Cybersecurity glossary

    Cybersecurity and human risk glossary

    Clear, self-contained definitions of the terms that matter: from social engineering and phishing to human risk management, retesting and leaked credentials.

    45terms defined6categories

    Showing 45 terms

    Account takeover (ATO)

    Taking control of a legitimate account with stolen credentials. From inside, the attacker reads, impersonates and escalates without raising alarms.

    Credentials & identity

    Attack surface

    The set of points where an attacker can try to get in: exposed systems, accounts, vendors and, above all, people.

    Security concepts

    Botnet

    A network of infected machines an attacker controls remotely to send spam, launch denial-of-service attacks or distribute malware.

    Malware & infrastructure

    Brute force attack

    Systematically trying password combinations until the right one is found. Its viability depends on password length and attempt limits.

    Credentials & identity

    Business email compromise (BEC)

    Fraud where the attacker poses as an executive or vendor from a legitimate or spoofed mailbox to divert payments or data. It usually carries no malware.

    Social engineering & phishing

    Click rate

    The percentage of people who click a phishing simulation. Useful as a signal, misleading as the only metric of a program.

    Human risk & behavior

    ClickFix

    An attack where victims run the malicious code themselves, following instructions from a fake verification step or error fix.

    Social engineering & phishing

    Credential stuffing

    Automated testing of credentials stolen from one service against many others. It works because people reuse passwords.

    Credentials & identity

    Dark web

    The part of the internet reachable only with special software, where anonymity enables markets for stolen credentials, malware and corporate access.

    Data & leaks

    Dark web monitoring

    Continuous surveillance of breaches and criminal markets to detect exposed company credentials or data, and react in hours instead of months.

    Data & leaks

    Data breach

    An incident where protected information is accessed, stolen or exposed without authorization. Its credentials fuel the next attacks.

    Data & leaks

    Data exfiltration

    Unauthorized transfer of information from the victim's systems to the attacker. It is the end goal of most intrusions.

    Data & leaks

    Data leak

    Exposure of sensitive information with no attack involved: a misconfigured database, an overshared file, an email to the wrong recipient.

    Data & leaks

    Deepfake

    Synthetic audio or video that imitates a real person. Applied to fraud, it turns a video call or voice note into an impersonation tool.

    Social engineering & phishing

    Human factor

    The human dimension of cybersecurity risk: the decisions and habits of people that an attacker can exploit. It is not a synonym for blame.

    Human risk & behavior

    Human risk management (HRM)

    The discipline that measures and reduces the security risk originating in people's behavior, using continuous data instead of annual courses.

    Human risk & behavior

    Human risk score

    An indicator that summarizes the security risk of a person or team based on observed behavior: simulations, exposed credentials, retests.

    Human risk & behavior

    Infostealer

    Malware that silently steals credentials, cookies and browser data, packaging them for sale on the dark web as stealer logs.

    Malware & infrastructure

    Keylogger

    Software or hardware that records every keystroke to capture passwords and conversations. A classic piece of digital espionage.

    Malware & infrastructure

    Leaked credentials

    Usernames and passwords exposed in breaches or stolen by malware, circulating on the dark web. They are the raw material of initial access to companies.

    Credentials & identity

    Malware

    Any software designed to damage, spy on or take control of a system without authorization. It almost always needs a person to let it in.

    Malware & infrastructure

    MFA fatigue

    A barrage of approval notifications until the victim accepts out of exhaustion. The attacker already has the password; only the second factor is missing.

    Credentials & identity

    Microlearning

    Training in short, specific doses delivered at the moment of the mistake. It uses the instant when a person is most receptive to learning.

    Human risk & behavior

    Multi-factor authentication (MFA)

    Identity verification with two or more independent factors. It makes a stolen password insufficient, though not invulnerable.

    Credentials & identity

    OSINT

    Intelligence built from public sources: websites, social media, records. The same information serves defense and attack preparation.

    Security concepts

    Password spraying

    An attack that tries a few common passwords against many accounts, instead of many passwords against one. That way it avoids lockouts.

    Credentials & identity

    Phishing

    An attack that impersonates a trusted sender, such as a bank, a colleague or a vendor, to steal credentials, data or money, or install malware.

    Social engineering & phishing

    Phishing simulation

    A controlled phishing attack a company sends to its own employees to measure who falls, for which kind of lure, and how often.

    Human risk & behavior

    Pretexting

    Social engineering built on an invented but plausible story: an audit, a vendor, a technician. The pretext justifies asking for data or access.

    Social engineering & phishing

    Quishing

    Phishing via QR code. The malicious link travels as an image, slips past email filters and opens on the phone, outside corporate defenses.

    Social engineering & phishing

    Ransomware

    Malware that encrypts the victim's data and demands payment to release it. It now adds the threat of publishing what was stolen if no payment is made.

    Malware & infrastructure

    Report rate

    The percentage of people who report a simulation or a real attack. It is the best early indicator of a security culture that works.

    Human risk & behavior

    Retest

    A new simulation of the same attack category, weeks after a failure and with a different template, to verify the person actually changed their behavior.

    Human risk & behavior

    Security awareness

    Programs that teach employees to recognize and report threats. Completing courses does not equal changed behavior: that is validated with a retest.

    Human risk & behavior

    Security culture

    What employees do about security when nobody is watching: reporting, verifying, asking. It is built through practice, not posters.

    Human risk & behavior

    Session hijacking

    Stealing the cookie or token that keeps an authenticated session open. It grants entry without a password and without a second factor.

    Credentials & identity

    Shadow AI

    Use of AI tools without company approval: sensitive data pasted into chatbots and decisions based on outputs nobody validates.

    Security concepts

    Shadow IT

    Tools and services employees use without IT approval. Every invisible account is risk that nobody is watching.

    Security concepts

    Smishing

    Phishing via SMS or mobile messaging. It exploits trust in the phone and the absence of filters: the message arrives direct, short and with a link.

    Social engineering & phishing

    Social engineering

    Psychological manipulation that leads a person to hand over information, access or money. It is the starting point of most successful cyberattacks.

    Social engineering & phishing

    Spear phishing

    Phishing aimed at a specific person, built with real data about their role, company and tools. Far more effective than mass campaigns.

    Social engineering & phishing

    Spoofing

    Forging a sender's identity: email, domain, phone number or website. It is the technical layer that makes impersonation believable.

    Social engineering & phishing

    Threat actor

    Any person or group with the intent and capability to attack: organized crime, state groups, hacktivists or insiders. Knowing them orders your defense.

    Security concepts

    Vishing

    Social engineering over a phone call. The attacker poses as tech support, a bank or a vendor to obtain access or payments in real time.

    Social engineering & phishing

    Whaling

    Spear phishing aimed at executives with signing power or privileged access. It goes after payments, strategic information or the executive's own mailbox.

    Social engineering & phishing