Glossary

Cybersecurity and IT terms, in plain English.

102 terms you will hear from IT providers, insurers, and auditors, each with a short definition and a link to a deeper guide where we have one.

Reviewed October 11, 2026

A

Access control
Rules and technology that decide who can reach which systems and data, and what they can do once there.
Learn more about Access control
Account takeover
When an attacker gains control of a legitimate user account, usually with stolen or guessed credentials, and uses it to steal data or commit fraud.
Learn more about Account takeover
Antivirus
Software that detects and blocks known malicious files, mostly by matching signatures. Modern endpoint protection adds behavior-based detection on top.
Learn more about Antivirus
Attack surface
Every point where an attacker could try to get in: internet-facing systems, user accounts, devices, applications, vendors, and people.
Authentication
Proving that a user or device is who it claims to be, typically with a password, a passkey, a token, or a combination of factors.
Learn more about Authentication
Authorization
Deciding what an authenticated user is allowed to do. Authentication answers who you are; authorization answers what you may access.

B

Backup
A separate copy of data kept so it can be restored after deletion, corruption, hardware failure, or ransomware. A backup is only proven by a successful restore.
Learn more about Backup
BCP (business continuity plan)
A documented plan for keeping critical business functions running during and after a disruption such as an outage, disaster, or cyberattack.
Learn more about BCP (business continuity plan)
BEC (business email compromise)
Fraud in which criminals impersonate or take over a trusted email account to trick staff into sending money or sensitive data.
Learn more about BEC (business email compromise)
Botnet
A network of compromised computers or devices controlled remotely by an attacker, often used for spam, credential attacks, or DDoS.
Break-fix IT
A support model where you pay a technician only when something breaks, rather than a flat fee for ongoing monitoring and maintenance.
Learn more about Break-fix IT
Brute-force attack
Trying many passwords or keys until one works. Account lockouts, rate limits, and MFA make brute force far less effective.
Learn more about Brute-force attack
BYOD (bring your own device)
Letting employees use personal phones or computers for work. It needs clear policy and device management to protect business data.
Learn more about BYOD (bring your own device)

C

CIS Controls
A prioritized set of security safeguards published by the Center for Internet Security, often used as a practical starting framework for small and midsize organizations.
Cloud backup
Backing up data to an off-site cloud service, which protects copies from local disasters and many on-premises attacks.
Learn more about Cloud backup
Cloud desktop
A Windows desktop hosted in the cloud and reached from any device, so apps and data live in a managed environment instead of on the local PC.
Learn more about Cloud desktop
CMMC
Cybersecurity Maturity Model Certification
The U.S. Department of Defense program that verifies contractors protect Federal Contract Information and Controlled Unclassified Information to required levels.
Learn more about CMMC
Co-managed IT
An arrangement in which an internal IT team shares responsibilities with an outside managed service provider for extra capacity, tools, or expertise.
Learn more about Co-managed IT
Conditional access
Microsoft Entra ID policies that grant, limit, or block sign-ins based on conditions such as user, device health, location, and risk.
Learn more about Conditional access
Credential stuffing
Automated attacks that try username and password pairs leaked from one breach against many other sites, exploiting password reuse.
Learn more about Credential stuffing
CUI (Controlled Unclassified Information)
Government information that is not classified but still requires safeguarding under law, regulation, or policy, common in defense contracts.
Cyber insurance
Insurance that covers costs from cyber incidents, such as response, recovery, legal fees, and business interruption. Insurers increasingly require specific controls.
Learn more about Cyber insurance

