Kasspar kasspar.com
GUIDE / Glossary

The words, in plain language.

Security jargon is a barrier on purpose for nobody. Here is what the common terms actually mean, tagged by whether each is an attack, a defence, a concept, a tool or an event.

26 of 26 terms
Phishingattack
A message that pretends to come from someone you trust so that you click a link, open a file, hand over a password or approve a payment. By email it is phishing; by text it is often called smishing; by phone, vishing.
Social engineeringattack
Manipulating a person rather than a computer: using urgency, authority, fear or helpfulness to get someone to do something they should not. Phishing is the most common form.
Two-factor authentication (2FA / MFA)defence
Proving who you are with two different things, usually a password plus a code from an app, a prompt on your phone, or a physical key. A stolen password alone is then not enough to sign in.
Passkeydefence
A newer way to sign in without a password, using your phone or computer’s own lock (fingerprint, face, PIN). Passkeys only work on the genuine site, so they cannot be phished.
Password managerdefence
An app that creates a long random password for every account and fills it in for you. You remember one strong passphrase; it remembers the rest.
Passphrasedefence
A password made of several unrelated words, such as "copper kettle whistles dawn". Long, memorable and much harder to guess than a short word with symbols.
Breachevent
When an organisation loses data it holds, usually to attackers who copy it. If your email and password were in a breach, assume criminals are trying that pair on other sites.
Credential stuffingattack
Taking email-and-password pairs from one breach and trying them automatically on many other services. It works because people reuse passwords.
Password sprayingattack
Trying a handful of very common passwords (like "Autumn2026!") against a large number of accounts, slowly enough to avoid lockouts. It catches anyone using a predictable password.
Brute forceattack
Guessing every possible combination. Practical only against short passwords, which is why length matters more than complexity.
Hashconcept
A scrambled version of a password that sites store instead of the password itself. If a database of hashes is stolen, attackers guess passwords offline by hashing candidates and comparing. Weak passwords fall first.
Ransomwareattack
Malicious software that encrypts your files and demands payment for the key. Often arrives through phishing or unpatched software. An offline or cloud backup is the real defence.
Malwareattack
Any software designed to do harm: viruses, ransomware, spyware, and tools that steal saved passwords. It usually arrives through downloads, attachments or unpatched holes.
Patch / updatedefence
A fix for a bug in software, often a security hole. Once a patch is published the hole becomes public knowledge, so installing promptly matters.
Vulnerabilityconcept
A flaw in software that an attacker can use. An "exploit" is the method of using it. "Zero-day" means the maker had zero days’ warning before it was used.
Encryptiondefence
Scrambling data so only someone with the right key can read it. Keeps a stolen laptop’s files private, and keeps your connection to a website private from the network in between.
VPNtool
A virtual private network encrypts your connection to a server elsewhere, hiding your traffic from the local network. Useful on public Wi-Fi; not a defence against phishing, malware or weak passwords.
Firewalldefence
A filter that blocks unwanted connections into a device or network. Modern phones, computers and routers include one; it should simply stay on.
SIM swappingattack
Convincing a phone carrier to move your number to a criminal’s SIM. They then receive your text-message codes. A carrier account PIN and app-based 2FA reduce the risk.
Business email compromise (BEC)attack
Impersonating a boss, colleague or supplier by email to trigger a payment or a change of bank details. Defeated by confirming through a known phone number.
Spoofingattack
Faking the sender of an email, the caller ID of a phone call, or the look of a website. Because senders can be faked, judge the request rather than the name on it.
Lookalike domainattack
A web address designed to resemble a real one: "northbridge-secure-login.com" for "northbridge.com", or a capital I for a lowercase l. Bookmarks protect you from these.
Backupdefence
A separate, recent copy of your important files, kept where the original device cannot delete it. The recovery plan for ransomware, theft and hardware failure alike.
Least privilegeconcept
Giving each person, app or account only the access it actually needs. Fewer keys means a single mistake unlocks less.
Security questionconcept
A "secret" answer used to reset passwords, often findable online (pet names, schools, birthplaces). Answer with a random made-up phrase stored in your password manager.
Cookie / sessionconcept
A small token your browser keeps after you sign in so you stay signed in. If malware steals it, an attacker can act as you without a password, which is one reason to keep devices clean and updated.