized access.

Credential Stuffing

An automated attack that uses lists of stolen username-password pairs to attempt logins across multiple services, exploiting password reuse to gain access to accounts.

Credential Theft

The act of stealing authentication credentials through techniques such as phishing, keylogging, or memory dumping tools like Mimikatz to gain unauthorized access to systems.

Cross-Site Request Forgery (CSRF)

A web vulnerability where an attacker tricks an authenticated user’s browser into sending an unintended request to a web server, performing actions without the user’s knowledge.

Cross-Site Scripting (XSS)

XSS is a web application vulnerability allowing attackers to inject and run malicious scripts in users’ browsers, enabling session hijacking, credential theft, and defacement; mitigated through secure coding and web application penetration testing.

CRUD Operations

Create, Read, Update, and Delete, the four basic operations for managing data in databases and applications, each requiring appropriate access control to prevent unauthorised modification.

Crypto Key

A piece of data used by a cryptographic algorithm to encrypt or decrypt information, requiring secure generation, storage, and rotation to maintain data protection.

Crypto Malware

Malicious software that encrypts a victim’s files and demands a ransom for the decryption key, a category of ransomware.

Cryptocurrency

A digital currency using cryptographic techniques for secure transactions, often demanded as ransom payment and targeted by cryptojacking and exchange hacks.

Cryptographer

A specialist who designs and analyses cryptographic algorithms and protocols to protect sensitive data and communications from interception.

Cryptographic Algorithm

A mathematical procedure used for encryption and decryption of data, such as AES or RSA, fundamental to protecting encrypted data and enabling internet protocol security.

Cryptor

A tool used by attackers to encrypt or obfuscate malware payloads, making them harder for antivirus software and EDR tools to detect.

Cryptojacking

The unauthorised use of a victim’s computing resources to mine cryptocurrency, often delivered through malicious scripts on websites or compromised endpoints.

CTF

Capture the Flag, a cybersecurity competition where participants solve security challenges to find hidden “flags,” used for training and skill development.

CVE – Common Vulnerabilities and Exposures

A public catalogue of known security vulnerabilities with unique identifiers, used across vulnerability assessment, patching, and remediation workflows to standardise tracking.

CVSS (Common Vulnerability Scoring System)

A standardised method for scoring vulnerability severity on a 0.0–10.0 scale based on exploitability and impact, used alongside business context to prioritise safe remediation.

Cyber Criminals

Individuals or groups who commit crimes using technology, motivated by financial gain, espionage, or disruption, ranging from lone operators to sophisticated organised networks.

Cyber Insurance

An insurance product that helps organisations offset the financial impact of cyber incidents such as data breaches, ransomware, and business operations disruption.

Cyber Operations

The coordinated use of cyber capabilities to achieve security objectives, including offensive and defensive activities conducted by military, intelligence, and private sector teams.

Cyber Risk Analyst

A professional who assesses, quantifies, and communicates cyber risk to support organisational decision-making and risk management.

Cyber Threat

A cyber threat is any actor, capability, or circumstance that could adversely impact an asset or organisation by exploiting a vulnerability. A threat is any circumstance that could adversely impact an asset or organization.

Cyberattack

See Cyber Attack.

Cybercriminals

See Cyber Criminals.

Cybersecurity

See the Top 7 definition above. Cybersecurity encompasses all security solutions, practices, and technologies used to protect information systems from cyber threats.

Cybersecurity Analytics

The application of data analysis, machine learning, and statistical methods to security data to identify patterns, detect threats, and improve decision-making.

Cybersecurity Manager

A professional who oversees an organisation’s cybersecurity programme, including policy development, team management, vendor relations, and security services delivery.

Cybersecurity Monitoring Services

Outsourced or in-house services providing continuous monitoring of networks, endpoints, and cloud environments for security threats and incidents.

Cybersecurity Transformation

The strategic initiative to modernise an organisation’s security capabilities, culture, and architecture to address evolving threats and regulatory requirements.

Cybersquatting

Registering domain names resembling established brands with the intent to sell them at a profit or use them for phishing and brand abuse.

Cyberweapon

A software tool or exploit specifically designed and deployed to disrupt, damage, or destroy targeted information systems or industrial control systems, often in a geopolitical context.

D

Dangling Markup

A web security issue where unclosed HTML tags can be exploited to capture and exfiltrate page content, including tokens and sensitive data from a web server response.

Dark AI

The use of AI technologies by threat actors for malicious purposes including automated phishing, deepfake generation, vulnerability discovery, and evasion of security tools.

Dark Net

An encrypted overlay network accessible only through specialised software such as Tor, used for anonymous communication and often associated with illegal marketplaces.

Dark Web Activity

Actions conducted on dark web forums and marketplaces, including the sale of stolen data, credentials, exploit kits, and ransomware-as-a-service tools.

Dark Web Monitoring

Services that scan dark web sources for an organisation’s compromised credentials, intellectual property, or mentions indicating potential security risks.

Data Aggregation

The process of collecting and combining data from multiple sources, which in security contexts can reveal sensitive information when individual data points are combined.

Data Backups

Copies of critical data maintained in secure, separate locations to enable recovery after ransomware, hardware failure, accidental deletion, or disaster, essential for any disaster recovery plan.

Data Breach

A data breach is unauthorized access to sensitive information. Data breaches can lead to identity theft and financial loss. In 2020, data breaches exposed over 37 billion records globally. Data breaches often result from exploited vulnerabilities in systems, and a data breach can occur through hacking or insider threats.

Data Compliance

Adherence to laws and regulations governing how sensitive data is collected, stored, processed, and shared, such as GDPR, HIPAA, and PCI DSS.

Data Encryption

Encryption transforms plaintext into ciphertext to conceal data meaning, protecting data at rest on disks and data in transit across networks using encryption keys.

Data Encryption Standard

An older symmetric encryption algorithm largely superseded by AES, historically significant but now considered insufficiently secure for protecting sensitive data.

Data Exfiltration

The unauthorised transfer of data from an organisation’s systems, often the final objective of a cyber attack, detected through data loss prevention tools and network traffic analysis.

Data Flow Mapping

Documenting how data moves through information systems, critical for data protection impact assessments, compliance, and identifying where sensitive data is exposed.

Data Gravity

The concept that data tends to attract applications and services to its location, influencing cloud architecture decisions and having implications for data sovereignty and security.

Data Logging

The systematic recording of data events and transactions for audit, debugging, and security analysis purposes.

Data Loss Prevention (DLP)

Data loss prevention prevents unauthorized data access and exfiltration. DLP includes strict access controls on sensitive resources, can block or monitor email attachments to prevent leaks, and technologies can prevent network file exchanges to external systems. DLP aims to protect sensitive data from falling into malicious hands.

Data Obfuscation

Techniques that mask or alter data to prevent unauthorised access while preserving usability for authorised purposes, including tokenisation and masking.

Data Onboarding

The process of ingesting and normalising data from various sources into a security platform, such as a SIEM or data lake, for analysis and correlation.

Data Plane

The part of a network architecture that carries user data traffic between endpoints, as opposed to the control plane which manages routing and signalling.

Data Poisoning

An attack against machine learning systems where malicious data is injected into training datasets to manipulate model outputs and degrade detection accuracy.

Data Portability

The ability to transfer data between systems or providers in a usable format, a right under GDPR and a consideration for cloud security architecture.

Data Privacy

The right of individuals to control how their personal information is collected, used, and shared, enforced through regulations like GDPR and organisational data protection policies.

Data Protection vs. Data Security

Data protection focuses on policies and compliance governing data use and privacy, while data security focuses on the technical security measures preventing unauthorized access and breaches.

Data Sovereignty

The principle that data is subject to the laws and regulations of the country where it is stored, influencing cloud deployment and data residency decisions.

Data Traffic

The flow of data packets across computer networks, monitored by security tools including firewalls, intrusion detection systems, and NDR for anomalous or malicious activity.

Database Monitoring

Continuous observation of database activity to detect unauthorized access, SQL injection attempts, privilege escalation, and compliance violations.

DDoS Attack

A distributed denial-of-service attack floods a service with traffic from many sources, often botnets, to exhaust system resources and disrupt availability. A denial-of-service (DoS) attack floods a system with traffic to exhaust resources.

Decompiler

A tool that converts compiled binary code back into human-readable source code, used in malware analysis and reverse engineering.

