Learn

Cybersecurity glossary

Short, plain definitions of the network, endpoint, post-quantum and compliance terms you'll meet when you secure a company network. One or two sentences per term, from Active Directory to ZTNA, with a link to the page that goes deeper wherever one exists.

119 terms

A

Active Directory

Active Directory is Microsoft's directory service for Windows networks. It stores users, computers and groups, and controls how they sign in and what they're allowed to reach.

Learn more about Active Directory integration

AES

The Advanced Encryption Standard (AES) is the symmetric encryption algorithm NIST standardized in 2001. AES-256-GCM uses a 256-bit key and also detects whether the data was tampered with.

Learn more about Crypto agility

Air gap

An air gap isolates a computer or network from the internet and from any other unsecured network, so there's no direct path for data to get in or out.

Learn more about Air-gapped networking

Antivirus

Antivirus software scans files, programs and memory for known malware, then blocks, quarantines or removes what it finds. Most modern products also watch for suspicious behavior, not only known signatures.

Learn more about Endpoint protection

Asymmetric encryption

Asymmetric encryption uses a pair of keys: a public key anyone can use to encrypt, and a private key that only its owner holds to decrypt. RSA is the best-known example.

ATO

An authorization to operate (ATO) is the formal decision by a senior official that a system's remaining security risk is acceptable, so it can go into use. It's a step in the RMF.

Learn more about Compliance crosswalk

B

Botnet

A botnet is a network of computers, phones or smart devices infected with malware and controlled remotely by an attacker, usually without their owners noticing. Botnets send spam and launch DDoS attacks.

Brute-force attack

A brute-force attack tries huge numbers of passwords, PINs or keys, one after another, until one works. Long unique passwords, MFA and locking accounts after repeated failures make it impractical.

Learn more about Endpoint monitoring

Business email compromise

Business email compromise (BEC) is fraud in which criminals use a hacked or spoofed business email account to trick staff into paying fake invoices, changing bank details or sending sensitive data.

BYOD

Bring your own device (BYOD) is a policy that lets employees use personal laptops, phones or tablets for work, which puts company data on devices the company doesn't own.

C

Certificate authority

A certificate authority (CA) is a trusted entity that issues and signs digital certificates, vouching that a public key really belongs to a named person, device or server.

Learn more about Certificate management

CISA

The Cybersecurity and Infrastructure Security Agency (CISA) is the US agency that leads the protection of federal civilian networks and coordinates the security of critical infrastructure. It publishes alerts and the Known Exploited Vulnerabilities catalog.

CMMC

The Cybersecurity Maturity Model Certification (CMMC) is the US Department of Defense program that verifies whether contractors protect federal contract information and controlled unclassified information, at one of three levels.

CNCS

CNCS, the Centro Nacional de Cibersegurança, is Portugal's national cybersecurity authority. It runs CERT.PT, which coordinates the response to incidents, and publishes cybersecurity guidance for organizations in Portugal.

CNPD

CNPD, the Comissão Nacional de Proteção de Dados, is Portugal's data protection authority. It supervises how the GDPR is applied in Portugal, handles complaints and can fine organizations that break the rules.

CNSA 2.0

CNSA 2.0, the Commercial National Security Algorithm Suite 2.0, is the US National Security Agency's list of quantum-resistant algorithms and transition deadlines for national security systems.

Learn more about Post-quantum cryptography

Compliance crosswalk

A compliance crosswalk maps the controls of one security framework to the matching controls in others, so a single piece of evidence can count toward several frameworks at once.

Learn more about Compliance crosswalk

Computer virus

A computer virus is malware that attaches itself to a legitimate file or program and spreads when that file is opened or run, copying itself to other files and devices.

Learn more about Endpoint protection

Control plane

The control plane is the part of a network or system that decides and distributes configuration and policy. It's separate from the data plane, which carries the actual traffic.

Learn more about QS-WAN

Credential stuffing

Credential stuffing is an attack that takes usernames and passwords leaked from one service and tries them automatically on many others, counting on people reusing the same password.

Learn more about Enterprise password manager

Crypto agility

Crypto agility is the ability to swap cryptographic algorithms, key sizes or protocols in a system without redesigning it or replacing its hardware.

