Skip to Content
Glossary Banner BG Image

Cybersecurity terms and concepts explained

Cybersecurity is becoming increasingly complex. Many organizations offer resources and information on the fundamental principles of cybersecurity, including endpoint protection, security services, and different types of cyberattacks. If you need information about these cybersecurity topics and many others, Sophos has you covered.

A

An Advanced Persistent Threat (APT) is a sophisticated, long-term cyberattack where an intruder establishes an undetected presence in a network. Instead of causing immediate disruption, the attacker focuses on stealing sensitive data continuously over an extended period. These campaigns are highly targeted and usually orchestrated by resource-rich groups, such as state-sponsored actors. Read more >>

Adware, short for advertising-supported software, is a type of application that automatically displays or downloads unwanted advertising material — such as pop-up windows, banner ads, and screen redirects — when a user is online or interacting with a program. While some adware is legitimate and consent-based, malicious variants infiltrate devices silently, tracking user behavior to serve hyper-targeted ads or hijacking web browsers to generate illicit revenue for threat actors. Read more >>

Antivirus software is designed to detect, prevent, and remove malicious software from a computer or network. It doesn't just wait for an infection; it scans files and applications to block digital threats like worms and trojans before they cause harm. This software serves as a fundamental baseline for protecting devices from digital compromise. Read more >>

Attack Surface Management (ASM) is the continuous process of discovering, analyzing, and securing all digital assets that an attacker could exploit. It provides complete visibility into an organization's entire digital footprint, including known infrastructure, hidden shadow IT, and exposed third-party vectors. This practice ensures that security teams can identify and patch vulnerabilities before adversaries find them. Read more >>

Artificial Intelligence (AI) has revolutionized the way IT security professionals address cybersecurity. Through our AI research and development of AI-powered cybersecurity tools and systems we now have the ability to enhance data protection against threats by quickly recognizing behavior patterns, automating processes, and detecting anomalies. Download our AI for cybersecurity toolkit.

B

A botnet is a network of internet-connected devices — including computers, servers, mobile hardware, and smart IoT endpoints — that have been infected with malware and placed under the remote control of a single malicious actor or cybercriminal syndicate. Each individual hijacked machine is known as a "bot" or "zombie." Working together as a distributed, automated force, botnets allow attackers to execute mass-scale campaigns that can easily overwhelm traditional system infrastructure and bypass baseline perimeter filters. Read more >>

Business Email Compromise (BEC) is a sophisticated cyberattack where criminals trick employees into transferring funds or revealing confidential information by impersonating trusted executives, colleagues, or vendors. Unlike traditional hacks, it rarely relies on malicious links or malware, using social engineering and text-based deception instead. It's one of the most financially devastating vectors facing modern organizations. Read more >>

C

Cloud security is a collection of procedures, policies, and technologies designed to protect data, applications, and virtual infrastructure hosted in cloud environments. It ensures data privacy, regulates access control, and defends systems from unauthorized external interference. This framework is essential for safeguarding digital assets across public, private, and hybrid cloud setups. Read more >>

Cyber insurance is a specialized risk management service that protects organizations from the financial and operational consequences of cyberattacks and data breaches. It doesn't prevent cybercrime from occurring, but it helps mitigate the heavy costs associated with recovery, legal fees, and business downtime. This coverage has become an essential safety net for businesses navigating today's hostile digital landscape. Read more >>

Cybercrime is any criminal activity that involves a computer, a networked device, or an interconnected digital environment. It encompasses illicit acts where technology is used as the primary tool to commit an offense, as well as campaigns where the technology infrastructure itself is the target of the attack. Today, cybercrime has evolved from isolated script exploits into a highly organized, industrialized, and multi-trillion-dollar global economy. Read more >>

Cybersecurity is the practice of protecting systems, networks, programs, and data from digital attacks. These cyberattacks are usually aimed at accessing, changing, or destroying sensitive information, extorting money from users, or interrupting normal business operations. Implementing effective cybersecurity measures is essential because everyone relies on critical digital infrastructure and connected devices. Read more >>

Cybersecurity consultants play a crucial role in safeguarding an organization's information systems by identifying potential security exposures and preparing defenses against future threats. They are instrumental in enhancing the overall security readiness of an organization through a variety of means, and they’re particularly valuable to companies with limited internal cybersecurity expertise that would like to supplement staff resources.

