Please find below a helpful list of definitions for some of the most common cyber security terms.If you are looking for a particular term that isn't in this list, please let us know and we will endeavour to add it for you.
🔴 A
Adware
Adware is a type of software that is used for showing advertisements on websites, browsers, apps and even devices. Often, adware consists of pop‑ups and other intrusive forms of advertising.
Affiliate
In cyber‑crime, an affiliate is a criminal who uses a ransomware group’s tools or platform to carry out attacks. Affiliates typically earn a share of the ransom payment, while the ransomware operators provide the malware, infrastructure and support.
AI (Artificial Intelligence)
Technology that allows computers and software to perform tasks that normally require human intelligence, such as recognising patterns, understanding language or making decisions.
AI Hallucination
When an artificial intelligence system produces incorrect, misleading or completely fabricated information.
AI‑Enhanced Cyber Attacks
Cyber attacks that use artificial intelligence to automate tasks such as phishing, scanning for vulnerabilities or writing malicious code.
AITM (Adversary‑in‑the‑Middle Attack)
An advanced form of Man‑in‑the‑Middle attack where criminals intercept and manipulate communication between a user and a legitimate service - often during login. AITM attacks commonly use fake websites or phishing pages to steal session cookies or bypass multi‑factor authentication, allowing attackers to impersonate the victim even after MFA has been completed.
Antivirus
Software that is designed to detect, stop and remove viruses and other kinds of malicious software.
Application (App)
Short for application - a software program, usually for a smartphone, tablet or computer.
Application Security (AppSec)
Security measures used to protect applications from vulnerabilities and attacks.
Attack Path
A visual representation of how an attacker could move through a system to exploit weaknesses.
Attack Surface
All the possible points where an attacker could try to gain access to a system.
Attack Surface Management (ASM)
Tools and processes that continuously discover and monitor an organisation’s digital footprint to identify potential entry points for attackers.
Attack Vector
The method used by an attacker to exploit a vulnerability, such as stolen credentials or misconfigured systems.
Attacker
A malicious actor who attempts to exploit systems to steal, damage or disrupt information.
🔴 B
BEC (Business Email Compromise)
A targeted scam where attackers impersonate executives or suppliers to trick organisations into sending money or sensitive information.
Blacklist / Deny List
A list of websites, IP addresses or applications that are blocked from accessing a device or network.
Botnet
A network of infected devices controlled remotely by attackers.
Breach
An incident where data or systems are accessed in an unauthorised way.
Browser
A software application (such as Chrome, Edge or Firefox) used to access and view websites and online services.
Brute Force Attack
Trying many password combinations automatically until the correct one is found.
Bug Bounty
A programme where organisations reward people for reporting security vulnerabilities.
BYOD (Bring Your Own Device)
A policy allowing employees to use personal devices for work.
🔴 C
Certificate
A digital identity used to authenticate computers, users or organisations.
Cloud
Shared computing resources accessed online instead of hosted locally.
Cloud Service Provider (CSP)
A company that provides cloud‑based services such as storage, computing power or applications.
Command and Control (C2)
The system or infrastructure that attackers use to communicate with infected devices or malware. C2 servers send instructions, receive stolen data and control how an attack behaves. Disrupting C2 communication is one of the main ways security teams stop active cyber attacks.
Correlation
The process of linking related pieces of telemetry or security data together to identify patterns or detect threats. Correlation helps analysts see the bigger picture - for example, connecting multiple small alerts into one meaningful incident.
CSPM (Cloud Security Posture Management)
Tools that automatically detect cloud misconfigurations.
CWPP (Cloud Workload Protection Platform)
Security tools that protect cloud workloads such as containers and virtual machines.
CVE (Common Vulnerabilities and Exposures)
A public list of known security flaws.
Credentials
Information used to verify identity - usually passwords, tokens or certificates.
Cross‑Site Request Forgery (CSRF)
An attack that tricks users into performing actions they didn’t intend.
Cross‑Site Scripting (XSS)
An attack where malicious scripts are injected into web pages.
Cyber Attack
Attempts to damage, disrupt or gain unauthorised access to systems.
Cyber Incident
A breach of security rules, such as unauthorised access or disruption.
Cyber Security
Protecting devices, networks and data from theft or damage.
🔴 D
Data At Rest
Data stored on disks, backups or removable media.
Data Centre
A data centre is a specialised facility that houses large numbers of computer servers, storage systems and networking equipment. Organisations use data centres to run applications, store data and deliver online services. They are designed for high security, reliable power, cooling and constant connectivity.
Data Classification
Labelling data based on sensitivity.
Data Leak Site (DLS)
A website operated by cyber criminals where stolen data is published or used as leverage during ransomware extortion.
