Pentesys cyber glossary

Tech talk.
Translated.

Search cyber acronyms and technical terms for a short, plain-English explanation—and understand why each one matters to your organisation.

Showing 97 of 97 terms

Exposure

Access broker

A criminal actor who sells or transfers access to compromised organisations, accounts or systems.

Cloud & application

Active Directory

Microsoft directory technology used to manage identities, devices, permissions and policy across an organisation.

Testing

Agentic security testing

Security testing in which AI agents can plan, execute and adapt actions as evidence changes, within an explicitly authorised scope.

Testing

AI-assisted penetration testing

Penetration-testing activity that uses AI to increase coverage, speed or repeatability while people retain control of scope and assurance decisions.

Core security

2FA

Two-Factor Authentication

A login check that requires two different forms of proof.

Cloud & application

API

Application Programming Interface

A defined way for software systems to exchange data or actions.

Exposure

ASM

Attack Surface Management

The ongoing process of finding, understanding and reducing assets an attacker could reach.

Governance

ASV

Approved Scanning Vendor

A company approved by the PCI Security Standards Council to perform required external vulnerability scans.

Attack simulation

ATT&CK

MITRE Adversarial Tactics, Techniques and Common Knowledge

A widely used knowledge base describing how real adversaries behave.

Testing

Attack path

A connected sequence of weaknesses, permissions or actions that could let an attacker reach an objective.

Attack simulation

Assumed breach

A test that begins from a controlled internal foothold or compromised identity rather than proving the initial entry route.

Testing

Authenticated role

A defined user type tested with authorised credentials, such as a standard user, administrator or separate tenant.

Core security

BEC

Business Email Compromise

Fraud that abuses email accounts or impersonation to trick people into sending money or information.

Cloud & application

BOLA

Broken Object Level Authorization

An API flaw that lets a user access another user's data by changing an object identifier.

Testing

Business logic

The rules and workflows that determine how an application should behave for different users and transactions.

Attack simulation

C2

Command and Control

Infrastructure an attacker uses to communicate with compromised systems.

Exposure

CAASM

Cyber Asset Attack Surface Management

A consolidated view of assets and security data from multiple internal sources.

Governance

CBEST

A Bank of England framework for intelligence-led security testing of important financial institutions.

Cloud & application

CDN

Content Delivery Network

A distributed service that delivers web content from locations closer to users and may provide traffic filtering or caching.

Exposure

Certificate Transparency

Public logs that record issued TLS certificates so domain owners and researchers can identify certificates associated with internet services.

Governance

CIS Controls

Center for Internet Security Critical Security Controls

A prioritised set of safeguards for reducing common cyber risk.

Testing

Closure statement

A record confirming the status of reported findings after remediation and retesting.

Cloud & application

CMS

Content Management System

Software used to create and manage website content, such as WordPress or Drupal.

Core security

CIA triad

Confidentiality, Integrity and Availability

Three core goals used to think about information security.

Governance

CISO

Chief Information Security Officer

The senior leader accountable for an organisation's information-security programme.

Governance

CNI

Critical National Infrastructure

Systems and assets whose disruption could seriously affect essential national services.

Cloud & application

CSPM

Cloud Security Posture Management

Continuous checks for insecure cloud configuration and policy drift.

Governance

CREST

An international not-for-profit accreditation and certification body for the cyber-security industry.

Exposure

CTEM

Continuous Threat Exposure Management

A continuous programme for discovering, prioritising, validating and mobilising action on exposure.

Governance

Cyber Essentials

A UK government-backed certification scheme focused on five technical controls that reduce common cyber attacks.

Governance

Cyber Essentials Plus

The independently tested level of Cyber Essentials covering the same five technical controls.

Testing

CVE

Common Vulnerabilities and Exposures

A public identifier for a specific disclosed security vulnerability.

Testing

CVE correlation

Matching observed software and versions to relevant published vulnerability records.

Testing

CVSS

Common Vulnerability Scoring System

A standard way to express the technical severity of a vulnerability, usually from 0 to 10.

