The key terms of information security, explained simply and without unnecessary jargon.
The process of verifying a user's identity before granting access to a resource — an application, a database, a mailbox.
Example: entering your password to open your work email.
A copy of your data, taken regularly and ideally kept isolated from the main network, so it can be restored after a failure, a mistake or an attack.
Example: a company hit by ransomware restores its files from an offline backup rather than paying.
A public, standardised identifier assigned to a known security vulnerability in a piece of software, hardware or a system. The register is maintained by MITRE.
Example: CVE-2025-12345 (the format is CVE-year-number), a single reference anyone in the field can look up.
A system for storing and organising information in a structured way, so it can be retrieved and used easily.
Example: customers, orders, invoices, stock — most business software runs on a database.
The part of the internet not indexed by ordinary search engines and reachable only through specific tools such as Tor. It is used for legitimate purposes as well as malicious ones.
Example: credentials stolen in a data breach may be offered for sale on dark web forums.
Transforming data using a key so that only an authorised person holding that key can read it.
Example: data that is stolen but encrypted stays unreadable to an attacker who does not hold the decryption key.
A device or piece of software that filters network traffic: it allows legitimate connections through and blocks the rest.
Example: a misconfigured firewall can leave a database port reachable from the internet without anyone noticing.
An umbrella term for any malicious software built to damage a system, steal information or take control of it — viruses, ransomware, spyware and so on.
Example: a booby-trapped attachment that quietly installs spyware on a workstation.
A login method that adds one or more checks after the password to confirm the user's identity. Even if a password is stolen, access stays blocked without the second factor.
Example: you enter your password, then your phone asks you to confirm the sign-in.
A technique for tricking someone, usually by email, into revealing confidential information or clicking a fraudulent link. It remains the most common entry point for cyberattacks.
Example: a fake "Your Microsoft 365 session has expired" email pushing you to click through and sign in again.
Malicious software that encrypts the files on a computer or server so they cannot be used, after which the attackers demand a ransom for the decryption key. National cybersecurity agencies strongly advise against paying: it does not guarantee recovery and it funds the attackers' business model.
Example: an employee opens a booby-trapped attachment; within minutes the server's files are inaccessible and a payment demand appears.
A technique that lets an attacker run malicious SQL queries when a web application fails to properly validate what the user types in.
Example: an attacker alters a form field or a URL to reach data they should not be able to see.
The protocol that encrypts traffic between a browser and a server, keeping the exchange private. It is what puts the padlock in the address bar (HTTPS).
Example: without a valid TLS certificate, anything typed into a site — a form, a payment — can be intercepted.
An encrypted connection that gives secure access to a remote network, as though the user were physically on it.
Example: someone working from home uses a VPN to reach their company's servers securely.
A vulnerability still unknown to the software vendor, for which no patch exists at the time it is discovered or exploited.
Example: a zero-day flaw exploited before the vendor has had any chance to release a security update.
No term matches your search.