cybersecurity glossary
Cybersecurity moves fast, and the terminology moves with it. This glossary defines the concepts that matter most — from foundational terms like firewalls and encryption to advanced topics like CTEM, attack surface management, and AI penetration testing.
Search...
A B C D E F G H I J K L M N O P Q R S T U V W X Y Z
A
Access control \
\
Access control is a security measure used to regulate who or what can view or use resources in a computing environment. It is used to protect confidential information, and is implemented through authentication, authorization, and encryption. Examples include physical, network, and application access control systems.\
\
Read More
Advanced Persistent Threat \
\
An Advanced Persistent Threat (APT) is a sophisticated, long-term cyberattack targeting specific entities. Learn how APTs work and how to defend against them.\
\
Read More
Application Penetration Testing \
\
Application Penetration Testing is a security testing technique used to identify vulnerabilities in web applications and software through simulated attacks.\
\
Read More
Attack Surface \
\
Attack Surface is a measure of the potential vulnerability of a system or network to malicious attacks. It is an important concept in cybersecurity, as it helps to identify and mitigate potential risks by reducing the number of components, simplifying the system architecture, and limiting the number of entry points.\
\
Read More
Previous Next
B
Botnet \
\
Botnets are networks of computers or other internet-connected devices infected with malicious software and controlled as a group without the knowledge of their owners. They are used to carry out malicious activities such as sending spam, launching DDoS attacks, stealing data, and spreading malware.\
\
Read More
Business Email Compromise (BEC) \
\
Business Email Compromise (BEC) is a targeted cybercrime where attackers use social engineering to access company email accounts and commit fraud.\
\
Read More
BYOD \
\
BYOD (Bring Your Own Device) is a policy that allows employees to use their own personal devices for work purposes. It is becoming increasingly popular in the workplace and should include security measures to protect company data and networks.\
\
Read More
Previous Next
C
CIS Controls \
\
CIS Controls are a set of best practices developed by the Center for Internet Security (CIS) to help organizations protect their networks and data from cyber threats. Organizations can use the CIS Controls to reduce their risk of a cyber attack, such as setting strong passwords, disabling unnecessary services, and using access control measures.\
\
Read More
CIS RAM \
\
CIS RAM is a free risk assessment method developed by the Center for Internet Security to help organizations measure and manage information security risk in alignment with the CIS Controls.\
\
Read More
Cloud computing \
\
Cloud Computing is a type of computing that uses a network of remote servers hosted on the Internet to store, manage, and process data. It is used for a variety of purposes, from storing and sharing data to running applications and cloud gaming.\
\
Read More
Cloud Security \
\
Cloud security protects data, applications, and infrastructure in cloud environments. Learn about cloud security best practices, risks, and testing approaches.\
\
Read More
COBIT \
\
COBIT is a framework for IT governance, risk management, and compliance that provides best practices and processes for managing IT resources. It is used by organizations of all sizes to ensure IT investments are managed effectively and efficiently, and to align IT objectives with business objectives.\
\
Read More
Cryptocurrency \
\
Cryptocurrency is a digital or virtual currency secured by cryptography and decentralized, used as a medium of exchange and an investment. Examples include Bitcoin, Ethereum, Litecoin, and Ripple.\
\
Read More
Cryptojacking \
\
Cryptojacking is a cyberattack where malicious actors secretly use a victim's computing resources to mine cryptocurrency without consent.\
\
Read More
Cyber Attack \
\
A cyber attack is any malicious activity targeting computer systems, networks, or devices. Learn about types, impacts, and how to defend against them.\
\
Read More
Cyber Maturity Model Certification (CMMC) \
\
CMMC is a DoD certification program requiring defense contractors to meet specific cybersecurity standards to protect Controlled Unclassified Information (CUI).\
\
Read More
Cyber Threat Intelligence \
\
Cyber threat intelligence (CTI) is the process of gathering and analyzing information about cyber threats to help organizations identify and respond to risks.\
\
Read More
Previous Next
D
Darknet \
\
