Glossary of Terms
This glossary will provide you with definitions of significant, common cybersecurity terms.
This glossary will provide you with definitions of significant, common cybersecurity terms.
An attack surface is the sum of all possible attack vectors a malicious actor can utilise to access a system and exfiltrate data. Attack vectors include but are not limited to phishing, malware, unpatched software and compromised passwords. The digital attack surface of an organisation comprises all hardware and software connected to a network whereas the physical attack surface encompasses all endpoint devices that a malicious actor can access within the context of a cyber attack.
Attack surface management (ASM) is the continuous monitoring, analysis, discovery, and remediation of the potential attack vectors and vulnerabilities that cumulatively build up an organisation’s attack surface. Providing real-time visibility into emerging vulnerabilities, ASM adopts the perspective of a malicious actor to pinpoint targets, evaluate opportunities, and manage risks. ASM’s ‘hacker perspective’ helps security operations teams take a proactive approach to combating threats and respond adequately to the challenges of an evolving attack surface.
Read the full articleIn this cyber-attack, also known as an attacker-in-the-middle attack, a threat actor appropriates sensitive data by monitoring communications between two parties. AITM attackers can thus access personal data such as login credentials, financial data such as credit card numbers, or overall account information that can lead to identity theft. The attacker in the middle can be a human, a bot, malware, or a specific device.
Application security posture management (ASPM) is an asset-first approach that offers comprehensive visibility into an application environment, employing automation techniques and holistic security measures to gain insight into and improve application security programs. ASPM solutions collect and analyse security data across the entire development, deployment and operation lifecycle of an app, providing full visibility and tackling vulnerabilities.
Advanced threat protection (ATP) is a bundle of cybersecurity solutions aiming to defend the assets of an organisation against sophisticated cyber threats, including advanced persistent threats (APT). Unlike traditional solutions with scheduled scans, ATP offers real-time threat visibility by combining endpoint security, cloud security, and identity-based security technologies. In leveraging ATP, organisations are better positioned to respond to sprawling attack surfaces and emerging threat vectors while enhancing their security posture with AI-powered proactive measures.
Read the full articleBusiness email compromise (BEC) is a form of email fraud whereby a malicious actor uses social engineering techniques to gain employees’ trust and infiltrate an organisation to appropriate funds and sensitive data. Typically, financial gain is at the core of a BEC attack. Employees are coerced into transferring money to fraudulent accounts, paying fraudulent invoices, or sharing confidential information. At times, BEC attackers may even hijack employee email accounts and conduct their operations from there.
Read the full articleCloud detection and response (CDR) refers to a bundle of techniques for detecting, analysing, and acting on potential cyber incidents in the cloud. Essentially, CDR makes use of techniques typical for Endpoint Detection and Response (EDR), Network Detection and Response (NDR), and Extended Detection and Response (XDR) solutions, albeit with a focus on cloud environments. Essentially, CDR solutions offer a mixture of real-time detection capabilities, automated incident response functions, plus analytics/reporting features.
Read the full articleCloud security refers to a bundle of technologies, policies and processes addressing threats specific to cloud environments and dedicated to protecting cloud computing systems. These include but are not limited to identity and access management technologies, tools for the encryption of cloud-based data, compliance management techniques plus tools for the protection of individual applications or the entire cloud infrastructure.
Cyber insurance or cybersecurity insurance covers financial losses that companies have because of cyber incidents such as ransomware attacks and data breaches. Cyber insurance may cover the costs of business interruption in the event of an incident and pays for financial losses resulting from reputational damage. Further, it may include legal expenses and third-party liability. As cyber threats are becoming more sophisticated, cyber insurance has become an important instrument in minimising the financial impact of an attack.
Cybersecurity awareness is the ongoing process of educating and training the employees of an organisation about evolving cyber threats. This includes techniques for recognising, reporting on, and preventing such threats, deep dives on how to respond in the event of an incident, as well as individual or department-specific risk management measures. Through ongoing training, employees are made aware of the implications of a successful attack and the ramifications involved in disclosing sensitive information, clicking on an infected link or downloading suspicious software.