Learn more about Crypto agility

CSIRT

A computer security incident response team (CSIRT), often called a CERT, receives reports of security incidents, helps contain them and coordinates the response. Countries, sectors and large companies run their own.

CVE

A CVE (Common Vulnerabilities and Exposures) entry is the public ID, written as CVE-year-number, given to a disclosed security flaw so everyone refers to the same one.

Learn more about Endpoint monitoring

Cyber Resilience Act

The Cyber Resilience Act (CRA) is the EU regulation that sets cybersecurity requirements for hardware and software products sold in the EU, including how their vulnerabilities are handled. Most obligations apply from December 2027.

Cyberattack

A cyberattack is any deliberate attempt to steal, alter, disable or destroy data, systems or networks, or to get into them without authorization.

Cybersecurity

Cybersecurity is the practice of protecting computers, networks, devices and data from attacks, unauthorized access and damage, using technology, processes and people's everyday habits.

D

Dark web

The dark web is the part of the internet that search engines don't index and that can only be reached with special software such as Tor. Stolen data and attack tools are often traded there.

Data breach

A data breach is an incident in which personal or confidential data is accessed, copied or disclosed without authorization. Under the GDPR, breaches that put people at risk must be reported to the authority within 72 hours.

DDoS attack

A distributed denial-of-service (DDoS) attack floods a website, server or network with traffic from many devices at once, often a botnet, until it slows down or stops responding to real users.

Deepfake

A deepfake is a video, image or audio clip generated or altered with AI to imitate a real person convincingly. Criminals use deepfakes in fraud, for example to fake an executive's voice on a call.

Default deny

Default deny is a policy rule that blocks every connection that hasn't been explicitly allowed. Access has to be granted on purpose instead of being taken away after a problem.

Learn more about Microsegmentation

Device control

Device control is a security control that decides which peripherals, such as USB storage drives, can connect to a computer and what they're allowed to do once connected.

Learn more about USB device control

Device enrollment

Device enrollment is the process of registering a device with a management system and giving it an identity, such as a certificate, before it's allowed to connect.

Learn more about Device enrollment

Digital certificate

A digital certificate is a file, usually in X.509 format, that binds a public key to an identity and is signed by a certificate authority. It expires and can be revoked early.

Learn more about Certificate management

Digital signature

A digital signature is a value created with a private key that proves who produced a piece of data and that it hasn't changed since. Anyone with the matching public key can check it.

Learn more about Security policy management

DNS filtering

DNS filtering blocks access to websites and services by checking each domain lookup against lists of malicious or unwanted domains before a connection is made.

Learn more about DNS filtering

DORA

The Digital Operational Resilience Act (DORA) is the EU regulation, applied since January 2025, that requires financial entities to manage ICT risk, report major incidents and test their resilience.

E

EDR

Endpoint detection and response (EDR) is software that records activity on laptops, servers and other endpoints, flags suspicious behavior and lets defenders contain and investigate it.

Learn more about Endpoint detection and response

Encryption

Encryption turns readable data into scrambled ciphertext that only someone holding the right key can turn back into its original, readable form.

Endpoint protection

Endpoint protection is security software on laptops, desktops and servers that prevents, detects and blocks threats such as malware directly on each device.

Learn more about Endpoint protection

ENISA

ENISA, the European Union Agency for Cybersecurity, helps EU countries and institutions raise their level of cybersecurity with guidance, threat reports, exercises and EU cybersecurity certification schemes.

Entra ID

Microsoft Entra ID, formerly Azure Active Directory, is Microsoft's cloud identity service. It signs users in to applications and controls which resources each person can reach.

Learn more about Entra ID SSO

Exploit

An exploit is code or a technique that takes advantage of a vulnerability to make software or hardware do something it shouldn't, such as run an attacker's commands.

F

FIPS 203

FIPS 203 is the NIST standard, published in August 2024, that specifies ML-KEM, a post-quantum algorithm for agreeing on shared encryption keys.

Learn more about Post-quantum cryptography

FIPS 204

FIPS 204 is the NIST standard, published in August 2024, that specifies ML-DSA, a post-quantum algorithm for creating and verifying digital signatures.