Darknet is a private network used to share data and information between users, often for activities that are not legal or considered unethical. It is used to access websites and services not available on the public internet, and to host websites not accessible through the public internet.\
\
Read More
Data Breach \
\
A data breach is an incident where sensitive data is accessed or stolen without authorization. Learn how data breaches occur and how to prevent them.\
\
Read More
Data Loss Prevention \
\
Data Loss Prevention (DLP) is a security strategy used to protect sensitive data from unauthorized access, use, or disclosure. DLP solutions can be used to detect and block the unauthorized transfer of data, as well as to monitor and control the transfer of data over the internet, email, and other communication channels.\
\
Read More
DDoS Attack \
\
A DDoS attack is a malicious attempt to disrupt the normal traffic of a targeted server, service, or network by overwhelming it with a flood of internet traffic. It is commonly used to target websites, online services, and networks.\
\
Read More
Declaration of Conformity \
\
A Declaration of Conformity in cybersecurity is a formal document attesting that an organization's security controls meet a recognized standard such as ISO 27001 or SOC 2.\
\
Read More
DMZ \
\
DMZ is a network security architecture that creates a separate, isolated network segment between an organization's internal network and the Internet. It is used to protect an organization's internal network from malicious traffic and to host public-facing services.\
\
Read More
Previous Next
E
Encryption \
\
Learn about Encryption, a process used to protect sensitive information from unauthorized access and ensure data is not modified or corrupted during transmission. Examples include online banking, secure email, and secure file sharing.\
\
Read More
Endpoint \
\
Endpoints are nodes in a network used for data exchange between two or more devices. They are used in computer networks, the Internet, and distributed systems, such as cloud computing.\
\
Read More
Endpoint Detection and Response \
\
Endpoint Detection and Response (EDR) is a security technology that detects, investigates, and responds to malicious activity on endpoints in real time.\
\
Read More
Ethical Hacking Tools \
\
Ethical Hacking Tools are software and hardware tools used to identify and exploit weaknesses in computer systems, networks, and applications. These tools can be used to test the security of a system, simulate attacks, detect malicious activity, and provide detailed reports on the security of a system.\
\
Read More
Previous Next
F
Firewall \
\
Firewalls are network security systems used to protect private networks from malicious activity and unauthorized access. They can be implemented as hardware, software, or a combination of both, and can be configured to allow or deny access based on source, destination, type of traffic, or application.\
\
Read More
FISMA \
\
FISMA is a US federal law that requires federal agencies to develop and implement an information security program to protect their information and information systems from threats. Examples include the Department of Defense's Risk Management Framework.\
\
Read More
Previous Next
G
Gap analysis \
\
Gap analysis compares an organization's current security posture to a target framework or standard to identify areas for improvement and build a security roadmap.\
\
Read More
GDPR \
\
The General Data Protection Regulation (GDPR) is a comprehensive data protection law that gives individuals more control over their personal data and requires organizations to comply with higher standards of accountability. It applies to any organization that processes the personal data of EU citizens, regardless of location.\
\
Read More
Previous Next
H
Hacker \
\
A Hacker is an individual who uses their technical knowledge to gain unauthorized access to computer systems, networks, or data. They may use their skills to gain access to confidential information, disrupt services, or cause damage to systems, or to create new software or applications. Ethical Hackers may use their skills to help organizations identify and fix security vulnerabilities.\
\
Read More
HIPAA \
\
HIPAA is a federal law that protects the privacy of individuals' health information and sets standards for its use and disclosure. Covered entities must comply with HIPAA regulations, including implementing safeguards to protect PHI.\
\
Read More
Hypervisor (VMM) \
\
Hypervisor (VMM) is a software program that enables multiple operating systems to run on the same physical computer. It is commonly used in cloud computing and virtual desktop infrastructure (VDI) solutions for greater efficiency and scalability.\
\
Read More
Previous Next
I
Identification \
\
