Attack Surface Management (ASM) is the continuous process of discovering, analyzing, and securing all digital assets that an attacker could exploit. It provides complete visibility into an organization's entire digital footprint, including known infrastructure, hidden shadow IT, and exposed third-party vectors. This practice ensures that security teams can identify and patch vulnerabilities before adversaries find them. Read more >>

Cybersecurity terms and concepts explained
Cybersecurity is becoming increasingly complex. Many organizations offer resources and information on the fundamental principles of cybersecurity, including endpoint protection, security services, and different types of cyberattacks. If you need information about these cybersecurity topics and many others, Sophos has you covered.
A
C
Cyber insurance is a specialized risk management service that protects organizations from the financial and operational consequences of cyberattacks and data breaches. It doesn't prevent cybercrime from occurring, but it helps mitigate the heavy costs associated with recovery, legal fees, and business downtime. This coverage has become an essential safety net for businesses navigating today's hostile digital landscape. Read more >>
Cybersecurity specialists protect an organization’s digital environment by identifying vulnerabilities, strengthening security controls, and responding quickly to emerging threats. The role blends technical expertise, analytical skills, and proactive risk management.
Cyber threat intelligence (CTI) represents evidence-based knowledge (e.g., context, mechanisms, indicators, implications, and action-oriented advice) about existing or emerging cyber threats.
The outsourced model of cybersecurity-as-a-service means that, rather than handling it internally, organizations work with a third-party partner with the expertise and resources to continuously monitor their security posture.
D
A data breach is a security incident in which sensitive, protected, or confidential data is copied, transmitted, viewed, or stolen by an individual unauthorized to do so. These incidents can impact any organization, from small businesses to global enterprises and government agencies. They involve the unauthorized exposure of personally identifiable information (PII), financial records, corporate intellectual property, or trade secrets. Read more >>
E
Endpoint security is the practice of safeguarding the devices that connect to a corporate network, such as laptops, smartphones, and servers. By blocking malicious threats at the device level, it ensures these entry points don't become gateways for cyberattacks. Read more >>
I
Incident response is an organized approach that organizations use to manage the aftermath of a security breach or cyberattack. The main goal is to limit data damage, shorten recovery times, and keep containment costs down when a crisis hits. It ensures that an enterprise can handle a digital threat systematically so teams don't panic or make errors. Read more >>
Indicators of Compromise (IoC) are digital clues or artifacts left behind on a network after a cyberattack occurs. They act like forensic evidence, showing security teams that a system's been breached or infected. By identifying these pieces of data, organizations can recognize active threats and start repairing the damage before it gets worse. Read more >>
An Intrusion Detection System (IDS) is a security application that monitors network traffic or device activity for suspicious behavior and known policy violations. It acts like a digital security camera, constantly watching data packets to flag potential threats. When it spots an anomaly, it immediately logs the event and alerts your administrative team so they can investigate further. Read more >>
J
JSON Web Token > JSON is an abbreviation for JavaScript Object Notation, a standard text-based format for storing and transporting data. A JSON Web Token, or JWT, is an open industry standard for sharing information between entities, such as clients and servers. JSON Web Tokens are both powerful and versatile, serving as a bridge between software application functionality and data security.
M
Managed Detection and Response (MDR) is a cybersecurity service that combines advanced technology with human expertise to monitor an organization's network around the clock. Instead of just sending alerts, MDR provider teams actively hunt for, investigate, and neutralize cyber threats before they cause damage. This service provides businesses with a dedicated, external security operations team to defend against modern attacks. Read more >>
A MSSP or managed security service provider protects an organization's applications, devices, and systems against cyberthreats. You can hire an MSSP to handle some or all aspects of your cyber protection. If you do, your service provider will manage your cybersecurity in alignment with your organization's security needs.
Mobile device management (MDM) is security software that lets your business implement policies to secure, monitor, and manage your end-user mobile devices. The software also protects your network devices and allows your employees to work remotely without compromising their security.
