Search cyber acronyms and technical terms for a short, plain-English explanation—and understand why each one matters to your organisation.
Showing 97 of 97 terms
Exposure
Access broker
A criminal actor who sells or transfers access to compromised organisations, accounts or systems.
Cloud & application
Active Directory
Microsoft directory technology used to manage identities, devices, permissions and policy across an organisation.
Testing
Agentic security testing
Security testing in which AI agents can plan, execute and adapt actions as evidence changes, within an explicitly authorised scope.
Testing
AI-assisted penetration testing
Penetration-testing activity that uses AI to increase coverage, speed or repeatability while people retain control of scope and assurance decisions.
Core security
2FA
Two-Factor Authentication
A login check that requires two different forms of proof.
Cloud & application
API
Application Programming Interface
A defined way for software systems to exchange data or actions.
Exposure
ASM
Attack Surface Management
The ongoing process of finding, understanding and reducing assets an attacker could reach.
Governance
ASV
Approved Scanning Vendor
A company approved by the PCI Security Standards Council to perform required external vulnerability scans.
Attack simulation
ATT&CK
MITRE Adversarial Tactics, Techniques and Common Knowledge
A widely used knowledge base describing how real adversaries behave.
Testing
Attack path
A connected sequence of weaknesses, permissions or actions that could let an attacker reach an objective.
Attack simulation
Assumed breach
A test that begins from a controlled internal foothold or compromised identity rather than proving the initial entry route.
Testing
Authenticated role
A defined user type tested with authorised credentials, such as a standard user, administrator or separate tenant.
Core security
BEC
Business Email Compromise
Fraud that abuses email accounts or impersonation to trick people into sending money or information.
Cloud & application
BOLA
Broken Object Level Authorization
An API flaw that lets a user access another user's data by changing an object identifier.
Testing
Business logic
The rules and workflows that determine how an application should behave for different users and transactions.
Attack simulation
C2
Command and Control
Infrastructure an attacker uses to communicate with compromised systems.
Exposure
CAASM
Cyber Asset Attack Surface Management
A consolidated view of assets and security data from multiple internal sources.
Governance
CBEST
A Bank of England framework for intelligence-led security testing of important financial institutions.
Cloud & application
CDN
Content Delivery Network
A distributed service that delivers web content from locations closer to users and may provide traffic filtering or caching.
Exposure
Certificate Transparency
Public logs that record issued TLS certificates so domain owners and researchers can identify certificates associated with internet services.
Governance
CIS Controls
Center for Internet Security Critical Security Controls
A prioritised set of safeguards for reducing common cyber risk.
Testing
Closure statement
A record confirming the status of reported findings after remediation and retesting.
Cloud & application
CMS
Content Management System
Software used to create and manage website content, such as WordPress or Drupal.
Core security
CIA triad
Confidentiality, Integrity and Availability
Three core goals used to think about information security.
Governance
CISO
Chief Information Security Officer
The senior leader accountable for an organisation's information-security programme.
Governance
CNI
Critical National Infrastructure
Systems and assets whose disruption could seriously affect essential national services.
Cloud & application
CSPM
Cloud Security Posture Management
Continuous checks for insecure cloud configuration and policy drift.
Governance
CREST
An international not-for-profit accreditation and certification body for the cyber-security industry.
Exposure
CTEM
Continuous Threat Exposure Management
A continuous programme for discovering, prioritising, validating and mobilising action on exposure.
Governance
Cyber Essentials
A UK government-backed certification scheme focused on five technical controls that reduce common cyber attacks.
Governance
Cyber Essentials Plus
The independently tested level of Cyber Essentials covering the same five technical controls.
Testing
CVE
Common Vulnerabilities and Exposures
A public identifier for a specific disclosed security vulnerability.
Testing
CVE correlation
Matching observed software and versions to relevant published vulnerability records.
Testing
CVSS
Common Vulnerability Scoring System
A standard way to express the technical severity of a vulnerability, usually from 0 to 10.
Cloud & application
DAST
Dynamic Application Security Testing
Testing a running application from the outside to find security weaknesses.
Core security
DDoS
Distributed Denial of Service
An attack that floods a service with traffic from many sources to make it unavailable.
Exposure
DNS
Domain Name System
The internet service that maps readable domain names to technical destinations.
Exposure
Dark-web monitoring
Monitoring selected criminal forums, marketplaces, leak sites and closed sources for authorised organisational identifiers.
Attack simulation
EDR
Endpoint Detection and Response
Technology that monitors laptops, servers and other endpoints for suspicious activity.
Exposure
EASM
External Attack Surface Management
Continuous discovery and monitoring of an organisation's internet-facing assets and exposure.
Cloud & application
Entra ID
Microsoft Entra ID
Microsoft's cloud identity and access-management service, formerly called Azure Active Directory.
Testing
EPSS
Exploit Prediction Scoring System
A probability estimate for whether a published vulnerability is likely to be exploited in the wild soon.
Cloud & application
IAM
Identity and Access Management
Policies and systems that control who can access which resources.
Testing
False positive
A reported issue that appears to be a security weakness but is not present or exploitable when properly checked.
Cloud & application
GraphQL
An API query language and runtime that lets clients request specific data through a structured schema.
Cloud & application
HSTS
HTTP Strict Transport Security
A web-security policy that tells browsers to use encrypted HTTPS connections for a domain.
Testing
Human verification
Review by a qualified tester who checks evidence and investigates important paths within an AI-led or automated scope.
Cloud & application
IDOR
Insecure Direct Object Reference
An access-control flaw where changing an identifier exposes another user's object or data.
Attack simulation
IoC
Indicator of Compromise
Evidence that may suggest a system or account has been compromised.
Exposure
IoT
Internet of Things
Physical devices that connect to networks and exchange data.
