Cybersecurity Glossary

Study Tools

Cybersecurity Glossary

A practical reference to common cybersecurity terms, concepts and security language.

Search for a term, browse alphabetically or use the comparisons below to understand concepts that are commonly confused.

šŸ”Ž

Search

Find a security concept quickly.

LOOK IT UP
🧠

Understand

Definitions are written in clear, practical language.

LEARN THE IDEA
šŸ”—

Connect

See how related cybersecurity concepts differ and overlap.

JOIN THE DOTS
Looking for an acronym?

This glossary focuses on cybersecurity concepts and terms. If you need to find what an acronym such as SIEM, SAML, AES, RTO or CASB stands for, visit the dedicated Cybersecurity Abbreviations page.

Search the Glossary

Try words such as encryption, risk, phishing, authentication or zero trust.

Showing 0 terms

Browse A–Z

A B C D E F G H I K L M N O P R S T V W Z
Cybersecurity terminology depends on context

Security standards, laws, vendors and professional frameworks sometimes define the same term slightly differently.

The definitions on CyberPrepHub are intended as clear learning explanations. Where a formal definition matters, consult the relevant standard, regulation or authoritative source.

Quick Reference

Commonly confused cybersecurity terms

Authentication

Proves or verifies WHO you are.

Authorisation

Determines WHAT you are allowed to do.

Threat

Something capable of causing harm.

Vulnerability

A weakness that could be exploited.

Risk

The potential consequence when threats can exploit vulnerabilities.

Encryption

Reversible protection using appropriate cryptographic keys.

Hashing

Produces a one-way digest and is not intended to be decrypted.

IDS

Detects suspicious activity and normally alerts.

IPS

Detects suspicious activity and can actively block it.

RPO

How much DATA LOSS can be tolerated?

RTO

How much DOWNTIME can be tolerated?

Five security concepts worth remembering

Threat What could HARM us?
Vulnerability Where are we WEAK?
Risk What could HAPPEN?
Control What REDUCES the risk?
Residual Risk What REMAINS afterwards?

Threat → Vulnerability → Risk → Control → Residual Risk

A

Access Control

The policies, processes and technical mechanisms used to determine who or what is allowed to access a resource and what actions they are permitted to perform.

Adversary

A person, group, organisation or other entity attempting to compromise, disrupt, misuse or otherwise act against the security objectives of a target.

Air Gap

Separation of a system or network from other networks, particularly untrusted environments such as the internet.

An air gap can substantially reduce connectivity-based exposure but should not be treated as absolute protection against every attack.

Allowlisting

A security approach in which only explicitly approved applications, connections, actions or entities are permitted.

Everything not specifically permitted is denied by default.

Anonymisation

Processing information so that it can no longer reasonably be linked to an identifiable individual.

The exact legal threshold for anonymisation can vary between privacy frameworks.

Asset

Anything of value to an organisation that should be appropriately protected or managed.

Assets can include hardware, software, information, services, people, intellectual property and reputation.

Attack Surface

The collection of points through which an attacker could attempt to enter, influence, extract data from or otherwise interact with a system.

Examples include network services, APIs, user accounts, applications, devices and human processes.

Attack Vector

The method or path an attacker uses to reach or compromise a target.

Phishing emails, vulnerable web applications and exposed remote-access services are examples of attack vectors.

Authentication

The process of verifying that a claimed identity is genuine.

Passwords, cryptographic credentials, biometrics and security keys can all form part of authentication.

Memory: Authentication = Who are you?

Authorisation (Authorization)

The process of determining what an authenticated user, service or other entity is permitted to access or perform.

Memory: Authorisation = What are you allowed to do?

Availability

The security objective of ensuring information, systems and services are accessible to authorised users when they are required.

Availability is one of the three elements of the CIA Triad.

B

Backdoor

A hidden or alternative method of accessing a system that bypasses normal authentication or security controls.

Backdoors may be deliberately created for malicious purposes or unintentionally introduced through insecure design.

Baseline

An approved starting point used for comparison or control.

A security baseline may define the minimum configuration or safeguards expected for a particular type of system.

Bastion Host

A deliberately hardened system positioned where it may be exposed to untrusted networks or used as a controlled access point to sensitive environments.

A privileged-access jump server is a common example.

Biometrics

Authentication or identification techniques that use measurable physical or behavioural characteristics.