Data Leakage (AI)
Sensitive information unintentionally revealed through AI prompts or training data.
Data Residency
Where data is stored geographically.
DDoS (Distributed Denial of Service)
Overloading a server with traffic from many sources to make it unavailable.
Deepfake Fraud
AI‑generated audio or video used to impersonate real people.
Denial of Service (DoS)
An attack where legitimate users are prevented from accessing a service, usually by overloading it with traffic or requests.
Dictionary Attack
Using common words or phrases to guess passwords.
Download Attack / Drive‑By Download
Unintentional installation of malicious software without the user’s knowledge.
Double Extortion
A ransomware tactic where attackers not only encrypt data but also steal it and threaten to leak it publicly if the ransom is not paid.
Dropper / Loader
Malware designed to install other malware.
🔴 E
EDR (Endpoint Detection & Response)
Security software that monitors devices for suspicious behaviour and responds automatically.
Encryption
A mathematical process that makes data unreadable without the correct key.
End User Device (EUD)
Devices such as smartphones, laptops and tablets used to access networks.
Exploit
Software or code that takes advantage of a vulnerability.
🔴 F
FIDO2 / Passkeys
Passwordless authentication using cryptographic keys instead of traditional passwords.
Firewall
Hardware or software that blocks unauthorised network traffic.
🔴 H
Hacker
Someone who uses computer skills to break into systems.
Honeypot / Honeynet
A decoy system used to attract attackers and study their behaviour.
🔴 I
IAB (Initial Access Broker)
Criminals who break into organisations and sell access to other attackers.
IAM (Identity Access Management)
Controls who can access what within an organisation.
Incident
A breach of security rules for a system or service, such as unauthorised access, misuse of systems, changes without consent or disruption of services.
Infostealer
Malware designed to steal passwords, cookies, crypto wallets and other sensitive data.
Insider Risks
Threats caused by legitimate users, either accidentally or maliciously.
Internet of Things (IoT)
Everyday objects that connect to the internet, such as fridges or TVs.
IP Address
A unique identifier for devices connected to the internet.
ISP (Internet Service Provider)
A company that provides access to the internet. ISPs supply the connection used at home or work, such as broadband, fibre or mobile data, and often provide additional services like email, routers or security filtering.
ITDR (Identity Threat Detection & Response)
Tools that detect attacks targeting user accounts and authentication systems.
🔴 K
Kill Chain
A model describing the stages of a cyber attack.
Kubernetes Security
Protecting containerised applications and clusters.
🔴 L
Least Privilege / Least‑Privileged Access (LPA)
Limiting user access to only what is necessary.
Living Off The Land (LOTL)
Attackers using built‑in tools like PowerShell instead of malware to avoid detection.
🔴 M
Macro
A small automated program often used in documents - can be abused by attackers.
Malvertising
Using online adverts to deliver malware.
Malware
Malicious software designed to damage or steal data.
MDR (Managed Detection and Response)
A security service where a specialist team monitors an organisation’s systems for threats, investigates suspicious activity and responds to attacks on behalf of the organisation. MDR provides expert support for companies that don’t have their own security operations team.
MITM (Man‑in‑the‑Middle Attack)
A cyber attack where a criminal secretly intercepts and possibly alters communication between two parties. The attacker places themselves “in the middle” of the conversation - often on insecure Wi‑Fi networks - to steal information, redirect traffic or impersonate one of the participants.
MITRE ATT&CK
A framework describing real‑world attacker techniques.
Mitigation
Steps taken to reduce, manage or fix security risks, such as applying patches, changing configurations or improving processes.
Model Poisoning (AI)
Corrupting an AI model during training so it behaves incorrectly.
Multi‑Factor Authentication (MFA)
Using two or more methods to verify identity.
🔴 N
N‑Day Vulnerability
A known vulnerability with a patch available, but still exploited.
Network
Two or more computers linked to share resources.
🔴 P
Patching
Applying updates to fix security issues.
Pentest / Penetration Test
An authorised test to find security weaknesses.
PhaaS (Phishing‑as‑a‑Service)
A criminal service where attackers can pay to use ready‑made phishing kits, fake login pages, email templates and hosting infrastructure. PhaaS makes it easy for less‑skilled criminals to run phishing campaigns without building anything themselves.
Pharming
Redirecting users to fake websites even when they enter the correct address.
PHI (Protected Health Information)
Sensitive health‑related information about a person, such as medical records, test results, diagnoses, treatment history or insurance details. PHI is protected by strict privacy laws because it reveals personal medical information.
Phishing
Mass emails asking for sensitive information or linking to fake websites.