Learn more about Post-quantum cryptography

Firewall

A firewall is a security control that allows or blocks network traffic according to rules based on addresses, ports, protocols or applications.

Learn more about Firewall rules

G

Gateway

A gateway is a device or piece of software at the edge of a network that passes traffic between networks and applies policy. In a VPN, it's where encrypted tunnels start or end.

Learn more about QS-WAN

GDPR

The General Data Protection Regulation (GDPR), RGPD in Portuguese, is the EU law that sets how organizations collect, use and protect personal data. It has applied since May 2018.

H

Hacking

Hacking is gaining access to computers, networks or data by exploiting technical or human weaknesses. Without permission it's usually a crime; with permission, as ethical hacking, it finds flaws before criminals do.

Harvest now, decrypt later

Harvest now, decrypt later is an attack strategy in which encrypted data is collected and stored today, to be decrypted once a powerful enough quantum computer exists.

Learn more about Post-quantum cryptography

HIPAA

The Health Insurance Portability and Accountability Act (HIPAA) is a 1996 US law. Its Security Rule requires healthcare organizations and their business associates to protect electronic health information.

Hybrid key exchange

A hybrid key exchange combines a classical algorithm, such as elliptic-curve Diffie-Hellman, with a post-quantum one, such as ML-KEM, so an attacker must break both to recover the key.

Learn more about Post-quantum cryptography

I

Identity theft

Identity theft is using someone else's personal information, such as their name, ID number or bank details, without permission, usually to commit fraud, open accounts or make purchases.

Incident response

Incident response is the organized way an organization detects, contains and recovers from a security incident, and then learns from it. It usually follows a written plan with assigned roles.

Insider threat

An insider threat is a security risk that comes from people with legitimate access, such as employees, contractors or partners, whether they cause harm on purpose or by mistake.

ISO 27001

ISO/IEC 27001 is the international standard for running an information security management system. Organizations can be certified against it by an accredited auditor.

K

Kernel

The kernel is the core of an operating system, controlling memory, processes and hardware with the highest privileges. Security software often runs kernel drivers, and a kernel flaw can expose the whole system.

Learn more about Endpoint detection and response

Keylogger

A keylogger is software or a small hardware device that records every key pressed on a keyboard, so an attacker can capture passwords, messages and card numbers.

L

LDAP

The Lightweight Directory Access Protocol (LDAP) is an open standard for querying and updating directory services such as Active Directory, often used to check sign-in credentials.

Learn more about Active Directory integration

Least privilege

Least privilege is the principle that every user, device and program gets only the access it needs to do its job, and nothing more.

M

Malware

Malware is any software written to harm a device, steal data or gain unauthorized access. Viruses, trojans, spyware and ransomware are all types of malware.

Learn more about Endpoint detection and response

Man-in-the-middle attack

A man-in-the-middle (MITM) attack puts the attacker secretly between two parties who think they're talking directly, so the attacker can read or change what they send. Encryption with properly verified certificates is the main defense.

MFA

Multi-factor authentication (MFA) requires two or more independent proofs of identity to sign in, such as a password plus a code from a phone or a hardware key.

Learn more about Device enrollment

Microsegmentation

Microsegmentation divides a network into small isolated segments, down to single devices or workloads, with rules that control exactly which traffic may pass between them.

Learn more about Microsegmentation

MITRE ATT&CK

MITRE ATT&CK is a free, public knowledge base of the tactics and techniques attackers use, built from real-world observations and used to map detections and find gaps.

Learn more about Endpoint monitoring

ML-DSA

ML-DSA, the Module-Lattice-Based Digital Signature Algorithm, is the post-quantum signature scheme standardized in FIPS 204. It was derived from CRYSTALS-Dilithium.

Learn more about Post-quantum cryptography

ML-KEM

ML-KEM, the Module-Lattice-Based Key-Encapsulation Mechanism, is the post-quantum algorithm standardized in FIPS 203 for agreeing on shared encryption keys. It was derived from CRYSTALS-Kyber.

Learn more about Post-quantum cryptography

N

Network access control

Network access control (NAC) decides which users and devices may connect to a network and what they can reach, based on identity, device state and policy.

Learn more about Network access control

Network segmentation

Network segmentation splits a network into separate zones with controlled traffic between them, so an intruder or a fault in one zone can't spread freely to the others.

