Preloader spinner

Cyber security has its own language, from common attack methods and security controls to governance, risk and incident response. This A-Z glossary explains key cyber security terms in clear, practical language for learners, IT professionals and anyone building their understanding of modern security.

A

Access Control

Policies and technical measures that determine who or what can access systems, applications, data or physical locations.

Advanced Persistent Threat (APT)

A prolonged, targeted cyber attack in which a capable threat actor establishes and maintains access to a network, often to steal data or conduct espionage.

B

Backdoor

A hidden method of bypassing normal authentication or security controls to gain access to a system or application.

Botnet

A network of compromised devices controlled by an attacker and commonly used for spam, fraud, malware distribution or distributed denial-of-service attacks.

C

Confidentiality

The principle that information should only be accessible to authorised people, systems or processes.

Credential Stuffing

An attack that uses stolen username and password combinations from one service to try to gain access to accounts on other services.

D

Data Loss Prevention (DLP)

Controls and technologies designed to detect and prevent sensitive information from being lost, leaked or transferred without authorisation.

Distributed Denial of Service (DDoS)

An attack in which many systems overwhelm a service with traffic or requests, making it slow or unavailable to legitimate users.

E

Encryption

The process of converting readable information into a protected form that can only be restored using the correct key or cryptographic process.

Endpoint Detection and Response (EDR)

Security technology that monitors endpoint devices for suspicious behaviour and supports detection, investigation and response to threats.

F

Firewall

A security control that allows or blocks network traffic according to configured rules, helping separate trusted and untrusted networks.

Forensics

The collection, preservation and analysis of digital evidence to understand security incidents, attacks or unauthorised activity.

G

Governance

The framework of policies, responsibilities, oversight and decision-making used to direct and control cyber security across an organisation.

Group Policy

A Microsoft mechanism for centrally applying configuration and security settings to users and computers in an Active Directory environment.

H

Hashing

A one-way process that converts data into a fixed-length value, commonly used for integrity checks and secure password storage.

Honeypot

A deliberately exposed or attractive system designed to lure attackers so their techniques can be detected, observed or analysed.

I

Identity and Access Management (IAM)

Processes and technologies used to manage digital identities, authentication, permissions and access rights.

Incident Response

The organised process for identifying, containing, investigating, removing and recovering from a cyber security incident.

J

Jump Server

A hardened intermediary system used to provide controlled administrative access to sensitive servers or network segments.

K

Key Management

The secure creation, storage, distribution, rotation and retirement of cryptographic keys used to protect information.

L

Least Privilege

The principle that users, applications and systems should receive only the minimum access rights needed to perform their tasks.

Lateral Movement

Techniques used by attackers to move from one compromised system or account to other parts of a network.

M

Malware

Malicious software designed to disrupt systems, steal information, spy on users, gain unauthorised access or perform other harmful actions.

Multi-Factor Authentication (MFA)

Authentication that requires two or more different forms of evidence, such as a password plus an authenticator app or security key.

N

Network Segmentation

Dividing a network into smaller zones so traffic can be controlled and the spread of attacks can be limited.

Non-Repudiation

The security property that provides evidence of an action or transaction so a party cannot credibly deny having performed it.

O

Open Source Intelligence (OSINT)

Information collected from publicly available sources and analysed for security, investigative or threat-intelligence purposes.

P

Penetration Testing

An authorised security assessment in which testers attempt to exploit weaknesses to demonstrate their real-world impact.

Phishing

A social engineering attack that uses deceptive messages or websites to trick people into revealing information, opening malicious content or taking unsafe actions.

Patch Management

The process of identifying, testing and applying software updates that fix vulnerabilities, defects or reliability issues.

Q

Quarantine

The isolation of a suspicious file, device, message or account so it cannot interact normally with other systems while it is investigated.

R

Ransomware

Malware that blocks access to systems or encrypts data and demands payment, often combined with data theft and extortion.

Risk Assessment

The process of identifying threats, vulnerabilities, likelihood and potential impact so security risks can be prioritised and treated.

S

Security Information and Event Management (SIEM)

A platform that collects and analyses security logs and events to support monitoring, alerting, investigation and compliance.

Security Operations Centre (SOC)

A team or function responsible for monitoring, detecting, investigating and responding to cyber security threats and incidents.

Social Engineering

The manipulation of people into revealing information or performing actions that weaken security.

T

Threat Intelligence

Evidence-based information about threat actors, attack methods and indicators that helps organisations understand and respond to cyber threats.

Trojan

Malware disguised as legitimate software or content that performs malicious actions once installed or opened.

U

User Awareness Training

Education that helps users recognise threats, follow secure practices and understand their responsibilities for protecting information and systems.

V

Vulnerability

A weakness in software, hardware, configuration, process or human behaviour that could be exploited by a threat.

Vulnerability Management

The continuous process of discovering, assessing, prioritising, remediating and tracking vulnerabilities across an organisation.

W

Web Application Firewall (WAF)

A security control that monitors and filters web traffic to protect applications from common attacks such as injection and malicious requests.

Whaling

A highly targeted phishing attack aimed at senior executives or other high-value individuals.

X

XDR (Extended Detection and Response)

A security approach that combines and correlates detection data across multiple sources such as endpoints, networks, identities and cloud services.

Y

YARA Rule

A pattern-based rule used by security analysts and malware researchers to identify files or data that match known or suspected malicious characteristics.

Z

Zero-Day Vulnerability

A vulnerability that is exploited before an effective patch or mitigation is widely available.

Zero Trust

A security model based on continuously verifying users, devices and access requests rather than automatically trusting activity because it originates inside a network.

Build your cyber security skills

Explore ExperTrain's instructor-led Cyber Security training, including practical courses and certification pathways from leading vendors. You can also browse our EC-Council certifications and CompTIA certifications.

Join our mailing list

Receive details on our new courses and special offers

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.