Skip to main content

MFE-IT

Cybersecurity glossary

Cybersecurity glossary

This cybersecurity glossary defines, in a single sentence, the key terms you will come across in our courses: threats, vulnerabilities, SIEM, Zero Trust, penetration testing… Each definition stands on its own. Not sure where to start? See our guide: Which cybersecurity course should you choose?

Cybersecurity

Cybersecurity is the set of practices, technologies and processes that protect systems, networks and data from digital attacks.

Threat

A threat is any potential event or actor that could harm a system (a hacker, malware, a human error).

Vulnerability

A vulnerability is a weakness in a system that a threat can exploit — for example an unpatched flaw or a weak password.

Risk

Risk is the combination of the likelihood that a threat exploits a vulnerability and the impact it would have; managing risk is the heart of security.

Exploit

An exploit is a piece of code or a technique that takes advantage of a specific vulnerability to compromise a system.

Malware

Malware is malicious software (viruses, trojans, spyware) designed to damage, steal or take control of a system.

Ransomware

Ransomware is malware that encrypts a victim’s data and demands a ransom to restore access.

Phishing

Phishing is a fraudulent message that impersonates a trusted sender to trick the recipient into revealing credentials or data.

Social engineering

Social engineering manipulates people (rather than machines) into breaking security rules — phishing is one of its forms.

Firewall

A firewall filters network traffic according to security rules to block unauthorised access.

Encryption

Encryption transforms data into an unreadable form without the right key, protecting its confidentiality in transit or at rest.

Multi-factor authentication (MFA)

MFA requires at least two proofs of identity (password plus a code, app or key), greatly reducing the risk of account takeover.

Zero Trust

Zero Trust is a security model that trusts no user or device by default and verifies every access request, inside or outside the network.

SIEM

A SIEM (Security Information and Event Management) collects and correlates logs from across the IT estate to detect and alert on security incidents.

SOC

A SOC (Security Operations Centre) is the team and platform that monitor, detect and respond to security incidents, often around the clock.

EDR / XDR

EDR (Endpoint Detection and Response) monitors and responds to threats on endpoints; XDR extends this correlation across endpoints, network and cloud.

Penetration testing (pentest)

A penetration test is an authorised simulated attack that finds and demonstrates exploitable weaknesses before real attackers do.

CVE

A CVE (Common Vulnerabilities and Exposures) is a public identifier for a specific known vulnerability, used to track and patch it.

Patch

A patch is a software correction that fixes a bug or closes a vulnerability; applying patches quickly is a core security practice.

DDoS

A DDoS (Distributed Denial of Service) attack floods a service with traffic from many sources to make it unavailable.

VPN

A VPN (Virtual Private Network) creates an encrypted tunnel over the internet to protect communications and access resources remotely.

Defense in depth

Defense in depth layers multiple, independent security controls so that if one fails, others still protect the system.

SQL injection

SQL injection is an attack that inserts malicious SQL through an input field to read or alter a database.

XSS (Cross-Site Scripting)

XSS injects malicious scripts into a web page viewed by other users, to steal data or hijack sessions.

DevSecOps

DevSecOps integrates security into the DevOps pipeline, automating checks so that security is built in from the start rather than added at the end.

The key cybersecurity terms, explained simply

For every project, we begin with a preliminary discussion with our experts to properly take into account your level, needs, professional context and goals.