Defence in depth is a comprehensive cybersecurity strategy that combines multiple mechanisms to address security vulnerabilities and protect the assets of an organisation. This way, if one aspect of the defence is compromised, additional defence layers remain in place to make sure that the attackers are intercepted. Defence-in-depth strategies are meant to both prevent attackers from infiltrating an organisation and tackle attacks that are already in progress, minimising the damage. Defence-in-depth strategies often employ more sophisticated machine learning techniques such as anomaly detection.
Incident response (IR) jointly refers to an organisation’s bundle of technologies and processes for detecting and acting against cyber security breaches. An incident response team is tasked with minimising the cost of business interruption and preventing damage, securing critical assets, anticipating attack vectors, and intercepting threat actors. An organisation’s incident response plan (IRP) is a bundle of processes in place for the identification, containment, and remediation of different types of cyber attacks.
Find out moreIdentity Threat Detection and Response (ITDR) is the process of identifying and responding to identity-related threats such as business email compromise, compromised passwords, and similar risks to an organisation’s security posture. Unlike device-centric detection and response solutions such as EDR, ITDR is focused on user activity and centres on the monitoring of access management logs from various sources including both local and cloud environments.
Read the full articleAn incident response service is an outsourced form of incident response that combines an array of best-in-class technologies to tackle threat detection and response within an organisation. Typically, incident response technologies include endpoint detection and response (EDR), attack surface management (ASM), security information and event management (SIEM), security orchestration, automation and response (SOAR), extended detection and response (XDR).
Find out moreEndpoint Detection and Response (EDR) is a cybersecurity solution focused on the protection of endpoint devices such as laptops and desktop computers, servers, and mobile and edge devices. With real-time threat detection analysis and automated response capabilities, EDR identifies, prevents, and responds to cyber threats while working to minimise the damage from a progressing attack. Best-of-breed EDR solutions include real-time endpoint data collection that is analysed for threats in real-time, automated threat response, investigation and remediation enablement, as well as proactive threat hunting support.
Read the full articleEndpoint management is the policy-driven control of networked endpoint devices (e.g. desktop computers, laptops, servers, mobile devices, etc.) needed for protecting these devices and the data they generate from cyber threats. Within organisations, endpoint management is a concerted effort that involves IT teams and MSPs concentrating their efforts on access management, enforcing policies for users and endpoint devices, software updates and patching.
Endpoint security is a bundle of policies and protection mechanisms that safeguard endpoints from digital threats such as data breaches, unauthorised access, and device manipulation. In this context, an endpoint is any physical connected device such as a laptop, a desktop computer, a server, an edge or a mobile device. With growing attack surfaces due to remote work and continuously evolving, globally orchestrated digital threats, endpoint security strategies help organisations to avoid business interruption, downtime, and reputational damage.
Read the full articleEndpoint protection is a combination of device and network defence mechanisms designed to combat the challenges of increasingly growing and complex attack surfaces emerging due to remote work and practices such as BYOD (Bring Your Own Device). This includes endpoint compliance mechanisms ensuring that a device adheres to an organisation’s policies before it can access the network as well as tools monitoring, controlling, and protecting software installed on devices.
Read the full articleEndpoint protection software is an umbrella term for a variety of cybersecurity applications that protect the end devices within an organisation. These include servers, desktop computers, laptops, and mobile devices. Some of the most typical types of endpoint protection software include anti-malware solutions, web browser security tools, mobile threat defence and device management products, endpoint detection and response as well as advanced threat protection tools, embedded systems security solutions and data loss prevention (DLP) software.
Exposure management is a cybersecurity strategy encompassing the monitoring of risk areas, as well as the identification, inventory-keeping, mapping, prioritisation, prevention and remediation of risks associated with the digital assets of an organisation. These digital assets include but are not limited to endpoints, applications, and data. Exposure management covers the entire attack surface to identify gaps and vulnerabilities, and so get ahead of threat actors. Exposure management is part of risk management as it helps organisations manage risk levels and gauge the potential business impact of a successful cyber attack.
