Cyber Terminologies Cyber glossary Cyber security, in plain English. Confused by a warning or an acronym? This jargon-free glossary explains the words behind cyber security in seconds — each with a real, everyday example and a link to a trusted source so you can go deeper whenever you want. Browse terms → Learn the basics 📖 50Terms defined 4Categories 50Trusted sources 100%Free & jargon-free The glossary Know the words, beat the jargon. Filter by category, read a plain-English explanation with an example, then open any term to learn more at a trusted source. Filter by categoryAll termsBasicsThreatsDefensesGovernance 50 cyber security terms · explained for absolute beginners 🛡️BasicsCybersecurityThe practice of protecting computers, phones, networks and data from digital attacks, theft and damage. It blends technology, good habits and plain common sense to keep your digital life safe.ExampleLocking your phone with a PIN and pausing before you click a strange link are both everyday cybersecurity.Learn more →🔐BasicsEncryptionA way of scrambling information into unreadable code so that only someone with the correct secret ‘key’ can turn it back into something meaningful. Even if the data is stolen, it stays useless without that key.ExampleWhen you see a padlock in your browser, encryption is quietly protecting your password as it travels to the website.Learn more →📱BasicsMulti-Factor Authentication (MFA)A login method that asks for two or more separate proofs that you are really you — usually something you know (a password) plus something you have (a code on your phone). Even if a thief steals your password, they still can’t get in.ExampleSigning into your bank and then typing a code texted to your phone is MFA in action.Learn more →🔥BasicsFirewallA digital gatekeeper that sits between your device or network and the internet, inspecting traffic and blocking anything that looks dangerous based on a set of safety rules.ExampleThink of it like a bouncer at a club who only lets in people on the guest list.Learn more →🪪BasicsAuthenticationThe process of proving you are who you claim to be before a system lets you in. Passwords, fingerprints and face scans are all ways of authenticating.ExampleUnlocking your phone with your face is authentication — the phone confirms it’s really you.Learn more →🌐BasicsVPNA Virtual Private Network wraps your internet traffic in an encrypted tunnel, hiding what you do from anyone snooping on the same network. It’s especially handy on public Wi-Fi.ExampleUsing a VPN at a coffee shop stops strangers on the same Wi-Fi from seeing which sites you visit.Learn more →📡BasicsNetwork SecurityAll the tools and habits that protect data while it moves across and within networks — keeping outsiders from sneaking in and stopping sensitive information from leaking out.ExampleThe password on your home Wi-Fi router is a small piece of network security keeping neighbours off your connection.Learn more →☁️BasicsCloud SecurityProtecting the data, apps and services you use over the internet — ‘the cloud’ — rather than on your own machine. Responsibility is shared between you and the cloud provider.ExampleChoosing a strong password for your Google Drive or iCloud account is part of cloud security.Learn more →🔑BasicsPassword & PassphraseA secret string of characters that unlocks your accounts. A passphrase — several random words joined together — is longer and far harder to crack than a short, complex-looking password.Example‘purple-tractor-cloud-village’ is a passphrase that’s both easier to remember and tougher to guess than ‘P@ss1’.Learn more →🧯BasicsAntivirusSoftware that scans your device for known malicious programs and blocks or removes them. Modern antivirus also watches for suspicious behaviour, not just viruses it already recognises.ExampleIf you download a file that’s secretly harmful, antivirus can catch and quarantine it before it runs.Learn more →📍BasicsIP AddressA unique number that identifies your device on a network, a bit like a postal address for your internet connection. It tells information where to be delivered.ExampleWhen you visit a website, your IP address tells it where to send the page back to.Learn more →🔒BasicsHTTPS (SSL/TLS)HTTPS is the secure version of a web address, powered by SSL/TLS encryption. It makes sure your connection to a site is private and hasn’t been tampered with along the way.ExampleThe ‘s’ and padlock in ‘https://’ mean your login details are encrypted on the way to the site.Learn more →💥BasicsData BreachAn incident where private information is accessed, stolen or exposed by someone who shouldn’t have it. Breaches can leak passwords, emails, card numbers and more.ExampleIf a shopping site is hacked and its customers’ emails end up posted online, that’s a data breach.Learn more →🎣ThreatPhishingA scam where attackers pose as someone you trust — a bank, a boss, a delivery service — to trick you into handing over passwords, money or personal details. It usually arrives by email, text or message.ExampleAn email saying ‘Your account is locked, click here to verify’ that leads to a fake login page is classic phishing.Learn more →🦠ThreatMalwareShort for ‘malicious software’ — any program built to harm, steal from or take control of a device. Viruses, ransomware and spyware are all types of malware.ExampleA free game download that secretly installs a program to spy on you is malware.Learn more →💰ThreatRansomwareA type of malware that locks up your files with encryption and demands a