This comprehensive cybersecurity glossary explains the technical terms you need to understand to make informed security decisions for your small business. We've defined each term in plain language with practical examples.
Network Security Terms
VPN (Virtual Private Network)
A service that creates a secure, encrypted connection over a less secure network (like the internet). VPNs protect data in transit and mask the user's IP address. For businesses, VPNs enable secure remote access to internal resources and protect data on public Wi-Fi networks.
Firewall
A security system that monitors and controls network traffic based on predetermined security rules. Firewalls can be hardware-based (physical devices) or software-based (installed on computers/servers). They act as a barrier between trusted internal networks and untrusted external networks like the internet.
IDS (Intrusion Detection System)
A system that monitors network or system activities for malicious activity or policy violations. IDS tools analyze traffic and generate alerts when suspicious activity is detected. They don't take action but inform administrators so they can respond.
IPS (Intrusion Prevention System)
An advanced security system that monitors network traffic for malicious activity and can automatically take action to block or stop detected threats. Unlike IDS, IPS can actively prevent attacks by blocking traffic, resetting connections, or modifying system configurations.
Authentication & Access Control
MFA (Multi-Factor Authentication)
A security method that requires users to provide two or more verification factors to gain access. MFA significantly reduces the risk of unauthorized access even if a password is compromised. Common factors include passwords (knowledge), codes sent to phones (possession), and fingerprints (inherence).
SSO (Single Sign-On)
A session and user authentication service that permits a user to use one set of login credentials to access multiple applications. SSO improves user experience by reducing password fatigue while maintaining security through centralized authentication management.
Zero Trust
A security model that requires verification of every user and device, regardless of location (inside or outside the traditional network perimeter). Zero Trust assumes no user or device is inherently trusted and continuously validates access requests based on identity, device health, and context.
Malware & Threat Terms
Ransomware
Malware that encrypts or locks a user's files and demands payment (usually in cryptocurrency) for their release. Ransomware attacks have increased dramatically, targeting businesses of all sizes. Prevention includes regular backups, patch management, employee training, and endpoint protection.
Phishing
A social engineering attack where cybercriminals impersonate trusted entities to trick victims into revealing sensitive information or installing malware. Phishing emails often contain urgent requests, fake login pages, or malicious attachments. Anti-phishing training is one of the most effective defenses.
Trojan Horse
Malicious software disguised as legitimate software. Trojans trick users into installing them, often through email attachments or fake downloads. Once installed, they can steal data, create backdoors, or download additional malware.
Endpoint Security Terms
EDR (Endpoint Detection and Response)
A category of security software that monitors endpoint devices (computers, servers, mobile devices) for advanced threats and provides tools to investigate and respond to incidents. EDR solutions provide real-time monitoring, threat detection, behavioral analysis, and incident response capabilities.
AV (Antivirus)
Software designed to prevent, detect, and remove malware. Traditional antivirus uses signature-based detection (matching malware against a database of known threats). Modern antivirus solutions also use behavioral analysis and cloud-based threat intelligence.
XDR (Extended Detection and Response)
A next-generation security platform that extends EDR capabilities across endpoints, networks, and cloud workloads. XDR provides unified visibility and response across multiple security layers, helping organizations reduce alert fatigue and improve threat detection.
Encryption Terms
AES (Advanced Encryption Standard)
A symmetric key encryption algorithm widely used across the globe. AES uses the same key for both encryption and decryption and is considered secure against both classical and quantum computer attacks. It's the standard for securing sensitive data in government and industry.
TLS (Transport Layer Security)
A cryptographic protocol designed to provide secure communication over a computer network. TLS is the successor to SSL (Secure Sockets Layer) and is used to encrypt web traffic (HTTPS), email, and other internet communications.
End-to-End Encryption
A method of secure communication where only the communicating end users can read the message. It prevents intermediaries (like service providers, internet service providers, or governments) from accessing the plaintext content of the communication.
Compliance & Risk Terms
HIPAA (Health Insurance Portability and Accountability Act)
A US law governing the use and disclosure of protected health information (PHI). HIPAA requires covered entities (healthcare providers, health plans, healthcare clearinghouses) to implement specific safeguards for PHI. Businesses handling health information must comply with HIPAA security and privacy rules.
PCI DSS (Payment Card Industry Data Security Standard)
A set of security standards designed to ensure all companies that handle, store, or transmit credit card information maintain a secure environment. PCI DSS applies to any business that accepts payment cards branded Visa, Mastercard, American Express, Discover, or Discover.
Risk Assessment
The process of identifying, analyzing, and evaluating information security risks. A risk assessment identifies assets, threats, vulnerabilities, and the potential impact of threats. This information helps organizations prioritize security investments and develop risk mitigation strategies.
Cloud Security Terms
SASE (Secure Access Service Edge)
A cloud-based network architecture that converges wide area network (WAN) capabilities with security services (firewall-as-a-service, secure web gateway, zero-trust network access). SASE delivers security from the cloud to any user, regardless of location.
IAM (Identity and Access Management)
A framework of policies and technologies for ensuring that the right people have the appropriate access to technology resources. IAM systems authenticate users, authorize their access, and manage their permissions throughout their lifecycle.
CSPM (Cloud Security Posture Management)
A category of security tools that continuously monitor cloud configurations for security and compliance risks. CSPM solutions help organizations maintain security best practices across multi-cloud environments by detecting misconfigurations and providing remediation guidance.
Incident Response Terms
IRP (Incident Response Plan)
A documented procedure for responding to cybersecurity incidents. An effective IRP defines roles and responsibilities, establishes communication protocols, outlines containment strategies, and provides procedures for evidence collection and recovery.
MTTD (Mean Time to Detect)
The average time it takes for an organization to identify a security incident from the moment it occurs. Reducing MTTD is a key goal of security monitoring and threat detection programs.
MTTR (Mean Time to Respond)
The average time it takes for an organization to respond to and remediate a security incident once it has been detected. Fast response minimizes damage and reduces recovery costs.
Additional Terms
DDoS (Distributed Denial of Service)
An attack that overwhelms a target server, service, or network with a flood of internet traffic from multiple sources. DDoS attacks aim to make online services unavailable to legitimate users. DDoS protection services can help absorb or filter malicious traffic.
CVE (Common Vulnerabilities and Exposures)
A standardized dictionary of publicly known cybersecurity vulnerabilities. Each CVE entry includes a unique identifier (CVE-YYYY-NNNNN), a description, and references to related security advisories. CVEs help organizations track and patch known vulnerabilities.
SOC (Security Operations Center)
A centralized unit that deals with security issues affecting an organization. A SOC monitors, detects, and responds to security threats 24/7 using people, processes, and technology. Many small businesses outsource SOC functions to managed security service providers (MSSPs).
Related Resources
Explore our comprehensive guides on specific security topics:
- Best VPNs for Small Business
- Best Password Managers for Small Business
- Best Antivirus for Small Business
- Best Website Security Tools
- Free Security Resources & Templates
SG
About Our Security Experts
The Small Business Security Guide editorial team is composed of independent cybersecurity analysts, risk assessment consultants, and technology writers. We focus exclusively on making enterprise-level security simple and accessible for small businesses.
Ready to Secure Your Business?
Download our free Cybersecurity Checklist for 10 Employees or take our free security assessment.