Deep Web vs Dark Web

The deep web includes all unindexed internet content such as private databases, while the dark web is a subset requiring special software for access and often associated with illicit activity.

Deepfake

AI-generated synthetic media, including video and audio, used in social engineering attacks to impersonate executives and trick users into transferring funds or sharing credentials.

Default Deny

A security principle where all access and activity is blocked unless explicitly permitted, the foundation of allowlisting, zero trust, and firewall rule design.

Defense In Depth

A layered security strategy that uses multiple security controls at different levels, so that if one layer fails, others continue to protect assets and data.

Dependencies

Software libraries, services, or components that an application relies on to function, creating supply chain risk when those dependencies contain vulnerabilities such as Log4J.

Detection Engineering

The practice of designing, building, testing, and maintaining detection rules and logic within SIEM, EDR, and other security tools to identify security threats and attack behaviours.

Device Code Phishing

A phishing technique that abuses OAuth device authorisation flows to trick users into granting attackers access to their accounts without revealing passwords.

Dictionary Attack

An attack that uses a predefined list of common words and phrases to guess passwords, less exhaustive than a brute force attack but faster against weak passwords.

Digital Certificate

An electronic document issued by a certificate authority that binds a public key to an entity’s identity, enabling encrypted communications and authentication across networks.

Digital Footprint

The trail of data created by an individual or organisation through online activity, which can be leveraged by attackers for reconnaissance and social engineering.

Digital Signature

A cryptographic mechanism that verifies the authenticity and data integrity of a message or document, ensuring it has not been altered and confirming the sender’s identity.

Disaster Recovery (Plan)

A disaster recovery plan is a documented strategy for restoring IT systems and business operations after a disruptive event such as a cyber attack, natural disaster, or hardware failure.

DLL Hijacking

An attack where a malicious DLL is placed in a location where a vulnerable application loads it instead of the legitimate library, enabling code execution.

DLL Side Loading

A technique where attackers place a malicious DLL alongside a legitimate application that loads it, often used to bypass application whitelisting and gain persistence.

DLP Antivirus

Integrated security solutions that combine data loss prevention capabilities with antivirus software to protect endpoints from both malware and data leakage.

DNS Changer

Malware that modifies DNS settings on a compromised system to redirect network traffic to attacker-controlled servers, enabling phishing and malware distribution.

DNS Poisoning

An attack that corrupts DNS cache data to redirect users to malicious websites, enabling credential theft and malware delivery without the user’s knowledge.

DNS Protection

Security services that filter DNS queries to block access to known malicious domains, preventing malware communication, phishing, and C2 traffic.

DNS Sinkhole

A DNS server configured to redirect traffic from malicious domains to a controlled address, used for threat analysis and to prevent compromised systems from reaching C2 servers.

DOC / DOC Files

Microsoft Word document file formats that can contain embedded macros, frequently abused as delivery vectors for malware and exploits such as Follina, a 2022 Microsoft Office zero-day vulnerability abused via malicious documents and MSDT.

DoH Protocol

DNS over HTTPS, a protocol that encrypts DNS queries within HTTPS traffic, improving privacy but potentially hindering security monitoring of DNS-based threats.

Domain Admin Groups

Active Directory groups with unrestricted access to all domain resources, representing the highest-value target for privilege escalation during penetration tests.

Domain Fronting

A technique that uses different domain names at different layers of communication to disguise the true destination of network traffic, sometimes used to bypass censorship or evade detection.

Domain Spoofing

Forging a domain name in emails, websites, or network communications to impersonate a trusted entity for phishing or fraud purposes.

Double Tagging

A VLAN hopping technique where an attacker adds two VLAN tags to a frame, allowing it to traverse trunk links and reach network segments that should be restricted.

Downgrade Attack

An attack that forces a system to use a weaker, less secure protocol or cipher, such as forcing NTLM instead of Kerberos, to exploit known weaknesses.

Downloader

Malware designed to download and install additional malicious payloads from the internet once it has compromised a system.

Doxware

A variant of ransomware that threatens to publish stolen sensitive data unless a ransom is paid, combining encryption with extortion.

Drive-by Download Attack

An attack where malware is automatically downloaded to a user’s device simply by visiting a compromised or malicious website, without any user interaction.

DTLS (Data Transport Layer Security)

A protocol that provides TLS encryption for datagram-based communications such as VoIP and VPN tunnels, protecting data in transit over UDP.

Dump Data

Extracted raw data from memory, databases, or storage, often obtained by attackers using tools like Mimikatz to harvest cached credentials and password hashes.

Dwell Time

The duration an attacker remains undetected within a compromised network, directly related to MTTD and a key indicator of detection and response maturity.

Dynamic ACLs

Access control lists that are applied dynamically based on user authentication or other conditions, providing flexible, context-aware network access control.

E

EDR vs MDR vs XDR

Endpoint detection and response (EDR) monitors endpoints; managed detection and response (MDR) outsources monitoring and response to an MSSP; extended detection and response (XDR) integrates detection and response across endpoints, network, identity, cloud, and email.

Elevation Control

A security mechanism that manages and restricts the ability of users and processes to elevate privileges on a system, preventing unauthorised administrative access.

Elevation Control in Endpoint Management

The application of least privilege principles within endpoint management platforms to ensure users only gain elevated permissions when authorised and necessary.

Email Spoofing

Forging the sender address in emails to make messages appear to come from a trusted source, a core technique in phishing and business email compromise.

EMV – Europay Mastercard & Visa

A global standard for chip-based payment card transactions designed to reduce card fraud compared to magnetic stripe technology.

Encryption

Encryption protects data by converting it into a secret code, reversible only with the correct encryption keys. It covers use cases including TLS for data in transit, disk encryption for data at rest, and SSH for secure remote admin.

End-to-End Encryption

Encryption where data is encrypted on the sender’s device and only decrypted on the recipient’s device, preventing intermediaries, including service providers, from reading the content.

Endpoint

Any user device, including laptops, workstations, smartphones, and VDI thin clients, connected to the network and requiring security controls, patching, and monitoring.

Endpoint Detection and Response (EDR)

Advanced endpoint security tools that detect suspicious behaviour, collect telemetry, and support investigation and containment. EDR complements antivirus software and feeds security operations center workflows.

Endpoint Monitoring

The continuous observation of endpoint activity, processes, and configurations to detect threats, enforce compliance, and support incident response.

Endpoint Protection Platforms (EPP)

Integrated security solutions deployed on endpoints to prevent malware, detect threats, and enforce security policies, often combining AV, firewall, and device control.

Endpoint Resilience

The ability of endpoints to self-heal, restore security agents, and maintain a secure state even after attacks, misconfigurations, or user interference.

Enterprise Solutions

Large-scale security products and services designed for complex organisations, often integrating multiple security tools, identity management, and compliance capabilities.

ESPM – Endpoint Security Posture Management

Tools that continuously assess and improve the security configuration and compliance of endpoints against baselines and policies.

Event Logging

The practice of recording system and application events, forming the raw data used by SIEM platforms, forensic analysts, and compliance auditors.

Evil Twin Attack

A wireless attack where an attacker sets up a rogue Wi-Fi access point mimicking a legitimate one to intercept network traffic and capture credentials.

Executables

Program files that contain code which runs directly on a computer system, frequently the payload format for malware delivery and requiring controls like application whitelisting.

Exploit

A piece of code, technique, or method that takes advantage of a vulnerability to cause unintended behaviour or to gain unauthorized access to systems.

Exploit Developer

A specialist who discovers vulnerabilities and creates exploit code, working as either a whitehat researcher or for offensive security teams.

Exploit Kit

A pre-packaged toolkit that automates the exploitation of known vulnerabilities in web browsers, plugins, and operating systems to deliver malware via drive-by downloads.

Exploit Pack

A collection of exploits bundled together for use in automated attack campaigns, often sold or leased on criminal forums.

Exploitation in the Wild (ITW)

A term indicating that a vulnerability or exploit is being actively used by threat actors in real attacks, increasing urgency for patching and mitigation.

Extended Detection and Response (XDR)

Integrated detection and response across endpoints, email, identity, network, and cloud, providing correlated visibility and automated response capabilities beyond standalone EDR.

Extensible Authentication Protocol

A framework for transporting authentication protocols, commonly used in wireless network security and VPN connections, supporting multiple authentication methods.