D

Dark web
Parts of the internet reachable only through special software, where stolen credentials and data are often traded.
Learn more about Dark web
Data breach
An incident in which protected information is accessed, disclosed, or stolen without authorization.
Learn more about Data breach
Data loss prevention (DLP)
Tools and policies that detect and stop sensitive data from being shared, emailed, or uploaded where it should not go.
Learn more about Data loss prevention (DLP)
Data retention policy
A written rule set for how long each type of record is kept and how it is securely disposed of afterward.
Learn more about Data retention policy
DDoS (distributed denial of service)
Flooding a website or network with traffic from many sources to make it unavailable to legitimate users.
Learn more about DDoS (distributed denial of service)
Deepfake
AI-generated or altered audio, video, or images that convincingly imitate a real person, increasingly used in voice and payment scams.
Learn more about Deepfake
Disaster recovery (DR)
The technical plan and tools for restoring systems and data after a major outage, disaster, or cyberattack.
Learn more about Disaster recovery (DR)
DKIM
DomainKeys Identified Mail
An email authentication method that adds a cryptographic signature so receiving servers can confirm a message came from an authorized sender and was not altered.
Learn more about DKIM
DMARC
Domain-based Message Authentication, Reporting and Conformance
A DNS policy that tells receiving mail servers what to do with messages that fail SPF or DKIM checks, and sends reports on who is sending as your domain.
Learn more about DMARC
DNS (Domain Name System)
The internet's directory that translates domain names into IP addresses and publishes records such as mail routing and email authentication.
Learn more about DNS (Domain Name System)
DNS filtering
Blocking access to known malicious or unwanted websites by refusing to resolve their domain names.

E

EDR (endpoint detection and response)
Endpoint security that records device activity, detects suspicious behavior, and lets responders isolate and investigate machines.
Learn more about EDR (endpoint detection and response)
Encryption
Scrambling data so only someone with the right key can read it. Used for data stored on devices (at rest) and data moving across networks (in transit).
Learn more about Encryption
Endpoint
Any device that connects to your network or data, including laptops, desktops, servers, phones, and tablets.
Learn more about Endpoint
Exploit
Code or a technique that takes advantage of a vulnerability to make software behave in a way its makers did not intend.

F

Firewall
A security device or software that inspects network traffic and allows or blocks it based on rules.
Learn more about Firewall
FTC Safeguards Rule
A U.S. rule requiring non-bank financial institutions, such as auto dealers, tax preparers, and mortgage brokers, to maintain an information security program.
Learn more about FTC Safeguards Rule

H

Help desk
The support team users contact for IT problems and requests, usually tracked through tickets with response and resolution targets.
Learn more about Help desk
HIPAA Security Rule
The HIPAA standard that requires covered entities and business associates to protect electronic protected health information with administrative, physical, and technical safeguards.
Learn more about HIPAA Security Rule

I

Identity and access management (IAM)
The processes and tools that create, manage, and remove user identities and control their access to systems.
Learn more about Identity and access management (IAM)
Immutable backup
A backup copy that cannot be changed or deleted for a set period, protecting it from ransomware and accidental or malicious deletion.
Learn more about Immutable backup
Incident response
The organized process of detecting, containing, eradicating, and recovering from a security incident, then learning from it.
Learn more about Incident response
Indicator of compromise (IOC)
Evidence that a system may have been breached, such as a malicious file hash, a suspicious IP address, or unusual sign-in activity.
Insider threat
Risk that comes from people with legitimate access, whether through malice, carelessness, or a compromised account.
Learn more about Insider threat
Intune
Microsoft Intune
Microsoft's cloud service for managing and securing devices and apps, including configuration, compliance policies, and remote wipe.
Learn more about Intune
IoT (Internet of Things)
Network-connected devices such as cameras, sensors, printers, and smart equipment, which often have weak default security.
Learn more about IoT (Internet of Things)
IT asset management
Tracking hardware, software, and licenses through their life cycle, from purchase to secure disposal.
Learn more about IT asset management
IT documentation
Records of how systems are built and run: network diagrams, credentials vaults, configurations, vendor contacts, and procedures.
Learn more about IT documentation

K

Keylogger
Malware or hardware that records keystrokes to capture passwords and other sensitive input.