PII (Personally Identifiable Information)
Information that can be used to identify a specific person, such as their name, address, email, phone number, date of birth, National Insurance number or passport details. Protecting PII is important because criminals can use it for identity theft or fraud.
Platform
The hardware and operating system on which applications run.
Pretexting
Creating a fake scenario to trick someone into giving information.
Prompt Injection (AI)
Manipulating an AI system into ignoring instructions or revealing information.
Proxy Server
A mediator between users and websites that hides the user’s IP address.
🔴 Q
Quantum Computing
A new type of computing that uses quantum physics to process information in ways traditional computers cannot. Quantum computers can solve certain problems much faster, which may eventually impact encryption, security and scientific research. They are still experimental and not widely used today.
Quishing
Phishing attacks delivered through QR codes.
🔴 R
RaaS (Ransomware‑as‑a‑Service)
A business model where ransomware creators rent out their tools and infrastructure to affiliates, who carry out attacks and share profits.
Ransomware
Ransomware is a form of cyber crime whereby a hacker gains access to a device or network, steals or encrypts data, and then demands a ransom payment in exchange for not leaking the data or providing a decryption key. Modern ransomware often involves “double extortion” (threatening to publish stolen data) and “triple extortion” (pressuring customers, partners or regulators to increase the impact).
Red Team / Blue Team / Purple Team
Red are attackers, Blue are defenders, Purple are both working together.
Router
Hardware that connects devices to the internet.
Runtime Protection
Detecting and blocking attacks inside running software.
🔴 S
SaaS (Software-as-a-Service)
Software delivered over the internet where users access applications through a browser instead of installing them locally.
SASE (Secure Access Service Edge)
Cloud‑based networking and security combined.
Sandboxing
Running files in a safe environment to test if they’re malicious.
Sanitisation
Securely erasing data.
SBOM (Software Bill of Materials)
A list of all components inside software.
Session Hijacking / Token Theft
Stealing login tokens to impersonate users.
Shadow IT
Hardware, software or services used inside an organisation without approval or visibility from IT or security teams.
Shadow SaaS
Unapproved or unknown cloud applications used by staff, often by signing up with work email addresses.
SIEM (Security Information & Event Management)
Collects logs to detect threats.
Single Sign‑On (SSO)
A login system that allows users to access multiple applications with one set of credentials.
Smishing
Phishing via SMS.
SOC (Security Operations Centre)
A dedicated team or facility responsible for monitoring, detecting and responding to cyber threats. The SOC watches over systems 24/7, investigates alerts and coordinates actions to keep the organisation secure.
Social Engineering
Manipulating people into giving information or performing actions.
SOAR (Security Orchestration, Automation & Response)
Automates security tasks and incident response.
Spear‑Phishing
Targeted phishing that appears to come from someone the victim knows.
Spyware
Malware that secretly collects information.
SQL Injection (SQLi)
Injecting malicious commands into a website’s database.
Supply Chain Attack
Attacking a supplier to reach their customers.
🔴 T
Tailgating / Piggybacking
Following someone into a secure area without permission.
Telemetry
The data collected from systems, devices, applications and security tools that shows what is happening in an environment. Telemetry helps security teams spot unusual behaviour, detect attacks and understand how systems are being used.
Threat Intelligence
Information about cyber threats used to improve security.
Triple Extortion
A ransomware tactic where attackers pressure third parties such as customers, partners or regulators to increase the impact.
Trojan
Malware disguised as legitimate software.
Two‑Factor Authentication (2FA)
Using two methods to verify identity.
🔴 V
Virus
Malware that self‑replicates and infects devices.
Virtual Private Network (VPN)
An encrypted connection for secure remote access.
Vishing
Phishing via phone calls or voice messages.
VM (Virtual Machine)
A virtual machine is a software‑based computer that runs inside another computer. It behaves like a real device with its own operating system, but it’s actually a “virtual” environment used for testing, isolation and running separate workloads safely.
Vulnerability
A weakness in software or systems.
🔴 W
Watering Hole Attack
Compromising a website that a target group is likely to visit.
Whaling
Phishing attacks aimed at senior executives.
Whitelist / Allow List
A list of approved websites or applications.
Worms
Malware that self‑replicates and spreads across networks.
🔴 X
XDR (Extended Detection and Response)
XDR is a security technology that brings together data from multiple sources - such as endpoints, identities, email, cloud services and networks - to detect threats more effectively. Instead of looking at each system separately, XDR combines everything into one view, making it easier to spot attacks and respond quickly.
🔴 Z
Zero Trust
A security model based on “never trust, always verify”.
Zero‑Day
A security flaw unknown to the manufacturer and exploited before a fix exists.
Data Source: Microsoft Copilot
Welcome to DBD. On March 8th 2026, DBD celebrated it's sixth anniversary and