Cybersecurity glossary
Short, plain definitions of the network, endpoint, post-quantum and compliance terms you'll meet when you secure a company network. One or two sentences per term, from Active Directory to ZTNA, with a link to the page that goes deeper wherever one exists.
119 terms
A
Active Directory
Active Directory is Microsoft's directory service for Windows networks. It stores users, computers and groups, and controls how they sign in and what they're allowed to reach.
AES
The Advanced Encryption Standard (AES) is the symmetric encryption algorithm NIST standardized in 2001. AES-256-GCM uses a 256-bit key and also detects whether the data was tampered with.
Air gap
An air gap isolates a computer or network from the internet and from any other unsecured network, so there's no direct path for data to get in or out.
Antivirus
Antivirus software scans files, programs and memory for known malware, then blocks, quarantines or removes what it finds. Most modern products also watch for suspicious behavior, not only known signatures.
Asymmetric encryption
Asymmetric encryption uses a pair of keys: a public key anyone can use to encrypt, and a private key that only its owner holds to decrypt. RSA is the best-known example.
ATO
An authorization to operate (ATO) is the formal decision by a senior official that a system's remaining security risk is acceptable, so it can go into use. It's a step in the RMF.
B
Botnet
A botnet is a network of computers, phones or smart devices infected with malware and controlled remotely by an attacker, usually without their owners noticing. Botnets send spam and launch DDoS attacks.
Brute-force attack
A brute-force attack tries huge numbers of passwords, PINs or keys, one after another, until one works. Long unique passwords, MFA and locking accounts after repeated failures make it impractical.
Business email compromise
Business email compromise (BEC) is fraud in which criminals use a hacked or spoofed business email account to trick staff into paying fake invoices, changing bank details or sending sensitive data.
BYOD
Bring your own device (BYOD) is a policy that lets employees use personal laptops, phones or tablets for work, which puts company data on devices the company doesn't own.
C
Certificate authority
A certificate authority (CA) is a trusted entity that issues and signs digital certificates, vouching that a public key really belongs to a named person, device or server.
CISA
The Cybersecurity and Infrastructure Security Agency (CISA) is the US agency that leads the protection of federal civilian networks and coordinates the security of critical infrastructure. It publishes alerts and the Known Exploited Vulnerabilities catalog.
CMMC
The Cybersecurity Maturity Model Certification (CMMC) is the US Department of Defense program that verifies whether contractors protect federal contract information and controlled unclassified information, at one of three levels.
CNCS
CNCS, the Centro Nacional de Cibersegurança, is Portugal's national cybersecurity authority. It runs CERT.PT, which coordinates the response to incidents, and publishes cybersecurity guidance for organizations in Portugal.
CNPD
CNPD, the Comissão Nacional de Proteção de Dados, is Portugal's data protection authority. It supervises how the GDPR is applied in Portugal, handles complaints and can fine organizations that break the rules.
CNSA 2.0
CNSA 2.0, the Commercial National Security Algorithm Suite 2.0, is the US National Security Agency's list of quantum-resistant algorithms and transition deadlines for national security systems.
Compliance crosswalk
A compliance crosswalk maps the controls of one security framework to the matching controls in others, so a single piece of evidence can count toward several frameworks at once.
Computer virus
A computer virus is malware that attaches itself to a legitimate file or program and spreads when that file is opened or run, copying itself to other files and devices.
Control plane
The control plane is the part of a network or system that decides and distributes configuration and policy. It's separate from the data plane, which carries the actual traffic.
Credential stuffing
Credential stuffing is an attack that takes usernames and passwords leaked from one service and tries them automatically on many others, counting on people reusing the same password.
Crypto agility
Crypto agility is the ability to swap cryptographic algorithms, key sizes or protocols in a system without redesigning it or replacing its hardware.
CSIRT
A computer security incident response team (CSIRT), often called a CERT, receives reports of security incidents, helps contain them and coordinates the response. Countries, sectors and large companies run their own.
CVE
A CVE (Common Vulnerabilities and Exposures) entry is the public ID, written as CVE-year-number, given to a disclosed security flaw so everyone refers to the same one.
Cyber Resilience Act
The Cyber Resilience Act (CRA) is the EU regulation that sets cybersecurity requirements for hardware and software products sold in the EU, including how their vulnerabilities are handled. Most obligations apply from December 2027.
Cyberattack
A cyberattack is any deliberate attempt to steal, alter, disable or destroy data, systems or networks, or to get into them without authorization.
Cybersecurity
Cybersecurity is the practice of protecting computers, networks, devices and data from attacks, unauthorized access and damage, using technology, processes and people's everyday habits.
D
Dark web
The dark web is the part of the internet that search engines don't index and that can only be reached with special software such as Tor. Stolen data and attack tools are often traded there.
