Security Quotient

The Cyber Security Glossary

Explore all essential cyber security terms in one place, ensuring you are on the same page with the fast-changing digital world.

ABCDEFGHIJKLMNOPQRSTUVWXYZ
A

Access Control

A security technique used to ensure that only authorized users can access certain resources or data.

Advanced Persistent Threat (APT)

A prolonged and targeted cyberattack in which an intruder gains and maintains access to a network over a long period of time.

Adversary

An entity (individual, group, or nation-state) that is attempting to gain unauthorized access to systems or networks for malicious purposes.

Adware

Software that automatically displays or downloads advertising material when a user is online.

Agentic AI

Artificial intelligence that acts autonomously or with minimal human intervention, often used in cybersecurity to detect and respond to threats.

Antivirus

Software designed to detect and remove malicious software from a computer system.

Attack Surface

The total number of vulnerabilities that can be exploited by attackers within a system or network.

Authentication

The process of verifying the identity of a user, device or system.

Authorization

The process of granting or denying access to resources based on an authenticated identity.

B

Backdoor

A method of bypassing normal authentication to gain access to a system or network.

Backup

A copy of important data or files stored separately to ensure recovery in the event of a data loss.

Behavior Assessments

The process of analyzing and evaluating user behavior to identify risks or vulnerabilities within an organizationโ€™s systems.

ReSeBI (Resilient Security Behavior Index)

Botnet

A network of infected computers (bots) that are controlled remotely to carry out cyberattacks, such as DDoS attacks.

Breach

The unauthorized access or acquisition of data from a system, often leading to exposure of sensitive information.

Brute Force Attack

A type of attack where an attacker tries all possible combinations to crack a password or encryption.

BYOD (Bring Your Own Device)

A policy allowing employees to use their personal devices (smartphones, tablets, etc.) for work-related tasks.

C

Call Back Phishing

A form of phishing where attackers impersonate legitimate entities and ask victims to call a phone number controlled by the attacker.

Chainlink Phishing

A type of phishing attack where malicious actors use social engineering to trick victims into clicking links that lead to fake websites.

CIA Triad

A widely accepted model consisting of confidentiality, integrity, and availability, representing the core principles of information security.

Clickfix Scam

A fraudulent tactic where attackers convince victims to click on a link by posing as a tool that offers to fix problems.

Cloud Security

The measures and technologies used to protect data, applications, and services stored in the cloud.

Credential

A set of user credentials (e.g., username and password) that allow access to a system or network.

Cryptography

The practice of securing information by transforming it into unreadable formats.

Cyber Attack

A deliberate attempt to compromise the integrity, confidentiality, or availability of a system.

Cyber Resilience

The ability of an organization to continue operating despite experiencing cyberattacks.

Building Human Cyber ResilienceISO 27001 Aligned Training

Cyber Security Awareness

The knowledge of potential cyber threats and best practices to protect data.

Essentials for EmployeesTransitioning to Behavior Management

Cyber Security Awareness Month

An annual event in October to promote safe online behaviors.

Success in Remote EnvironmentsMeasuring Campaign Success

Cyber Security Behavior

The actions and practices employees adopt concerning security.

Psychology-driven BehaviorKPIs for Behavior and Culture

Cyber Security Culture

Collective attitudes and practices related to security within an organization.

Shaping the Vision for CultureAssessing State of Culture
D

Dark Web

A part of the internet not indexed by search engines, often used for illicit activities.

Data Encryption

Converting data into a coded format to prevent unauthorized access.

Data Leak

The unintended exposure of sensitive data to unauthorized parties.

Data Loss Prevention (DLP)

A strategy to ensure sensitive data is not lost or misused.

Data Privacy & Protection

Safeguarding sensitive data from unauthorized access.

Designing Effective Privacy Training

DDoS (Distributed Denial-of-Service)

An attack flooding a target system with traffic to make it unavailable.

Deepfake

Media where AI is used to create realistic but fake content.

DPDP Act

Digital Personal Data Protection Act (India), regulating personal data processing.

What Senior Leadership Must Know
E

Email Bombing

Flooding an inbox with massive volumes of unsolicited emails.

Email Security

Protecting email from phishing, malware, and other threats.

Encryption

Securing data by converting it into an unreadable format.

Endpoint Security

Protecting devices like computers and smartphones.

Exploit

Code that takes advantage of a vulnerability to cause damage.

G

Gamified Cyber Security Training

An interactive approach using game elements to engage users.

Gamified Training Essentials

GDPR

EU regulation governing data protection and privacy.

GDPR Aligned Training
H

Hacker

An individual using technical skills to gain unauthorized access.

Hashing

Converting data into a fixed-size string for integrity checks.

Honeypot

A decoy system set up to attract and monitor attackers.

Human Error

Mistakes made by individuals leading to security breaches.

Minimizing Human Error
I

Identity Theft

Fraudulent acquisition of personal information for financial gain.

Incident Response

Procedures used to detect and recover from security incidents.

Insider Threat

A threat originating from within an organization.

Securing Against Insider Threats

ISO 27001

International standard for information security management.

ISO 27001 for SMEsSimplified Guide to ISO 27001
M

Malware

Software designed to harm or compromise a computer system.

Micro Learning

A strategy involving small, bite-sized lessons.

Micro Learning in Cyber Security

Multi-factor Authentication (MFA)

Verification requiring two or more forms of identity.

P

Patch Management

Applying updates to fix vulnerabilities in software.

Personally Identifiable Information (PII)

Data used to identify an individual.

7 Steps to Protect PII

Phishing

Social engineering designed to trick users into revealing sensitive data.

Phishing Tests

Simulated attacks to assess susceptibility to scams.

Fully Managed Phishing Tests
S

Security Awareness Training

Programs educating employees about threats.

Selecting Ideal Training PartnersMeasuring Effectiveness

Social Engineering

Technique used to deceive people into divulging confidential info.

Steganography

Concealing data within another file.

Z

Zero-Day

A vulnerability unknown to the vendor with no patch available.

Zero-Trust

A framework assuming no user should be trusted by default.

Securing Guest Wi-Fi