Cloud & application

DAST

Dynamic Application Security Testing

Testing a running application from the outside to find security weaknesses.

Core security

DDoS

Distributed Denial of Service

An attack that floods a service with traffic from many sources to make it unavailable.

Exposure

DNS

Domain Name System

The internet service that maps readable domain names to technical destinations.

Exposure

Dark-web monitoring

Monitoring selected criminal forums, marketplaces, leak sites and closed sources for authorised organisational identifiers.

Attack simulation

EDR

Endpoint Detection and Response

Technology that monitors laptops, servers and other endpoints for suspicious activity.

Exposure

EASM

External Attack Surface Management

Continuous discovery and monitoring of an organisation's internet-facing assets and exposure.

Cloud & application

Entra ID

Microsoft Entra ID

Microsoft's cloud identity and access-management service, formerly called Azure Active Directory.

Testing

EPSS

Exploit Prediction Scoring System

A probability estimate for whether a published vulnerability is likely to be exploited in the wild soon.

Cloud & application

IAM

Identity and Access Management

Policies and systems that control who can access which resources.

Testing

False positive

A reported issue that appears to be a security weakness but is not present or exploitable when properly checked.

Cloud & application

GraphQL

An API query language and runtime that lets clients request specific data through a structured schema.

Cloud & application

HSTS

HTTP Strict Transport Security

A web-security policy that tells browsers to use encrypted HTTPS connections for a domain.

Testing

Human verification

Review by a qualified tester who checks evidence and investigates important paths within an AI-led or automated scope.

Cloud & application

IDOR

Insecure Direct Object Reference

An access-control flaw where changing an identifier exposes another user's object or data.

Attack simulation

IoC

Indicator of Compromise

Evidence that may suggest a system or account has been compromised.

Exposure

IoT

Internet of Things

Physical devices that connect to networks and exchange data.

Governance

ISO 27001

ISO/IEC 27001

An international standard for establishing, operating and improving an information security management system.

Attack simulation

Lateral movement

Techniques used to move from one compromised system, identity or service to others within an environment.

Core security

Least privilege

Giving people, accounts and systems only the access required to perform their authorised purpose.

Governance

IR

Incident Response

The organised process for preparing for, detecting, containing and recovering from security incidents.

Core security

MFA

Multi-Factor Authentication

Authentication using two or more different factors, such as a password and a device.

Attack simulation

NDR

Network Detection and Response

Monitoring and analysis used to identify suspicious behaviour across network traffic.

Governance

NIST CSF

NIST Cybersecurity Framework

A framework for managing cybersecurity risk using outcomes organised around Govern, Identify, Protect, Detect, Respond and Recover.

Governance

NIS2

Network and Information Systems Directive 2

European Union legislation that strengthens cybersecurity risk-management and incident-reporting duties for covered organisations.

Attack simulation

OSINT

Open-Source Intelligence

Information collected legally from publicly available sources.

Cloud & application

OWASP

Open Worldwide Application Security Project

A nonprofit community that publishes widely used application-security guidance and tools.

Governance

PCI DSS

Payment Card Industry Data Security Standard

A security standard for organisations that store, process or transmit payment-card data.

Testing

PTaaS

Penetration Testing as a Service

A delivery model that manages scoping, testing, findings, remediation and retesting through an ongoing platform.

Attack simulation

Privilege escalation

Gaining permissions beyond those originally available to an account or compromised system.

Attack simulation

Purple teaming

A collaborative security exercise in which offensive testers and defenders work through attack techniques together.

Attack simulation

Red teaming

A controlled, objective-led simulation of a credible attacker used to test prevention, detection and response across people, process and technology.

Cloud & application

REST

Representational State Transfer

A common architectural style for APIs that operate on resources using standard web methods.

Testing

Retesting

Testing reported weaknesses again after remediation to confirm that the fix works and the material attack path is closed.

Testing

Risk scoring

A method for expressing the relative urgency of an asset, exposure or finding using technical and contextual evidence.

