The Cyber Security Glossary
Explore all essential cyber security terms in one place, ensuring you are on the same page with the fast-changing digital world.
Access Control
A security technique used to ensure that only authorized users can access certain resources or data.
Advanced Persistent Threat (APT)
A prolonged and targeted cyberattack in which an intruder gains and maintains access to a network over a long period of time.
Adversary
An entity (individual, group, or nation-state) that is attempting to gain unauthorized access to systems or networks for malicious purposes.
Adware
Software that automatically displays or downloads advertising material when a user is online.
Agentic AI
Artificial intelligence that acts autonomously or with minimal human intervention, often used in cybersecurity to detect and respond to threats.
Antivirus
Software designed to detect and remove malicious software from a computer system.
Attack Surface
The total number of vulnerabilities that can be exploited by attackers within a system or network.
Authentication
The process of verifying the identity of a user, device or system.
Authorization
The process of granting or denying access to resources based on an authenticated identity.
Backdoor
A method of bypassing normal authentication to gain access to a system or network.
Backup
A copy of important data or files stored separately to ensure recovery in the event of a data loss.
Behavior Assessments
The process of analyzing and evaluating user behavior to identify risks or vulnerabilities within an organizationโs systems.
ReSeBI (Resilient Security Behavior Index)Botnet
A network of infected computers (bots) that are controlled remotely to carry out cyberattacks, such as DDoS attacks.
Breach
The unauthorized access or acquisition of data from a system, often leading to exposure of sensitive information.
Brute Force Attack
A type of attack where an attacker tries all possible combinations to crack a password or encryption.
BYOD (Bring Your Own Device)
A policy allowing employees to use their personal devices (smartphones, tablets, etc.) for work-related tasks.
Call Back Phishing
A form of phishing where attackers impersonate legitimate entities and ask victims to call a phone number controlled by the attacker.
Chainlink Phishing
A type of phishing attack where malicious actors use social engineering to trick victims into clicking links that lead to fake websites.
CIA Triad
A widely accepted model consisting of confidentiality, integrity, and availability, representing the core principles of information security.
Clickfix Scam
A fraudulent tactic where attackers convince victims to click on a link by posing as a tool that offers to fix problems.
Cloud Security
The measures and technologies used to protect data, applications, and services stored in the cloud.
Credential
A set of user credentials (e.g., username and password) that allow access to a system or network.
Cryptography
The practice of securing information by transforming it into unreadable formats.
Cyber Attack
A deliberate attempt to compromise the integrity, confidentiality, or availability of a system.
Cyber Resilience
The ability of an organization to continue operating despite experiencing cyberattacks.
Building Human Cyber ResilienceISO 27001 Aligned TrainingCyber Security Awareness
The knowledge of potential cyber threats and best practices to protect data.
Essentials for EmployeesTransitioning to Behavior ManagementCyber Security Awareness Month
An annual event in October to promote safe online behaviors.
Success in Remote EnvironmentsMeasuring Campaign SuccessCyber Security Behavior
The actions and practices employees adopt concerning security.
Psychology-driven BehaviorKPIs for Behavior and CultureCyber Security Culture
Collective attitudes and practices related to security within an organization.
Shaping the Vision for CultureAssessing State of CultureDark Web
A part of the internet not indexed by search engines, often used for illicit activities.
Data Encryption
Converting data into a coded format to prevent unauthorized access.
Data Leak
The unintended exposure of sensitive data to unauthorized parties.
Data Loss Prevention (DLP)
A strategy to ensure sensitive data is not lost or misused.
Data Privacy & Protection
Safeguarding sensitive data from unauthorized access.
Designing Effective Privacy TrainingDDoS (Distributed Denial-of-Service)
An attack flooding a target system with traffic to make it unavailable.
Deepfake
Media where AI is used to create realistic but fake content.
DPDP Act
Digital Personal Data Protection Act (India), regulating personal data processing.
What Senior Leadership Must KnowEmail Bombing
Flooding an inbox with massive volumes of unsolicited emails.
Email Security
Protecting email from phishing, malware, and other threats.
Encryption
Securing data by converting it into an unreadable format.
Endpoint Security
Protecting devices like computers and smartphones.
Exploit
Code that takes advantage of a vulnerability to cause damage.
Gamified Cyber Security Training
An interactive approach using game elements to engage users.
Gamified Training EssentialsHacker
An individual using technical skills to gain unauthorized access.
Hashing
Converting data into a fixed-size string for integrity checks.
Honeypot
A decoy system set up to attract and monitor attackers.
Identity Theft
Fraudulent acquisition of personal information for financial gain.
Incident Response
Procedures used to detect and recover from security incidents.
ISO 27001
International standard for information security management.
ISO 27001 for SMEsSimplified Guide to ISO 27001Malware
Software designed to harm or compromise a computer system.
Multi-factor Authentication (MFA)
Verification requiring two or more forms of identity.
Patch Management
Applying updates to fix vulnerabilities in software.
Phishing
Social engineering designed to trick users into revealing sensitive data.
Security Awareness Training
Programs educating employees about threats.
Selecting Ideal Training PartnersMeasuring EffectivenessSocial Engineering
Technique used to deceive people into divulging confidential info.
Steganography
Concealing data within another file.
Zero-Day
A vulnerability unknown to the vendor with no patch available.