Cyber security has its own language, from common attack methods and security controls to governance, risk and incident response. This A-Z glossary explains key cyber security terms in clear, practical language for learners, IT professionals and anyone building their understanding of modern security.
A
Access Control
Policies and technical measures that determine who or what can access systems, applications, data or physical locations.
Advanced Persistent Threat (APT)
A prolonged, targeted cyber attack in which a capable threat actor establishes and maintains access to a network, often to steal data or conduct espionage.
B
Backdoor
A hidden method of bypassing normal authentication or security controls to gain access to a system or application.
Botnet
A network of compromised devices controlled by an attacker and commonly used for spam, fraud, malware distribution or distributed denial-of-service attacks.
C
Confidentiality
The principle that information should only be accessible to authorised people, systems or processes.
Credential Stuffing
An attack that uses stolen username and password combinations from one service to try to gain access to accounts on other services.
D
Data Loss Prevention (DLP)
Controls and technologies designed to detect and prevent sensitive information from being lost, leaked or transferred without authorisation.
Distributed Denial of Service (DDoS)
An attack in which many systems overwhelm a service with traffic or requests, making it slow or unavailable to legitimate users.
E
Encryption
The process of converting readable information into a protected form that can only be restored using the correct key or cryptographic process.
Endpoint Detection and Response (EDR)
Security technology that monitors endpoint devices for suspicious behaviour and supports detection, investigation and response to threats.
F
Firewall
A security control that allows or blocks network traffic according to configured rules, helping separate trusted and untrusted networks.
Forensics
The collection, preservation and analysis of digital evidence to understand security incidents, attacks or unauthorised activity.
G
Governance
The framework of policies, responsibilities, oversight and decision-making used to direct and control cyber security across an organisation.
Group Policy
A Microsoft mechanism for centrally applying configuration and security settings to users and computers in an Active Directory environment.
H
Hashing
A one-way process that converts data into a fixed-length value, commonly used for integrity checks and secure password storage.
Honeypot
A deliberately exposed or attractive system designed to lure attackers so their techniques can be detected, observed or analysed.
I
Identity and Access Management (IAM)
Processes and technologies used to manage digital identities, authentication, permissions and access rights.
Incident Response
The organised process for identifying, containing, investigating, removing and recovering from a cyber security incident.
J
Jump Server
A hardened intermediary system used to provide controlled administrative access to sensitive servers or network segments.
K
Key Management
The secure creation, storage, distribution, rotation and retirement of cryptographic keys used to protect information.
L
Least Privilege
The principle that users, applications and systems should receive only the minimum access rights needed to perform their tasks.
Lateral Movement
Techniques used by attackers to move from one compromised system or account to other parts of a network.
M
Malware
Malicious software designed to disrupt systems, steal information, spy on users, gain unauthorised access or perform other harmful actions.
Multi-Factor Authentication (MFA)
Authentication that requires two or more different forms of evidence, such as a password plus an authenticator app or security key.
N
Network Segmentation
Dividing a network into smaller zones so traffic can be controlled and the spread of attacks can be limited.
Non-Repudiation
The security property that provides evidence of an action or transaction so a party cannot credibly deny having performed it.
O
Open Source Intelligence (OSINT)
Information collected from publicly available sources and analysed for security, investigative or threat-intelligence purposes.
P
Penetration Testing
An authorised security assessment in which testers attempt to exploit weaknesses to demonstrate their real-world impact.
Phishing
A social engineering attack that uses deceptive messages or websites to trick people into revealing information, opening malicious content or taking unsafe actions.
Patch Management
The process of identifying, testing and applying software updates that fix vulnerabilities, defects or reliability issues.
Q
Quarantine
The isolation of a suspicious file, device, message or account so it cannot interact normally with other systems while it is investigated.
R
Ransomware
Malware that blocks access to systems or encrypts data and demands payment, often combined with data theft and extortion.
Risk Assessment
The process of identifying threats, vulnerabilities, likelihood and potential impact so security risks can be prioritised and treated.
S
Security Information and Event Management (SIEM)
A platform that collects and analyses security logs and events to support monitoring, alerting, investigation and compliance.
Security Operations Centre (SOC)
A team or function responsible for monitoring, detecting, investigating and responding to cyber security threats and incidents.
Social Engineering
The manipulation of people into revealing information or performing actions that weaken security.
T
Threat Intelligence
Evidence-based information about threat actors, attack methods and indicators that helps organisations understand and respond to cyber threats.
Trojan
Malware disguised as legitimate software or content that performs malicious actions once installed or opened.
U
User Awareness Training
Education that helps users recognise threats, follow secure practices and understand their responsibilities for protecting information and systems.
V
Vulnerability
A weakness in software, hardware, configuration, process or human behaviour that could be exploited by a threat.
Vulnerability Management
The continuous process of discovering, assessing, prioritising, remediating and tracking vulnerabilities across an organisation.
W
Web Application Firewall (WAF)
A security control that monitors and filters web traffic to protect applications from common attacks such as injection and malicious requests.
Whaling
A highly targeted phishing attack aimed at senior executives or other high-value individuals.
X
XDR (Extended Detection and Response)
A security approach that combines and correlates detection data across multiple sources such as endpoints, networks, identities and cloud services.
Y
YARA Rule
A pattern-based rule used by security analysts and malware researchers to identify files or data that match known or suspected malicious characteristics.
Z
Zero-Day Vulnerability
A vulnerability that is exploited before an effective patch or mitigation is widely available.
Zero Trust
A security model based on continuously verifying users, devices and access requests rather than automatically trusting activity because it originates inside a network.
Build your cyber security skills
Explore ExperTrain's instructor-led Cyber Security training, including practical courses and certification pathways from leading vendors. You can also browse our EC-Council certifications and CompTIA certifications.