Examples include fingerprints, facial characteristics, iris patterns and voice characteristics.

Botnet

A collection of compromised systems or devices controlled together, usually without the legitimate owners' knowledge.

Botnets can be used for activities such as distributed denial-of-service attacks, spam, credential attacks and malware distribution.

Brute-Force Attack

An attack that repeatedly tries possible passwords, keys or other values until the correct one is discovered.

Rate limiting, strong authentication and multifactor authentication can help reduce the effectiveness of password brute forcing.

C

Certificate

A digitally signed electronic record used to associate information such as an identity or system name with a public cryptographic key.

Digital certificates are an important component of Public Key Infrastructure.

Chain of Custody

The documented history of who collected, handled, transferred, stored and controlled evidence from the point it was acquired onwards.

A reliable chain of custody helps demonstrate that evidence has been appropriately protected from alteration or substitution.

Cipher

A cryptographic algorithm used to transform information between readable and protected forms.

Modern ciphers normally operate together with cryptographic keys.

Cloud Security

The policies, controls, technologies and responsibilities used to protect data, identities, workloads and services operating in cloud environments.

Compensating Control

An alternative safeguard used when the preferred or required control cannot be implemented as originally intended.

The alternative should address the relevant security objective and reduce the associated risk appropriately.

Confidentiality

The security objective of preventing information from being disclosed to unauthorised people, systems or processes.

Confidentiality is one of the three elements of the CIA Triad.

Configuration Management

The controlled process of establishing, documenting, maintaining and changing the configuration of systems and technology.

Good configuration management helps prevent unauthorised or accidental changes from creating security weaknesses.

Credential

Information or evidence used to support an identity or authentication process.

Passwords, certificates, security tokens and cryptographic keys can all function as credentials in different systems.

Cryptography

The use of mathematical techniques to protect information and communications.

Cryptography can support confidentiality, integrity, authentication and non-repudiation.

Cybersecurity

The discipline concerned with protecting digital systems, networks, services and information against threats, attacks, misuse and disruption.

D

Data Classification

The process of assigning information to categories based on factors such as sensitivity, value, criticality or required protection.

Classification helps determine appropriate handling and security controls.

Data Exfiltration

The unauthorised transfer or removal of information from an organisation, system or controlled environment.

Exfiltration may occur over networks, cloud services, email, removable media or other channels.

Data Loss Prevention

Technologies and processes designed to identify sensitive information and detect or prevent inappropriate storage, use or movement of that information.

DLP can operate across data at rest, in transit and in use.

Data Minimisation

The principle of limiting the collection, processing and retention of information to what is genuinely required for the intended purpose.

Less unnecessary data generally means less unnecessary exposure.

Data Remanence

Residual information that remains on storage media after an attempt has been made to delete or remove it.

This is why ordinary file deletion should not automatically be treated as secure data destruction.

Defence in Depth

A security strategy that uses multiple layers of safeguards so that the failure of one control does not automatically result in complete compromise.

It is also commonly written as Defense in Depth.

Digital Signature

A cryptographic mechanism used to provide evidence about the origin and integrity of digital information.

Digital signatures typically use asymmetric cryptography.

Disaster Recovery

The processes and capabilities used to restore technology, systems and supporting services following a serious disruption or disaster.

Disaster recovery is usually a component of the wider business continuity programme.

Due Care

Taking reasonable and appropriate actions to protect assets, people and the organisation against recognised risks.

Think: doing what a responsible organisation should do.

Due Diligence

The ongoing investigation, assessment and monitoring used to understand risk and confirm that appropriate protective measures continue to be effective.

Think: checking that due care remains appropriate.

E

Endpoint

A device or system that connects to and communicates across a network.

Laptops, desktops, smartphones and servers can all be considered endpoints depending on context.

Encryption

The cryptographic transformation of readable information into a protected form that should be unintelligible without appropriate cryptographic key material.

Encryption primarily supports confidentiality.

Exploit

Code, a technique or a sequence of actions that takes advantage of a vulnerability to produce an unintended result.

Exposure

A condition in which an asset is reachable or subject to circumstances that could result in compromise, loss or other adverse impact.

Exposure does not necessarily mean a vulnerability has already been exploited.

F

Failover

The process of switching operations from a failed or unavailable system to an alternative system or component.

Failover can support resilience and availability.