payment — a ransom — to unlock them. Paying is risky and doesn’t guarantee you’ll get your files back.ExampleWaking up to find every document on your PC scrambled, with a note demanding $500, is a ransomware attack.Learn more →🧠ThreatSocial EngineeringTricking people, rather than hacking machines, to gain access or information. Attackers exploit trust, fear or a sense of urgency to make you drop your guard.ExampleA caller pretending to be IT support and urgently asking for your password is using social engineering.Learn more →🌊ThreatDDoS AttackA Distributed Denial-of-Service attack floods a website or service with so much fake traffic that it slows to a crawl or crashes, blocking real users. The traffic often comes from thousands of hijacked devices at once.ExampleImagine a shop doorway so jammed with fake customers that genuine ones can’t get inside.Learn more →🧩ThreatVulnerabilityA weakness or flaw in software, hardware or a process that attackers can exploit to break in. Keeping systems updated closes many vulnerabilities before they’re used.ExampleAn outdated app with a known bug is a vulnerability — like a broken latch on a window.Learn more →👁️ThreatSpywareMalware that secretly watches what you do and reports back to an attacker, capturing passwords, messages or browsing habits without your knowledge.ExampleA hidden program logging every key you type to steal your banking login is spyware.Learn more →🐴ThreatTrojanMalware disguised as something harmless or useful to trick you into installing it. Once inside, it quietly opens the door for attackers — named after the legendary Trojan Horse.ExampleA ‘free PDF converter’ that actually installs a hidden backdoor is a Trojan.Learn more →🪱ThreatWormA type of malware that copies itself and spreads automatically from device to device across a network — with no need for you to click or open anything.ExampleA worm can infect one office computer, then quietly spread to every other machine on the network.Learn more →🕳️ThreatZero-DayA brand-new vulnerability the software maker doesn’t know about yet — so there are ‘zero days’ to prepare a fix. Attackers race to exploit it before a patch can be released.ExampleIf hackers find a secret flaw in a popular app before the company does, that’s a zero-day.Learn more →🤖ThreatBotnetA network of infected devices secretly controlled by an attacker, often used to send spam or launch DDoS attacks. Your device could be part of one without you ever noticing.ExampleThousands of hacked home cameras working together to crash a website form a botnet.Learn more →🕵️ThreatMan-in-the-MiddleAn attack where someone secretly sits between you and the service you’re using, eavesdropping on — or altering — your data as it passes. Public Wi-Fi is a common hunting ground.ExampleA hacker on the same café Wi-Fi quietly intercepting your messages is a man-in-the-middle attack.Learn more →🔨ThreatBrute Force AttackAn attack that tries huge numbers of password combinations, one after another, until one works. Long, unique passwords make this approach painfully slow for attackers.ExampleSoftware guessing ‘password1’, ‘password2’… millions of times to crack your login is a brute-force attack.Learn more →💉ThreatSQL InjectionA trick where attackers slip malicious commands into a website’s input boxes to fool its database into revealing or changing data. It targets poorly built web forms.ExampleTyping sneaky code into a login box to make a site dump every user’s details is SQL injection.Learn more →🔗DefenseZero TrustA security approach that trusts no one by default: every user and device must prove itself for every request, even inside the network. The motto is ‘never trust, always verify’.ExampleBeing asked to re-verify before opening a sensitive file, even after logging in, reflects zero trust.Learn more →📦DefensePatch ManagementThe routine of keeping software up to date so that known security holes get fixed. Attackers love out-of-date systems because the way in is already public.ExampleThose ‘update available’ notifications you keep postponing? Installing them is patch management.Learn more →🧑💻DefenseEthical HackingAuthorised, legal hacking done to find and fix weaknesses before criminals can exploit them. Ethical hackers use the same tools as attackers, but to help rather than harm.ExampleA company hiring an expert to try breaking into its own systems is ethical hacking.Learn more →🗝️DefensePenetration TestingA controlled, simulated cyberattack carried out to uncover real security gaps in a system. It’s ethical hacking with a clear scope, goal and report at the end.ExampleHiring testers to attack your website and list every way they got in is a penetration test.Learn more →🚨DefenseIncident ResponseThe organised plan for detecting, containing and recovering from a cyberattack. A good plan limits the damage and gets things back to normal faster.ExampleWhen a company spots a breach and follows set steps to isolate it and restore systems, that’s incident response.Learn more →💾DefenseBackupA spare copy of your important data, kept safely so you can recover it if the original is lost, damaged or held to ransom. The best backups are stored separately from the original.ExampleCopying your photos to an external drive means a virus can’t wipe out your only copy.Learn more →📊DefenseSIEMSecurity Information and Event Management tools gather activity logs from across an organisation and analyse them to spot signs of an attack. They act as the security team’s radar.ExampleA SIEM might