A–C

Air Gap

A physical isolation of a computer or network from unsecured networks, including the internet. Air-gapped systems cannot be reached by network-based attacks. Used for the most sensitive systems (nuclear control, classified government, critical infrastructure). Air-gapped backups are immune to ransomware that targets connected backup systems.

APT (Advanced Persistent Threat)

A sophisticated, long-term cyberattack campaign, typically conducted by nation-state actors or well-funded criminal groups. APTs are characterized by: advanced techniques, persistence (maintaining access for months or years), and specific targets (government, critical infrastructure, defense). Examples: APT28 (Russia), APT41 (China), Lazarus Group (North Korea).

Attack Surface

The sum of all points where an attacker can attempt to enter or extract data from an environment. Includes: network interfaces, APIs, user accounts, physical access points, and third-party integrations. Reducing attack surface is a fundamental security principle.

CASB (Cloud Access Security Broker)

A security policy enforcement point between cloud service users and cloud service providers. CASBs provide visibility into cloud usage, enforce security policies, and protect data in cloud applications. Key capabilities: discovery of shadow IT, data loss prevention, threat protection, and compliance monitoring.

CSPM (Cloud Security Posture Management)

Tools that continuously monitor cloud environments for misconfigurations, compliance violations, and security risks. Provides visibility across multiple cloud providers. Leading tools: Wiz, Prisma Cloud, Orca Security.

CVE (Common Vulnerabilities and Exposures)

A standardized identifier for publicly known cybersecurity vulnerabilities. CVE IDs (e.g., CVE-2021-44228 for Log4Shell) provide a common reference for vulnerability tracking and remediation. CVSS (Common Vulnerability Scoring System) scores rate vulnerability severity from 0–10.

D–F

DDoS (Distributed Denial of Service)

An attack that overwhelms a target system with traffic from multiple sources, making it unavailable to legitimate users. DDoS attacks target: network bandwidth, application layer (HTTP floods), and protocol vulnerabilities. Mitigation: DDoS scrubbing services (Cloudflare, Akamai, AWS Shield).

Defense in Depth

A security strategy that uses multiple layers of security controls so that a failure in any single layer does not result in a complete compromise. Layers include: physical security, network security, endpoint security, application security, and data security.

EDR (Endpoint Detection and Response)

Security software that monitors endpoint activity (process execution, file changes, network connections) to detect and respond to threats. EDR provides visibility into endpoint behavior that traditional antivirus misses. Leading vendors: CrowdStrike, Microsoft Defender, SentinelOne.

Exfiltration

The unauthorized transfer of data from a system or network. Data exfiltration is a key objective of many cyberattacks. Detection: DLP tools, network monitoring for unusual outbound data transfers, and UEBA (User and Entity Behavior Analytics).

Firewall

A network security device that monitors and controls incoming and outgoing network traffic based on security rules. Next-generation firewalls (NGFW) extend traditional firewalls with application identification, user identity awareness, and integrated threat prevention.

FIDO2 / WebAuthn

An open authentication standard that enables phishing-resistant multi-factor authentication using hardware security keys or device biometrics. FIDO2 is the strongest MFA method — it cannot be phished because authentication is bound to the specific website. Recommended for privileged access and high-security environments.

G–I

IDS/IPS (Intrusion Detection/Prevention System)

IDS monitors network traffic for known attack patterns and anomalous behavior, generating alerts. IPS actively blocks detected threats. Signature-based detection identifies known attacks; anomaly-based detection identifies deviations from normal behavior.

Incident Response

The organized approach to addressing and managing a security incident. The NIST incident response lifecycle: Prepare, Detect and Analyze, Contain, Eradicate, Recover, and Post-Incident Activity. Effective incident response requires documented plans, trained teams, and regular exercises.

Insider Threat

A security risk that originates from within the organization — employees, contractors, or business partners with legitimate access. Insider threats can be malicious (deliberate sabotage or data theft) or negligent (accidental misconfiguration or policy violation). Mitigation: least privilege access, behavioral monitoring, and security awareness training.

IOC (Indicator of Compromise)

Forensic evidence that a system has been compromised. IOCs include: malicious IP addresses, domain names, file hashes, registry keys, and behavioral patterns. Threat intelligence platforms share IOCs to enable proactive detection across organizations.

J–M

Lateral Movement

The techniques attackers use to progressively move through a network after initial compromise, seeking higher privileges and access to valuable systems. Microsegmentation is the primary control for limiting lateral movement. Detection: network monitoring for unusual internal traffic patterns.

Least Privilege

The principle that users, systems, and processes should have only the minimum access required to perform their functions. Least privilege limits the blast radius of a compromise — a compromised account with limited privileges can do less damage than one with broad access.

MFA (Multi-Factor Authentication)

Authentication requiring two or more verification factors: something you know (password), something you have (hardware token, phone), or something you are (biometric). MFA is the single most effective control for preventing account compromise. Phishing-resistant MFA (FIDO2) is preferred for privileged access.

