Skip to Content
Glossary Banner BG Image

Cybersecurity terms and concepts explained

Cybersecurity is becoming increasingly complex. Many organizations offer resources and information on the fundamental principles of cybersecurity, including endpoint protection, security services, and different types of cyberattacks. If you need information about these cybersecurity topics and many others, Sophos has you covered.

A

An Advanced Persistent Threat (APT) is a sophisticated, long-term cyberattack where an intruder establishes an undetected presence in a network. Instead of causing immediate disruption, the attacker focuses on stealing sensitive data continuously over an extended period. These campaigns are highly targeted and usually orchestrated by resource-rich groups, such as state-sponsored actors. Read more >>

Antivirus software is designed to detect, prevent, and remove malicious software from a computer or network. It doesn't just wait for an infection; it scans files and applications to block digital threats like worms and trojans before they cause harm. This software serves as a fundamental baseline for protecting devices from digital compromise. Read more >>

Artificial Intelligence (AI) has revolutionized the way IT security professionals address cybersecurity. Through our AI research and development of AI-powered cybersecurity tools and systems we now have the ability to enhance data protection against threats by quickly recognizing behavior patterns, automating processes, and detecting anomalies. Download our AI for cybersecurity toolkit.

B

Business Email Compromise (BEC) is a sophisticated cyberattack where criminals trick employees into transferring funds or revealing confidential information by impersonating trusted executives, colleagues, or vendors. Unlike traditional hacks, it rarely relies on malicious links or malware, using social engineering and text-based deception instead. It's one of the most financially devastating vectors facing modern organizations. Read more >>

C

D

Data loss prevention (DLP) is a cybersecurity strategy and set of technologies that identify, monitor, and protect sensitive data from unauthorized access, exposure, or theft so that confidential information stays within your organization and is used only in approved ways. DLP helps prevent data breaches and exfiltration, enforce data-handling policies, support regulatory compliance, reduce insider risk, and maintain customer confidence.

E

Endpoint Detection and Response (EDR) is a cybersecurity solution that continuously monitors individual devices such as laptops, desktops, and servers to detect malicious activity. Unlike traditional security tools, EDR records behavioral data in real time, allowing security teams to investigate threats and quickly isolate compromised devices before an attack spreads across the corporate network. Read more >> 

Endpoint management focuses on managing the security posture of all connected end-user devices or endpoints within an organization's network. Endpoints are the devices that connect to a network and include desktop computers, laptops, smartphones, tablets, servers, and other devices.

I

iOS Mobile Security is a mobile device management tactic that protects Apple's iPhone Operating System (iOS)-powered devices, such as iPhones and iPads, from various security threats and vulnerabilities.

K

A keylogger is a type of surveillance software or hardware designed to record every keystroke made on a computer or mobile device. This activity occurs covertly, capturing everything from personal messages and search queries to sensitive login credentials and financial details. The recorded data is then sent back to an unauthorized third party without the user's knowledge. Read more >>

M

The MITRE Adversarial Tactics, Techniques, and Common Knowledge or MITRE ATT&CK framework was designed for a simple reason: to solve problems for a safer world. This framework is available for free to anyone that wants to level up their cybersecurity. Your organization can use the MITRE ATT&CK framework to understand how cybercriminals operate. From here, you can prepare for cyberattacks and limit your risk of data breaches.

N

P

Phishing is a type of cyberattack where attackers send fraudulent messages designed to trick people into revealing sensitive information or downloading malicious software. These deceptive communications often impersonate trusted organizations like banks, utilities, or work colleagues. It's one of the most common and dangerous methods threat actors use to compromise security defenses. Read more >>

R

S

Spear phishing is a highly targeted cyberattack where scammers send customized messages to a specific individual or organization. Instead of blasting thousands of random emails, attackers research their victims to make the deception look entirely authentic. It's a calculated effort to trick you into handing over passwords, financial data, or corporate secrets. Read more >>

T

Threat hunting is a proactive cybersecurity practice where security analysts actively search through networks and systems to detect hidden threats that have bypassed automated security tools. Instead of waiting for an alert to trigger, hunters assume an attacker is already inside the environment. This method uncovers stealthy malicious activity before it's able to cause widespread operational damage. Read more >>

V

A Virtual Private Network (VPN) is a service that creates a secure, encrypted connection between a user's device and the internet. By routing web traffic through an isolated digital tunnel, it hides the user's actual IP address and protects their data from unauthorized interception. This ensures privacy and data security when accessing corporate networks or utilizing public internet connections. Read more >>

X

Z

Zero Trust Security is a modern cybersecurity framework built on a simple premise: never trust, always verify. It removes the old assumption that users and devices inside an organization's network perimeter are automatically safe. Instead, this model requires continuous authentication, authorization, and validation for every single connection attempt before granting access to corporate data and applications. Read more >>