Endpoint Detection and Response (EDR) solutions go beyond traditional software, offering advanced features to tackle evolving cyber threats. They provide real-time monitoring, advanced threat detection, incident investigation, and behavioral analysis for comprehensive protection. When choosing an EDR solution, focus on key features like threat detection, response and blocking, visibility and reporting, integration, scalability, and adherence to industry security and compliance standards.
Read the full articleThis is a type of managed service specifically geared towards helping organisations overcome the lack of dedicated in-house cybersecurity personnel while offering a deep dive into an organisation’s cybersecurity posture. Managed cybersecurity service is a complex bundle that can include identity and access management (IAM) tools and consultations, compliance monitoring and support, as well as cyber risk assessment, rating and monitoring.
Managed detection and response (MDR) is a cybersecurity solution that surveils, identifies and responds to threats in real-time, 24/7. Known for its proactive protection capabilities, MDR is a concatenation of human expertise and high-end technology incorporating threat detection, threat hunting, remediation and response functionalities. Unlike traditional services, MDR can detect and manage ongoing attacks, minimising the damage and proactively helping organisations work on their security posture. MDR enables access to a security operations centre (SOC) staffed with cybersecurity experts focusing on threat hunting, incident response, and threat intelligence.
Read the full articleManaged Extended Detection and Response (MXDR) is a fully managed cybersecurity service that goes beyond classic solutions in combining a fully managed Endpoint Detection and Response (EDR) solution with processes and human expertise, usually delivered in the form of a 24/7 Security Operations Center (SOC). MXDR exists to safeguard the entire infrastructure of an organisation against emerging cyber threats.
Read the full articlePart of identity and access management (IAM), this is an identity verification method whereby users must produce at least two different pieces of information to verify their identity. Typically, this includes a password and a passcode, provided using different devices. Two-factor authentication (2FA) is the classic form of multifactor authentication. Even though it requires users to produce exactly two pieces of evidence, it offers a level of protection that is already making it difficult for threat actors to access user credentials.
A Managed Security Service Provider (MSSP) may offer managed endpoint protection as a service—an outsourced form of endpoint protection and management based on the business strategy, compliance requirements, and protection needs of an organisation. Endpoints encompass laptops, desktop computers, servers, mobile devices, virtual machines, and cloud applications.
Managed Security Service Providers (MSSPs) are external IT security providers who adapt their Managed Security Services (MSS) to the needs of a company to offer comprehensive protection. MSSPs orchestrate complex protection architectures comprising endpoint, web and cloud security services, intrusion prevention (IPS) and intrusion detection (IDS) systems, as well as expert support via an in-house Security Operations Centre (SOC). This form of outsourced monitoring and management enhances a company’s security posture via 24/7 incident response management, SIEM-based management, and proactive vulnerability detection mechanisms, among others.
Managed security services (MSS) are bundled technology offerings that protect digital assets and IT infrastructures from cyber threats. Delivered by external cybersecurity vendors, MSS help companies keep current with cybersecurity know-how and compliance requirements while leveraging MSS scalability to adapt to their evolving needs. Outsourcing instead of building an in-house solution helps organisations alleviate the burden placed on internal IT experts.
MDR providers (Managed Detection and Response providers) are cybersecurity service companies that deliver 24/7 threat monitoring, detection, and response on behalf of their clients. They combine advanced security technology, such as endpoint detection, cloud monitoring, and threat intelligence, with expert human analysis to identify and respond to cyber threats in real time. Unlike traditional security tools or MSSPs, MDR providers take an active role in investigating, containing, and helping to remediate incidents, often working as an extension of a company’s internal IT or security team.
Read the full articleAn Open Extended Detection and Response (XDR) solution integrates a security toolset with offerings coming from several different vendors. Rather than locking you into one way of doing detection and response, Open XDR enables organisations to combine several best-of-breed tools and technologies. With Open XDR, organisations benefit from the flexibility of working with multiple state-of-the-art solutions and are not tied to working with just one vendor’s technology and data sources.
Phishing is a form of social engineering using fraudulent emails, phone calls and text messages to lure account holders into downloading malware, sharing account credentials, personal information, financial data or any other type of sensitive information. Phishing explicitly targets the human actors within an organisation and relies on human error. Classic forms of phishing include spear phishing, smishing, vishing, and social media phishing.
