GUIDE / Glossary
The words, in plain language.
Security jargon is a barrier on purpose for nobody. Here is what the common terms actually mean, tagged by whether each is an attack, a defence, a concept, a tool or an event.
26 of 26 terms
- Phishingattack
- A message that pretends to come from someone you trust so that you click a link, open a file, hand over a password or approve a payment. By email it is phishing; by text it is often called smishing; by phone, vishing.
- Social engineeringattack
- Manipulating a person rather than a computer: using urgency, authority, fear or helpfulness to get someone to do something they should not. Phishing is the most common form.
- Two-factor authentication (2FA / MFA)defence
- Proving who you are with two different things, usually a password plus a code from an app, a prompt on your phone, or a physical key. A stolen password alone is then not enough to sign in.
- Passkeydefence
- A newer way to sign in without a password, using your phone or computer’s own lock (fingerprint, face, PIN). Passkeys only work on the genuine site, so they cannot be phished.
- Password managerdefence
- An app that creates a long random password for every account and fills it in for you. You remember one strong passphrase; it remembers the rest.
- Passphrasedefence
- A password made of several unrelated words, such as "copper kettle whistles dawn". Long, memorable and much harder to guess than a short word with symbols.
- Breachevent
- When an organisation loses data it holds, usually to attackers who copy it. If your email and password were in a breach, assume criminals are trying that pair on other sites.
- Credential stuffingattack
- Taking email-and-password pairs from one breach and trying them automatically on many other services. It works because people reuse passwords.
- Password sprayingattack
- Trying a handful of very common passwords (like "Autumn2026!") against a large number of accounts, slowly enough to avoid lockouts. It catches anyone using a predictable password.
- Brute forceattack
- Guessing every possible combination. Practical only against short passwords, which is why length matters more than complexity.
- Hashconcept
- A scrambled version of a password that sites store instead of the password itself. If a database of hashes is stolen, attackers guess passwords offline by hashing candidates and comparing. Weak passwords fall first.
- Ransomwareattack
- Malicious software that encrypts your files and demands payment for the key. Often arrives through phishing or unpatched software. An offline or cloud backup is the real defence.
- Malwareattack
- Any software designed to do harm: viruses, ransomware, spyware, and tools that steal saved passwords. It usually arrives through downloads, attachments or unpatched holes.
- Patch / updatedefence
- A fix for a bug in software, often a security hole. Once a patch is published the hole becomes public knowledge, so installing promptly matters.
- Vulnerabilityconcept
- A flaw in software that an attacker can use. An "exploit" is the method of using it. "Zero-day" means the maker had zero days’ warning before it was used.
- Encryptiondefence
- Scrambling data so only someone with the right key can read it. Keeps a stolen laptop’s files private, and keeps your connection to a website private from the network in between.
- VPNtool
- A virtual private network encrypts your connection to a server elsewhere, hiding your traffic from the local network. Useful on public Wi-Fi; not a defence against phishing, malware or weak passwords.
- Firewalldefence
- A filter that blocks unwanted connections into a device or network. Modern phones, computers and routers include one; it should simply stay on.
- SIM swappingattack
- Convincing a phone carrier to move your number to a criminal’s SIM. They then receive your text-message codes. A carrier account PIN and app-based 2FA reduce the risk.
- Business email compromise (BEC)attack
- Impersonating a boss, colleague or supplier by email to trigger a payment or a change of bank details. Defeated by confirming through a known phone number.
- Spoofingattack
- Faking the sender of an email, the caller ID of a phone call, or the look of a website. Because senders can be faked, judge the request rather than the name on it.
- Lookalike domainattack
- A web address designed to resemble a real one: "northbridge-secure-login.com" for "northbridge.com", or a capital I for a lowercase l. Bookmarks protect you from these.
- Backupdefence
- A separate, recent copy of your important files, kept where the original device cannot delete it. The recovery plan for ransomware, theft and hardware failure alike.
- Least privilegeconcept
- Giving each person, app or account only the access it actually needs. Fewer keys means a single mistake unlocks less.
- Security questionconcept
- A "secret" answer used to reset passwords, often findable online (pet names, schools, birthplaces). Answer with a random made-up phrase stored in your password manager.
- Cookie / sessionconcept
- A small token your browser keeps after you sign in so you stay signed in. If malware steals it, an attacker can act as you without a password, which is one reason to keep devices clean and updated.