Data breach
A data breach is an incident in which personal or confidential data is accessed, copied or disclosed without authorization. Under the GDPR, breaches that put people at risk must be reported to the authority within 72 hours.
DDoS attack
A distributed denial-of-service (DDoS) attack floods a website, server or network with traffic from many devices at once, often a botnet, until it slows down or stops responding to real users.
Deepfake
A deepfake is a video, image or audio clip generated or altered with AI to imitate a real person convincingly. Criminals use deepfakes in fraud, for example to fake an executive's voice on a call.
Default deny
Default deny is a policy rule that blocks every connection that hasn't been explicitly allowed. Access has to be granted on purpose instead of being taken away after a problem.
Device control
Device control is a security control that decides which peripherals, such as USB storage drives, can connect to a computer and what they're allowed to do once connected.
Device enrollment
Device enrollment is the process of registering a device with a management system and giving it an identity, such as a certificate, before it's allowed to connect.
Digital certificate
A digital certificate is a file, usually in X.509 format, that binds a public key to an identity and is signed by a certificate authority. It expires and can be revoked early.
Digital signature
A digital signature is a value created with a private key that proves who produced a piece of data and that it hasn't changed since. Anyone with the matching public key can check it.
DNS filtering
DNS filtering blocks access to websites and services by checking each domain lookup against lists of malicious or unwanted domains before a connection is made.
DORA
The Digital Operational Resilience Act (DORA) is the EU regulation, applied since January 2025, that requires financial entities to manage ICT risk, report major incidents and test their resilience.
E
EDR
Endpoint detection and response (EDR) is software that records activity on laptops, servers and other endpoints, flags suspicious behavior and lets defenders contain and investigate it.
Encryption
Encryption turns readable data into scrambled ciphertext that only someone holding the right key can turn back into its original, readable form.
Endpoint protection
Endpoint protection is security software on laptops, desktops and servers that prevents, detects and blocks threats such as malware directly on each device.
ENISA
ENISA, the European Union Agency for Cybersecurity, helps EU countries and institutions raise their level of cybersecurity with guidance, threat reports, exercises and EU cybersecurity certification schemes.
Entra ID
Microsoft Entra ID, formerly Azure Active Directory, is Microsoft's cloud identity service. It signs users in to applications and controls which resources each person can reach.
Exploit
An exploit is code or a technique that takes advantage of a vulnerability to make software or hardware do something it shouldn't, such as run an attacker's commands.
F
FIPS 203
FIPS 203 is the NIST standard, published in August 2024, that specifies ML-KEM, a post-quantum algorithm for agreeing on shared encryption keys.
FIPS 204
FIPS 204 is the NIST standard, published in August 2024, that specifies ML-DSA, a post-quantum algorithm for creating and verifying digital signatures.
Firewall
A firewall is a security control that allows or blocks network traffic according to rules based on addresses, ports, protocols or applications.
G
Gateway
A gateway is a device or piece of software at the edge of a network that passes traffic between networks and applies policy. In a VPN, it's where encrypted tunnels start or end.
GDPR
The General Data Protection Regulation (GDPR), RGPD in Portuguese, is the EU law that sets how organizations collect, use and protect personal data. It has applied since May 2018.
H
Hacking
Hacking is gaining access to computers, networks or data by exploiting technical or human weaknesses. Without permission it's usually a crime; with permission, as ethical hacking, it finds flaws before criminals do.
Harvest now, decrypt later
Harvest now, decrypt later is an attack strategy in which encrypted data is collected and stored today, to be decrypted once a powerful enough quantum computer exists.
HIPAA
The Health Insurance Portability and Accountability Act (HIPAA) is a 1996 US law. Its Security Rule requires healthcare organizations and their business associates to protect electronic health information.
Hybrid key exchange
A hybrid key exchange combines a classical algorithm, such as elliptic-curve Diffie-Hellman, with a post-quantum one, such as ML-KEM, so an attacker must break both to recover the key.
I
Identity theft
Identity theft is using someone else's personal information, such as their name, ID number or bank details, without permission, usually to commit fraud, open accounts or make purchases.
Incident response
Incident response is the organized way an organization detects, contains and recovers from a security incident, and then learns from it. It usually follows a written plan with assigned roles.
Insider threat
An insider threat is a security risk that comes from people with legitimate access, such as employees, contractors or partners, whether they cause harm on purpose or by mistake.
ISO 27001
ISO/IEC 27001 is the international standard for running an information security management system. Organizations can be certified against it by an accredited auditor.
K
Kernel
The kernel is the core of an operating system, controlling memory, processes and hardware with the highest privileges. Security software often runs kernel drivers, and a kernel flaw can expose the whole system.
