Knowledge · Glossary

The terms,
in plain language.

Over sixty of the security and regulatory terms that come up — defined clearly, without the jargon.

Glossary

ACN
Agenzia per la Cybersicurezza Nazionale — Italy's national cybersecurity authority.
Advanced Persistent Threat (APT)
A stealthy, well-resourced adversary that maintains long-term access to a target.
Assessment
A structured review of security posture, gaps and priorities against a defined standard.
Attack surface
The sum of all points where an attacker could try to enter a system or extract data.
Authentication
Verifying that a user or system is who it claims to be.
Backup
A separate copy of data that can be restored after loss, corruption or ransomware.
Botnet
A network of compromised devices controlled remotely by an attacker.
Business Email Compromise (BEC)
Fraud that impersonates executives or partners to redirect payments or data.
CISO
Chief Information Security Officer — the executive accountable for security.
Cloud security
Protecting data, applications and infrastructure hosted in cloud services.
CRA
Cyber Resilience Act — EU regulation setting security requirements for products with digital elements.
CSIRT
Computer Security Incident Response Team — coordinates response to incidents.
CVE
Common Vulnerabilities and Exposures — a public identifier for a known vulnerability.
CVSS
Common Vulnerability Scoring System — a standard severity score for vulnerabilities.
Data breach
Unauthorised access to, or disclosure of, protected data.
Data protection
Safeguarding personal data in line with the law and good practice.
DDoS
Distributed Denial of Service — flooding a service with traffic to take it offline.
Deepfake
Synthetic audio, image or video generated by AI to imitate a real person.
Digital forensics
Sound acquisition, preservation and analysis of digital evidence to a legal standard.
DORA
Digital Operational Resilience Act — EU regulation on ICT risk for the financial sector.
Due diligence
Investigation of a target's risk and liabilities before a transaction.
Encryption
Encoding data so that only authorised parties can read it.
Endpoint security
Protecting laptops, phones and servers — the devices attackers target first.
Expert witness
An independent specialist who provides technical opinion and testimony in legal proceedings.
Firewall
A control that filters network traffic based on defined rules.
GDPR
General Data Protection Regulation — the EU's data-protection law.
Governance
The structures and accountability through which security is directed and overseen.
Hardening
Reducing a system's attack surface by removing weaknesses and tightening configuration.
Identity & Access Management (IAM)
Controlling who can access what, and under which conditions.
Incident response
The disciplined process of preparing for, containing and recovering from a security incident.
ISO/IEC 27001
The international standard for information security management systems (ISMS).
Malware
Malicious software designed to damage, disrupt or gain unauthorised access.
Managed Detection & Response (MDR)
Outsourced monitoring, detection and response to threats.
MFA
Multi-factor authentication — verifying identity with more than one independent factor.
MITRE ATT&CK
A knowledge base of real-world attacker tactics and techniques.
NIS2
The EU directive raising cybersecurity requirements for essential and important entities.
NIST CSF
The NIST Cybersecurity Framework — a widely used model for managing cyber risk.
OSINT
Open-Source Intelligence — information gathered from publicly available sources.
OT security
Securing operational technology that runs industrial and physical processes.
Patch management
Keeping software up to date to close known vulnerabilities.
Penetration testing
Authorised, simulated attack to identify weaknesses before adversaries do.
Phishing
Deceptive messages that trick people into revealing credentials or installing malware.
Post-quantum cryptography (PQC)
Encryption designed to resist attacks from future quantum computers.
Ransomware
Malware that encrypts data and demands payment to restore access.
Red team
A group that simulates a real adversary to test defences end to end.
Retainer
An ongoing engagement, billed monthly, that guarantees availability and continuity.
Risk assessment
Identifying, analysing and prioritising risks to inform decisions.
SBOM
Software Bill of Materials — an inventory of the components inside a piece of software.
SIEM
Security Information and Event Management — centralised logging, correlation and alerting.
SOAR
Security Orchestration, Automation and Response — automating security operations.
SOC
Security Operations Centre — the team and tooling that monitor and respond to threats.
Social engineering
Manipulating people, rather than technology, to breach security.
Supply chain security
Managing the risk introduced by third parties, vendors and their software.
Third-party risk
The exposure created by suppliers, partners and service providers.
Threat intelligence
Actionable knowledge about adversaries, their tools and their targets.
Threat modelling
Systematically identifying how a system could be attacked, to prioritise defences.
Two-factor authentication (2FA)
A form of MFA that uses exactly two independent factors.
vCISO
A fractional, CISO-grade security leader engaged on a retainer rather than as a full-time hire.
VPN
Virtual Private Network — an encrypted tunnel for secure remote connectivity.
Vulnerability
A weakness that could be exploited to compromise a system.
Zero Trust
A security model that never assumes trust and verifies every request explicitly.
Zero-day
A vulnerability exploited before a fix is available.