D

The dark web is a hidden part of the internet that is intentionally unindexed by traditional search engines and requires specialized software, configuration, or authorization to access. It forms a small subset of the deep web and utilizes encrypted overlay networks, such as Tor (The Onion Router) or I2P (Invisible Internet Project), to provide users and website operators with a high degree of anonymity. While it hosts legitimate privacy-focused communication platforms, it is widely recognized as a hub for illicit marketplaces and cybercriminal infrastructure. Read more >>

A data breach is a security incident in which sensitive, protected, or confidential data is copied, transmitted, viewed, or stolen by an individual unauthorized to do so. These incidents can impact any organization, from small businesses to global enterprises and government agencies. They involve the unauthorized exposure of personally identifiable information (PII), financial records, corporate intellectual property, or trade secrets. Read more >>

The deep web refers to the vast portion of the World Wide Web that is not indexed by traditional search engines. Unlike public websites, deep web content cannot be discovered through a simple web search because it sits behind authentication walls, paywalls, or digital security gates. It encompasses routine, legitimate digital resources including private email inboxes, online banking portals, corporate intranets, and cloud storage databases. Read more >>

A Distributed Denial of Service (DDoS) attack is a malicious attempt to disrupt the normal traffic of a targeted server, service, or network by overwhelming the target or its surrounding infrastructure with a flood of internet traffic. DDoS attacks achieve their scale by utilizing multiple compromised computer systems as sources of attack traffic. Exploited machines can include traditional computers, servers, and insecure Internet of Things (IoT) devices. Read more >>

Data loss prevention (DLP) is a cybersecurity strategy and set of technologies that identify, monitor, and protect sensitive data from unauthorized access, exposure, or theft so that confidential information stays within your organization and is used only in approved ways. DLP helps prevent data breaches and exfiltration, enforce data-handling policies, support regulatory compliance, reduce insider risk, and maintain customer confidence.

E

Email security refers to the collective strategies, technologies, and policies used to protect electronic communications from unauthorized access, data loss, or malicious exploitation. It safeguards email accounts, content, and attachments from dangerous cyber threats like malware, phishing, and spam. Read more >>

Encryption is the process of converting readable data, known as plaintext, into an unreadable, scrambled format called ciphertext using a mathematical algorithm and a cryptographic key. It serves as a fundamental pillar of data security, ensuring confidentiality by making information entirely useless to anyone who does not possess the specific decryption key required to reverse the process. Read more >>

Endpoint Detection and Response (EDR) is a cybersecurity solution that continuously monitors individual devices such as laptops, desktops, and servers to detect malicious activity. Unlike traditional security tools, EDR records behavioral data in real time, allowing security teams to investigate threats and quickly isolate compromised devices before an attack spreads across the corporate network. Read more >> 

Endpoint management focuses on managing the security posture of all connected end-user devices or endpoints within an organization's network. Endpoints are the devices that connect to a network and include desktop computers, laptops, smartphones, tablets, servers, and other devices.

F

A firewall is a network security device that monitors and filters incoming and outgoing network traffic based on an organization's previously established security rules. At its most basic, a firewall essentially functions as a barrier between a trusted internal network and an untrusted external network, such as the internet. Read more >>

Firewalls play a critical role in defending against ransomware by blocking initial access, reducing exposed services, inspecting encrypted traffic, and stopping attackers before they can move deeper into the network. As ransomware operators increasingly target perimeter vulnerabilities and encrypted channels, organizations need modern firewalls that enforce zero trust, strengthen segmentation, and support rapid detection and response. With integrated capabilities like deep TLS inspection, intrusion prevention, and coordinated threat response, firewalls help businesses limit the impact of an intrusion and maintain stronger resilience against evolving ransomware threats.

G

The General Data Protection Regulation (GDPR) is a comprehensive European Union privacy law that regulates how organizations collect, process, and store personal data. It applies to any entity worldwide that targets or collects data related to people in the EU. This framework shifts ownership of personal information back to the individual, forcing corporations to handle data with total transparency and strict security controls. Read more >>

Securing a multi-cloud environment is challenging due to the increased attack surface and lack of visibility across cloud hosts and services. This is where cloud governance enters the picture. Cloud governance is a framework of policies established by a business that will define and enforce how they create, store, and share data in the cloud and ensure regulatory compliance.

H

Hacking is the process of identifying and exploiting vulnerabilities within a computer system, network, or digital device to gain access or control over its components. At its core, hacking involves manipulating digital systems to perform actions they were not originally designed or intended to allow. While commonly associated with cybercriminals, hacking encompasses a broad spectrum of activities ranging from illegal data theft to authorized safety testing. Read more >>

A honeypot is a decoy security system designed to mimic a legitimate digital asset, such as a server, database, or network segment. It's intentionally left vulnerable to lure cybercriminals away from real, sensitive corporate data. By attracting attackers into a controlled environment, organizations can safely monitor their behavior and gather valuable threat intelligence. Read more >>

I

Identity Threat Detection and Response (ITDR) is a security framework designed to protect user credentials, directory services, and the authentication infrastructure from targeted attacks. Instead of monitoring physical laptops or parsing firewall logs, it focuses entirely on user behavior and access privileges. It operates on the realistic assumption that user accounts will eventually be compromised, working to catch intruders who are hiding behind legitimate passwords before they can cause operational chaos. Read more >>

