Glossary

Security terms, explained plainly

Short, accurate definitions of the terms that come up when you buy, run or audit security. Written by practitioners, without the jargon.

Detection & responseThreatsVulnerability & exposureCompliancePentesting & red teamingCloud security

Detection & response

Managed detection and response (MDR)A service where an external team of security analysts monitors your environment 24/7…Read definition Security operations centre (SOC)The team, processes and technology responsible for monitoring an organisation’s environment…Read definition Extended detection and response (XDR)A security approach that correlates detection data across endpoints, identity, email, cloud and network in one place…Read definition Security information and event management (SIEM)A platform that collects and stores logs from across your environment, normalises them and runs detection rules…Read definition

Threats

RansomwareMalicious software that encrypts or steals an organisation’s data and demands payment to restore access or prevent publi…Read definition Business email compromise (BEC)A fraud where attackers take over or impersonate a business email account to trick staff…Read definition PhishingA social engineering attack that uses email, text or messaging to trick people into clicking a malicious link…Read definition Social engineeringManipulating people, rather than technology, into breaking security procedures, such as sharing passwords…Read definition

Vulnerability & exposure

Vulnerability managementThe continuous process of finding, prioritising…Read definition Common Vulnerabilities and Exposures (CVE)A public catalogue of known security vulnerabilities, where each entry gets a unique identifier, such as CVE-2024-3400…Read definition External attack surface management (EASM)Continuously discovering and monitoring everything an organisation exposes to the internet, including forgotten servers…Read definition Continuous threat exposure management (CTEM)A programme, described by Gartner, for continuously identifying, prioritising…Read definition

Compliance

NIS2 DirectiveThe EU’s updated cybersecurity directive, (EU) 2022/2555…Read definition Digital Operational Resilience Act (DORA)The EU regulation, (EU) 2022/2554, that sets ICT risk management, incident reporting…Read definition ISO/IEC 27001The international standard for an information security management system (ISMS): a structured way to manage security ris…Read definition CCPA cybersecurity auditAn annual…Read definition

Pentesting & red teaming

Penetration testingAn authorised, simulated attack in which security testers try to find and exploit weaknesses in systems…Read definition Pentesting as a service (PTaaS)Penetration testing delivered through an online platform, so you can request tests…Read definition Red teamingA goal-based simulated attack that tests how well an organisation detects and responds to a realistic adversary…Read definition Purple teamingA collaborative exercise where attackers (red) and defenders (blue) work together in real time…Read definition

Cloud security

Cloud security posture management (CSPM)Tools and processes that continuously check cloud environments such as Azure…Read definition Shared responsibility modelThe division of security duties between a cloud provider and its customer: the provider secures the cloud itself…Read definition Cloud-native application protection platform (CNAPP)A category of cloud security platform that combines posture management, workload protection…Read definition Cloud detection and response (CDR)Detecting and responding to active threats in cloud environments, using cloud audit logs…Read definition

Missing a term?

Tell us what you’d like explained and we’ll add it.

Suggest a term