Cybersecurity Glossary
Understanding the terminology of cybersecurity and IT management
Advanced Threat Protection
Comprehensive security measures that detect, prevent, and respond to sophisticated cyber threats using multiple layers of defense.
Anti-Phishing
Technology and training that protects against fraudulent emails designed to steal passwords, financial information, or install malware.
BCDR (Business Continuity & Disaster Recovery)
Comprehensive plan and technology that ensures business operations can continue during and after a disaster, including data backup and system failover.
BEC (Business Email Compromise)
Sophisticated scam where criminals impersonate executives or vendors via email to trick employees into transferring money or sensitive data.
CDR (Cloud Detection & Response)
Monitoring and threat detection for cloud services and SaaS applications such as Microsoft 365 and Google Workspace, flagging and responding to suspicious sign-ins, mailbox rules and data access.
Co-Managed IT
Collaborative IT support model where external providers work alongside internal IT teams using shared tools and processes.
CVSS Score
Common Vulnerability Scoring System - a standardized way to rate the severity of security vulnerabilities from 0 (none) to 10 (critical).
Cyber Risk Assessment
Systematic evaluation of an organization's security vulnerabilities, threats, and potential business impact to prioritize security investments.
Dark Web Monitoring
Service that scans hidden parts of the internet where stolen data is often sold to alert you if your credentials have been compromised.
DMARC (Domain-based Message Authentication, Reporting & Conformance)
An email authentication standard that tells receiving mail servers what to do with messages that fail SPF or DKIM checks for your domain, which stops attackers sending email that appears to come from you.
Documentation
Comprehensive record-keeping of all IT infrastructure, configurations, passwords, and procedures stored in a secure, searchable platform for easy access and management.
EDR (Endpoint Detection & Response)
Security technology that monitors endpoint devices for suspicious activities and provides tools to investigate and respond to threats in real-time.
Endpoint
Any device that connects to your network including desktops, laptops, servers, mobile devices, and IoT devices that can be entry points for cyber threats.
Endpoint Backup
Automated backup solution that protects data on individual devices like laptops and desktops, typically storing copies in the cloud.
Fractional CTO
Part-time chief technology officer service that provides strategic IT leadership and planning for businesses that do not need a full-time executive.
Full NOC Coverage
Complete 24/7 Network Operations Center monitoring and management of all network infrastructure, servers, and critical systems with proactive issue resolution.
GRC (Governance, Risk & Compliance)
A framework that helps organizations align IT with business objectives while managing risk and meeting compliance requirements.
ISC2 (International Information System Security Certification Consortium)
Global nonprofit organization that provides cybersecurity education, certification, and professional development for security professionals.
IT Automation
The use of software to create repeatable instructions and processes to replace or reduce human interaction with IT systems, improving efficiency and reducing errors.
MDR (Managed Detection & Response)
A service that combines detection software with human analysts who monitor, investigate and respond to threats around the clock. Many small businesses get MDR through a provider that partners with a dedicated security operations center.
MFA (Multi-Factor Authentication)
A sign-in method that requires two or more proofs of identity, such as a password plus an authenticator app prompt. It blocks most attacks that rely on stolen passwords.
Microsoft 365 Hardening
Process of configuring Microsoft 365 security settings according to best practices to minimize attack surface and maximize protection.
NGAV (Next-Generation Antivirus)
AI-powered antivirus that goes beyond signatures to detect and prevent known and unknown malware using behavioral analysis and machine learning.
NOC (Network Operations Center)
A centralized location where IT technicians directly support the efforts of remote monitoring and management of network infrastructure.
Phishing
A fraudulent email, text or call that impersonates a trusted person or company to trick someone into revealing credentials, opening malware or sending money.
Phishing Simulation
Controlled fake phishing attacks sent to employees to test their security awareness and provide immediate training when they fail.
PSA (Professional Services Automation)
Software suite that helps manage projects, time tracking, billing, and service delivery for IT service providers and MSPs.
Ransomware
Malicious software that encrypts files or systems and demands payment for the decryption key.
Ransomware Detection & Rollback
Security capability that identifies ransomware attacks in real-time and can restore encrypted files to their pre-attack state without paying ransom.
RMM (Remote Monitoring & Management)
Software platform that allows IT service providers to remotely monitor, manage, and maintain endpoints, networks, and computers from a centralized console.
SaaS Backup
Third-party backup solution for cloud applications like Microsoft 365 and Google Workspace, protecting against accidental deletion and ransomware.
Security Awareness Training
Educational program that teaches employees to recognize and avoid cyber threats like phishing, social engineering, and unsafe browsing.
SOC (Security Operations Center)
24/7 facility where security experts monitor, detect, analyze, and respond to cybersecurity incidents using technology, processes, and expertise.
Third-Party Patch Management
Automated system that keeps non-Microsoft software (like Adobe, Java, Chrome) updated with the latest security patches to prevent vulnerabilities.
Zero-Day Vulnerability
A security flaw unknown to the software vendor that hackers can exploit before a patch is available, making it extremely dangerous.
Don't See a Term?
Have a cybersecurity or IT term you'd like us to explain? We're happy to help clarify any technology concepts.
Ask About a TermSee These Terms in Action
Security Services
EDR, partner-delivered 24/7 MDR, endpoint protection, and data security.
View ServicesIndustry Expertise
HIPAA compliance, PCI-DSS, and industry-specific security for healthcare, legal, and accounting.
See IndustriesLearn More
Deep-dive articles on ransomware, phishing, endpoint security, and more.
Read Blog