Incident response is an organized approach that organizations use to manage the aftermath of a security breach or cyberattack. The main goal is to limit data damage, shorten recovery times, and keep containment costs down when a crisis hits. It ensures that an enterprise can handle a digital threat systematically so teams don't panic or make errors. Read more >>

Indicators of Compromise (IoC) are digital clues or artifacts left behind on a network after a cyberattack occurs. They act like forensic evidence, showing security teams that a system's been breached or infected. By identifying these pieces of data, organizations can recognize active threats and start repairing the damage before it gets worse. Read more >>

An Intrusion Detection System (IDS) is a security application that monitors network traffic or device activity for suspicious behavior and known policy violations. It acts like a digital security camera, constantly watching data packets to flag potential threats. When it spots an anomaly, it immediately logs the event and alerts your administrative team so they can investigate further. Read more >>

iOS Mobile Security is a mobile device management tactic that protects Apple's iPhone Operating System (iOS)-powered devices, such as iPhones and iPads, from various security threats and vulnerabilities.

J

JSON Web Token > JSON is an abbreviation for JavaScript Object Notation, a standard text-based format for storing and transporting data. A JSON Web Token, or JWT, is an open industry standard for sharing information between entities, such as clients and servers. JSON Web Tokens are both powerful and versatile, serving as a bridge between software application functionality and data security.

K

Kali Linux is an open-source, Debian-based Linux distribution specifically engineered for advanced penetration testing, ethical hacking, and network security auditing. Developed and maintained by Offensive Security (OffSec), it serves as a specialized operating system pre-loaded with hundreds of industry-standard security tools. It provides a stable, unified platform for security researchers, digital forensics experts, and defensive teams to evaluate infrastructure resilience. Read more >>

A keylogger is a type of surveillance software or hardware designed to record every keystroke made on a computer or mobile device. This activity occurs covertly, capturing everything from personal messages and search queries to sensitive login credentials and financial details. The recorded data is then sent back to an unauthorized third party without the user's knowledge. Read more >>

L

M

Malware, short for malicious software, is an umbrella term for any code or program intentionally developed to infect, disrupt, damage, or gain unauthorized access to a computer system, network, or device. It includes a vast array of digital threats ranging from covert background spyware to destructive file-locking tools. Read more >>

Managed Detection and Response (MDR) is a cybersecurity service that combines advanced technology with human expertise to monitor an organization's network around the clock. Instead of just sending alerts, MDR provider teams actively hunt for, investigate, and neutralize cyber threats before they cause damage. This service provides businesses with a dedicated, external security operations team to defend against modern attacks. Read more >>

Multi-Factor Authentication (MFA) is an advanced identity verification framework that requires users to provide two or more independent credentials before gaining access to an application, server, or digital network. By layering multiple validation checkpoints, MFA ensures that compromising a single password is not enough for an attacker to breach an account. It represents a foundational element of Zero Trust security architectures, shifting verification from static credentials to continuous, context-aware identity validation. Read more >>

The MITRE Adversarial Tactics, Techniques, and Common Knowledge or MITRE ATT&CK framework was designed for a simple reason: to solve problems for a safer world. This framework is available for free to anyone that wants to level up their cybersecurity. Your organization can use the MITRE ATT&CK framework to understand how cybercriminals operate. From here, you can prepare for cyberattacks and limit your risk of data breaches.

N

P

A password manager is a software application designed to securely store, generate, and manage digital credentials, personal identification numbers (PINs), and sensitive notes. Operating as an encrypted digital vault, it eliminates the need for users to memorize dozens of complex passwords. Instead, users only need to remember a single, strong master password to unlock their entire credential repository, which then automatically fills in login screens across websites and applications. Read more >>

Phishing is a type of cyberattack where attackers send fraudulent messages designed to trick people into revealing sensitive information or downloading malicious software. These deceptive communications often impersonate trusted organizations like banks, utilities, or work colleagues. It's one of the most common and dangerous methods threat actors use to compromise security defenses. Read more >>

R

Ransomware is a malicious software strain that locks a victim out of their digital files, databases, or entire operating systems, demanding a financial payment to restore access. Modern attacks have evolved past simple data encryption; threat actors now systematically steal proprietary records first, threatening public leaks or direct client harassment to maximize financial leverage. Read more >>

S

Secure Access Service Edge (SASE) is a cloud-based security framework that merges network connectivity with comprehensive cybersecurity functions. Instead of routing traffic through a physical data center to secure it, SASE delivers protection directly to the user or device at the edge of the network. This approach allows organizations to secure remote workers and cloud applications seamlessly. Read more >>