F

False Flag

A deceptive technique where attackers deliberately leave evidence pointing to another threat actor or nation state to mislead incident responders and forensic analysts.

False Positive

A security alert that incorrectly identifies benign activity as malicious, contributing to alert fatigue and cyber fatigue among security teams.

FDE Security

Full Disk Encryption, the practice of encrypting an entire storage device to protect data at rest if the device is lost, stolen, or decommissioned.

FQDN

Fully Qualified Domain Name, the complete domain name of a host on the internet, used in DNS resolution, certificate management, and firewall rules.

Federal Information Security Management Act (FISMA)

US legislation requiring federal agencies and contractors to implement information security programmes, including risk assessment and continuous monitoring.

File Integrity Monitoring (FIM)

Security tools that detect unauthorised changes to critical system files, configurations, and executables, essential for compliance and early breach detection.

Fileless Malware

Malicious software that operates entirely in memory without writing files to disk, evading traditional antivirus software and requiring behavioural detection by EDR.

Firewall

A firewall prevents unauthorized access to a network or system by monitoring and filtering network traffic based on defined rules. Firewalls prevent unauthorized access to networks and are a core network security device.

Firewall Costs

The total cost of ownership for firewall solutions including hardware, licensing, management, and the operational burden of maintaining and updating rules and policies.

Footholds

The initial position an attacker establishes inside a target network after the initial access phase, used as a base for lateral movement and privilege escalation.

Forensic Analyst

A cybersecurity professional who investigates security incidents by analysing digital evidence from systems, memory, network captures, and logs.

Form Grabber

Malware that intercepts data submitted through web forms before it is encrypted by the browser, stealing credentials and payment information.

Fraud Prevention

Technologies and processes designed to detect and prevent fraudulent activities across digital channels, often leveraging behavioural analytics and machine learning.

Full Disk Access (FDA)

An operating system permission granting applications complete access to all files on a device’s storage, a sensitive privilege that must be carefully controlled.

G

General Data Protection Regulation (GDPR)

The EU regulation governing the collection, processing, and storage of personal data, imposing strict requirements on organisations worldwide that handle EU residents’ data.

Generic Device

An unmanaged or unrecognised device connecting to a network, representing a potential shadow IT risk and requiring NAC policies for identification and control.

Geofencing

Using geographical boundaries to trigger security actions such as blocking access, alerting on anomalous logins, or restricting mobile device functionality.

Glitching

A hardware attack technique that introduces electrical or timing faults to cause a system to behave unexpectedly, potentially bypassing security checks.

Golden Ticket Attack

A Kerberos-based attack where an adversary forges a ticket-granting ticket using a compromised KRBTGT account, granting unlimited domain access, a critical Active Directory security threat.

Google Cloud Platform (GCP)

Google’s cloud computing platform, offering infrastructure, analytics, and AI services, each requiring specific security configurations and monitoring.

Google Dorking

Using advanced Google search operators to discover exposed sensitive information, misconfigured servers, or vulnerable web applications indexed by search engines.

Grabber

Malware designed to capture specific types of data from a victim’s system, such as cryptocurrency wallets, browser-stored credentials, or session cookies.

H

Hacker

A person who uses technical skills to explore and exploit computer systems. Hackers can be ethical (whitehat) or malicious (blackhat) depending on intent and authorisation.

Hacktivism

Hacking motivated by political or social causes rather than financial gain, often involving website defacement, DDoS, or data leaks to promote a message.

Handshake Protocol

The initial exchange between client and server that establishes the parameters of a secure connection, including TLS versions, cipher suites, and encryption keys.

Hash Value

A fixed-length output generated by a hashing algorithm from input data, used for password storage, file integrity verification, and digital signatures.

Hashing

The process of converting data into a fixed-size hash value using a one-way function, fundamental to password management tools, file verification, and blockchain.

Health Insurance Portability and Accountability Act (HIPAA)

US legislation that mandates data protection standards for healthcare organisations handling patient health information, overlapping with HIT security requirements.

Heap Spraying

An exploitation technique that fills a process’s memory heap with malicious code, increasing the probability that a vulnerability will redirect execution to attacker-controlled instructions.

Hoax Attack

A fake threat or alarm designed to cause panic, waste resources, or distract security teams from real attacks.

Honey Token

A decoy credential, file, or data record designed to alert defenders when accessed, indicating that an attacker has penetrated defences and is exploring the network.

Honeypots

Deliberately vulnerable systems designed to attract and study attackers, providing intelligence on techniques, tools, and attack patterns.

Hooking

A technique where malware intercepts system calls or API functions to monitor, modify, or redirect behaviour, used for credential theft and evasion.

Horizontal Port Scan

A scanning technique that probes a single port across many IP addresses to identify hosts running a specific service, often used in reconnaissance.

HTTP/2

The second major version of HTTP, offering performance improvements including multiplexing and header compression, with distinct security considerations for web server configuration.

HTTP/3

The latest HTTP version using QUIC over UDP, improving speed and resilience, requiring updated security monitoring as it changes how network traffic appears.

Human Identity

The unique attributes and credentials that identify a person within identity and access management systems, distinct from machine or service identities.

Human Risk Management

The practice of measuring and reducing security risk caused by human behaviour through awareness training, phishing simulations, and policy enforcement is called as Human Risk Management. Cyphere supports businesses with human risk management solution to uplift human awareness, process improvements along with technoligical controls.

HUMINT

Human intelligence, information gathered through human interaction rather than technical means, relevant in social engineering assessments and physical penetration testing.

Hypervisor

Software that creates and manages virtual machines, forming the foundation of virtualisation and cloud computing, and a critical target for attacks seeking to escape VM isolation.

I

IaC Scanning

The automated analysis of infrastructure as code templates such as Terraform, ARM, and YAML for security misconfigurations, policy violations, and secrets exposure before deployment.

Identity Abuse

The malicious use of stolen or manipulated identities to gain unauthorized access to systems, data, or financial resources.

Identity and Access Management Specialist

A professional who designs and implements IAM solutions to manage digital identities and their access rights across systems, cloud services, and applications.

Identity Segmentation

A zero trust approach that applies access policies based on user identity rather than network location, enforcing least privilege at the identity layer.

IEEE 802.1 Standards

A family of networking standards governing LAN architecture, VLANs, and port-based network access control (802.1X), fundamental to network segmentation and NAC.

IGA vs IAM

Identity Governance and Administration focuses on compliance, audit, and lifecycle management of identities, while identity and access management focuses on authentication, authorisation, and access management enforcement.

IIS Logs

Log files generated by Microsoft’s Internet Information Services web server, containing request details useful for security analysis, incident investigation, and web application forensics.

Incident Responder

A cybersecurity professional responsible for managing the detection, analysis, containment, and recovery phases of security incidents.

Incident Response

See Top 7 definition. Incident response is a structured approach to managing cyber incidents, covering preparation, identification, containment, eradication, and recovery.

Indicator of Attack (IOA)

Behavioural signals indicating an ongoing attack, such as unusual process execution or suspicious authentication patterns, enabling proactive detection before damage occurs.

Indicators of Compromise (IOCs)

Forensic artefacts such as file hashes, malicious IP addresses, domains, or registry changes that indicate a system has been compromised.

Information Security or InfoSec

The practice of protecting information and information systems from unauthorised access, use, disclosure, disruption, modification, or destruction to ensure confidentiality, integrity, and availability.

Infrastructure-as-a-Service (IaaS)

A cloud computing model providing virtualised computing resources over the internet, where the customer manages operating systems, applications, and data while the provider manages physical infrastructure.

Ingress Controller

A Kubernetes component that manages external access to services within a cluster, enforcing routing rules, TLS termination, and access control.

Initial Access

The first phase of a cyber attack where the adversary establishes a foothold in the target environment, often through phishing, exploitation, or compromised credentials.

Initialization Vector

A random or pseudorandom value used alongside an encryption key to ensure identical plaintext blocks produce different ciphertext, preventing pattern analysis.

Injection Attack

Injection attacks involve inserting malicious input into interpreters such as SQL, OS commands, or LDAP to alter application logic, exfiltrate data, or execute commands on the target system.

Insider Threat

A security risk originating from within the organisation, including malicious employees, negligent users, or compromised accounts, requiring user behaviour analytics and access controls.