Learn about Identification, the process of recognizing or establishing the identity of a person, object, or concept. Examples include verifying a person's identity, confirming the authenticity of a document, and assigning a unique identifier to an object or concept.\
\
Read More
Identity Theft \
\
Identity Theft is a type of fraud that involves stealing someone's personal information to commit financial crimes. It can have serious consequences for the victim and can be difficult to detect.\
\
Read More
Incident Response \
\
Incident Response is the process of responding to and managing the aftermath of a security breach or cyberattack. It involves steps to contain the damage, investigate the incident, and restore affected systems and data. It is also used to identify the root cause and prevent similar incidents from occurring.\
\
Read More
Infrastructure-as-a-Service (IaaS) \
\
IaaS is a cloud computing model that provides users with access to virtualized computing resources such as servers, storage, and networking. It is used to host applications and services, and can be scaled up or down as needed. It is a cost-effective solution for businesses that need to quickly deploy and manage their IT infrastructure.\
\
Read More
Initial Access Brokers \
\
Initial Access Brokers are cybercriminals who sell unauthorized access to compromised networks, often enabling ransomware and other attacks.\
\
Read More
Internal Penetration Testing \
\
Internal penetration testing simulates attacks on an organization's internal network to identify vulnerabilities before malicious actors can exploit them.\
\
Read More
Intrusion detection system (IDS) \
\
Intrusion Detection System (IDS) is a type of security software that monitors a network or system for malicious activity or policy violations. It is designed to detect and respond to unauthorized access, misuse, and other malicious activities.\
\
Read More
Intrusion Prevention System (IPS) \
\
An Intrusion Prevention System (IPS) monitors network traffic to detect and block malicious activity including phishing, malware, and DoS attacks in real time.\
\
Read More
ISO 27001 \
\
ISO 27001 is an international standard for information security management systems. Learn about its requirements, benefits, and how to prepare for certification.\
\
Read More
Previous Next
K
Keyboard logger \
\
Keyboard loggers are a type of surveillance software used to monitor and record every keystroke typed on a computer's keyboard. It is often used by Hackers, employers, and parents to track passwords, emails, and other sensitive information.\
\
Read More
Previous Next
M
Macro virus \
\
Macro viruses are a type of computer virus written in the same macro language used for software programs. They are spread through documents, applications, email attachments, and file sharing. Examples include macros that automatically format text in Microsoft Word documents.\
\
Read More
Malicious Apps \
\
Malicious apps are designed to harm or exploit a user's device or data. Learn how to identify and protect yourself from malicious mobile applications.\
\
Read More
Malware \
\
Malware is malicious software designed to damage, disrupt, or gain unauthorized access to computer systems. Learn about types, prevention, and detection.\
\
Read More
Managed Detection and Response (MDR) \
\
Managed Detection and Response (MDR) is a security service that provides organizations with the ability to detect, investigate, and respond to cyber threats. MDR services are used to supplement existing security infrastructure and provide an additional layer of protection against cyber threats.\
\
Read More
MTTD and MTTR \
\
MTTD and MTTR are metrics used to measure the performance of a system or process in terms of how quickly it can detect and repair any issues that arise. They are used to measure effectiveness, compare performance, and track performance over time.\
\
Read More
Multi-Factor Authentication (MFA) \
\
Multi-Factor Authentication (MFA) is an authentication method that requires more than one form of authentication to verify a user's identity. It is used to protect against unauthorized access to sensitive data and systems, and is often used in combination with other security measures. Examples include entering a username and password, and then providing a one-time code or scanning a fingerprint.\
\
Read More
Previous Next
N
Network Firewall \
\
A network firewall is a hardware/software security system that monitors and controls network traffic to protect against unauthorized access and cyber threats.\
\
Read More
Network Penetration Testing \
\
Network Penetration Testing is a security testing technique used to identify vulnerabilities in a network or system. It is a simulated attack to identify potential weaknesses that could be exploited by malicious actors.\
\
Read More