Exposure

Root domain

An organisation-owned base domain used as a starting point for discovering related internet-facing assets.

Testing

Rules of engagement

The authorised objectives, scope, techniques, exclusions, contacts, safety controls and stop conditions for a security test.

Cloud & application

RCE

Remote Code Execution

A vulnerability that can allow an attacker to run code on a target system from elsewhere.

Governance

RTO

Recovery Time Objective

The target maximum time for restoring a service after disruption.

Governance

RPO

Recovery Point Objective

The maximum acceptable amount of data loss measured in time.

Cloud & application

SAST

Static Application Security Testing

Analysis of source code or compiled code to identify possible security weaknesses without running the application.

Cloud & application

SBOM

Software Bill of Materials

An inventory of the software components and dependencies used in a product.

Attack simulation

SIEM

Security Information and Event Management

A platform that collects and analyses security logs and events from multiple systems.

Cloud & application

SOAP

Simple Object Access Protocol

A structured messaging protocol commonly used by enterprise web services.

Attack simulation

SOC

Security Operations Centre

The people, processes and technology responsible for monitoring and responding to security events.

Governance

SOC 2

An assurance-reporting framework covering controls relevant to security, availability, processing integrity, confidentiality and privacy.

Cloud & application

SSL

Secure Sockets Layer

The older name still commonly used for encrypted web connections and certificates, although modern systems use TLS.

Exposure

Stealer logs

Records created by information-stealing malware that may contain credentials, cookies, device details or other captured data.

Testing

Stop conditions

Pre-agreed events that require testing activity to pause or end immediately.

Attack simulation

Threat-led penetration testing

Penetration testing shaped by the tactics and objectives of threat actors relevant to the organisation.

Governance

TIBER-EU

Threat Intelligence-Based Ethical Red Teaming

A European framework for controlled intelligence-led testing of critical financial entities.

Cloud & application

TLS

Transport Layer Security

The modern protocol used to encrypt data between services, including HTTPS web connections.

Attack simulation

White cell

A small authorised control group that governs a covert or sensitive security exercise.

Cloud & application

SQLi

SQL Injection

An injection flaw where unsafe input changes a database query.

Cloud & application

SSRF

Server-Side Request Forgery

A flaw that tricks a server into making requests chosen by an attacker.

Governance

SLA

Service Level Agreement

A defined commitment for service performance, such as response or remediation times.

Attack simulation

TTPs

Tactics, Techniques and Procedures

Patterns describing an adversary's goals, methods and detailed ways of operating.

Testing

VA

Vulnerability Assessment

A systematic process for identifying and evaluating possible weaknesses.

Testing

VAPT

Vulnerability Assessment and Penetration Testing

A broad label combining vulnerability identification with manual penetration testing.

Cloud & application

WAF

Web Application Firewall

A control that filters web traffic to block or limit malicious requests.

Attack simulation

XDR

Extended Detection and Response

Detection and investigation across several security data sources, often endpoints, identity, email and cloud.

Cloud & application

XSS

Cross-Site Scripting

A web flaw that allows attacker-controlled script to run in another user's browser.

Core security

Zero day

A vulnerability that is being exploited, or becomes known, before an effective fix is available to defenders.

Core security

Zero Trust

A security approach that removes inherent network trust and verifies each access request using context and policy.

Clear, not casual

Plain English, grounded in recognised security language.

Definitions have been simplified for accessibility using recognised terminology from the UK National Cyber Security Centre, NIST and OWASP. They are practical explanations, not contractual or regulatory definitions.

From terminology to action

Know the words. Now see your exposure.

Take the two-minute exposure check for a practical view of visibility, validation, remediation and resilience.

Check your exposure now

Assurance that joins up

Recognised expertise, built around your environment.

Pentesys combines independent assurance, qualified testers and practical integration with the systems your teams already use.

Explore the Pentesys product families

ONE PLATFORM. FOUR WAYS TO REDUCE EXPOSURE.

Start with the security outcome you need, then explore the Pentesys product family built around it.