Federation

An identity arrangement in which separate organisations, systems or security domains establish trust so that identity information can be accepted across boundaries.

Firewall

A security control that permits, blocks or otherwise manages network traffic according to defined rules and security policy.

Firewalls may operate at different layers and can be deployed on networks, individual hosts or cloud environments.

Forensics

The disciplined collection, preservation, examination and analysis of evidence for investigation.

Digital forensics focuses specifically on evidence associated with digital devices, systems and data.

G

Governance

The structures, responsibilities, policies and decision-making processes used to direct and oversee an organisation.

Security governance helps ensure cybersecurity supports organisational objectives and that appropriate accountability exists.

H

Hardening

The process of reducing a system's attack surface and improving its security configuration.

Hardening may include removing unnecessary software, disabling unused services, changing insecure defaults and applying appropriate security settings.

Hashing

A one-way mathematical process that transforms input data into a fixed-size output commonly called a hash or digest.

Hashing is commonly used for integrity checking and as part of secure password-storage designs.

Important: hashing is not encryption and is not intended to be decrypted.

Honeypot

A deliberately created decoy system, service or resource designed to attract or detect attackers and help defenders observe malicious activity.

I

Identification

The act of claiming or presenting an identity to a system.

Entering a username identifies the account being claimed; authentication then attempts to verify that claim.

Identity

The collection of attributes or characteristics used to represent a person, device, service or other entity within a system.

Incident

An event or series of events that compromises, threatens or violates security policies, systems, information or business operations.

Incident Response

The organised process used to prepare for, detect, analyse, contain, eradicate and recover from cybersecurity incidents.

Mature incident response also includes learning from incidents and improving controls afterwards.

Indicator of Compromise

Observable information that may indicate that malicious activity or a security compromise has occurred.

Examples can include malicious file hashes, network addresses, unusual process activity or attacker-created artefacts.

Integrity

The security objective of protecting information and systems against unauthorised or improper modification or destruction.

Integrity also supports confidence that information remains accurate and trustworthy.

Intrusion Detection System

A security system that monitors activity for signs of attacks, suspicious behaviour or policy violations and generates alerts when relevant activity is detected.

Memory: IDS = Detect and alert.

Intrusion Prevention System

A security system capable of detecting suspicious activity and taking action to prevent or block it.

Memory: IPS = Detect and prevent.

K

Key Management

The processes used to securely generate, distribute, store, protect, rotate, recover, revoke and destroy cryptographic keys.

Strong encryption can be undermined by poor key management.

L

Least Privilege

The principle that users, applications and processes should receive only the permissions necessary to perform their authorised functions.

Permissions should not be granted merely because they may be convenient.

Logging

Recording events and activity generated by systems, applications, networks or security controls.

Logs can support monitoring, troubleshooting, investigations, accountability and auditing.

Logic Bomb

Malicious code designed to execute when a specific condition or event occurs.

The trigger might be a date, account deletion, file change or another system condition.

M

Malware

Software or code created to perform malicious or unauthorised actions.

Malware includes categories such as ransomware, trojans, worms, spyware and malicious remote-access tools.

Man-in-the-Middle Attack

An attack in which an adversary positions themselves between communicating parties so they can intercept and potentially modify communications.

It is commonly abbreviated as MitM.

Microsegmentation

Fine-grained segmentation that creates smaller security boundaries around workloads, applications or resources.

It can help restrict lateral movement and unnecessary communication within an environment.

Multifactor Authentication

Authentication using two or more independent categories of authentication factors.

Common factor categories are something you know, something you have and something you are.

Two passwords are not multifactor authentication because both belong to the same factor category.

N

Network Segmentation

Dividing a network into separate zones or segments and controlling communication between them.

Segmentation can limit exposure, reduce lateral movement and help apply different security controls to different environments.

Non-Repudiation

The ability to provide evidence supporting the origin or occurrence of an action so that the responsible party cannot credibly deny it later.

Digital signatures can contribute to non-repudiation.

Nonce

A value intended for one-time or unique use within a cryptographic or security protocol.

Nonces can help prevent replay of previously valid messages or transactions.

O

Obfuscation

Deliberately making code, data or behaviour harder for people or tools to understand.

Obfuscation can hinder analysis but should not be confused with cryptographic protection such as encryption.

P

Passkey

A modern authentication credential based on public-key cryptography that can replace traditional passwords for supported services.