Learn more about Microsegmentation

NIS2

NIS2 is the EU directive, Directive (EU) 2022/2555, that sets cybersecurity risk-management and incident-reporting duties for essential and important entities across 18 sectors.

NIST

The National Institute of Standards and Technology (NIST) is a US federal agency that publishes widely used security standards and guidance, including the Cybersecurity Framework and the post-quantum standards FIPS 203 and FIPS 204.

NIST CSF

The NIST Cybersecurity Framework (CSF) is a voluntary framework for managing cybersecurity risk. Version 2.0, released in 2024, groups its outcomes into six functions: Govern, Identify, Protect, Detect, Respond and Recover.

O

On-premises

On-premises describes software and hardware that run in facilities an organization owns or controls, instead of in a cloud provider's data centers.

Learn more about Air-gapped networking

OT

Operational technology (OT) is the hardware and software that monitor and control physical processes, such as industrial control systems (ICS) and SCADA in plants, utilities and transport.

Learn more about Industries

P

Password manager

A password manager is an application that stores passwords in an encrypted vault, generates strong unique ones and fills them in, so people don't have to reuse or memorize them.

Learn more about Enterprise password manager

Patch

A patch is an update from a software or hardware vendor that fixes a vulnerability or a bug. Installing patches promptly closes known weaknesses before attackers can use them.

PCI DSS

The Payment Card Industry Data Security Standard (PCI DSS) sets security requirements for any organization that stores, processes or transmits payment card data. The PCI Security Standards Council maintains it.

Penetration testing

Penetration testing is an authorized, simulated attack on systems, networks or applications, carried out by security testers to find weaknesses before real attackers do.

Phishing

Phishing is an attack in which fake emails, messages or websites pose as a trusted organization to trick people into giving away passwords or payment details, or into installing malware.

POA&M

A plan of action and milestones (POA&M) is a document that lists each known security weakness, the steps to fix it, who owns the fix and when it's due.

Learn more about Compliance crosswalk

Post-quantum cryptography

Post-quantum cryptography (PQC) is public-key cryptography designed to resist attacks from both classical and quantum computers, while running on today's hardware and networks.

Learn more about Post-quantum cryptography

Q

QKD

Quantum key distribution (QKD) uses the quantum states of light to create a shared encryption key, and any eavesdropping disturbs those states and shows up. It needs dedicated optical hardware.

Learn more about Secure file transfer

Quantum-safe

Quantum-safe describes cryptography expected to stay secure against attacks by quantum computers. The term covers both post-quantum algorithms and quantum key distribution.

Learn more about Post-quantum cryptography

Quishing

Quishing is phishing through a QR code, printed or sent by email, that takes whoever scans it to a fake website built to steal passwords or payment details.

R

Ransomware

Ransomware is malware that encrypts or locks an organization's files and systems, then demands payment to release them. Many variants also steal data first and threaten to publish it.

Learn more about Endpoint detection and response

Remote access VPN

A remote access VPN connects individual people's devices to an organization's private network over the internet, so they can reach internal systems from wherever they work.

Learn more about Secure remote access

Risk score

A risk score is a single number that sums up how exposed a system or organization is, calculated from weighted factors such as vulnerabilities, misconfigurations and active alerts.

Learn more about Risk scoring

RMF

The Risk Management Framework (RMF), defined in NIST SP 800-37, is a seven-step process for managing security and privacy risk in information systems, from preparation to continuous monitoring.

Learn more about Compliance crosswalk

Rootkit

A rootkit is malware built to hide itself and other malicious software from users and security tools, often by running deep in the operating system, at kernel level.

S

SASE

Secure access service edge (SASE) is an architecture that delivers networking, such as SD-WAN, together with security services, such as ZTNA and secure web gateways, from the cloud.

SD-WAN

A software-defined wide area network (SD-WAN) connects sites through central software that steers traffic across several links, such as MPLS, broadband and 4G or 5G, based on policy.

SIEM

Security information and event management (SIEM) software collects logs and events from across an organization, correlates them to spot threats and keeps them for investigations and audits.

Learn more about SIEM integration

Site-to-site VPN

A site-to-site VPN permanently links two whole networks, such as a head office and a branch, through gateways at each end, so the devices behind them need no VPN software of their own.

