Attack Surface Management (ASM) is the continuous process of discovering, analyzing, and securing all digital assets that an attacker could exploit. It provides complete visibility into an organization's entire digital footprint, including known infrastructure, hidden shadow IT, and exposed third-party vectors. This practice ensures that security teams can identify and patch vulnerabilities before adversaries find them. Read more >>

Cybersecurity terms and concepts explained
Cybersecurity is becoming increasingly complex. Many organizations offer resources and information on the fundamental principles of cybersecurity, including endpoint protection, security services, and different types of cyberattacks. If you need information about these cybersecurity topics and many others, Sophos has you covered.
A
A holistic cybersecurity strategy to protect Active Directory (AD), a Microsoft Windows directory service. Active Directory Security focuses on securing user credentials, access to company systems, sensitive data, software applications, and more from unauthorized access.
Artificial Intelligence (AI) has revolutionized the way IT security professionals address cybersecurity. Through our AI research and development of AI-powered cybersecurity tools and systems we now have the ability to enhance data protection against threats by quickly recognizing behavior patterns, automating processes, and detecting anomalies. Download our AI for cybersecurity toolkit.
B
Business Email Compromise (BEC) is a sophisticated cyberattack where criminals trick employees into transferring funds or revealing confidential information by impersonating trusted executives, colleagues, or vendors. Unlike traditional hacks, it rarely relies on malicious links or malware, using social engineering and text-based deception instead. It's one of the most financially devastating vectors facing modern organizations. Read more >>
C
Cyber insurance is a specialized risk management service that protects organizations from the financial and operational consequences of cyberattacks and data breaches. It doesn't prevent cybercrime from occurring, but it helps mitigate the heavy costs associated with recovery, legal fees, and business downtime. This coverage has become an essential safety net for businesses navigating today's hostile digital landscape. Read more >>
D
A data breach is a security incident in which sensitive, protected, or confidential data is copied, transmitted, viewed, or stolen by an individual unauthorized to do so. These incidents can impact any organization, from small businesses to global enterprises and government agencies. They involve the unauthorized exposure of personally identifiable information (PII), financial records, corporate intellectual property, or trade secrets. Read more >>
Data loss prevention (DLP) is a cybersecurity strategy and set of technologies that identify, monitor, and protect sensitive data from unauthorized access, exposure, or theft so that confidential information stays within your organization and is used only in approved ways. DLP helps prevent data breaches and exfiltration, enforce data-handling policies, support regulatory compliance, reduce insider risk, and maintain customer confidence.
Discover DNS security's role in protecting networks from cyberthreats. Learn about DNS encryption, filtering, and securing DNS requests.
E
Endpoint security is the practice of safeguarding the devices that connect to a corporate network, such as laptops, smartphones, and servers. By blocking malicious threats at the device level, it ensures these entry points don't become gateways for cyberattacks. Read more >>
If not properly protected, your company’s endpoints—laptops, tablets, mobile devices, and more—become vulnerable, regardless of where employees are located. Learn best practices and strategies to secure your remote workforce.
I
Incident response is an organized approach that organizations use to manage the aftermath of a security breach or cyberattack. The main goal is to limit data damage, shorten recovery times, and keep containment costs down when a crisis hits. It ensures that an enterprise can handle a digital threat systematically so teams don't panic or make errors. Read more >>
M
The MITRE Adversarial Tactics, Techniques, and Common Knowledge or MITRE ATT&CK framework was designed for a simple reason: to solve problems for a safer world. This framework is available for free to anyone that wants to level up their cybersecurity. Your organization can use the MITRE ATT&CK framework to understand how cybercriminals operate. From here, you can prepare for cyberattacks and limit your risk of data breaches.
N
Network security includes any solutions that your organization utilizes to protect its network applications, devices, and users. Network security as a service gives organizations the option to outsource their data protection to a team of IT security professionals.
Next-generation antivirus (NGAV) solutions protect your business against known and unknown cyberthreats. The solution looks at your files, processes, applications, and network connections and the relationships between them. This helps you identify malicious intent, behaviors, and activities — and block them.
In response to the increased threat of cyberattacks and the associated need to increase defences, the Council of the European Union (EU) and the European Parliament adopted the Network and Information Security 2.0 Directive (NIS2) in December 2022.
P
Phishing is a type of cyberattack where attackers send fraudulent messages designed to trick people into revealing sensitive information or downloading malicious software. These deceptive communications often impersonate trusted organizations like banks, utilities, or work colleagues. It's one of the most common and dangerous methods threat actors use to compromise security defenses. Read more >>
R
There is no stopping ransomware attacks. However, businesses can use tried-and-true ransomware mitigation technologies and techniques to address these attacks before they get out of hand.
Remote ransomware is when adversaries compromise an unmanaged device and then use it to remotely encrypt protected devices on the same network. Most other endpoint solutions fall short in this scenario - meaning a single unmanaged/unprotected device can result in the entire estate being encrypted, even if the computers are running up-to-date protection.
Organizations of all sizes need to be aware of Ransomware-as-a-Service (RaaS). Due to the RaaS delivery model, and it’s a quickly growing threat to your data and systems because criminals with virtually no technical knowledge can execute a ransomware attack easily for a significant profit.
S
Spear phishing is a highly targeted cyberattack where scammers send customized messages to a specific individual or organization. Instead of blasting thousands of random emails, attackers research their victims to make the deception look entirely authentic. It's a calculated effort to trick you into handing over passwords, financial data, or corporate secrets. Read more >>
Sophos provides global cybersecurity solutions that defend organizations of all sizes against the latest cyberthreats. Among its many offerings are managed security as a service and endpoint, antivirus, firewall, and advanced threat prevention products.
Supervisory control and data acquisition (SCADA) refers to a system commonly used by natural gas companies and other utility providers.
T
Threat hunting is a proactive cybersecurity practice where security analysts actively search through networks and systems to detect hidden threats that have bypassed automated security tools. Instead of waiting for an alert to trigger, hunters assume an attacker is already inside the environment. This method uncovers stealthy malicious activity before it's able to cause widespread operational damage. Read more >>