Network Security \
\
Network Security is the practice of protecting networks, systems, and programs from digital attacks. It involves authorization of access, prevention and detection of unauthorized access, and the use of firewalls, antivirus software, intrusion detection systems, and encryption.\
\
Read More
Network Security Assessment \
\
Network Security Assessment is a process of evaluating the security of a computer network, identifying potential security risks, and recommending measures to improve the security. Qualified security professionals review the network architecture, security policies, and security controls to ensure the network's security posture.\
\
Read More
NIST Cybersecurity Framework \
\
The NIST Cybersecurity Framework provides guidelines for managing cybersecurity risk across five core functions: Identify, Protect, Detect, Respond, and Recover.\
\
Read More
Previous Next
P
Password \
\
Learn about passwords, a secret string of characters used to authenticate a user's identity and gain access to a system, application, or website. Understand how passwords are used to protect sensitive data and examples of how to create a secure password.\
\
Read More
Password Cracking \
\
Password cracking is the process of attempting to gain access to a system or account by guessing or recovering passwords. It is used by malicious actors to gain access to sensitive information or systems, and by security professionals to test the strength of passwords and identify weak passwords.\
\
Read More
PCI DSS \
\
PCI DSS is a set of security standards for organizations that handle credit card data. Learn about requirements, compliance, and how penetration testing fits in.\
\
Read More
Penetration Testing \
\
Penetration Testing is a security testing technique used to evaluate the security of a computer system or network by simulating an attack to identify potential vulnerabilities and security weaknesses.\
\
Read More
Phishing \
\
Phishing is a social engineering cyberattack that deceives victims into revealing sensitive data. Learn how phishing works and how to defend against it.\
\
Read More
Platform-as-a-Service (PaaS) \
\
Platform-as-a-Service (PaaS) is a cloud computing model providing a platform for developing and deploying applications without managing underlying infrastructure.\
\
Read More
Privilege Escalation \
\
Learn about privilege escalation, a type of attack that allows an attacker to gain access to more resources or privileges than they are normally allowed. Examples and usage of privilege escalation are discussed, such as gaining access to sensitive data or other user accounts.\
\
Read More
Proxy server \
\
A Proxy server is a computer or network service that acts as an intermediary between a client and a server. It can be used to improve network performance, filter content, and protect against malicious activity.\
\
Read More
Previous Next
R
Ransomware \
\
Ransomware is malicious software that encrypts files and demands payment for decryption. Learn how ransomware spreads and how to protect your organization.\
\
Read More
Ransomware-as-a-Service \
\
Ransomware-as-a-Service (RaaS) is a type of cybercrime in which criminals offer ransomware as a service to other criminals. It is a lucrative business for criminals, as it allows them to monetize their skills and resources without having to invest in the development of the ransomware themselves.\
\
Read More
Red Team Vs. Blue Team \
\
Red Team vs. Blue Team is a security assessment where attackers and defenders work simultaneously to test and improve an organization's security posture.\
\
Read More
Risk assessment \
\
Risk assessment is the process of identifying and evaluating security risks to help organizations prioritize investments and reduce their attack exposure.\
\
Read More
Previous Next
S
Secure Shell (SSH) \
\
Secure Shell (SSH) is a network protocol used to securely transfer data between two computers over an unsecured network. It is commonly used to access remote servers, transfer files, and manage network services, and is a secure alternative to the traditional Telnet protocol.\
\
Read More
Security Control \
\
Security control is a measure taken to protect systems, networks, and data from unauthorized access, malicious attacks, and other security risks. Examples of security controls include firewalls, antivirus software, encryption, authentication, and access control.\
\
Read More
Security Information and Event management (SIEM) \
\
Security Information and Event Management (SIEM) is a type of security software used to detect and respond to security threats, such as malicious activity, unauthorized access, and data breaches. It can also generate reports and analyze trends to improve security posture.\
\
Read More
Security Operations \