Integrations

Connections between security tools and IT systems that enable data exchange, automated workflows, and coordinated response across the security stack.

Interactive Login

A login session where the user actively provides credentials at the console or remote desktop, producing distinct audit events compared to service or network logons.

Intrusion Detection System (IDS)

An intrusion detection system monitors network traffic and system activity for signs of malicious activity or policy violations, generating alerts for analyst review.

IOC

See Indicators of Compromise.

IoT Cybersecurity

The practice of securing Internet of Things devices, which often lack robust security controls and can be recruited into botnets or used as entry points to gain network access.

IoT Security Engineer

A specialist focused on securing IoT devices, protocols, and ecosystems against exploitation, data leakage, and network-based attacks.

IP (Internet Protocol) Address

A numerical label assigned to each device on a network that uses internet protocol for communication. IP addresses are fundamental to network routing, firewall rules, and threat intelligence.

IPS (Intrusion Prevention System)

An intrusion prevention system IPS actively blocks malicious network traffic in real time, sitting inline on the network to prevent detected threats from reaching their targets. Intrusion prevention systems block malicious network traffic.

IRSF

International Revenue Share Fraud, a telecom fraud scheme where attackers generate calls to premium rate numbers to steal revenue, often using compromised VoIP systems.

ITDR (Identity Threat Detection and Response)

A security category focused on detecting and responding to identity-based threats, including credential theft, privilege escalation, and account takeover within Active Directory and cloud IAM.

J

Just-in-Time (JIT)

A privileged access model that grants elevated permissions only for limited periods and specific tasks, reducing the window of opportunity for attackers and minimising standing privilege risk.

K

Kerberos

A network authentication protocol that uses tickets to allow nodes to prove their identity securely, the default authentication mechanism in Active Directory environments.

Keylogger

Spyware that records keystrokes to capture passwords, messages, and other sensitive data typed by the user, often delivered through phishing or trojan horse malware.

Keystroke Logging

The process of recording keyboard inputs, used legitimately for monitoring and maliciously for credential theft, closely related to keylogger deployment.

L

LaaS

Logging as a Service, a cloud-based service that provides centralized logging infrastructure, simplifying log management and SIEM integration.

LAN (Local Area Network)

A network connecting devices within a limited area such as an office or building, where network segmentation, NAC, and ARP spoofing defences are critical.

LAN ID

An identifier associated with a local area network segment, used in VLAN configuration and network access control policies.

Lateral Movement

The technique attackers use to move between systems within a compromised network after initial access, often leveraging pass-the-hash, cached credentials, and misconfigured permissions to reach high-value targets.

Layer 7

The application layer of the OSI model, where attacks such as SQL injection, XSS, and API abuse operate, requiring web application firewalls and application-level security measures.

Least Privilege

The principle of giving users and services only the minimum access they need for their role, directly connected to zero trust, micro-segmentation, JIT access, and IAM design.

Log Files

Files containing recorded system events, application activity, and security alerts, forming the raw data for forensic analysis, compliance, and SIEM correlation.

Log Format

The structure and schema used to record log data, standardisation of which improves parsing, correlation, and analysis across diverse IT systems.

Log Management

The process of collecting, storing, analysing, and retaining log data from across an organisation’s infrastructure for security monitoring and compliance.

Log Parsing

Extracting and interpreting structured data from raw log files, a critical step in SIEM processing and security analytics.

Log Retention

Policies defining how long log data must be stored to meet compliance requirements, support investigations, and enable retrospective threat hunting.

Log Rotation

The automated practice of archiving and replacing active log files to manage storage, prevent data loss, and maintain system performance.

Log Streaming

The real-time transmission of log data from sources to centralised analysis platforms, enabling immediate detection and response to security events.

Logging Level

The severity or verbosity setting that determines which events are recorded in logs, from debug-level detail to critical-only alerts.

LOLBins

Living Off the Land Binaries, legitimate system utilities such as PowerShell and certutil that attackers repurpose for malicious activities to evade detection by security tools.

Long Term Evolution (LTE)

A mobile broadband standard providing high-speed wireless connectivity, with security considerations around SIM-based authentication and mobile device management.

LOTL

Living Off the Land, an attacker strategy that uses legitimate built-in tools and processes already present in the target environment to avoid detection.

Low-Code Platform Security

Security considerations specific to low-code and no-code development platforms, where rapid application building can introduce security vulnerabilities if guardrails are insufficient.

M

Mac Flooding

An attack that overwhelms a network switch’s MAC address table with fake entries, forcing it to broadcast all traffic and enabling the attacker to sniff data.

Machine Learning (ML)

A subset of artificial intelligence where systems learn from data to improve performance on tasks, used in cybersecurity for threat detection, anomaly identification, and predictive analytics.

Magic Number

A specific byte sequence at the beginning of a file that identifies its format, used in security analysis to detect disguised malicious files.

Malspam

Mass email campaigns distributing malware through infected attachments or links, often using social engineering to trick users into opening payloads.

Malvertising

The injection of malicious code into legitimate advertising networks to deliver malware through ad displays, redirecting users without their knowledge.

Malware

Malware is software designed to disrupt, damage, or gain unauthorized access to systems. Categories include viruses, worms, trojans, ransomware, spyware, adware, and fileless variants. A Trojan horse disguises itself as legitimate software.

Malware Analysis

The process of examining malicious software to understand its behaviour, origin, and capabilities, informing detection rules and incident response.

Malware Analyst

A cybersecurity professional who reverse-engineers and analyses malware samples to extract indicators of compromise and understand threat actor techniques.

Malware Packer

A tool that compresses and encrypts malware to change its signature and evade detection by antivirus software and security tools.

Man-in-the-Middle

An attack where an adversary secretly intercepts and potentially alters communication between two parties who believe they are communicating directly, enabling credential theft and data manipulation.

Managed Detection and Response (MDR)

A managed security service providing outsourced threat monitoring, detection, and response capabilities, combining technology and human expertise.

Managed IT Services

Outsourced management of IT infrastructure and operations, often including patching, monitoring, and basic security services.

Managed Security Service Providers (MSSP)

External providers that operate SOC, monitoring, and response security services on behalf of organisations, allowing businesses to exchange data with specialist teams who provide 24/7 coverage.

Mean Time to Respond (MTTR)

A metric measuring the average time from threat detection to resolution, directly reflecting operational excellence and incident response maturity.

Media Servers

Servers that store and deliver multimedia content, requiring hardening and access control to prevent unauthorised access and data exfiltration.

MFA Token

A physical device or software application that generates one-time codes used as a second factor in multi factor authentication workflows.

Mimikatz

A widely used post-exploitation tool that extracts plaintext passwords, hashes, and Kerberos tickets from Windows memory, central to pass-the-hash and credential theft attacks.

Mobile Device Management (MDM)

Technology for managing and securing smartphones and tablets across BYOD and corporate fleets, enforcing encryption, remote wipe, app whitelisting, and compliance policies on each mobile device.

Mobile Malware

Malicious software targeting mobile operating systems, distributed through fake apps, phishing, or compromised websites to steal data, intercept communications, or enrol devices in botnets.

Mobile Threat Defense

Security solutions specifically designed to protect mobile devices from malware, phishing, network attacks, and OS-level exploits.

MTAN

Mobile Transaction Authentication Number, a one-time code sent via SMS for transaction verification, increasingly targeted by SIM swapping and interception attacks.

Multi-Factor Authentication (MFA)

Multi-factor authentication requires two or more verification methods to confirm a user’s identity, significantly reducing the risk of account compromise. Certificate-based authentication uses SSL certificates for secure access. Password Authentication Protocol sends passwords in clear text and should be avoided. Two-step authentication adds an extra verification step after password entry.

Multihoming

Connecting a device or network to multiple network paths for redundancy and load balancing, requiring careful security configuration to prevent unintended exposure.

N

NAT Rules

Network Address Translation rules that map private IP addresses to public ones, used in firewalls and routers to control traffic flow and obscure internal network topology.

National Institute of Standards and Technology (NIST)

A US agency that publishes cybersecurity frameworks and standards, including the NIST CSF and 800-53 controls, widely used globally for security maturity assessments.

Negative Digital Footprint

Harmful or unwanted information about an individual or organisation available online, which can be exploited for social engineering or reputational damage.

Network Control

Policies and technologies that govern how data flows across networks, including firewalls, ACLs, NAC, and segmentation controls.