Keylogger
A keylogger is software or a small hardware device that records every key pressed on a keyboard, so an attacker can capture passwords, messages and card numbers.
L
LDAP
The Lightweight Directory Access Protocol (LDAP) is an open standard for querying and updating directory services such as Active Directory, often used to check sign-in credentials.
Least privilege
Least privilege is the principle that every user, device and program gets only the access it needs to do its job, and nothing more.
M
Malware
Malware is any software written to harm a device, steal data or gain unauthorized access. Viruses, trojans, spyware and ransomware are all types of malware.
Man-in-the-middle attack
A man-in-the-middle (MITM) attack puts the attacker secretly between two parties who think they're talking directly, so the attacker can read or change what they send. Encryption with properly verified certificates is the main defense.
MFA
Multi-factor authentication (MFA) requires two or more independent proofs of identity to sign in, such as a password plus a code from a phone or a hardware key.
Microsegmentation
Microsegmentation divides a network into small isolated segments, down to single devices or workloads, with rules that control exactly which traffic may pass between them.
MITRE ATT&CK
MITRE ATT&CK is a free, public knowledge base of the tactics and techniques attackers use, built from real-world observations and used to map detections and find gaps.
ML-DSA
ML-DSA, the Module-Lattice-Based Digital Signature Algorithm, is the post-quantum signature scheme standardized in FIPS 204. It was derived from CRYSTALS-Dilithium.
ML-KEM
ML-KEM, the Module-Lattice-Based Key-Encapsulation Mechanism, is the post-quantum algorithm standardized in FIPS 203 for agreeing on shared encryption keys. It was derived from CRYSTALS-Kyber.
N
Network access control
Network access control (NAC) decides which users and devices may connect to a network and what they can reach, based on identity, device state and policy.
Network segmentation
Network segmentation splits a network into separate zones with controlled traffic between them, so an intruder or a fault in one zone can't spread freely to the others.
NIS2
NIS2 is the EU directive, Directive (EU) 2022/2555, that sets cybersecurity risk-management and incident-reporting duties for essential and important entities across 18 sectors.
NIST
The National Institute of Standards and Technology (NIST) is a US federal agency that publishes widely used security standards and guidance, including the Cybersecurity Framework and the post-quantum standards FIPS 203 and FIPS 204.
NIST CSF
The NIST Cybersecurity Framework (CSF) is a voluntary framework for managing cybersecurity risk. Version 2.0, released in 2024, groups its outcomes into six functions: Govern, Identify, Protect, Detect, Respond and Recover.
O
On-premises
On-premises describes software and hardware that run in facilities an organization owns or controls, instead of in a cloud provider's data centers.
OT
Operational technology (OT) is the hardware and software that monitor and control physical processes, such as industrial control systems (ICS) and SCADA in plants, utilities and transport.
P
Password manager
A password manager is an application that stores passwords in an encrypted vault, generates strong unique ones and fills them in, so people don't have to reuse or memorize them.
Patch
A patch is an update from a software or hardware vendor that fixes a vulnerability or a bug. Installing patches promptly closes known weaknesses before attackers can use them.
PCI DSS
The Payment Card Industry Data Security Standard (PCI DSS) sets security requirements for any organization that stores, processes or transmits payment card data. The PCI Security Standards Council maintains it.
Penetration testing
Penetration testing is an authorized, simulated attack on systems, networks or applications, carried out by security testers to find weaknesses before real attackers do.
Phishing
Phishing is an attack in which fake emails, messages or websites pose as a trusted organization to trick people into giving away passwords or payment details, or into installing malware.
POA&M
A plan of action and milestones (POA&M) is a document that lists each known security weakness, the steps to fix it, who owns the fix and when it's due.
Post-quantum cryptography
Post-quantum cryptography (PQC) is public-key cryptography designed to resist attacks from both classical and quantum computers, while running on today's hardware and networks.
Q
QKD
Quantum key distribution (QKD) uses the quantum states of light to create a shared encryption key, and any eavesdropping disturbs those states and shows up. It needs dedicated optical hardware.
Quantum-safe
Quantum-safe describes cryptography expected to stay secure against attacks by quantum computers. The term covers both post-quantum algorithms and quantum key distribution.
Quishing
Quishing is phishing through a QR code, printed or sent by email, that takes whoever scans it to a fake website built to steal passwords or payment details.
R
Ransomware
Ransomware is malware that encrypts or locks an organization's files and systems, then demands payment to release them. Many variants also steal data first and threaten to publish it.
Remote access VPN
A remote access VPN connects individual people's devices to an organization's private network over the internet, so they can reach internal systems from wherever they work.
Risk score
A risk score is a single number that sums up how exposed a system or organization is, calculated from weighted factors such as vulnerabilities, misconfigurations and active alerts.