\
Security operations is the process of managing and monitoring the security of an organization's systems, networks, and data. It involves the implementation of security policies, procedures, and technologies to protect the organization's assets from unauthorized access, malicious attacks, and other security threats.\
\
Read More
Security Operations Center (SOC) \
\
Learn about Security Operations Centers (SOCs), a centralized unit within an organization responsible for monitoring, detecting, analyzing, and responding to security threats and incidents. SOCs are staffed by security professionals and equipped with tools and technologies to detect and respond to security threats.\
\
Read More
Security Orchestration Platform \
\
A security orchestration platform automates and streamlines security operations including incident response, threat intelligence, and vulnerability management.\
\
Read More
Security Orchestration Tools \
\
Security orchestration tools automate and integrate security operations including vulnerability management, threat intelligence, and incident response workflows.\
\
Read More
Security Perimeter \
\
Establish a Security Perimeter to protect your organization's internal network from external threats. Combinations of hardware, software, and policies are used to prevent unauthorized access and common examples include firewalls, intrusion detection systems, and virtual private networks (VPNs).\
\
Read More
Security Policy \
\
A security policy is a set of rules and regulations that govern how an organization or individual handles data and information security. It outlines measures taken to protect data from unauthorized access, modification, or destruction, as well as procedures for responding to security incidents and breaches.\
\
Read More
Session Hijacking \
\
Session Hijacking is a type of cyber attack in which an attacker steals a user's session ID to gain access to sensitive information and restricted areas of a website or network. Examples include gaining access to a user's bank account or launching other types of attacks.\
\
Read More
Shadow IT \
\
Shadow IT refers to unauthorized IT systems and apps used without IT department approval. Learn about the security risks, including the rise of Shadow AI.\
\
Read More
Social Engineering \
\
Social engineering attacks exploit human psychology to gain unauthorized access to systems or data. Learn about phishing, vishing, pretexting, and defenses.\
\
Read More
Spear Phishing \
\
Spear phishing is a targeted social engineering attack aimed at specific individuals or organizations. Learn how these personalized attacks work and how to defend against them.\
\
Read More
Spoofing \
\
Spoofing is a type of cyber attack in which an attacker disguises themselves as a legitimate user to gain access to sensitive information, disrupt services, or launch further attacks. Examples of spoofing include creating false identities, manipulating data, and sending malicious emails.\
\
Read More
Spyware \
\
Spyware is a type of malicious software that is installed on a computer or device without the user's knowledge or consent. It is used to collect personal information, monitor activity, display ads, and redirect users to malicious websites.\
\
Read More
Static Application Security Testing \
\
Static Application Security Testing (SAST) analyzes application source code to identify security vulnerabilities like SQL injection and XSS before deployment.\
\
Read More
Strategic Advisory \
\
Cybersecurity strategic advisory helps organizations build security programs, align security posture to business risk, and make informed decisions about security investments.\
\
Read More
Supply Chain Attack \
\
A supply chain attack targets less-secure elements in an organization's supply chain to distribute malware or steal data. Learn how to identify and prevent them.\
\
Read More
Previous Next
T
Threat Actor \
\
A threat actor is an individual or group engaged in malicious cyber activities. Learn about state-sponsored, criminal, and hacktivist threat actor categories.\
\
Read More
Threat Hunting \
\
Threat hunting is a proactive approach to cybersecurity that involves actively searching for malicious activity or indicators of compromise (IOCs) on a network or system. It is used to detect malicious actors, malicious code, and suspicious activity before it can cause damage.\
\
Read More
Threat Management \
\
Threat Management is the process of identifying, assessing, and responding to potential threats to an organization or individual. It involves the use of various strategies and techniques to mitigate risks and protect physical assets, data, and systems.\
\
Read More
Threat & Vulnerability Management \
\
