Skip to Content
Glossary Banner BG Image

Cybersecurity terms and concepts explained

Cybersecurity is becoming increasingly complex. Many organizations offer resources and information on the fundamental principles of cybersecurity, including endpoint protection, security services, and different types of cyberattacks. If you need information about these cybersecurity topics and many others, Sophos has you covered.

A

An Advanced Persistent Threat (APT) is a sophisticated, long-term cyberattack where an intruder establishes an undetected presence in a network. Instead of causing immediate disruption, the attacker focuses on stealing sensitive data continuously over an extended period. These campaigns are highly targeted and usually orchestrated by resource-rich groups, such as state-sponsored actors. Read more >>

Artificial Intelligence (AI) has revolutionized the way IT security professionals address cybersecurity. Through our AI research and development of AI-powered cybersecurity tools and systems we now have the ability to enhance data protection against threats by quickly recognizing behavior patterns, automating processes, and detecting anomalies. Download our AI for cybersecurity toolkit.

C

H

A honeypot is a decoy security system designed to mimic a legitimate digital asset, such as a server, database, or network segment. It's intentionally left vulnerable to lure cybercriminals away from real, sensitive corporate data. By attracting attackers into a controlled environment, organizations can safely monitor their behavior and gather valuable threat intelligence. Read more >>

I

Indicators of Compromise (IoC) are digital clues or artifacts left behind on a network after a cyberattack occurs. They act like forensic evidence, showing security teams that a system's been breached or infected. By identifying these pieces of data, organizations can recognize active threats and start repairing the damage before it gets worse. Read more >>

M

Managed Detection and Response (MDR) is a cybersecurity service that combines advanced technology with human expertise to monitor an organization's network around the clock. Instead of just sending alerts, MDR provider teams actively hunt for, investigate, and neutralize cyber threats before they cause damage. This service provides businesses with a dedicated, external security operations team to defend against modern attacks. Read more >>

N

R

S

Security Information and Event Management (SIEM) is a security solution that helps organizations recognize potential threats and vulnerabilities before they disrupt business operations. It acts as a centralized platform, gathering and analyzing log data from an entire digital infrastructure in real time. This technology gives security teams a comprehensive view of activities across their network to simplify threat detection and compliance monitoring. Read more >>

T

Threat hunting is a proactive cybersecurity practice where security analysts actively search through networks and systems to detect hidden threats that have bypassed automated security tools. Instead of waiting for an alert to trigger, hunters assume an attacker is already inside the environment. This method uncovers stealthy malicious activity before it's able to cause widespread operational damage. Read more >>

Threat intelligence is the organized collection and analysis of data regarding cybercriminals, their motives, and their tactical methods. Instead of just reacting to random network anomalies, this information allows security teams to understand exactly who's targeting them and how an attack will likely unfold. It transforms raw security data into predictive, actionable guidance to ensure intruders won't catch you off guard. Read more >>

Telemetry refers to the collection, transmission, and measurement of data. It involves the use of sensors to retrieve information from remote sources. The telemetry you collect gives you insights that you can use to effectively administer and manage your IT infrastructure.

V

Vulnerability management is a continuous cybersecurity process that identifies, evaluates, and fixes security weaknesses in an organization's software and hardware. Instead of treating security as a one-time setup, it's a permanent inspection routine that discovers flaws before hackers can exploit them. This practice helps businesses keep their digital infrastructure secure against constantly evolving software threats. Read more >>

X