Cybersecurity glossary
Key cybersecurity terms explained: what each one means, how to spot the threat and what to do.
Business email compromise (BEC)
Business email compromise (BEC) is fraud in which an attacker writes as a CEO, supplier or partner and asks for a payment or a change of bank details. Often there is no malicious link at all, just a convincing request.
Clean desk policy
A clean desk policy is the rule that when you leave your workstation no confidential documents, password notes or storage media are left on the desk, and the screen is locked. It is one of the ISO 27001 controls (A.7.7).
Credential stuffing
Credential stuffing is an attack in which email and password pairs stolen in other sites' breaches are tried automatically against thousands of services. It works because people reuse the same password in several places.
Data breach
A data breach is when personal or confidential data reaches someone who has no right to it, through an attack, a lost device or a file sent by mistake. For personal data, the law requires prompt notification.
Deepfake
A deepfake is an AI-generated fake voice, video or photo that resembles a real person. Scammers use them to call in a manager's voice or show a fake colleague on a video call to obtain a transfer or access.
Human risk management
Human risk management is an approach that measures and reduces cyber risk caused by employee behaviour: who clicked a phishing link, who skipped training, which department carries the most risk. It is the next step beyond awareness training.
Malware
Malware is any software that harms a computer, phone or network: viruses, trojans, spyware and ransomware. It most often spreads through email attachments, dangerous links and unofficial downloads.
MFA fatigue attack
In an MFA fatigue attack the attacker already has the victim's password and sends approval prompts to their phone over and over until the person taps "approve" out of fatigue or by mistake. It is sometimes paired with a call "from IT".
Password manager
A password manager is software that stores all your passwords encrypted and generates a long, unique password for every account. You only remember one master password, which should be protected with 2FA.
Personal data
Personal data is any information that can identify a living person: a name, personal ID number, phone, email, IP address or photo. Health, biometric and criminal record data are special categories that require stricter protection.
Phishing
Phishing is fraud in which an attacker impersonates a trusted organisation or person in an email, message or link to get the victim to hand over a password or card details, or to open a malicious file. It is the most common starting point of cyberattacks on organisations.
Phishing simulation
A phishing simulation is a safe, controlled test phishing email a company sends to its own employees. It shows who would click in a real attack, and whoever clicks immediately gets a short training course.
Pretexting
Pretexting is a social engineering technique in which the attacker tells a prepared story (the pretext): a new colleague, an auditor, a courier or an IT technician. The story exists to make the request seem logical and harmless.
Quishing (QR code phishing)
Quishing is phishing with a QR code. The attacker places a fake QR code in an email, on a parking meter, a restaurant menu or a poster. Scanning it opens a fake page on the phone that asks for login details or a payment.
Ransomware
Ransomware is malware that encrypts a company's files and demands a ransom to restore them, often with a threat to publish the stolen data as well. Attacks usually begin with a phishing email or a stolen password.
Security awareness training
Security awareness training is regular training that teaches employees to recognise phishing, social engineering and other threats and to respond correctly. The modern approach combines short courses, phishing simulations and measured results.
Shadow IT
Shadow IT is software, cloud services and AI tools employees use for work without IT's knowledge or approval: a personal Google Drive, an unknown file converter, client data pasted into ChatGPT.
Smishing
Smishing is phishing by SMS or messenger. The scammer sends a short message in the name of a courier, bank, government agency or fine, with a link to a fake page that asks for card details or a one-time code.
Social engineering
Social engineering is manipulating a person into handing over information, access or money themselves. The attacker plays on trust, authority, fear, curiosity and urgency. Phishing, vishing and pretexting are all forms of social engineering.
Spear phishing
Spear phishing is phishing tailored to one person or team. The attacker researches the target on LinkedIn, the company website or social media first, then writes an email that reads like genuine work correspondence, with the right names, projects and tone.
Two-factor authentication (2FA)
Two-factor authentication (2FA) means logging in requires a second proof besides the password: a code from an app, a security key or a fingerprint. A stolen password alone is no longer enough.
Vishing
Vishing is phishing over a phone call. The caller poses as the bank, IT support, the police or a manager and, during the call, asks for a password, a one-time code, a transfer or the installation of remote access software.
Start with your team's risk baseline
15-30 employees, one phishing simulation and a one-page report for management. No annual commitment.