An Advanced Persistent Threat (APT) is a sophisticated, long-term cyberattack where an intruder establishes an undetected presence in a network. Instead of causing immediate disruption, the attacker focuses on stealing sensitive data continuously over an extended period. These campaigns are highly targeted and usually orchestrated by resource-rich groups, such as state-sponsored actors. Read more >>

Cybersecurity terms and concepts explained
Cybersecurity is becoming increasingly complex. Many organizations offer resources and information on the fundamental principles of cybersecurity, including endpoint protection, security services, and different types of cyberattacks. If you need information about these cybersecurity topics and many others, Sophos has you covered.
A
Artificial Intelligence (AI) has revolutionized the way IT security professionals address cybersecurity. Through our AI research and development of AI-powered cybersecurity tools and systems we now have the ability to enhance data protection against threats by quickly recognizing behavior patterns, automating processes, and detecting anomalies. Download our AI for cybersecurity toolkit.
C
Cybersecurity specialists protect an organization’s digital environment by identifying vulnerabilities, strengthening security controls, and responding quickly to emerging threats. The role blends technical expertise, analytical skills, and proactive risk management.
Cyber threat intelligence (CTI) represents evidence-based knowledge (e.g., context, mechanisms, indicators, implications, and action-oriented advice) about existing or emerging cyber threats.
The outsourced model of cybersecurity-as-a-service means that, rather than handling it internally, organizations work with a third-party partner with the expertise and resources to continuously monitor their security posture.
H
A honeypot is a decoy security system designed to mimic a legitimate digital asset, such as a server, database, or network segment. It's intentionally left vulnerable to lure cybercriminals away from real, sensitive corporate data. By attracting attackers into a controlled environment, organizations can safely monitor their behavior and gather valuable threat intelligence. Read more >>
I
Indicators of Compromise (IoC) are digital clues or artifacts left behind on a network after a cyberattack occurs. They act like forensic evidence, showing security teams that a system's been breached or infected. By identifying these pieces of data, organizations can recognize active threats and start repairing the damage before it gets worse. Read more >>
M
Managed Detection and Response (MDR) is a cybersecurity service that combines advanced technology with human expertise to monitor an organization's network around the clock. Instead of just sending alerts, MDR provider teams actively hunt for, investigate, and neutralize cyber threats before they cause damage. This service provides businesses with a dedicated, external security operations team to defend against modern attacks. Read more >>
N
A network detection and response solution uses AI, Machine Learning, and other non-signature-based analytical techniques to identify and respond to suspicious network activity.
R
Remote ransomware is when adversaries compromise an unmanaged device and then use it to remotely encrypt protected devices on the same network. Most other endpoint solutions fall short in this scenario - meaning a single unmanaged/unprotected device can result in the entire estate being encrypted, even if the computers are running up-to-date protection.
Managed risk in cybersecurity is the process of identifying, assessing, and mitigating possible cybersecurity threats to an organization’s information technology (IT) systems, networks, applications, and data.
S
Security Information and Event Management (SIEM) is a security solution that helps organizations recognize potential threats and vulnerabilities before they disrupt business operations. It acts as a centralized platform, gathering and analyzing log data from an entire digital infrastructure in real time. This technology gives security teams a comprehensive view of activities across their network to simplify threat detection and compliance monitoring. Read more >>
Sophos provides global cybersecurity solutions that defend organizations of all sizes against the latest cyberthreats. Among its many offerings are managed security as a service and endpoint, antivirus, firewall, and advanced threat prevention products.
T
Threat hunting is a proactive cybersecurity practice where security analysts actively search through networks and systems to detect hidden threats that have bypassed automated security tools. Instead of waiting for an alert to trigger, hunters assume an attacker is already inside the environment. This method uncovers stealthy malicious activity before it's able to cause widespread operational damage. Read more >>
Threat intelligence is the organized collection and analysis of data regarding cybercriminals, their motives, and their tactical methods. Instead of just reacting to random network anomalies, this information allows security teams to understand exactly who's targeting them and how an attack will likely unfold. It transforms raw security data into predictive, actionable guidance to ensure intruders won't catch you off guard. Read more >>
A threat actor is anyone who is either a key driver of or participates in a malicious action that targets an organization's IT security.
Telemetry refers to the collection, transmission, and measurement of data. It involves the use of sensors to retrieve information from remote sources. The telemetry you collect gives you insights that you can use to effectively administer and manage your IT infrastructure.
V
Vulnerability management is a continuous cybersecurity process that identifies, evaluates, and fixes security weaknesses in an organization's software and hardware. Instead of treating security as a one-time setup, it's a permanent inspection routine that discovers flaws before hackers can exploit them. This practice helps businesses keep their digital infrastructure secure against constantly evolving software threats. Read more >>
X
Extended Detection and Response (XDR) is a cybersecurity approach that automatically collects and correlates security data from multiple sources. By looking beyond just endpoints, it integrates telemetry from emails, servers, cloud workloads, and networks into a single console. Read more >>