flag that one account logged in from two different countries minutes apart — a red flag.Learn more →🖥️DefenseEndpoint Protection (EDR)Software that guards individual devices — laptops, phones, servers — and can detect and respond to threats on them. It goes beyond basic antivirus by watching how programs behave.ExampleIf your work laptop suddenly starts encrypting files on its own, EDR can stop it mid-attack.Learn more →🎚️DefenseLeast PrivilegeGiving each person or program only the access it genuinely needs — and nothing more. This limits how much damage can be done if an account is ever compromised.ExampleA cashier can open the till but not the company bank account — that’s least privilege.Learn more →🎓DefenseSecurity Awareness TrainingTeaching people to recognise and avoid cyber threats like phishing and scams. Because so many attacks target humans rather than machines, trained people are a powerful defence.ExamplePractice phishing emails your employer sends to test and coach staff are awareness training.Learn more →📰DefenseThreat IntelligenceCollected, analysed information about current and emerging cyber threats that helps defenders stay a step ahead. It answers ‘who might attack us, how, and why?’ExampleA warning that a new scam is targeting your industry this week is threat intelligence.Learn more →🧪DefenseSandboxingRunning a suspicious file or program inside a sealed-off ‘sandbox’ where it can’t touch the real system, so you can safely watch what it tries to do.ExampleOpening an unknown attachment in a sandbox lets analysts see if it’s malware without any risk.Learn more →🧱DefenseDefense in DepthLayering several security measures so that if one fails, others still protect you. No single wall has to be perfect because there are backups behind it.ExampleA locked door, an alarm and a guard dog together are defense in depth for a house.Learn more →📋GovernanceRisk ManagementThe process of spotting what could go wrong, judging how likely and how serious it is, and deciding what to do about it. It helps you spend limited time and money on the biggest dangers first.ExampleDeciding to back up customer data because losing it would be catastrophic is risk management.Learn more →📑GovernanceComplianceMeeting the laws, regulations and standards that apply to how an organisation handles data and security. Falling short can mean fines, legal trouble or lost trust.ExampleA hospital following strict rules on protecting patient records is staying compliant.Learn more →🔏GovernancePrivacyThe right to control how your personal information is collected, used and shared. Good privacy practice means handling people’s data lawfully, openly and respectfully.ExampleA website that lets you choose which data it may collect is respecting your privacy.Learn more →📐GovernanceFrameworkA structured set of best practices and guidelines that organisations follow to manage security consistently. It gives everyone a shared roadmap instead of guesswork.ExampleThe NIST Cybersecurity Framework is a popular, checklist-style guide many organisations build on.Learn more →🇪🇺GovernanceGDPRThe General Data Protection Regulation, a European law that gives people strong rights over their personal data and sets strict rules for organisations that handle it. Its influence reaches far beyond Europe.ExampleThose ‘we use cookies’ consent banners you see everywhere exist largely because of GDPR.Learn more →📜GovernanceSecurity PolicyA written set of rules describing how an organisation protects its systems and data, and what staff are expected to do. It turns good intentions into clear, shared expectations.ExampleA rule that all laptops must be encrypted and locked when left unattended is part of a security policy.Learn more →✅GovernanceAuditA formal review that checks whether security controls are actually working and rules are being followed. Audits catch gaps and blind spots before attackers can.ExampleAn outside expert reviewing exactly who can access sensitive files is running a security audit.Learn more →♻️GovernanceBusiness Continuity & RecoveryPlans for keeping essential operations running during a crisis and getting systems back quickly afterwards. They prepare an organisation for its worst day in advance.ExampleA shop that can still take payments after its main system fails has planned for continuity.Learn more →🗂️GovernanceData ClassificationSorting information by how sensitive it is — public, internal, confidential — so the right level of protection can be applied. Not every piece of data needs the same lock.ExampleMarking salary records ‘confidential’ but a public brochure ‘public’ is data classification.Learn more →🔺GovernanceCIA TriadThe three core goals of security: Confidentiality (keep data private), Integrity (keep it accurate and untampered) and Availability (keep it accessible when needed). Almost every security decision protects one of these.ExampleEncrypting a file protects confidentiality; keeping a backup protects availability.Learn more → 🧭 Want to go deeper? Each term above links to a trusted source. For a full reference, explore the Cloudflare Learning Center or the official NIST security glossary. Learn with Oluma → Put it into practice Know the words? Now build the skills. Take your understanding further with free lessons in our Learning Hub, then test yourself with the security quiz. Start learning → Take the quiz Share this: Share on X (Opens in new window) X Share on Facebook (Opens in new window) Facebook Like this:Like Loading… Related