Skip to Content
Glossary Banner BG Image

Cybersecurity terms and concepts explained

Cybersecurity is becoming increasingly complex. Many organizations offer resources and information on the fundamental principles of cybersecurity, including endpoint protection, security services, and different types of cyberattacks. If you need information about these cybersecurity topics and many others, Sophos has you covered.

A

Attack Surface Management (ASM) is the continuous process of discovering, analyzing, and securing all digital assets that an attacker could exploit. It provides complete visibility into an organization's entire digital footprint, including known infrastructure, hidden shadow IT, and exposed third-party vectors. This practice ensures that security teams can identify and patch vulnerabilities before adversaries find them. Read more >>

C

Cyber insurance is a specialized risk management service that protects organizations from the financial and operational consequences of cyberattacks and data breaches. It doesn't prevent cybercrime from occurring, but it helps mitigate the heavy costs associated with recovery, legal fees, and business downtime. This coverage has become an essential safety net for businesses navigating today's hostile digital landscape. Read more >>

D

A data breach is a security incident in which sensitive, protected, or confidential data is copied, transmitted, viewed, or stolen by an individual unauthorized to do so. These incidents can impact any organization, from small businesses to global enterprises and government agencies. They involve the unauthorized exposure of personally identifiable information (PII), financial records, corporate intellectual property, or trade secrets. Read more >>

E

I

Incident response is an organized approach that organizations use to manage the aftermath of a security breach or cyberattack. The main goal is to limit data damage, shorten recovery times, and keep containment costs down when a crisis hits. It ensures that an enterprise can handle a digital threat systematically so teams don't panic or make errors. Read more >>

Indicators of Compromise (IoC) are digital clues or artifacts left behind on a network after a cyberattack occurs. They act like forensic evidence, showing security teams that a system's been breached or infected. By identifying these pieces of data, organizations can recognize active threats and start repairing the damage before it gets worse. Read more >>

An Intrusion Detection System (IDS) is a security application that monitors network traffic or device activity for suspicious behavior and known policy violations. It acts like a digital security camera, constantly watching data packets to flag potential threats. When it spots an anomaly, it immediately logs the event and alerts your administrative team so they can investigate further. Read more >>

J

JSON Web Token > JSON is an abbreviation for JavaScript Object Notation, a standard text-based format for storing and transporting data. A JSON Web Token, or JWT, is an open industry standard for sharing information between entities, such as clients and servers. JSON Web Tokens are both powerful and versatile, serving as a bridge between software application functionality and data security.

M

Managed Detection and Response (MDR) is a cybersecurity service that combines advanced technology with human expertise to monitor an organization's network around the clock. Instead of just sending alerts, MDR provider teams actively hunt for, investigate, and neutralize cyber threats before they cause damage. This service provides businesses with a dedicated, external security operations team to defend against modern attacks. Read more >>

The MITRE Adversarial Tactics, Techniques, and Common Knowledge or MITRE ATT&CK framework was designed for a simple reason: to solve problems for a safer world. This framework is available for free to anyone that wants to level up their cybersecurity. Your organization can use the MITRE ATT&CK framework to understand how cybercriminals operate. From here, you can prepare for cyberattacks and limit your risk of data breaches.

N

R

S

Secure Access Service Edge (SASE) is a cloud-based security framework that merges network connectivity with comprehensive cybersecurity functions. Instead of routing traffic through a physical data center to secure it, SASE delivers protection directly to the user or device at the edge of the network. This approach allows organizations to secure remote workers and cloud applications seamlessly. Read more >>

Spear phishing is a highly targeted cyberattack where scammers send customized messages to a specific individual or organization. Instead of blasting thousands of random emails, attackers research their victims to make the deception look entirely authentic. It's a calculated effort to trick you into handing over passwords, financial data, or corporate secrets. Read more >>

T

Threat hunting is a proactive cybersecurity practice where security analysts actively search through networks and systems to detect hidden threats that have bypassed automated security tools. Instead of waiting for an alert to trigger, hunters assume an attacker is already inside the environment. This method uncovers stealthy malicious activity before it's able to cause widespread operational damage. Read more >>

Threat intelligence is the organized collection and analysis of data regarding cybercriminals, their motives, and their tactical methods. Instead of just reacting to random network anomalies, this information allows security teams to understand exactly who's targeting them and how an attack will likely unfold. It transforms raw security data into predictive, actionable guidance to ensure intruders won't catch you off guard. Read more >>

Telemetry refers to the collection, transmission, and measurement of data. It involves the use of sensors to retrieve information from remote sources. The telemetry you collect gives you insights that you can use to effectively administer and manage your IT infrastructure.

V

Vulnerability management is a continuous cybersecurity process that identifies, evaluates, and fixes security weaknesses in an organization's software and hardware. Instead of treating security as a one-time setup, it's a permanent inspection routine that discovers flaws before hackers can exploit them. This practice helps businesses keep their digital infrastructure secure against constantly evolving software threats. Read more >>

X

Z

Zero Trust Security is a modern cybersecurity framework built on a simple premise: never trust, always verify. It removes the old assumption that users and devices inside an organization's network perimeter are automatically safe. Instead, this model requires continuous authentication, authorization, and validation for every single connection attempt before granting access to corporate data and applications. Read more >>