MITRE ATT&CK

A globally accessible knowledge base of adversary tactics and techniques based on real-world observations. Used for threat modeling, detection development, and security assessment. ATT&CK matrices cover enterprise, mobile, and ICS environments. Security vendors use ATT&CK coverage as a benchmark for detection capabilities.

MDR (Managed Detection and Response)

A managed security service that provides 24/7 threat detection and response using a combination of technology and human expertise. MDR providers use proprietary technology and threat intelligence to detect threats that automated tools miss. Distinct from MSSP (which manages security tools) — MDR focuses specifically on detection and response.

N–P

NDR (Network Detection and Response)

Security solutions that analyze network traffic to detect threats that endpoint controls miss: lateral movement, command-and-control communications, data exfiltration, and insider threats. NDR uses machine learning to detect anomalous behavior patterns in network traffic.

PAM (Privileged Access Management)

Tools and processes for managing, monitoring, and securing privileged access to critical systems. Key capabilities: just-in-time access provisioning, session recording, password vaulting, and approval workflows. Leading vendors: CyberArk, BeyondTrust, Delinea.

Penetration Testing

An authorized simulated cyberattack against a system to evaluate its security. Penetration testers attempt to exploit vulnerabilities to demonstrate actual impact. Distinct from vulnerability assessment (which identifies vulnerabilities without exploiting them). Should be conducted annually at minimum.

Phishing

A social engineering attack that tricks users into revealing credentials or installing malware, typically via deceptive emails. Spear phishing targets specific individuals with personalized content. Business email compromise (BEC) impersonates executives to authorize fraudulent transactions. Mitigation: email security, security awareness training, and phishing-resistant MFA.

Q–S

Ransomware

Malware that encrypts victim files and demands payment for the decryption key. Modern ransomware uses double extortion: encrypt files AND exfiltrate data, threatening to publish it if ransom is not paid. Prevention: MFA, EDR, network segmentation, regular patching. Recovery: offline immutable backups.

SASE (Secure Access Service Edge)

A cloud-delivered security architecture that combines network security (CASB, SWG, ZTNA, FWaaS) with WAN capabilities (SD-WAN). SASE provides consistent security for users regardless of location. Leading vendors: Zscaler, Palo Alto Prisma, Netskope.

SIEM (Security Information and Event Management)

A platform that collects, analyzes, and correlates security events from across the environment to detect threats and support incident investigation. SIEM provides centralized visibility across network, endpoint, identity, and application security events. Leading vendors: Microsoft Sentinel, Splunk, IBM QRadar.

SOC (Security Operations Center)

A team of security professionals responsible for monitoring, detecting, and responding to security incidents. SOC analysts monitor security tools, investigate alerts, and respond to incidents. 24/7 SOC coverage is required for organizations with significant security requirements. Managed SOC (MSSP/MDR) provides coverage without building an in-house team.

Supply Chain Attack

An attack that targets software or hardware supply chains to compromise systems at scale. The SolarWinds attack (2020) compromised a software update mechanism to deliver malware to thousands of organizations. Mitigation: software bill of materials (SBOM), vendor security assessments, and code signing verification.

T–Z

Threat Intelligence

Evidence-based knowledge about existing or emerging threats, including context, mechanisms, indicators, and actionable advice. Threat intelligence enables proactive defense by providing advance warning of threats and attack techniques. Sources: commercial threat intelligence feeds, ISAC (Information Sharing and Analysis Centers), and government sources (CISA, FBI).

TLS (Transport Layer Security)

A cryptographic protocol that provides secure communication over a network. TLS 1.3 is the current standard; TLS 1.0 and 1.1 are deprecated. TLS encrypts data in transit to prevent eavesdropping and tampering. Over 90% of internet traffic is now encrypted with TLS.

Vulnerability

A weakness in a system that can be exploited by an attacker. Vulnerabilities are classified by severity (CVSS score), exploitability, and impact. Vulnerability management: identify vulnerabilities through scanning, prioritize by risk, and remediate within defined timeframes based on severity.

XDR (Extended Detection and Response)

A security platform that integrates telemetry from multiple security layers (endpoint, network, cloud, identity, email) to provide correlated detection and response. XDR extends EDR with broader visibility and automated correlation across security domains. Leading vendors: CrowdStrike, Palo Alto Cortex, Microsoft Defender XDR.

Zero-Day Vulnerability

A vulnerability that is unknown to the software vendor and has no available patch. Zero-day vulnerabilities are highly valuable to attackers because there is no defense until a patch is released. Mitigation: defense in depth, behavioral detection (EDR/XDR), and network segmentation to limit blast radius.

Zero Trust

A security strategy based on "never trust, always verify." Every access request is authenticated and authorized based on identity, device health, and context — regardless of network location. Zero trust replaces the traditional perimeter model that trusted everything inside the network. NIST SP 800-207 is the authoritative reference.