Skip to Content
Glossary Banner BG Image

Cybersecurity terms and concepts explained

Cybersecurity is becoming increasingly complex. Many organizations offer resources and information on the fundamental principles of cybersecurity, including endpoint protection, security services, and different types of cyberattacks. If you need information about these cybersecurity topics and many others, Sophos has you covered.

C

Cybersecurity consultants play a crucial role in safeguarding an organization's information systems by identifying potential security exposures and preparing defenses against future threats. They are instrumental in enhancing the overall security readiness of an organization through a variety of means, and they’re particularly valuable to companies with limited internal cybersecurity expertise that would like to supplement staff resources.

E

Endpoint Detection and Response (EDR) is a cybersecurity solution that continuously monitors individual devices such as laptops, desktops, and servers to detect malicious activity. Unlike traditional security tools, EDR records behavioral data in real time, allowing security teams to investigate threats and quickly isolate compromised devices before an attack spreads across the corporate network. Read more >> 

I

Incident response is an organized approach that organizations use to manage the aftermath of a security breach or cyberattack. The main goal is to limit data damage, shorten recovery times, and keep containment costs down when a crisis hits. It ensures that an enterprise can handle a digital threat systematically so teams don't panic or make errors. Read more >>

M

Managed Detection and Response (MDR) is a cybersecurity service that combines advanced technology with human expertise to monitor an organization's network around the clock. Instead of just sending alerts, MDR provider teams actively hunt for, investigate, and neutralize cyber threats before they cause damage. This service provides businesses with a dedicated, external security operations team to defend against modern attacks. Read more >>

N

R

S

Security Information and Event Management (SIEM) is a security solution that helps organizations recognize potential threats and vulnerabilities before they disrupt business operations. It acts as a centralized platform, gathering and analyzing log data from an entire digital infrastructure in real time. This technology gives security teams a comprehensive view of activities across their network to simplify threat detection and compliance monitoring. Read more >>

T

Threat hunting is a proactive cybersecurity practice where security analysts actively search through networks and systems to detect hidden threats that have bypassed automated security tools. Instead of waiting for an alert to trigger, hunters assume an attacker is already inside the environment. This method uncovers stealthy malicious activity before it's able to cause widespread operational damage. Read more >>

Threat intelligence is the organized collection and analysis of data regarding cybercriminals, their motives, and their tactical methods. Instead of just reacting to random network anomalies, this information allows security teams to understand exactly who's targeting them and how an attack will likely unfold. It transforms raw security data into predictive, actionable guidance to ensure intruders won't catch you off guard. Read more >>

V

Vulnerability management is a continuous cybersecurity process that identifies, evaluates, and fixes security weaknesses in an organization's software and hardware. Instead of treating security as a one-time setup, it's a permanent inspection routine that discovers flaws before hackers can exploit them. This practice helps businesses keep their digital infrastructure secure against constantly evolving software threats. Read more >>