An Advanced Persistent Threat (APT) is a sophisticated, long-term cyberattack where an intruder establishes an undetected presence in a network. Instead of causing immediate disruption, the attacker focuses on stealing sensitive data continuously over an extended period. These campaigns are highly targeted and usually orchestrated by resource-rich groups, such as state-sponsored actors. Read more >>

Cybersecurity terms and concepts explained
Cybersecurity is becoming increasingly complex. Many organizations offer resources and information on the fundamental principles of cybersecurity, including endpoint protection, security services, and different types of cyberattacks. If you need information about these cybersecurity topics and many others, Sophos has you covered.
A
Antivirus software is designed to detect, prevent, and remove malicious software from a computer or network. It doesn't just wait for an infection; it scans files and applications to block digital threats like worms and trojans before they cause harm. This software serves as a fundamental baseline for protecting devices from digital compromise. Read more >>
Artificial Intelligence (AI) has revolutionized the way IT security professionals address cybersecurity. Through our AI research and development of AI-powered cybersecurity tools and systems we now have the ability to enhance data protection against threats by quickly recognizing behavior patterns, automating processes, and detecting anomalies. Download our AI for cybersecurity toolkit.
B
Business Email Compromise (BEC) is a sophisticated cyberattack where criminals trick employees into transferring funds or revealing confidential information by impersonating trusted executives, colleagues, or vendors. Unlike traditional hacks, it rarely relies on malicious links or malware, using social engineering and text-based deception instead. It's one of the most financially devastating vectors facing modern organizations. Read more >>
C
The outsourced model of cybersecurity-as-a-service means that, rather than handling it internally, organizations work with a third-party partner with the expertise and resources to continuously monitor their security posture.
D
Data loss prevention (DLP) is a cybersecurity strategy and set of technologies that identify, monitor, and protect sensitive data from unauthorized access, exposure, or theft so that confidential information stays within your organization and is used only in approved ways. DLP helps prevent data breaches and exfiltration, enforce data-handling policies, support regulatory compliance, reduce insider risk, and maintain customer confidence.
E
Endpoint Detection and Response (EDR) is a cybersecurity solution that continuously monitors individual devices such as laptops, desktops, and servers to detect malicious activity. Unlike traditional security tools, EDR records behavioral data in real time, allowing security teams to investigate threats and quickly isolate compromised devices before an attack spreads across the corporate network. Read more >>
Endpoint security is the practice of safeguarding the devices that connect to a corporate network, such as laptops, smartphones, and servers. By blocking malicious threats at the device level, it ensures these entry points don't become gateways for cyberattacks. Read more >>
Endpoint management focuses on managing the security posture of all connected end-user devices or endpoints within an organization's network. Endpoints are the devices that connect to a network and include desktop computers, laptops, smartphones, tablets, servers, and other devices.
If not properly protected, your company’s endpoints—laptops, tablets, mobile devices, and more—become vulnerable, regardless of where employees are located. Learn best practices and strategies to secure your remote workforce.
I
iOS Mobile Security is a mobile device management tactic that protects Apple's iPhone Operating System (iOS)-powered devices, such as iPhones and iPads, from various security threats and vulnerabilities.
K
A keylogger is a type of surveillance software or hardware designed to record every keystroke made on a computer or mobile device. This activity occurs covertly, capturing everything from personal messages and search queries to sensitive login credentials and financial details. The recorded data is then sent back to an unauthorized third party without the user's knowledge. Read more >>
M
Mobile device management (MDM) is security software that lets your business implement policies to secure, monitor, and manage your end-user mobile devices. The software also protects your network devices and allows your employees to work remotely without compromising their security.
The MITRE Adversarial Tactics, Techniques, and Common Knowledge or MITRE ATT&CK framework was designed for a simple reason: to solve problems for a safer world. This framework is available for free to anyone that wants to level up their cybersecurity. Your organization can use the MITRE ATT&CK framework to understand how cybercriminals operate. From here, you can prepare for cyberattacks and limit your risk of data breaches.
N
Next-generation antivirus (NGAV) solutions protect your business against known and unknown cyberthreats. The solution looks at your files, processes, applications, and network connections and the relationships between them. This helps you identify malicious intent, behaviors, and activities — and block them.
In response to the increased threat of cyberattacks and the associated need to increase defences, the Council of the European Union (EU) and the European Parliament adopted the Network and Information Security 2.0 Directive (NIS2) in December 2022.
P
Phishing is a type of cyberattack where attackers send fraudulent messages designed to trick people into revealing sensitive information or downloading malicious software. These deceptive communications often impersonate trusted organizations like banks, utilities, or work colleagues. It's one of the most common and dangerous methods threat actors use to compromise security defenses. Read more >>
R
There is no stopping ransomware attacks. However, businesses can use tried-and-true ransomware mitigation technologies and techniques to address these attacks before they get out of hand.
Remote ransomware is when adversaries compromise an unmanaged device and then use it to remotely encrypt protected devices on the same network. Most other endpoint solutions fall short in this scenario - meaning a single unmanaged/unprotected device can result in the entire estate being encrypted, even if the computers are running up-to-date protection.
Organizations of all sizes need to be aware of Ransomware-as-a-Service (RaaS). Due to the RaaS delivery model, and it’s a quickly growing threat to your data and systems because criminals with virtually no technical knowledge can execute a ransomware attack easily for a significant profit.
S
Spear phishing is a highly targeted cyberattack where scammers send customized messages to a specific individual or organization. Instead of blasting thousands of random emails, attackers research their victims to make the deception look entirely authentic. It's a calculated effort to trick you into handing over passwords, financial data, or corporate secrets. Read more >>
The server hardening process reduces your business' attack surface and helps you guard against ransomware, malware, and other cyberthreats. You can follow this process to protect all points of entry against cyberattacks, address cybersecurity weaknesses, and optimize your security posture.
Security as a service (SECaaS) is a form of outsourced security. With SECaaS, you receive cybersecurity services delivered through the cloud.
Sophos provides global cybersecurity solutions that defend organizations of all sizes against the latest cyberthreats. Among its many offerings are managed security as a service and endpoint, antivirus, firewall, and advanced threat prevention products.
T
Threat hunting is a proactive cybersecurity practice where security analysts actively search through networks and systems to detect hidden threats that have bypassed automated security tools. Instead of waiting for an alert to trigger, hunters assume an attacker is already inside the environment. This method uncovers stealthy malicious activity before it's able to cause widespread operational damage. Read more >>
V
A Virtual Private Network (VPN) is a service that creates a secure, encrypted connection between a user's device and the internet. By routing web traffic through an isolated digital tunnel, it hides the user's actual IP address and protects their data from unauthorized interception. This ensures privacy and data security when accessing corporate networks or utilizing public internet connections. Read more >>
X
Extended Detection and Response (XDR) is a cybersecurity approach that automatically collects and correlates security data from multiple sources. By looking beyond just endpoints, it integrates telemetry from emails, servers, cloud workloads, and networks into a single console. Read more >>
Z
Zero Trust Security is a modern cybersecurity framework built on a simple premise: never trust, always verify. It removes the old assumption that users and devices inside an organization's network perimeter are automatically safe. Instead, this model requires continuous authentication, authorization, and validation for every single connection attempt before granting access to corporate data and applications. Read more >>