Network Detection and Response (NDR)

Security solutions that analyse network traffic to detect threats, anomalies, and lateral movement that may evade endpoint-based detection.

Network Redirector

A network component that redirects traffic between systems, which can be abused by attackers to intercept communications or redirect users to malicious destinations.

Network Security Engineer

A professional responsible for designing, implementing, and maintaining network security infrastructure including firewalls, IPS, VPNs, and network segmentation.

Network Segmentation

Dividing computer networks into zones with controls between them to limit the spread of attacks, protect sensitive data, and enforce access policies between network resources.

Network Traffic Management

The practice of monitoring and controlling the flow of data across networks to optimise performance, ensure availability, and support security monitoring.

Next-Generation Antivirus (NGAV)

Advanced antivirus software that uses behavioural analysis, machine learning, and cloud-based intelligence rather than relying solely on signature matching to detect threats.

NFC

Near Field Communication, a short-range wireless technology used for contactless payments and data exchange, with security considerations around eavesdropping and relay attacks.

NFS

Network File System, a protocol allowing file access over networks, requiring proper authentication and access control to prevent unauthorized access.

NGFW IPS

Next-generation firewalls with integrated intrusion prevention system capabilities, combining traditional firewall rules with deep packet inspection and application awareness.

NTLM

An older Microsoft authentication protocol with known weaknesses including relay attacks and pass-the-hash exploitation, which should be disabled where possible and replaced with Kerberos.

O

Object Linking and Embedding (OLE)

A Microsoft technology allowing embedding of objects within documents, historically exploited to deliver malware through malicious macros and embedded objects in DOC files.

Observability

The ability to understand the internal state of systems through their external outputs, including logs, metrics, and traces, critical for security monitoring and detection engineering.

On-Prem

Short for on-premises, referring to IT infrastructure hosted and managed within an organisation’s own facilities rather than in the cloud.

One-Time Password

A password valid for a single authentication session, generated by hardware tokens, software apps, or SMS, used as part of multi factor authentication.

Open Banking

A regulatory framework enabling secure sharing of financial data between institutions via APIs, requiring strong API security, consent management, and data protection.

OpenID Connect

An identity layer built on OAuth 2.0 that enables client applications to verify user identity and obtain profile information, commonly used for SSO.

Open Source Intelligence (OSINT)

Intelligence gathered from publicly available sources such as social media, websites, and public records, used for threat assessment and reconnaissance.

OpenSSL

An open-source cryptographic library implementing SSL and TLS protocols, historically affected by critical vulnerabilities such as Heartbleed.

Open Web Application Security Project (OWASP)

A nonprofit that publishes widely used application security resources including the OWASP Top 10, testing guides, and tools for improving code security.

osquery

An open-source tool that allows querying operating system data using SQL syntax, useful for endpoint visibility, compliance checking, and threat hunting.

Outbound Phishing Attacks

Phishing campaigns originating from within an organisation’s compromised infrastructure, often used to target customers, partners, or supply chain contacts.

Over-the-Air Technology

Methods for remotely updating firmware or software on devices wirelessly, requiring integrity verification and encryption to prevent tampering.

P

Packet Capture (PCAP)

The interception and recording of data packets traversing a network, used for forensic analysis, troubleshooting, and security investigation.

Parser

A software component that interprets structured data, such as log files or network protocols, extracting meaningful information for analysis by security tools.

Pass the Hash (PtH)

An attack technique where stolen hashed credentials are used to authenticate without cracking the password, particularly effective in compromised Active Directory environments.

Pass-the-Cookie

An attack where stolen session cookies are used to bypass authentication and impersonate a user, often used to circumvent multi factor authentication after initial access.

Password Management Tool

Software that generates, stores, and auto-fills strong, unique passwords for users, significantly reducing credential reuse and vulnerability to brute force attacks. Password management tools are essential for good cyber hygiene.

Password Security Storage

Secure methods for storing passwords including salted hashing, key derivation functions, and hardware security modules, preventing exposure during a data breach.

Password Spraying

An attack that tries a small number of commonly used passwords across many accounts to avoid lockout thresholds, targeting organisations with weak password policies.

Passwordless Security

Authentication methods that eliminate traditional passwords, using biometrics, FIDO2 security keys, or device-based authentication to reduce phishing and credential theft risk.

Payload

The malicious component of an exploit or malware that performs the actual harmful action, such as encrypting files, establishing a backdoor, or exfiltrating data.

Payment Card Industry Data Security Standard (PCI-DSS)

A global security standard for organisations handling cardholder data, requiring specific security controls including encryption, access control, monitoring, and regular penetration testing.

Penetration Testing (Pen Test)

See Top 7 definition. A penetration test is an authorised simulated attack to identify exploitable weaknesses, covering network, web/mobile app, cloud, OT, and red teaming approaches.

Persistence

The techniques attackers use to maintain access to a compromised system across reboots, credential changes, and remediation attempts.

Persistent Foothold

A durable presence within a target network that survives system restarts and cleanup efforts, often achieved through registry modifications, scheduled tasks, or firmware implants.

Personally Identifiable Information (PII)

Data that can identify an individual, such as names, addresses, and national insurance numbers, subject to strict data protection regulations.

Phishing

Phishing is a fraudulent attempt to acquire sensitive information like passwords and financial data. Phishing uses emails that appear to be from trusted sources and aims to acquire sensitive information like passwords. Spear phishing targets specific individuals or organizations. Smishing refers to phishing via SMS text messages.

Pharming

Pharming uses underlying phishing setup and it redirects users to fake websites to steal credentials. These campaigns are run in numbers, targeting masses at large to harvest credentials so that they can be traded in the dark web / underground markets. 

pharming

Phishing-as-a-Service (PhaaS)

Criminal platforms that provide ready-made phishing kits, hosting, and campaign management tools, lowering the barrier for conducting phishing attacks.

Physical Security Tester

A professional who assesses physical security controls such as locks, badges, surveillance, and staff awareness through authorised intrusion attempts.

Platform Consolidation

The strategic reduction of overlapping security tools into integrated platforms to reduce complexity, improve visibility, and lower costs.

Platform-as-a-Service (PaaS)

A cloud computing model providing a platform for developing, deploying, and managing applications without managing underlying infrastructure.

Polymorphic Virus

A virus that changes its code with each infection cycle to evade signature-based detection, requiring behavioural and heuristic analysis to identify.

Post Office Protocol

An email retrieval protocol (POP3) that downloads messages from a mail server, with security concerns around unencrypted credential transmission.

Potentially Unwanted Application

Software that is not classified as malware but may be undesirable, such as adware, toolbars, or bundled programs that degrade performance or privacy.

PPC Security

Protecting pay-per-click advertising campaigns from click fraud, competitor abuse, and bot activity that wastes advertising budgets. Best in class cusotmer oriented PPC agencies like 408 Media often make sure that account protection concerns of advertisers are at the forefront of their methodology.

Pretexting

A social engineering technique where an attacker fabricates a scenario to manipulate a victim into providing information or performing actions that compromise security.

Principle of Least Privilege (POLP)

See Least Privilege. Granting the minimum level of access necessary for a user, process, or system to perform its function.

Privileged Access Management

Solutions that control, monitor, and audit access to critical systems by privileged users, including credential vaulting, session recording, and JIT access.

Privilege Escalation

The act of exploiting a bug, misconfiguration, or design flaw to gain higher privileges than originally granted, such as moving from a standard user to domain admin.

Prompt Injection Attack

An attack against AI language models where crafted input manipulates the model into ignoring safety instructions, revealing training data, or performing unintended actions.

Proxy

An intermediary server that forwards requests between clients and servers, used for caching, content filtering, anonymisation, and SSL inspection.

Punycode

A character encoding used to represent Unicode characters in domain names, exploited in homograph attacks to create phishing domains visually identical to legitimate ones.

Purple Team

A collaborative security exercise where red team (offensive) and blue team (defensive) work together to improve detection, response, and overall security posture.

Q

Quantum Computing

Emerging computing technology using quantum mechanics that could eventually break current cryptographic algorithms, driving research into post-quantum cryptography.

Quantum Cryptography

Cryptographic methods based on quantum mechanics principles, including quantum key distribution, designed to be secure against quantum computing attacks.

Quishing (QR Code Phishing)

A phishing technique that uses malicious QR codes to redirect victims to fake websites or trigger malware downloads when scanned.