Security Information and Event Management (SIEM) is a security solution that helps organizations recognize potential threats and vulnerabilities before they disrupt business operations. It acts as a centralized platform, gathering and analyzing log data from an entire digital infrastructure in real time. This technology gives security teams a comprehensive view of activities across their network to simplify threat detection and compliance monitoring. Read more >>

Spear phishing is a highly targeted cyberattack where scammers send customized messages to a specific individual or organization. Instead of blasting thousands of random emails, attackers research their victims to make the deception look entirely authentic. It's a calculated effort to trick you into handing over passwords, financial data, or corporate secrets. Read more >>

Spyware is a type of malicious software designed to infiltrate a computer system or device, monitor user activity, and gather sensitive information without the user's knowledge or consent. Operating entirely in the background, it acts as a digital surveillance tool. It records everything from keystrokes and login credentials to personal files and browsing habits, transmitting this stolen data back to a remote threat actor. Read more >>

In the field of modern software and application development, a Software Development Kit (SDK) represents a comprehensive tool or utility that helps programmers and developers with a variety of resources to write software programs and build custom applications. SDKs are widely used in the cybersecurity industry too. Anti-malware, Anti-spam, Email Filtering and Data Loss Prevention (DLP) are some commonly used SDKs by various security vendors.

T

Threat hunting is a proactive cybersecurity practice where security analysts actively search through networks and systems to detect hidden threats that have bypassed automated security tools. Instead of waiting for an alert to trigger, hunters assume an attacker is already inside the environment. This method uncovers stealthy malicious activity before it's able to cause widespread operational damage. Read more >>

Threat intelligence is the organized collection and analysis of data regarding cybercriminals, their motives, and their tactical methods. Instead of just reacting to random network anomalies, this information allows security teams to understand exactly who's targeting them and how an attack will likely unfold. It transforms raw security data into predictive, actionable guidance to ensure intruders won't catch you off guard. Read more >>

A Trojan horse, or simply a Trojan, is a type of malicious software that masquerades as a legitimate, safe program to trick users into executing it. Named after the famous ancient Greek stratagem, its primary technique is deception rather than forced infiltration. Once a user runs the software, it secretly activates its payload to steal data, download secondary malware, or grant attackers administrative control over the host device. Read more >>

Two-Factor Authentication (2FA) is an identity management security process that requires users to provide two distinct forms of identification before gaining access to an account, application, or digital resource. Instead of relying solely on a traditional password, 2FA introduces an additional layer of verification. This defense-in-depth strategy ensures that even if an attacker manages to compromise a user's password, they cannot access the account without also possessing the secondary authentication factor. Read more >>

Telemetry refers to the collection, transmission, and measurement of data. It involves the use of sensors to retrieve information from remote sources. The telemetry you collect gives you insights that you can use to effectively administer and manage your IT infrastructure.

V

A Virtual Private Network (VPN) is a service that creates a secure, encrypted connection between a user's device and the internet. By routing web traffic through an isolated digital tunnel, it hides the user's actual IP address and protects their data from unauthorized interception. This ensures privacy and data security when accessing corporate networks or utilizing public internet connections. Read more >>

A computer virus is a type of malicious software (malware) that propagates by attaching its code to a legitimate host file, document, or application program. Mirroring its biological namesake, a computer virus cannot execute or replicate independently; it relies entirely on human action — such as opening an email attachment or launching a downloaded installer — to trigger its execution and infect other system files. Read more >>

Vulnerability management is a continuous cybersecurity process that identifies, evaluates, and fixes security weaknesses in an organization's software and hardware. Instead of treating security as a one-time setup, it's a permanent inspection routine that discovers flaws before hackers can exploit them. This practice helps businesses keep their digital infrastructure secure against constantly evolving software threats. Read more >>

W

From data storage and databases to virtual servers, containers, and networking software, cloud workloads are an essential technology to create, collaborate, solve problems, and get work done from anywhere.

Sophos Workspace Protection is a browser — and workspace-centric security approach that protects users, apps, and data wherever work happens — reducing complexity while improving visibility and control for hybrid organizations.

Wireshark is an open-source, industry-standard network packet analyzer used to capture, inspect, and dissect digital traffic running across a computer network in real time. It acts like a digital microscope for network administrators and security analysts, translating raw binary data streams moving through network interfaces into a highly readable, structured format. This tool is fundamental for network troubleshooting, protocol software development, and deep-dive cybersecurity forensics. Read more >>

X

Z

Zero Trust Security is a modern cybersecurity framework built on a simple premise: never trust, always verify. It removes the old assumption that users and devices inside an organization's network perimeter are automatically safe. Instead, this model requires continuous authentication, authorization, and validation for every single connection attempt before granting access to corporate data and applications. Read more >>