Security Glossary
Plain-English definitions for the cybersecurity terms you'll encounter most.
Phishing
Fraudulent emails or messages designed to trick victims into revealing credentials or installing malware.
Ransomware
Malicious software that encrypts a victim's files and demands payment for the decryption key.
MFA
Multi-Factor Authentication — requiring a second proof of identity (app, key, or biometric) beyond a password.
Zero-Day
A software vulnerability that is unknown to the vendor and has no available patch yet.
Social Engineering
Manipulating people into breaking security procedures through deception, urgency, or trust.
Malware
Any malicious software — viruses, spyware, trojans, worms — designed to damage or access a system.
Firewall
A network security device that filters incoming and outgoing traffic based on security rules.
Encryption
Scrambling data so only someone with the correct key can read it — essential for protecting data at rest and in transit.
vCISO
Virtual Chief Information Security Officer — a security leader provided as a service, ideal for organizations without a full-time need.
SIEM
Security Information and Event Management — a system that aggregates and analyzes log data to detect threats.
Patch
A software update that fixes a security vulnerability. Prompt patching closes known exploit paths.
Endpoint
Any device that connects to a network — laptops, phones, servers — each a potential entry point for attackers.