L

Lateral movement
How attackers spread from the first compromised machine to other systems on a network, often using stolen credentials.
Learn more about Lateral movement
Least privilege
Giving each user and system only the access needed to do its job, nothing more.
Learn more about Least privilege

M

Malware
Any software designed to harm, spy on, or take control of a system, including viruses, worms, trojans, spyware, and ransomware.
Learn more about Malware
Managed service provider (MSP)
A company that takes ongoing responsibility for some or all of an organization's IT operations, usually for a predictable monthly fee.
Learn more about Managed service provider (MSP)
MDR (managed detection and response)
A service in which a security team monitors your detection tools around the clock, investigates alerts, and helps contain threats.
Learn more about MDR (managed detection and response)
MFA (multi-factor authentication)
Requiring two or more kinds of proof to sign in, such as a password plus an app prompt, hardware key, or passkey.
Learn more about MFA (multi-factor authentication)
MFA fatigue
An attack that floods a user with sign-in approval prompts, hoping they approve one to make the prompts stop. Number matching and phishing-resistant MFA reduce it.
Learn more about MFA fatigue
Microsoft 365
Microsoft's subscription suite of cloud email, file storage, collaboration, and Office apps, secured through Entra ID and related tools.
Learn more about Microsoft 365

N

Network segmentation
Dividing a network into separate zones so a problem in one area, such as guest Wi-Fi or IoT devices, cannot easily reach critical systems.
Learn more about Network segmentation
NIST Cybersecurity Framework (CSF)
A voluntary framework from the U.S. National Institute of Standards and Technology that organizes security into Govern, Identify, Protect, Detect, Respond, and Recover.
Learn more about NIST Cybersecurity Framework (CSF)

O

Offboarding
The steps for removing a departing employee's access, recovering devices, and preserving business data.
Learn more about Offboarding

P

Passkey
A phishing-resistant replacement for passwords that uses a cryptographic key pair stored on a device and unlocked with a PIN or biometric.
Learn more about Passkey
Password manager
An encrypted vault that generates, stores, and fills unique passwords so people do not reuse them.
Learn more about Password manager
Patch management
The process of testing and installing software updates that fix security flaws and bugs, on a reliable schedule.
Learn more about Patch management
Penetration testing
An authorized simulated attack that tries to exploit weaknesses to show how far a real attacker could get.
Learn more about Penetration testing
Personally identifiable information (PII)
Information that can identify a specific person, such as a name combined with a Social Security, account, or driver's license number.
Learn more about Personally identifiable information (PII)
PHI (protected health information)
Individually identifiable health information held by HIPAA covered entities or business associates.
Learn more about PHI (protected health information)
Phishing
Fraudulent messages that impersonate trusted senders to steal credentials, deliver malware, or trick people into payments.
Learn more about Phishing

Q

Quishing
Phishing that uses QR codes to send victims to malicious sites, often bypassing email link scanners.
Learn more about Quishing

R

Ransomware
Malware that encrypts or steals data and demands payment to restore access or prevent publication.
Learn more about Ransomware
Recovery point objective (RPO)
The maximum amount of data, measured in time, that a business can afford to lose after a disruption.
Learn more about Recovery point objective (RPO)
Recovery time objective (RTO)
The maximum acceptable time to restore a system or process after a disruption.
Learn more about Recovery time objective (RTO)
Remote access
Connecting to business systems from outside the office, ideally through secured, monitored methods with MFA.
Learn more about Remote access
Risk assessment
Identifying threats and vulnerabilities, estimating their likelihood and impact, and deciding which safeguards to prioritize.
Learn more about Risk assessment
RMM (remote monitoring and management)
Software MSPs use to monitor device health, deploy patches, and support computers remotely.
Learn more about RMM (remote monitoring and management)