The MITRE Adversarial Tactics, Techniques, and Common Knowledge or MITRE ATT&CK framework was designed for a simple reason: to solve problems for a safer world. This framework is available for free to anyone that wants to level up their cybersecurity. Your organization can use the MITRE ATT&CK framework to understand how cybercriminals operate. From here, you can prepare for cyberattacks and limit your risk of data breaches.
N
Network security includes any solutions that your organization utilizes to protect its network applications, devices, and users. Network security as a service gives organizations the option to outsource their data protection to a team of IT security professionals.
In response to the increased threat of cyberattacks and the associated need to increase defences, the Council of the European Union (EU) and the European Parliament adopted the Network and Information Security 2.0 Directive (NIS2) in December 2022.
R
There is no stopping ransomware attacks. However, businesses can use tried-and-true ransomware mitigation technologies and techniques to address these attacks before they get out of hand.
S
Secure Access Service Edge (SASE) is a cloud-based security framework that merges network connectivity with comprehensive cybersecurity functions. Instead of routing traffic through a physical data center to secure it, SASE delivers protection directly to the user or device at the edge of the network. This approach allows organizations to secure remote workers and cloud applications seamlessly. Read more >>
Spear phishing is a highly targeted cyberattack where scammers send customized messages to a specific individual or organization. Instead of blasting thousands of random emails, attackers research their victims to make the deception look entirely authentic. It's a calculated effort to trick you into handing over passwords, financial data, or corporate secrets. Read more >>
The server hardening process reduces your business' attack surface and helps you guard against ransomware, malware, and other cyberthreats. You can follow this process to protect all points of entry against cyberattacks, address cybersecurity weaknesses, and optimize your security posture.
A security operations center (SOC) is a team of security analysts, engineers, and others who monitor, detect, respond to, and remediate cyberthreats. The SOC team ensures security issues are instantly identified and addressed 24/7/365.
Security as a service (SECaaS) is a form of outsourced security. With SECaaS, you receive cybersecurity services delivered through the cloud.
Sophos provides global cybersecurity solutions that defend organizations of all sizes against the latest cyberthreats. Among its many offerings are managed security as a service and endpoint, antivirus, firewall, and advanced threat prevention products.
T
Threat hunting is a proactive cybersecurity practice where security analysts actively search through networks and systems to detect hidden threats that have bypassed automated security tools. Instead of waiting for an alert to trigger, hunters assume an attacker is already inside the environment. This method uncovers stealthy malicious activity before it's able to cause widespread operational damage. Read more >>
Threat intelligence is the organized collection and analysis of data regarding cybercriminals, their motives, and their tactical methods. Instead of just reacting to random network anomalies, this information allows security teams to understand exactly who's targeting them and how an attack will likely unfold. It transforms raw security data into predictive, actionable guidance to ensure intruders won't catch you off guard. Read more >>
A threat actor is anyone who is either a key driver of or participates in a malicious action that targets an organization's IT security.
Telemetry refers to the collection, transmission, and measurement of data. It involves the use of sensors to retrieve information from remote sources. The telemetry you collect gives you insights that you can use to effectively administer and manage your IT infrastructure.
V
Vulnerability management is a continuous cybersecurity process that identifies, evaluates, and fixes security weaknesses in an organization's software and hardware. Instead of treating security as a one-time setup, it's a permanent inspection routine that discovers flaws before hackers can exploit them. This practice helps businesses keep their digital infrastructure secure against constantly evolving software threats. Read more >>
X
Extended Detection and Response (XDR) is a cybersecurity approach that automatically collects and correlates security data from multiple sources. By looking beyond just endpoints, it integrates telemetry from emails, servers, cloud workloads, and networks into a single console. Read more >>
Z
Zero Trust Security is a modern cybersecurity framework built on a simple premise: never trust, always verify. It removes the old assumption that users and devices inside an organization's network perimeter are automatically safe. Instead, this model requires continuous authentication, authorization, and validation for every single connection attempt before granting access to corporate data and applications. Read more >>