Governance
ISO 27001
ISO/IEC 27001
An international standard for establishing, operating and improving an information security management system.
Attack simulation
Lateral movement
Techniques used to move from one compromised system, identity or service to others within an environment.
Core security
Least privilege
Giving people, accounts and systems only the access required to perform their authorised purpose.
Governance
IR
Incident Response
The organised process for preparing for, detecting, containing and recovering from security incidents.
Core security
MFA
Multi-Factor Authentication
Authentication using two or more different factors, such as a password and a device.
Attack simulation
NDR
Network Detection and Response
Monitoring and analysis used to identify suspicious behaviour across network traffic.
Governance
NIST CSF
NIST Cybersecurity Framework
A framework for managing cybersecurity risk using outcomes organised around Govern, Identify, Protect, Detect, Respond and Recover.
Governance
NIS2
Network and Information Systems Directive 2
European Union legislation that strengthens cybersecurity risk-management and incident-reporting duties for covered organisations.
Attack simulation
OSINT
Open-Source Intelligence
Information collected legally from publicly available sources.
Cloud & application
OWASP
Open Worldwide Application Security Project
A nonprofit community that publishes widely used application-security guidance and tools.
Governance
PCI DSS
Payment Card Industry Data Security Standard
A security standard for organisations that store, process or transmit payment-card data.
Testing
PTaaS
Penetration Testing as a Service
A delivery model that manages scoping, testing, findings, remediation and retesting through an ongoing platform.
Attack simulation
Privilege escalation
Gaining permissions beyond those originally available to an account or compromised system.
Attack simulation
Purple teaming
A collaborative security exercise in which offensive testers and defenders work through attack techniques together.
Attack simulation
Red teaming
A controlled, objective-led simulation of a credible attacker used to test prevention, detection and response across people, process and technology.
Cloud & application
REST
Representational State Transfer
A common architectural style for APIs that operate on resources using standard web methods.
Testing
Retesting
Testing reported weaknesses again after remediation to confirm that the fix works and the material attack path is closed.
Testing
Risk scoring
A method for expressing the relative urgency of an asset, exposure or finding using technical and contextual evidence.
Exposure
Root domain
An organisation-owned base domain used as a starting point for discovering related internet-facing assets.
Testing
Rules of engagement
The authorised objectives, scope, techniques, exclusions, contacts, safety controls and stop conditions for a security test.
Cloud & application
RCE
Remote Code Execution
A vulnerability that can allow an attacker to run code on a target system from elsewhere.
Governance
RTO
Recovery Time Objective
The target maximum time for restoring a service after disruption.
Governance
RPO
Recovery Point Objective
The maximum acceptable amount of data loss measured in time.
Cloud & application
SAST
Static Application Security Testing
Analysis of source code or compiled code to identify possible security weaknesses without running the application.
Cloud & application
SBOM
Software Bill of Materials
An inventory of the software components and dependencies used in a product.
Attack simulation
SIEM
Security Information and Event Management
A platform that collects and analyses security logs and events from multiple systems.
Cloud & application
SOAP
Simple Object Access Protocol
A structured messaging protocol commonly used by enterprise web services.
Attack simulation
SOC
Security Operations Centre
The people, processes and technology responsible for monitoring and responding to security events.
Governance
SOC 2
An assurance-reporting framework covering controls relevant to security, availability, processing integrity, confidentiality and privacy.
Cloud & application
SSL
Secure Sockets Layer
The older name still commonly used for encrypted web connections and certificates, although modern systems use TLS.
Exposure
Stealer logs
Records created by information-stealing malware that may contain credentials, cookies, device details or other captured data.
Testing
Stop conditions
Pre-agreed events that require testing activity to pause or end immediately.
Attack simulation
Threat-led penetration testing
Penetration testing shaped by the tactics and objectives of threat actors relevant to the organisation.
Governance
TIBER-EU
Threat Intelligence-Based Ethical Red Teaming
A European framework for controlled intelligence-led testing of critical financial entities.
Cloud & application
TLS
Transport Layer Security
The modern protocol used to encrypt data between services, including HTTPS web connections.
Attack simulation
White cell
A small authorised control group that governs a covert or sensitive security exercise.
Cloud & application
SQLi
SQL Injection
An injection flaw where unsafe input changes a database query.
Cloud & application
SSRF
Server-Side Request Forgery
A flaw that tricks a server into making requests chosen by an attacker.
Governance
SLA
Service Level Agreement
A defined commitment for service performance, such as response or remediation times.
Attack simulation
TTPs
Tactics, Techniques and Procedures
Patterns describing an adversary's goals, methods and detailed ways of operating.
Testing
VA
Vulnerability Assessment
A systematic process for identifying and evaluating possible weaknesses.
Testing
VAPT
Vulnerability Assessment and Penetration Testing
A broad label combining vulnerability identification with manual penetration testing.
Cloud & application
WAF
Web Application Firewall
A control that filters web traffic to block or limit malicious requests.
Attack simulation
XDR
Extended Detection and Response
Detection and investigation across several security data sources, often endpoints, identity, email and cloud.
Cloud & application
XSS
Cross-Site Scripting
A web flaw that allows attacker-controlled script to run in another user's browser.
Core security
Zero day
A vulnerability that is being exploited, or becomes known, before an effective fix is available to defenders.
Core security
Zero Trust
A security approach that removes inherent network trust and verifies each access request using context and policy.
Clear, not casual
Plain English, grounded in recognised security language.
Definitions have been simplified for accessibility using recognised terminology from the UK National Cyber Security Centre, NIST and OWASP. They are practical explanations, not contractual or regulatory definitions.
From terminology to action
Know the words. Now see your exposure.
Take the two-minute exposure check for a practical view of visibility, validation, remediation and resilience.