S

Security awareness training
Ongoing education and simulated phishing that teach employees to recognize and report threats.
Learn more about Security awareness training
Session hijacking
Stealing a valid session token or cookie to take over a signed-in session without needing the password or MFA.
Learn more about Session hijacking
Shadow IT
Apps, cloud services, or devices employees use for work without IT's knowledge or approval.
Learn more about Shadow IT
SharePoint
Microsoft 365's platform for team sites, document libraries, and intranets, often used to replace on-premises file servers.
Learn more about SharePoint
SIEM (security information and event management)
A system that collects and correlates logs from across an environment to detect and investigate security events.
Learn more about SIEM (security information and event management)
SLA (service level agreement)
A contract term that defines expected service levels, such as response and resolution times for support tickets.
Learn more about SLA (service level agreement)
Smishing
Phishing by text message, often posing as a delivery service, bank, or executive.
Learn more about Smishing
SOC (security operations center)
A team, in-house or outsourced, that monitors security tools, investigates alerts, and coordinates response.
Social engineering
Manipulating people rather than technology to gain access, information, or money.
Learn more about Social engineering
SPF (Sender Policy Framework)
A DNS record listing which servers are allowed to send email for a domain, helping receivers spot spoofed mail.
Learn more about SPF (Sender Policy Framework)
Spoofing
Disguising a message, website, phone number, or address to appear to come from a trusted source.
Learn more about Spoofing
SQL injection
An attack that inserts malicious database commands through website input fields to read or alter data.
Learn more about SQL injection

T

Tabletop exercise
A discussion-based rehearsal where a team walks through a simulated incident to test its plan and decision-making.
Learn more about Tabletop exercise
Threat hunting
Proactively searching an environment for signs of attackers that automated tools have not flagged.
Learn more about Threat hunting
Two-factor authentication (2FA)
A form of MFA that uses exactly two factors, typically a password and a code or app approval.
Learn more about Two-factor authentication (2FA)

V

vCIO (virtual chief information officer)
An outsourced technology advisor who builds IT roadmaps, budgets, and strategy without a full-time executive hire.
Learn more about vCIO (virtual chief information officer)
Vendor risk management
Assessing and monitoring the security of suppliers and service providers that access your systems or data.
Learn more about Vendor risk management
Vishing
Voice phishing: scam phone calls that impersonate banks, vendors, IT support, or executives.
Learn more about Vishing
VoIP (voice over IP)
Phone service delivered over the internet instead of traditional phone lines.
Learn more about VoIP (voice over IP)
VPN (virtual private network)
An encrypted tunnel that connects a remote device to a private network over the internet.
Vulnerability
A weakness in software, hardware, configuration, or process that an attacker could exploit.
Learn more about Vulnerability
Vulnerability management
The continuous cycle of finding, prioritizing, fixing, and verifying security weaknesses.
Learn more about Vulnerability management

W

WISP (written information security program)
A documented security program describing how a business protects personal information, required by Massachusetts 201 CMR 17.00 for many organizations.
Learn more about WISP (written information security program)

X

XDR (extended detection and response)
Detection and response that correlates signals across endpoints, email, identity, network, and cloud rather than endpoints alone.
Learn more about XDR (extended detection and response)

Z

Zero trust
A security model that never assumes trust based on network location and verifies every user, device, and request.
Learn more about Zero trust
Zero-day
A vulnerability that attackers exploit before the vendor has released a fix.

Still have questions?

See our IT and cybersecurity questions answered, browse the learning center, or ask us directly about managed IT and cybersecurity services.

Free IT & cybersecurity assessment

Understand your priorities before IT and security problems become expensive.

Start with a no-obligation conversation about your technology, Microsoft 365 environment, backup readiness, and material cybersecurity concerns.

  • Preliminary security and IT review
  • Microsoft 365 configuration discussion
  • Backup and recovery-readiness review
  • Prioritized next-step recommendations

By submitting, you ask Meta IT Pro to contact you about this request and acknowledge our Privacy Policy. Do not include passwords, authentication codes, financial details, medical records, or other sensitive information.