Read the full articleThis type of malware holds exfiltrated sensitive data hostage, demanding that the victim pay a ransom. In a classic ransomware attack, the threat actors demand a ransom in exchange for the encryption keys to the stolen data. Today, ransomware attacks include more sophisticated tactics such as double and triple extortion. Notable forms of ransomware include leakware, mobile ransomware, scareware, and wipers.
Security as a service (SECaaS) is typically a cloud solution that delivers enterprise-grade security technologies in the form of a subscription-based SaaS offering. SECaaS extends across the entire spectrum of cybersecurity solutions, from identity and access management (IAM) to endpoint security and proactive incident response (IR). The SaaS route gives organisations greater flexibility while simplifying management and costing less.
Security information and event management (SIEM) systems are complex security solutions that combine user and entity behaviour analytics (UEBA) with AI and machine learning capabilities to help organisations identify anomalous behaviour and automate threat detection and incident response processes. Most SIEM systems include capabilities such as log management, event correlation and advanced analytics, incident monitoring and alerts, and compliance management.
A security operations center (SOC) is an outsourced or in-house team of IT security experts dedicated to guarding an organisation against digital threats on a 24/7 basis. A SOC is a complex bundle of human expertise, cybersecurity technologies, and mitigation and remediation strategies aiming to provide insights into an organisation’s threat landscape in real time. A SOC is typically responsible for preventive maintenance, testing and planning, threat monitoring, detection and response, as well as recovery strategies and compliance.
Read the full articleSecurity operations center as a service (SOCaaS) is a subscription-based cloud service for best-in-class managed 24/7 threat detection and response solutions. Similar to traditional SOCs, SOCaaS encompasses threat monitoring and detection, intrusion prevention, attack surface management (ASM) and analysis, threat intelligence, and SIEM systems. A SOCaaS costs less, is highly scalable, and reduces complexity in tackling trivial tasks and preventing alert fatigue.
Read the full articleSpear phishing is a personalised form of phishing that targets an individual, a group or an organisation. Typically, spear phishing employs social engineering techniques to convince the targeted entity to share sensitive data, download malicious software, click on a link, or even transfer funds to fraudulent accounts. Spear phishers can go to great lengths in obtaining information about their target to craft compelling and credible scam messages.
Spoofing is a form of social engineering whereby threat actors pretend to be a person or an entity that the target can trust. Spoofing can extend to various communication channels and techniques and typically involves two components—a fake entity and social engineering techniques that prompt the targets to act. Spoofing attacks include email, website, and phone call fraud, as well as IP spoofing, URL spoofing, DNS spoofing, ARP spoofing, and GPS spoofing.
Threat intelligence, or threat intel, is a bundle of actionable insights used for the detection and prevention of cyber threats within an organisation. Threat intelligence enables cybersecurity teams to make data-driven decisions and assume a proactive approach in cybersecurity analysis, helping organisations prevent incidents before they occur and thwart the progress of ongoing attacks. As an iterative bundle of practices, threat intelligence relies on continually improving the cycle of data collection, processing, analysis, dissemination and feedback.
Vulnerability management is the ongoing process of discovery, categorisation, prioritisation, tackling, and reporting on the security weaknesses within an IT infrastructure. Typical vulnerabilities include firewall misconfigurations and unpatched software. As digital realms are becoming more complex, vulnerability management is taking on a process-oriented cyclical approach instead of focusing on isolated events.
Extended detection and response (XDR) refers to an open architecture encompassing cybersecurity tools and operations across endpoints, users, data, applications, networks, and cloud environments. XDR is a bundled offering comprising tools and functionalities aiming to deliver end-to-end threat visibility and optimised workflows that ultimately enable teams to detect and respond to threats more efficiently and at a greater speed. XDR solutions come with the flexibility of integrating multiple third-party security offerings, unifying technologies to achieve better prevention, detection, and response.
Unified endpoint management (UEM) is software that enables security teams to consistently monitor and manage the endpoints within an organisation. UEM acts as a single source of truth that consolidates all data coming from endpoints such as servers, desktop computers, laptops, or mobile devices, irrespective of their location or operating system.