Reference

Cybersecurity glossary

Plain-English definitions of 56 terms you will meet in audits, vendor questionnaires, news and policy. Jump by letter or use your browser's find.

A

Access control
Rules and mechanisms that decide who can view or change what. Broken access control is the most common web application weakness.
Advanced persistent threat (APT)
A well-resourced attacker who gains access and stays hidden for a long time, usually to steal data rather than cause immediate disruption.
Attack surface
Everything an attacker could try: exposed services, user accounts, devices, third-party integrations and people.
Authentication
Proving you are who you claim to be — a password, a code from an app, a hardware key or biometrics.
Authorisation
What an authenticated user is allowed to do. Authentication asks "who are you?"; authorisation asks "may you do this?".

B

Backup (3-2-1 rule)
Three copies of your data, on two different media, with one copy off-site. Test restores regularly.
Brute-force attack
Guessing passwords or keys by trying many combinations. Rate limiting, lockouts and MFA defeat it.
Business email compromise (BEC)
Fraud where an attacker impersonates a senior person or vendor by email to trigger a payment or data release.

C

CERT-In
India's national Computer Emergency Response Team, which issues advisories and incident-reporting directions.
Credential stuffing
Trying username/password pairs leaked from one breach against other sites, relying on password reuse.
CVE
Common Vulnerabilities and Exposures — a public identifier (e.g. CVE-2024-12345) for a specific known vulnerability.
CVSS
Common Vulnerability Scoring System — a 0–10 score describing a vulnerability's severity.

D

Data breach
Unauthorised access to, or disclosure of, personal or confidential data.
Data minimisation
Collecting and keeping only the data you actually need — a core principle of privacy law.
DDoS (distributed denial of service)
Flooding a service with traffic from many sources so legitimate users cannot reach it.
DevSecOps
Building security checks into the software development and deployment pipeline rather than at the end.
DKIM, SPF, DMARC
Email authentication standards that help receivers verify a message really came from your domain, reducing impersonation.
DPDP Act
India's Digital Personal Data Protection Act, 2023 — the law governing how organisations process personal data.

E

Encryption at rest / in transit
Scrambling stored data (at rest) and data moving over networks (in transit) so it is unreadable without the key.
Endpoint
Any device that connects to your network — laptops, lab PCs, phones, servers.
Endpoint detection and response (EDR)
Software that monitors endpoints for suspicious behaviour and lets responders investigate and contain it.

F

Firewall
A control that allows or blocks network traffic based on rules; exists at the network edge, on hosts and in the cloud.

H

Hardening
Reducing a system's attack surface by removing unnecessary services, applying secure settings and patching.
Hashing
Turning data into a fixed-length fingerprint that cannot be reversed. Passwords should be stored as salted hashes (bcrypt, argon2).

I

Incident response
The organised process of detecting, containing, eradicating and recovering from a security incident, then learning from it.
Insider threat
Risk from people with legitimate access — malicious, careless or compromised.
ISO/IEC 27001
An international standard for an information security management system; certification demonstrates a managed security programme.

L

Least privilege
Giving each person and system only the access they need to do their job, and no more.

M

Malware
Malicious software: viruses, worms, trojans, spyware, ransomware.
Multi-factor authentication (MFA)
Requiring a second proof of identity (an app code, hardware key) in addition to a password. Stops most account takeovers.

N

NIST Cybersecurity Framework
A widely used framework organising security activities into Govern, Identify, Protect, Detect, Respond and Recover.

O

OSINT
Open-source intelligence — information gathered from public sources, used by both attackers and defenders.
OWASP Top 10
The Open Worldwide Application Security Project's list of the most critical web application risks.

P

Patch management
The process of applying software updates that fix vulnerabilities, promptly and consistently.
Penetration test
An authorised, human-led simulated attack that finds and demonstrates exploitable weaknesses.
Phishing
Fraudulent messages that trick people into revealing credentials, paying money or installing malware. Variants: spear-phishing (targeted), smishing (SMS), vishing (voice), quishing (QR codes).
Principle of defence in depth
Layering multiple controls so that if one fails, others still protect the asset.
Privilege escalation
Gaining higher access than intended — for example a student account becoming an administrator.
Proctoring
Supervision of online examinations, through live monitoring, recording or automated flagging of suspicious behaviour.

R

Ransomware
Malware that encrypts data and demands payment for the key, often also threatening to leak the data.
Red team / blue team
Red teams simulate attackers; blue teams defend. Purple teaming brings them together to improve detection.
Risk assessment
Identifying what could go wrong, how likely it is, how bad it would be, and what to do about it.

S

Secure by design
Building security into a product from the start rather than adding it later; a principle promoted by CISA and partner agencies.
Security awareness training
Teaching people to recognise and respond to threats such as phishing and social engineering.
Security operations centre (SOC)
A team and tooling that monitor systems continuously for threats and respond to them.
SIEM
Security information and event management — a platform that collects logs from many systems and raises alerts.
Single sign-on (SSO)
One login that grants access to many applications; simplifies access and centralises MFA and offboarding.
Social engineering
Manipulating people rather than technology — pretexting, impersonation, urgency — to gain access.
SQL injection
Inserting database commands through user input; prevented by parameterised queries.
Supply-chain attack
Compromising an organisation through a trusted vendor, library or update.

T

Threat intelligence
Information about current attackers, their methods and indicators, used to improve defences.
TLS / HTTPS
The protocol that encrypts web traffic. Look for HTTPS and modern TLS (1.2 or 1.3) everywhere.

V

Vulnerability
A weakness that could be exploited. A vulnerability scan finds known ones automatically; a penetration test confirms what is exploitable.
Vulnerability disclosure policy (VDP)
A public statement of how security researchers can report vulnerabilities to you safely and what to expect in return.

Z

Zero trust
An approach that never assumes trust based on network location; every access request is verified.
Zero-day
A vulnerability that is exploited before the vendor has a fix available.