RMF
The Risk Management Framework (RMF), defined in NIST SP 800-37, is a seven-step process for managing security and privacy risk in information systems, from preparation to continuous monitoring.
Rootkit
A rootkit is malware built to hide itself and other malicious software from users and security tools, often by running deep in the operating system, at kernel level.
S
SASE
Secure access service edge (SASE) is an architecture that delivers networking, such as SD-WAN, together with security services, such as ZTNA and secure web gateways, from the cloud.
SD-WAN
A software-defined wide area network (SD-WAN) connects sites through central software that steers traffic across several links, such as MPLS, broadband and 4G or 5G, based on policy.
SIEM
Security information and event management (SIEM) software collects logs and events from across an organization, correlates them to spot threats and keeps them for investigations and audits.
Site-to-site VPN
A site-to-site VPN permanently links two whole networks, such as a head office and a branch, through gateways at each end, so the devices behind them need no VPN software of their own.
Smishing
Smishing is phishing by text message: an SMS or chat message that poses as a bank, courier or public service and pushes the reader to tap a link or share personal details.
SOC
A security operations center (SOC) is the team, processes and tools that monitor an organization's systems and respond to security incidents. It can be in-house or outsourced.
SOC 2
SOC 2 is an audit report, based on AICPA criteria, on how a service organization controls security, availability, processing integrity, confidentiality and privacy. Customers often ask software vendors for one.
Spear phishing
Spear phishing is phishing aimed at a specific person or organization, using details such as names, roles or recent events to make the message believable.
Split tunneling
Split tunneling is a VPN setting that sends only traffic bound for company resources through the tunnel, while everything else goes straight to the internet. A full tunnel sends all traffic through the VPN.
Spoofing
Spoofing is faking an email address, phone number, website or network address so that a message or connection appears to come from a trusted source.
Spyware
Spyware is malware that secretly monitors what a person does on a device, such as browsing, messages or location, and sends that information to someone else.
SSE
Security service edge (SSE) is the security half of SASE: services such as ZTNA, secure web gateways and cloud access security brokers, delivered from the cloud without the networking part.
SSO
Single sign-on (SSO) lets a person sign in once with an identity provider and then open several applications without entering credentials again for each one.
Supply chain attack
A supply chain attack compromises a trusted supplier, such as a software vendor or service provider, to reach that supplier's customers through its updates, tools or access.
Symmetric encryption
Symmetric encryption uses the same secret key to encrypt and decrypt data. It's fast, which is why it protects bulk data, and AES is the standard example.
T
TLS
Transport Layer Security (TLS) is the protocol that encrypts and authenticates data traveling between two systems, such as a browser and a website. TLS 1.3 is the current version.
Trojan
A Trojan, or Trojan horse, is malware disguised as a legitimate program or file. Once someone installs or opens it, it gives attackers access or installs other malware.
Two-factor authentication
Two-factor authentication (2FA) is a form of MFA that asks for exactly two different proofs of identity, typically a password plus a one-time code, an app prompt or a security key.
V
Vishing
Vishing is phishing by phone call or voicemail, where the caller poses as a bank, supplier or technical support to get payment details, passwords or remote access to a computer.
VLAN
A virtual LAN (VLAN) is a logical network carved out of a physical one, so devices on the same switches can be kept in separate groups with separate rules.
VPN
A virtual private network (VPN) creates an encrypted tunnel over a public network such as the internet, so data can travel between a device and a private network without being read.
Vulnerability
A vulnerability is a weakness in software, hardware, configuration or process that an attacker could exploit. Publicly disclosed vulnerabilities get a CVE ID and, usually, a severity score.
W
Whaling
Whaling is spear phishing aimed at senior executives, such as a CEO or finance director, usually to get a large payment authorized or confidential information revealed.
Worm
A worm is malware that copies itself and spreads across networks on its own, without anyone opening a file, by exploiting vulnerabilities in the systems it reaches.
X
XDR
Extended detection and response (XDR) correlates detection data from endpoints, networks, cloud services and email in one platform, instead of from endpoints alone as EDR does.
Z
Zero trust
Zero trust is a security model that grants no automatic trust based on network location. Every user, device and request must be verified and authorized, every time.
Zero-day
A zero-day is a vulnerability that attackers know about or exploit before the vendor has released a fix, so defenders have had zero days to patch it.
ZTNA
Zero trust network access (ZTNA) gives people access to specific applications only after checking their identity and context, instead of putting them on the whole network.
No term matches that search. Try a shorter word, or tell us which term to add.
Missing a term?
If you came across a term in an audit questionnaire or a vendor proposal and it is not here, tell us which one and we will define it.
Social engineering
Social engineering is manipulating people, rather than breaking into systems, to get them to break security rules, for example by posing as a colleague, supplier or IT support to obtain a password or payment.