R

Race Condition

A software flaw where the outcome depends on the sequence or timing of uncontrollable events, which can be exploited to bypass security controls or escalate privileges.

Rainbow Table

A precomputed table of hash values used to reverse cryptographic hash functions and crack passwords, defeated by salted hashing.

RAM Scraper

Malware that extracts sensitive data, such as payment card information, from a system’s memory before it is encrypted or written to disk.

Ransomware

Ransomware encrypts files, demanding payment for decryption, often combined with double-extortion where attackers also threaten to publish stolen data. Ransomware attacks can cost businesses an average of $1.85 million. Ransomware as a service (RaaS) allows criminals to lease ransomware tools. In 2021, ransomware attacks increased by 151% compared to 2020. Ransomware can lead to significant business disruptions and data loss.

Ransomware Recovery

The process of restoring systems and data after a ransomware incident through backups, decryption tools, and incident response procedures.

Ransomware-as-a-Service (RaaS)

A criminal business model where ransomware developers lease their tools and infrastructure to affiliates in exchange for a share of ransom payments.

RC5 Algorithm

A symmetric-key block cipher known for its simplicity and variable key size, used in some encryption implementations.

Recovery Point Objective

The maximum acceptable amount of data loss measured in time, determining backup frequency and data replication strategies.

Recovery Time Objective

The maximum acceptable downtime before business operations must be restored after a disruption, a key metric in business continuity planning.

Red Team

An offensive security team that simulates real-world adversaries to test an organisation’s detection, response, and overall security controls through authorised attack scenarios.

Remote Access

The ability to connect to systems or networks from outside the physical location, typically through VPN, RDP, or SSH, requiring strong authentication and monitoring.

Remote Access Trojan (RAT)

Malware that gives an attacker remote control over a compromised system, enabling surveillance, data theft, and command execution.

Remote Administration Tools

Legitimate software for remote system management that can be abused by attackers as stealthy backdoors if deployed without authorisation.

Remote Code Execution (RCE)

A vulnerability that allows an attacker to execute arbitrary code on a target system remotely, one of the most critical security vulnerability classes.

Remote Desktop Protocol

Microsoft’s RDP, used for remote access to Windows systems, frequently targeted in brute force attacks and ransomware campaigns if exposed without proper hardening and access controls.

Remote Monitoring and Management (RMM) Tools

Software used by IT teams and managed service providers to remotely monitor and manage endpoints, increasingly targeted by attackers for supply chain compromise.

Remote Shell

A command-line interface established on a remote system after exploitation, allowing an attacker to execute commands and interact with the compromised machine.

Repacking

Modifying and repackaging legitimate software or mobile apps with malicious code for redistribution through unofficial channels.

Reverse Engineer

A cybersecurity professional who deconstructs software, malware, or hardware to understand functionality, identify vulnerabilities, and extract threat intelligence.

RFC

Request for Comments, the formal document series defining internet standards and protocols, referenced in security configuration and protocol analysis.

Risk and Compliance Specialist

A professional who manages the intersection of cybersecurity risk and regulatory compliance, ensuring organisational practices meet legal and industry standards.

cyber risk

Rogue Access Point

An unauthorised wireless access point connected to a network, enabling attackers to intercept traffic, steal credentials, or gain network access.

Rogue Apps

Unauthorised or malicious applications installed on devices, often introduced through shadow IT or social engineering.

Root Access

The highest level of administrative privilege on Unix/Linux systems, granting complete control over the system and all its resources.

Rootkit

Stealthy malware that embeds itself deeply in an operating system or firmware to hide its presence and provide persistent, privileged access to attackers.

S

SaaS Security Posture Management (SSPM)

Tools that continuously monitor and improve the security configuration of SaaS applications, identifying misconfigurations, excessive permissions, and compliance gaps.

Same-Origin Policy (SOP)

A browser security mechanism that prevents web pages from making requests to a different domain, mitigating XSS and data theft attacks.

Sandbox Escape

An exploit technique where malware or an attacker breaks out of a sandboxed environment to access the host system or broader network.

Sandboxing

Isolating applications or suspicious files in a controlled environment to observe their behaviour without risking damage to production systems, used in email gateways and malware analysis.

SASE – Secure Access Service Edge

A cloud-delivered architecture that converges networking and security functions, including firewall, CASB, and zero trust network access, into a single service.

Scam

A fraudulent scheme designed to deceive victims into providing money, credentials, or access, encompassing phishing, social engineering, and financial fraud.

Scam Likely Call

Calls flagged by carriers as potentially fraudulent, often associated with vishing and social engineering attempts.

Scareware

Malicious software that deceives users into believing their system is infected, then tricks them into purchasing fake security solutions or downloading actual malware.

Script Kiddie

An unskilled individual who uses pre-built tools and scripts to launch attacks without understanding the underlying techniques.

SDK IT

Software Development Kits used in IT for building applications, requiring security review to ensure included libraries do not introduce vulnerabilities.

SecOps

The collaboration between security and IT operations teams to integrate security practices into daily operational workflows.

Secret Key Authentication

An authentication method where both parties share a secret key for verifying identity and encrypting communication, as used in symmetric encryption protocols.

Secure Element Application

A tamper-resistant hardware component that securely stores cryptographic keys and executes sensitive operations, commonly used in mobile payments and smart cards.

Security Analyst

A cybersecurity professional who monitors security events, investigates alerts, and responds to incidents within a security operations center.

Security by Obscurity

A flawed security approach that relies on keeping system design or implementation details secret rather than implementing robust security controls.

Security Data Lake

A centralised repository that stores large volumes of security data from diverse sources for advanced analytics, threat hunting, and machine learning.

Security Dependencies

External libraries, services, or components that a system relies on, where vulnerabilities in dependencies can expose the entire application to risk.

Security Director

A senior leadership role overseeing an organisation’s entire security programme, including strategy, budget, team management, and vendor relationships.

Security Email

Email communications specifically related to security alerts, incidents, or advisories, requiring authentication protocols like DMARC, DKIM, and SPF to prevent spoofing.

Security Issues

Any weakness, misconfiguration, or vulnerability within IT systems that could be exploited to compromise security, identified through audits, assessments, and monitoring.

Security Misconfiguration

Insecure or unintended settings in systems, applications, or cloud services that create exposure, such as open storage buckets, default credentials, or overly permissive ACLs.

Security Operations Center (SOC)

A security operations center provides continuous monitoring, triage, threat hunting, and incident handling for an organisation. SOC capability maturity reflects how advanced and integrated its processes, tooling, and staffing are.

Security Operations Report

A periodic summary of SOC activity, incidents handled, threat trends, and metrics such as MTTD and MTTR, used for governance and continuous improvement.

Security Orchestration

The coordination and automation of security workflows across multiple security tools and teams to accelerate detection, response, and remediation.

Security Orchestration, Automation and Response (SOAR)

Platforms that orchestrate and automate security responses based on SIEM, threat intelligence, and other tool inputs, reducing manual effort and response time.

Security Posture

See Top 7 definition. The overall strength of an organisation’s security controls, continuously assessed and improved through CTEM, audits, and posture management programmes.

Security Proof of Concept

A demonstration that a vulnerability can be exploited or a security control is effective, used during penetration tests and product evaluations.

SEO Poisoning

An attack that manipulates search engine results to direct users to malicious websites hosting malware, phishing pages, or exploit kits.

Server Monitoring

Continuous observation of server health, performance, and security events to detect anomalies, failures, and potential compromises.

Service-Oriented Architecture (SOA)

A software design pattern where services communicate over a network, requiring API security, authentication, and access management between components.

Session

A period of interaction between a user and a system, tracked through tokens or cookies, which must be protected against hijacking and fixation attacks.

Session Hijacking

An attack where an adversary takes over a valid user session to gain unauthorized access, typically by stealing session tokens or cookies.

Shadow Data

Data stored outside approved systems and governance processes, increasing risk of exposure and compliance violations.

SID in Computer Systems

A Security Identifier, a unique value assigned to users, groups, and computer accounts in Windows environments, used for access control decisions.

SIEM

Security Information and Event Management (SIEM) centralises security logs and analyses events from across the enterprise, enabling detection, correlation, and compliance reporting. SIEM platforms correlate data from firewalls, EDR, IAM, and other systems.