The user normally proves access to the passkey through a trusted device using a mechanism such as a device PIN or biometric unlock.

Patch Management

The process of identifying, evaluating, testing, deploying and tracking software or firmware updates used to correct defects and security vulnerabilities.

Penetration Testing

An authorised security assessment in which testers attempt to identify and exploit weaknesses to demonstrate how an attacker might compromise systems or information.

Penetration testing should operate within an agreed scope and rules of engagement.

Phishing

A social-engineering attack that uses deceptive messages or websites to persuade victims to disclose information, execute malicious actions or provide access.

Phishing commonly uses email but can also occur through messaging, websites and other communication channels.

Privilege Escalation

Gaining permissions greater than those originally available to an account, process or attacker.

An attacker moving from a normal user account to administrator or root privileges is a common example.

Public Key Infrastructure

The people, policies, technologies and processes used to create, manage, distribute, validate and revoke digital certificates and associated cryptographic keys.

It is commonly abbreviated as PKI.

R

Ransomware

Malware used to deny access to systems or information and demand payment or another action from the victim.

Modern ransomware operations may also steal information and threaten publication in addition to encrypting systems.

Recovery Point Objective

The maximum acceptable amount of data loss measured in time following a disruption.

Memory: RPO = how far back can the data go?

Recovery Time Objective

The target maximum period within which a system, service or business activity should be restored following disruption.

Memory: RTO = how long can we be down?

Residual Risk

The risk that remains after security controls or other risk treatments have been applied.

Security rarely reduces every risk to zero.

Risk

The potential for an uncertain event or condition to negatively affect objectives, assets or operations.

Cybersecurity risk is often considered using factors such as likelihood, threat, vulnerability and potential impact.

Risk Appetite

The broad amount and type of risk an organisation is willing to pursue or retain in support of its objectives.

Risk appetite should be determined by appropriate organisational leadership rather than individual technical teams.

Risk Assessment

The structured process of identifying and analysing risk so that organisations can understand potential threats, vulnerabilities, likelihoods and consequences.

Risk Treatment

The action chosen to address an identified risk.

Common approaches include reducing or mitigating the risk, avoiding it, transferring or sharing it, and accepting it where appropriate.

Root Cause Analysis

A structured investigation intended to identify the underlying causes of a problem or incident rather than focusing only on its immediate symptoms.

Effective root-cause analysis can help prevent recurrence.

S

Salt

A unique or suitably random value combined with data before hashing.

In password storage, salts help ensure identical passwords do not automatically produce identical stored hashes and make large-scale precomputed attacks less effective.

Sanitisation

A process intended to make access to data on media infeasible to the level required by the selected sanitisation method.

Depending on requirements and media technology, approaches can include Clear, Purge or Destroy.

Security Architecture

The structured design of security principles, components, controls and relationships within systems and technology environments.

Good security architecture attempts to build appropriate protection into the design rather than adding security only after deployment.

Security Control

A safeguard or countermeasure intended to reduce security risk or help achieve a security objective.

Controls may be administrative, technical or physical and may perform preventive, detective, corrective or other functions.

Security Policy

A high-level statement of management direction and expectations for security within an organisation.

Policies generally define what is required rather than every technical detail of how it must be implemented.

Segregation of Duties

Dividing critical responsibilities between multiple people or roles so that one individual does not control every stage of a sensitive activity.

It can reduce fraud, abuse and accidental misuse.

Session

A temporary logical interaction established between a user or system and a service, often after successful authentication.

Session identifiers and tokens therefore require appropriate protection.

Social Engineering

Manipulating people into performing actions or revealing information that benefits an attacker.

Social engineering exploits human trust, urgency, fear, authority, curiosity and other behavioural factors rather than relying purely on technical vulnerabilities.

Spoofing

Falsifying identity or technical information so that malicious activity appears to originate from a trusted or different source.

Examples include email spoofing, IP spoofing and caller-ID spoofing.

Supply Chain Attack

An attack that compromises a target through a supplier, software dependency, service provider, update mechanism or another component of its supply chain.

Attackers may target a trusted provider because compromising one supplier can create access to many downstream organisations.

T

Threat

A circumstance, event or entity capable of causing harm to systems, information, people or organisational objectives.

A threat does not need to have successfully exploited anything yet.