Smishing

Smishing is phishing by text message: an SMS or chat message that poses as a bank, courier or public service and pushes the reader to tap a link or share personal details.

SOC

A security operations center (SOC) is the team, processes and tools that monitor an organization's systems and respond to security incidents. It can be in-house or outsourced.

SOC 2

SOC 2 is an audit report, based on AICPA criteria, on how a service organization controls security, availability, processing integrity, confidentiality and privacy. Customers often ask software vendors for one.

Social engineering

Social engineering is manipulating people, rather than breaking into systems, to get them to break security rules, for example by posing as a colleague, supplier or IT support to obtain a password or payment.

Spear phishing

Spear phishing is phishing aimed at a specific person or organization, using details such as names, roles or recent events to make the message believable.

Split tunneling

Split tunneling is a VPN setting that sends only traffic bound for company resources through the tunnel, while everything else goes straight to the internet. A full tunnel sends all traffic through the VPN.

Learn more about VPN split tunneling

Spoofing

Spoofing is faking an email address, phone number, website or network address so that a message or connection appears to come from a trusted source.

Spyware

Spyware is malware that secretly monitors what a person does on a device, such as browsing, messages or location, and sends that information to someone else.

SSE

Security service edge (SSE) is the security half of SASE: services such as ZTNA, secure web gateways and cloud access security brokers, delivered from the cloud without the networking part.

SSO

Single sign-on (SSO) lets a person sign in once with an identity provider and then open several applications without entering credentials again for each one.

Learn more about Entra ID SSO

Supply chain attack

A supply chain attack compromises a trusted supplier, such as a software vendor or service provider, to reach that supplier's customers through its updates, tools or access.

Symmetric encryption

Symmetric encryption uses the same secret key to encrypt and decrypt data. It's fast, which is why it protects bulk data, and AES is the standard example.

T

TLS

Transport Layer Security (TLS) is the protocol that encrypts and authenticates data traveling between two systems, such as a browser and a website. TLS 1.3 is the current version.

Learn more about Crypto agility

Trojan

A Trojan, or Trojan horse, is malware disguised as a legitimate program or file. Once someone installs or opens it, it gives attackers access or installs other malware.

Two-factor authentication

Two-factor authentication (2FA) is a form of MFA that asks for exactly two different proofs of identity, typically a password plus a one-time code, an app prompt or a security key.

V

Vishing

Vishing is phishing by phone call or voicemail, where the caller poses as a bank, supplier or technical support to get payment details, passwords or remote access to a computer.

VLAN

A virtual LAN (VLAN) is a logical network carved out of a physical one, so devices on the same switches can be kept in separate groups with separate rules.

Learn more about Microsegmentation

VPN

A virtual private network (VPN) creates an encrypted tunnel over a public network such as the internet, so data can travel between a device and a private network without being read.

Learn more about Secure remote access

Vulnerability

A vulnerability is a weakness in software, hardware, configuration or process that an attacker could exploit. Publicly disclosed vulnerabilities get a CVE ID and, usually, a severity score.

W

Whaling

Whaling is spear phishing aimed at senior executives, such as a CEO or finance director, usually to get a large payment authorized or confidential information revealed.

Worm

A worm is malware that copies itself and spreads across networks on its own, without anyone opening a file, by exploiting vulnerabilities in the systems it reaches.

X

XDR

Extended detection and response (XDR) correlates detection data from endpoints, networks, cloud services and email in one platform, instead of from endpoints alone as EDR does.

Z

Zero trust

Zero trust is a security model that grants no automatic trust based on network location. Every user, device and request must be verified and authorized, every time.

Learn more about Microsegmentation

Zero-day

A zero-day is a vulnerability that attackers know about or exploit before the vendor has released a fix, so defenders have had zero days to patch it.

ZTNA

Zero trust network access (ZTNA) gives people access to specific applications only after checking their identity and context, instead of putting them on the whole network.

Learn more about Network access control

No term matches that search. Try a shorter word, or tell us which term to add.

Missing a term?

If you came across a term in an audit questionnaire or a vendor proposal and it is not here, tell us which one and we will define it.

Scroll to Top