SIEM vs EDR and MDR

SIEM provides broad log correlation and compliance, EDR focuses on endpoint detection and response, and MDR offers outsourced monitoring and expert response, each serving different but complementary roles.

Single Factor Authentication

Authentication using only one verification method, typically a password, providing weaker security compared to multi factor authentication.

SIP Gateway

A device that bridges traditional telephony and VoIP networks, requiring hardening against toll fraud and eavesdropping.

SIP Proxy

A server that routes SIP signalling messages in VoIP networks, needing security controls to prevent call hijacking and denial of service.

Skimmer

A device or malicious code that captures payment card data during transactions, deployed on ATMs, POS terminals, or compromised e-commerce websites.

Smishing

See Phishing. Phishing conducted via SMS text messages to trick users into clicking malicious links or revealing sensitive data.

SNMP – Simple Network Management Protocol

A protocol for monitoring and managing network devices, requiring secure configuration (SNMPv3) to prevent unauthorized access to device data and configurations.

Snort Rules

Detection signatures used by the Snort intrusion detection system to identify specific patterns in network traffic associated with known attacks.

SOAP

Simple Object Access Protocol, an XML-based messaging protocol for web services that requires input validation and access control to prevent injection and XML-based attacks.

SOC Analyst

A cybersecurity professional working within a SOC who monitors alerts, triages incidents, performs initial investigation, and escalates confirmed threats.

Software Security

The discipline of designing, developing, and maintaining software to resist attacks, encompassing secure coding, testing, and vulnerability management throughout the lifecycle.

Software-as-a-Service (SaaS)

A cloud delivery model where applications are hosted and managed by a provider and accessed over the internet, requiring SSPM and data governance.

SPAN

Switch Port Analyzer, a network feature that copies traffic from one port to another for monitoring, enabling network detection and packet capture.

Spear Phishing

A highly targeted phishing attack directed at specific individuals or organisations, using personalised content to increase the likelihood of success.

Spyware

Spyware secretly collects user data without consent, monitoring browsing habits, keystrokes, and personal information, often delivered through trojan horse malware or bundled with legitimate software.

SQL Injection (SQLi)

A type of injection attack where malicious SQL statements are inserted into application queries to manipulate databases, exfiltrate data, or bypass authentication.

SSH

Secure Shell, an encrypted protocol for secure remote access to systems and network devices, the recommended replacement for unencrypted Telnet and VTY access.

SSL

Secure Sockets Layer, the predecessor to TLS, providing encrypted communication between clients and servers, now largely deprecated in favour of TLS.

SSL Offloading

The practice of handling SSL/TLS encryption and decryption on a dedicated device rather than the web server, improving performance while maintaining security.

SSL Termination

The process of decrypting SSL/TLS traffic at a network boundary device such as a load balancer or reverse proxy before passing it to backend servers.

SSL Traffic

Encrypted network traffic using SSL/TLS protocols, requiring inspection capabilities at network boundaries to detect threats hidden within encrypted data.

SSL VPN

A virtual private network VPN that uses SSL/TLS to provide secure remote access to network resources through a web browser or lightweight client. A virtual private network VPN creates an encrypted tunnel for secure communication.

Stack Trace

A debug output showing the sequence of function calls leading to an error, which if exposed in production can reveal application internals to attackers.

Stager

A small piece of malware code that downloads and executes a larger payload, used in multi-stage attack chains to avoid detection.

Stateful Firewall

A firewall that tracks the state of network connections and makes filtering decisions based on the context of the traffic flow, not just individual packets.

Static Application Security Testing (SAST)

Analysing application source code or binaries for security vulnerabilities without executing the program, typically performed early in the development lifecycle as part of a shift-left strategy.

Stealthware

Malware designed to evade detection by security tools, using techniques such as rootkit functionality, encryption, and anti-analysis mechanisms.

Steganography

The technique of hiding data within other files such as images or audio, used by attackers to exfiltrate data or deliver payloads without triggering security alerts.

Structured Logging

Recording log events in a consistent, machine-parseable format such as JSON, improving the efficiency of SIEM analysis and automated processing.

Suricata

An open-source network threat detection engine capable of real-time intrusion detection, inline prevention, and network security monitoring.

Symmetric Encryption Algorithms

Cryptographic algorithms that use a single shared key for both encryption and decryption, including AES and RC5, offering speed but requiring secure key distribution.

Syslog

A standard protocol for sending log messages from network devices and servers to a centralised logging server, foundational for SIEM and compliance monitoring.

System Development

The process of designing, building, testing, and deploying IT systems, where integrating security throughout the lifecycle (shift left) reduces vulnerabilities.

T

Tabletop Exercise

A discussion-based exercise where stakeholders walk through a simulated security incident scenario to test and improve incident response plans without deploying technical resources.

TCP/IP

Transmission Control Protocol/Internet Protocol, the fundamental communication protocol suite of the internet, governing how data packets are addressed, transmitted, and received.

Telemetry

Data collected from endpoints, networks, and applications about system behaviour, performance, and security events, feeding EDR, XDR, and SIEM platforms.

Text Bomb

A message containing specially crafted characters or code that causes a device or application to crash or become unresponsive when processed.

Threat Actor

An individual or group responsible for cyber attacks, ranging from script kiddies and cybercriminals to APT groups and nation-state operators.

Threat Actor Profiling

The practice of analysing and documenting threat actor capabilities, motivations, infrastructure, and TTPs to inform defensive strategies and threat assessments.

Threat Hunting

Proactive searching through networks and datasets for indicators of threats that have evaded existing automated detection mechanisms.

Threat Intelligence

Analysed information about current and emerging cyber threats used to inform security decisions, detection rules, and risk management strategies.

Threat Intelligence Analyst

A professional who collects, analyses, and disseminates threat intelligence to support organisational security decision-making and incident response.

Threat Intelligence Feed

A stream of curated threat data, including IOCs, malicious IP addresses, domains, and file hashes, integrated into security tools for automated detection.

TLS Encryption

Transport Layer Security, the successor to SSL, providing encrypted communications between clients and servers, essential for protecting data in transit across networks.

Token

A digital object representing authentication credentials, session state, or authorisation grants, used in MFA, OAuth, and API security.

Token Theft

The act of stealing authentication or session tokens to impersonate legitimate users and bypass security controls.

Tor Mirror

A duplicate of a website hosted on the Tor network, providing anonymous access and often used for censorship circumvention or hosting criminal content.

Traitorware

Software that silently collects and transmits user data to third parties, functioning as commercial spyware under the guise of legitimate applications.

Transparency, Consent, & Control (TCC)

A macOS security framework that manages application permissions to access sensitive user data like files, camera, and microphone.

TrickBot

A modular banking trojan that evolved into a versatile malware platform used for credential theft, network reconnaissance, and ransomware deployment.

Trojan Bitcoin Miner

A trojan horse that covertly uses a victim’s computing resources to mine cryptocurrency without consent.

Trojan Horse

Malware that disguises itself as legitimate software to trick users into installing it, then executes malicious actions once inside the system.

TTPs

Tactics, Techniques, and Procedures, the patterns of behaviour used by threat actors, documented in frameworks such as MITRE ATT&CK.

Tunnel

An encrypted communication channel created within a network protocol, such as a VPN or SSH tunnel, used to securely transmit data across untrusted networks.

Type Confusion

A programming vulnerability where an object is treated as a different type than intended, potentially allowing arbitrary code execution.

Typosquatting

Registering domain names that are intentional misspellings of popular websites to capture mistyped URLs for phishing, malware distribution, or traffic theft.

U

UDP

User Datagram Protocol, a connectionless transport protocol used for speed-sensitive applications like DNS and VoIP, with security considerations around amplification attacks.

UEFI

Unified Extensible Firmware Interface, the modern firmware standard replacing BIOS, which can be targeted by bootkits to achieve persistence below the operating system level.

Unauthorized Access

Any access to systems, data, or resources without proper authorisation, which access control ensures resources are granted only to entitled users to prevent.

Unified Audit

A centralised auditing capability that consolidates audit events across multiple services and platforms into a single view, simplifying compliance and investigation.

URL Spoofing

Disguising a malicious URL to appear legitimate, used in phishing campaigns to trick users into visiting attacker-controlled websites.

User Agent

A string sent by software, typically a browser, identifying itself to a web server, sometimes manipulated by attackers to evade detection or fingerprint targets.