Threat Actor

A person, group or organisation responsible for or capable of carrying out malicious cyber activity.

Threat actors can include criminals, insiders, hacktivists, state-sponsored groups and other adversaries.

Threat Intelligence

Analysed information about threats, adversaries and malicious activity intended to support security decisions.

Useful threat intelligence should provide context rather than simply presenting disconnected indicators.

Threat Modeling

A structured process for identifying potential threats, attack paths, security weaknesses and required controls during the design or review of a system.

The goal is to think about how a system might be attacked before those attacks become real incidents.

Tokenisation

Replacing sensitive information with a substitute value or token so that systems which do not need the original information can operate without directly storing it.

Tokenisation is commonly used to reduce unnecessary exposure of sensitive data.

Trojan

Malware that disguises itself as legitimate or desirable software in order to persuade a user or system to execute it.

Unlike a worm, a trojan is not defined by automatically self-propagating between systems.

V

Vulnerability

A weakness or flaw in technology, configuration, design, process or behaviour that could be exploited or otherwise contribute to a security compromise.

Memory: Threat = potential danger. Vulnerability = weakness.

Vulnerability Management

The ongoing process of identifying, assessing, prioritising, remediating and tracking vulnerabilities across an organisation's assets.

Vulnerability management is a lifecycle process rather than simply running a vulnerability scanner.

W

Watering Hole Attack

An attack in which an adversary compromises or imitates a website or online resource that members of the intended target group are likely to visit.

The attacker waits for victims to come to the compromised location rather than contacting each victim directly.

Whaling

A targeted form of phishing aimed at senior executives, high-value decision makers or other prominent individuals.

Whaling attacks often use carefully researched business scenarios to make the request appear credible.

Worm

Malware capable of propagating between systems or across networks, often without requiring the user to manually copy or execute it on every new target.

Worm functionality can allow malware to spread rapidly through vulnerable environments.

Z

Zero-Day Vulnerability

A vulnerability for which an effective fix may not yet be available to defenders at the time it becomes known or is exploited.

A zero-day exploit is an exploit used against such a vulnerability.

Zero Trust

A security approach that avoids granting implicit trust simply because a user or system is inside a particular network or organisational boundary.

Access decisions instead consider factors such as identity, device, resource, policy, context and risk.

Zero Trust does not mean "trust nobody"

It means trust should not be assumed solely from network location or previous access.

Concept Connections

How important security terms fit together

Identity

Identification Authentication Authorisation Least Privilege

Risk

Threat Vulnerability Risk Control Residual Risk

Cryptography

Encryption Hashing Digital Signature Certificate Key Management

Operations

Logging Detection Incident Incident Response Forensics

Attack

Threat Actor Attack Vector Vulnerability Exploit Compromise

Resilience

Availability Failover RPO RTO Disaster Recovery
🧠 How to learn cybersecurity terminology Don't try to memorise isolated dictionary definitions

Cybersecurity terminology becomes much easier to remember when concepts are connected rather than memorised independently.

šŸ“– Definition → What does the term mean?
šŸŽÆ Purpose → Why does it matter?
šŸ”— Relationship → What other concepts connect to it?
šŸ’” Example → What would it look like in the real world?
🧠 Recall → Can I explain it without reading the definition?

Key takeaways

Cybersecurity terminology is easier to understand when related concepts are learned together rather than memorised as isolated definitions.

Authentication verifies identity; authorisation determines permissions.

A threat is a potential source of harm, while a vulnerability is a weakness.

Risk describes the potential adverse consequence created by uncertainty, threats, vulnerabilities and impact.

Security controls reduce risk, but some residual risk normally remains.

Encryption and hashing are not interchangeable: encryption is designed to be reversible with appropriate key material, while hashing is designed as a one-way transformation.

Least privilege limits users and systems to the access they actually require.

Defence in depth uses multiple security layers rather than relying on a single safeguard.

Vulnerability management is an ongoing lifecycle, not simply the act of running a scanner.

Incident response extends beyond detection and should include containment, recovery and organisational learning.

Most importantly: understanding what a security term means is useful — understanding how it connects to other security concepts is better.

šŸ“š Sources & Further Reading Authoritative security terminology resources

CyberPrepHub definitions are written as concise learning explanations rather than copied dictionary definitions. Formal terminology should be interpreted in the context of the relevant standard or publication.