Threat & Vulnerability Management (TVM) is a continuous program for identifying, prioritizing, and remediating security vulnerabilities across an organization.\
\
Read More
Trojan Horse \
\
Trojan Horse is a type of malicious software disguised as legitimate software, used to gain access to a computer system without the user's knowledge or consent. Examples include malicious attachments and malicious websites.\
\
Read More
Two-Factor Authentication \
\
Two-Factor Authentication is an additional layer of security that requires two forms of authentication when logging into an account. It is used by banks, social media sites, and other services to increase security and protect online accounts.\
\
Read More
Previous Next
U
UEBA \
\
UEBA is a type of security analytics that uses machine learning and data science to detect anomalies in user and entity behavior. It can be used to detect malicious activities, insider threats, and anomalous behavior in user accounts.\
\
Read More
User Account \
\
Learn about User Accounra, which are unique profiles used to access computer systems, websites, and applications. User accounts store personal information and preferences, and track user activity. Examples of usage are provided.\
\
Read More
Previous Next
V
Vishing \
\
Vishing is a voice-based social engineering attack that deceives victims into revealing sensitive information over phone calls. Learn how to recognize and prevent vishing.\
\
Read More
VPN \
\
A Virtual Private Network (VPN) is a secure connection between two or more devices that allows for private data exchange over a public network. It is used to protect data and provide access to restricted networks and websites, as well as bypass geographic restrictions.\
\
Read More
Vulnerability Management Tools \
\
Vulnerability management tools are software applications that help organizations identify, assess, and remediate security vulnerabilities in their IT systems. These tools can be used to detect and address potential security risks, as well as to monitor and track the progress of remediation efforts.\
\
Read More
Vulnerability Scanning \
\
Vulnerability scanning identifies and classifies security weaknesses in systems and applications. Learn how it works and how it differs from penetration testing.\
\
Read More
Previous Next
W
Whaling \
\
Whaling is a targeted phishing attack aimed at senior executives like CEOs and CFOs. Learn how whaling attacks work and how to protect your leadership team.\
\
Read More
Whitelisting \
\
Whitelisting is a security measure used to protect computer systems and networks from malicious software and other unauthorized access. It is used to allow only approved programs, websites, and other digital resources to be accessed or used.\
\
Read More
Wireless Security \
\
Wireless Security is the practice of protecting networks, devices, and data that use wireless connections from unauthorized access. It involves the use of various security protocols and technologies to protect wireless networks from malicious attacks and unauthorized access.\
\
Read More
Wire Transfer Fraud \
\
Wire Transfer Fraud is a type of financial fraud that involves the unauthorized transfer of funds from one account to another without the account holder's knowledge or consent. Criminals use stolen or fake identities to gain access to bank accounts and transfer funds.\
\
Read More
Previous Next
X
XDR \
\
XDR (Extended Detection and Response) is a security framework that unifies threat detection and response across endpoints, networks, cloud, and email into a single platform.\
\
Read More
Previous Next
Z
Zero Trust \
\
Zero Trust is a security model that assumes all users, devices, and networks are untrusted and must be verified before access is granted. It is used to protect organizations from malicious actors and insider threats and is implemented through authentication methods and access control policies.\
\
Read More
Previous Next
Back to Top
Previous Next
Clear
No results found...
Previous Next
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Start Playing Offense to Play Better Defense
Book a Demo
Copyright © 2026Evolve Security. Evolve Security is trademarked in the United States.
Stay in the know. Subscribe today!
312-957-5682
123 N. Waker Dr., Suite: 2125 Chicago, IL 60606
info@evolvesecurity.com
Connect
Contact Us Request a demo
Services
Services Overview AI Penetration Testing Application Penetration Testing Cloud Penetration Testing Network Penetration Testing Embedded Systems Red Team Advisory
Platform
Darwin Attack Overview Risk Scoring Asset & Threat Intelligence Human-In-The-Loop Dashboards & Reporting Platform Integrations
Resources
Blogs Events Videos Podcasts
Company
About Careers Evolve Academy Partner Program
Privacy Policy Terms of Service Vulnerability Disclosure Policy Report Issue