These definitions come from the jargon decoder at the back of SECURED: The Cybersecurity Survival Guide. Keep them handy when you're reading an IT proposal, a cyber insurance application, or a vendor contract.
Authentication
The process of proving you are who you say you are, usually with a password or code.
Botnet
A network of infected computers controlled by a criminal to launch large- scale attacks like sending spam or knocking websites offline.
Business Email Compromise (BEC)
A scam where a criminal impersonates a trusted person via email to trick an employee into sending money or sensitive information.
Cloud Computing
Using someone else's computers and storage over the internet instead of owning and managing your own. Learn more.
Compliance
The work you do to prove you are following a specific set of security or privacy rules required by laws, industries, or customers. Learn more.
Cyber Insurance
An insurance policy designed to help your business cover the costs of recovering from a cyberattack. Learn more.
DDoS (Distributed Denial-of-Service) Attack
An attack that knocks a website offline by flooding it with so much junk traffic that it can't respond to legitimate customers.
Encryption
The process of scrambling your data so it's unreadable to anyone without the correct "key" to unscramble it.
Endpoint Detection and Response (EDR)
A modern version of antivirus that actively watches for suspicious behavior on your computers, not just known viruses. Learn more.
Firewall
A digital security guard that stands between your internal business network and the public internet, controlling what traffic is allowed in and out. Learn more.
Incident Response
The plan and actions you take to manage the aftermath of a security breach or cyberattack. Learn more.
IP Address
A unique address for a device on the internet, similar to a street address for a house.
Malware
A general term for any software, like viruses, spyware, or ransomware, designed to harm or disrupt a computer system.
Managed Service Provider (MSP)
An IT company that you hire to manage your technology and cybersecurity on an ongoing basis. Learn more.
Multi-Factor Authentication (MFA)
A security process that requires more than one method of proving your identity to log in, like a password plus a code from your phone. Learn more.
Network Segmentation
Dividing your company's computer network into smaller, isolated zones to prevent an attack from spreading.
Patch Management
The process of regularly updating your software and systems to fix security holes before criminals can exploit them. Learn more.
Penetration Testing
Hiring a team of ethical hackers to try to break into your systems to find security weaknesses before real criminals do.
Phishing
A deceptive email, text, or message designed to trick you into revealing sensitive information or clicking a malicious link.
Ransomware
Malicious software that locks up all your files and demands a payment (a ransom) to get them back. Learn more.
Remote Desktop Protocol (RDP)
A built-in Windows tool that allows you to control a computer remotely over a network connection.
Risk
The potential for loss or damage when a threat exploits a vulnerability in your business.
Server
A powerful computer that provides data or services to other computers (called clients) on a network.
Social Engineering
The art of manipulating people into giving up confidential information or performing an action they shouldn't.
Threat Actor
Any person or group who has the intent and capability to launch a cyberattack, from individual hackers to organized criminal groups.
Two-Factor Authentication (2FA)
A security process that requires exactly two methods of proving your identity to log in, such as a password and a text message code.
VPN (Virtual Private Network)
A tool that creates a secure, encrypted connection over a public network like the internet, often used for remote work.
Vulnerability
A weakness or flaw in software, hardware, or a process that could be exploited by an attacker.
Zero-Day Exploit
An attack that takes advantage of a security vulnerability on the same day it becomes known to the public, before a patch is available.
Zero Trust
A modern security model built on the principle of "never trust, always verify," which requires continuous authentication for all users and devices.

