Skip to Content
Glossary Banner BG Image

Cybersecurity terms and concepts explained

Cybersecurity is becoming increasingly complex. Many organizations offer resources and information on the fundamental principles of cybersecurity, including endpoint protection, security services, and different types of cyberattacks. If you need information about these cybersecurity topics and many others, Sophos has you covered.

A

Artificial Intelligence (AI) has revolutionized the way IT security professionals address cybersecurity. Through our AI research and development of AI-powered cybersecurity tools and systems we now have the ability to enhance data protection against threats by quickly recognizing behavior patterns, automating processes, and detecting anomalies. Download our AI for cybersecurity toolkit.

B

Business Email Compromise (BEC) is a sophisticated cyberattack where criminals trick employees into transferring funds or revealing confidential information by impersonating trusted executives, colleagues, or vendors. Unlike traditional hacks, it rarely relies on malicious links or malware, using social engineering and text-based deception instead. It's one of the most financially devastating vectors facing modern organizations. Read more >>

C

Cyber insurance is a specialized risk management service that protects organizations from the financial and operational consequences of cyberattacks and data breaches. It doesn't prevent cybercrime from occurring, but it helps mitigate the heavy costs associated with recovery, legal fees, and business downtime. This coverage has become an essential safety net for businesses navigating today's hostile digital landscape. Read more >>

D

Data loss prevention (DLP) is a cybersecurity strategy and set of technologies that identify, monitor, and protect sensitive data from unauthorized access, exposure, or theft so that confidential information stays within your organization and is used only in approved ways. DLP helps prevent data breaches and exfiltration, enforce data-handling policies, support regulatory compliance, reduce insider risk, and maintain customer confidence.

E

Endpoint management focuses on managing the security posture of all connected end-user devices or endpoints within an organization's network. Endpoints are the devices that connect to a network and include desktop computers, laptops, smartphones, tablets, servers, and other devices.

F

A firewall is a network security device that monitors and filters incoming and outgoing network traffic based on an organization's previously established security rules. At its most basic, a firewall essentially functions as a barrier between a trusted internal network and an untrusted external network, such as the internet. Read more >>

I

An Intrusion Detection System (IDS) is a security application that monitors network traffic or device activity for suspicious behavior and known policy violations. It acts like a digital security camera, constantly watching data packets to flag potential threats. When it spots an anomaly, it immediately logs the event and alerts your administrative team so they can investigate further. Read more >>

L

M

N

R

S

Secure Access Service Edge (SASE) is a cloud-based security framework that merges network connectivity with comprehensive cybersecurity functions. Instead of routing traffic through a physical data center to secure it, SASE delivers protection directly to the user or device at the edge of the network. This approach allows organizations to secure remote workers and cloud applications seamlessly. Read more >>

V

A Virtual Private Network (VPN) is a service that creates a secure, encrypted connection between a user's device and the internet. By routing web traffic through an isolated digital tunnel, it hides the user's actual IP address and protects their data from unauthorized interception. This ensures privacy and data security when accessing corporate networks or utilizing public internet connections. Read more >>

Z

Zero Trust Security is a modern cybersecurity framework built on a simple premise: never trust, always verify. It removes the old assumption that users and devices inside an organization's network perimeter are automatically safe. Instead, this model requires continuous authentication, authorization, and validation for every single connection attempt before granting access to corporate data and applications. Read more >>