Cybersecurity Glossary: 40 Terms Explained in Plain English

Security articles are full of acronyms and technical terms. Use this glossary as a quick reference whenever you meet an unfamiliar word.
Accounts and access
- 2FA / MFA: a second proof of identity besides your password.
- Passkey: a cryptographic login stored on your device that replaces a password.
- SSO: signing in to many services through one trusted account.
- Credential stuffing: trying leaked passwords on other sites.
- Brute force: guessing passwords by trying every combination.
Attacks
- Phishing: a fake message designed to steal information.
- Smishing / vishing: phishing by text message or phone call.
- Malware: software designed to cause harm.
- Ransomware: malware that locks files and demands payment.
- Spyware / stalkerware: software that secretly monitors a device.
- Zero-day: a flaw attackers exploit before a fix exists.
- Man-in-the-middle: an attacker secretly intercepting communication.
- Social engineering: manipulating people instead of breaking systems.
Defences
- Encryption: scrambling data so only authorised people can read it.
- End-to-end encryption: only the sender and recipient can read the message.
- Firewall: a filter for network traffic.
- VPN: an encrypted tunnel between your device and a server.
- Patch: a software update that fixes a security flaw.
- Sandbox: an isolated area to run untrusted code.
Privacy
- Cookie: a small file websites use to remember you.
- Tracker: code that follows activity across sites.
- Fingerprinting: identifying you by browser and device details.
- Metadata: data about data, such as who you contacted and when.
- Data broker: a company that collects and sells personal data.
- PII: personally identifiable information such as name, address or ID number.
Key takeaway: Bookmark this page. Understanding a handful of terms makes security advice much easier to follow and apply.