User and Entity Behavior Analytics (UEBA)

Analytics platforms that establish baselines of normal user and entity behaviour and flag anomalies that may indicate compromised accounts, insider threats, or lateral movement.

User Identity Management

The processes and tools for creating, maintaining, and deactivating user accounts and credentials throughout their lifecycle, a core component of access management.

USSD

Unstructured Supplementary Service Data, a mobile communication protocol used for interactive services, sometimes exploited in mobile fraud and social engineering attacks.

V

VAST Threat Modeling

Visual, Agile, and Simple Threat modelling, a scalable approach to identifying security risks in software and system architectures.

Virtual Local Area Network

A logical network partition within a physical network, used for network segmentation and traffic isolation to improve security and performance.

Virtual Machines (VM)

Virtualised instances running on a hypervisor, common in on-premises and cloud computing environments, requiring the same hardening, patching, and monitoring as physical servers.

Virtual Private Network (VPN)

A virtual private network creates an encrypted tunnel over a public network to securely connect remote users to network resources, protecting data in transit and providing network access control.

Virus

See Computer Virus. A self-replicating malicious program that spreads by attaching to legitimate files and executing when the host file runs.

Vishing

Voice phishing, a social engineering attack conducted over phone calls to trick victims into revealing sensitive information or transferring money.

VoIP

Voice over Internet Protocol, telephony delivered over IP networks, requiring security measures against eavesdropping, toll fraud, and denial of service.

VPN

See Virtual Private Network.

Vulnerability

A vulnerability is a weakness in a system that can be exploited by a threat actor to compromise confidentiality, integrity, or availability. See Top 7 for full definition.

Vulnerability Management Lifecycle

The end-to-end process of discovering, evaluating, prioritising, remediating, and verifying vulnerabilities across an organisation’s assets on an ongoing basis.

W

Watering Hole Attack

An attack where threat actors compromise a website frequently visited by the target audience, infecting visitors’ systems with malware.

Weaponization

The phase in the kill chain where an attacker creates a deliverable payload by combining an exploit with malware, preparing it for delivery to the target.

Web Application Firewall (WAF)

A security tool that filters and monitors HTTP traffic between a web application and the internet, protecting against attacks such as SQL injection, XSS, and CSRF.

Web Server

A system that hosts and delivers web content, requiring hardening, patching, and monitoring to prevent exploitation of security vulnerabilities.

Web Spider

An automated program that crawls websites to index content, which can be used by attackers for reconnaissance and by security teams for vulnerability scanning.

Website Application Security

The practice of protecting web applications from security threats through secure coding, testing, WAF deployment, and continuous monitoring.

Website Defacement

An attack where an adversary alters the visual appearance of a website, often motivated by hacktivism, to damage reputation or spread propaganda.

Website Logging

Recording web server activity, including requests, errors, and access attempts, for security monitoring, forensics, and compliance.

Cybersecurity Researcher

A professional who investigates new security vulnerabilities, attack techniques, and defensive strategies, often publishing findings to improve industry-wide security.

DevSecOps Engineer

A professional who integrates security practices into DevOps workflows, automating security testing in CI/CD pipelines and promoting a shift-left approach to security.

Security Protocol

A set of rules governing secure communication between systems, including TLS, IPsec (internet protocol security), and Kerberos, ensuring data confidentiality and integrity.

Zero-Day Vulnerability

A zero-day vulnerability is a security flaw known to the attacker before a fix is available. Zero-days are highly valuable to attackers because there is no patch, making detection and response critical.

Application Firewall

A firewall specifically designed to protect applications by inspecting traffic at the application layer, blocking injection attacks, and enforcing access policies.

ASLR

See Address Space Layout Randomization.

Asset Discovery

The process of identifying all devices, services, and applications on a network, essential for understanding the attack surface and maintaining accurate asset inventories.

Debug Logging

Detailed logging of system operations and variable states intended for troubleshooting, which can expose sensitive information if left enabled in production environments.

Log Aggregation

The process of collecting log data from multiple sources into a centralised location for unified analysis, correlation, and long-term storage.

Web Shell

A script uploaded to a web server that provides an attacker with remote command execution, serving as a persistent foothold for further exploitation.

White Team

The neutral team in a security exercise that designs scenarios, monitors rules of engagement, and judges outcomes between red and blue teams.

Wiper Attack

A destructive cyber attack that permanently deletes or corrupts data on targeted systems, motivated by sabotage rather than financial gain.

X

XML External Entity Injection

An attack against applications parsing XML input, exploiting insecure XML parsers to access files, execute server-side request forgery, or cause denial of service.

XSRF

See Cross-Site Request Forgery (CSRF).

XSS (Cross-Site Scripting)

See Cross-Site Scripting entry under C. XSS enables attackers to inject malicious scripts into web pages viewed by other users.

Y

YARA Rules

Pattern-matching rules used by security researchers and tools to identify and classify malware based on textual or binary patterns within files and memory.

Z

Zero-Day Vulnerabilities

See Zero-Day Vulnerability. Flaws exploited before the vendor is aware or has released a fix, requiring rapid mitigation through network segmentation, monitoring, and compensating controls.

Zero Trust Architecture

A security design approach that removes implicit trust from network perimeters and requires continuous validation of identity, device posture, and context for every access request. Zero Trust is a security model where no user or device is automatically trusted.

Zero Trust Network Access (ZTNA)

A technology that enforces zero trust principles for remote access, replacing traditional VPNs by granting application-level access based on identity, device, and context.

Zero Trust Security

The broader security philosophy and implementation of never implicitly trusting and always verifying, applying to networks, applications, data, and users.

Zeus Trojan

A notorious banking trojan that steals financial credentials through keystroke logging and form grabbing, and whose source code spawned numerous derivative malware families.

Zip Bomb

A malicious archive file designed to crash or overwhelm the system that attempts to decompress it, consuming massive computing resources.

Zombie Botnet

A network of compromised devices, referred to as zombies, remotely controlled by an attacker to carry out coordinated attacks such as DDoS, spam, and cryptojacking.

Which Cyber Security Concepts Should You Master First?

The right starting point depends on your role:

  • Choose to master risk assessment, risk management, acceptable risk, and security posture if you lead strategy or sit on a board. These concepts drive investment decisions and regulatory compliance.

  • Prioritise IAM, least privilege, zero trust, network segmentation, CSPM, and patching if you run IT or cloud operations. These directly reduce your attack surface and protect business operations.

  • Focus on SIEM, EDR/XDR, MITRE ATT&CK, IOA/IOC, MTTD/MTTR if you build or mature a SOC capability. These are the building blocks of effective detection and response.

  • Emphasise phishing, ransomware, cyber hygiene, BYOD, shadow IT, and browser misuse for company-wide security awareness programmes. Human risk remains the most exploited vector, and these concepts help every employee make safer decisions.

Cyphere helps organisations prioritise and operationalise these concepts through tailored penetration testing, risk consulting, and remediation support, from SME cyber security engagements to enterprise-wide programmes.

Final Thoughts

A shared cyber security glossary reduces misunderstandings between technical teams, leadership, and external partners. When everyone from the SOC analyst to the board director understands the difference between a vulnerability and an exploit, or between risk tolerance and acceptable risk, organisations make better, faster decisions.

Understanding the language of attackers, including kill chains, lateral movement, C2 servers, and zero-day exploits, and the language of defenders, including GRC, CTEM, SOC, CSPM, and safe remediation, is critical for effective decision-making across every level of the business.

We encourage you to reuse and adapt this glossary within your security policies, training materials, and board packs. If you need deeper assessments or a bespoke maturity roadmap, get in touch with Cyphere to discuss how our CREST-accredited team can help strengthen your security posture.

Good Security Practices Start With the Right Foundations

Explore actionable insights that help businesses map their attack surface and address exploitable risks ranked by real business impact.

Trusted by 150+ UK orgs

Related Reads

Join 1000+ subscribers getting the best tips on cybersecurity, security management, and more!

You may opt-out at any time. Read our privacy policy.

Request a Consultation

No obligations. Free retests included. Call us directly 0333 050 9002. View our privacy policy.

How "Defensible" is your firm compared to UK peers?

Most SMBs and mid-market firms have “silent” gaps in their people, process and tech controls implementation. Take the 90-second maturity audit to see your percentile rank.