Glossary

A plain-English reference for IT and cybersecurity terms, organized by topic

An icon with a question mark inside a circle, indicating a mystery or unknown content.
Open book with a large letter A on the left page and several lines on the right page
Information icon with a lowercase 'i' inside a circle

Security & Protection

Authenticator app — A smartphone app that generates a temporary login code, used as part of multi-factor authentication. Why it matters: It's more secure than receiving codes by text message, since it isn't vulnerable to certain phone-based scams.

CIS (Center for Internet Security) Controls — A widely respected set of best-practice security guidelines that help organizations prioritize which protections matter most. Why it matters: It gives structure to "what should we focus on first," based on real-world threat data rather than guesswork.

Conditional access — Rules that adjust login requirements based on context, like requiring extra verification if someone logs in from an unfamiliar location or device. Why it matters: It adds smart, situational protection without making everyday logins more of a hassle.

Content filtering — A tool that blocks access to malicious, inappropriate, or risky websites before your team can accidentally visit them. Why it matters: It adds a layer of protection against threats that start with a single bad click, and helps keep browsing focused and safe.

Dark web monitoring — A service that watches hidden corners of the internet for stolen credentials tied to your business. Why it matters: It gives you an early warning if your information shows up somewhere it shouldn't, before it's used against you.

Data breach — An incident where sensitive information is accessed or exposed without authorization. Why it matters: Beyond the immediate disruption, a breach can affect client trust and, depending on your industry, carry compliance consequences.

Email security — Tools and settings that filter out malicious emails before they reach your inbox. Why it matters: Since email is the most common way attacks get in, this is often your first line of defense.

Encryption — A method of scrambling data so it can only be read by someone with the proper key or credentials. Why it matters: Even if data is intercepted or stolen, encryption keeps it unreadable and effectively useless to whoever took it.

Endpoint detection and response (EDR) — Advanced monitoring software that watches devices for suspicious behavior and can automatically respond to stop a threat in progress. Why it matters: It goes a step beyond traditional antivirus, catching and containing threats that might otherwise slip through.

Endpoint monitoring — Ongoing, automated oversight of every device connecting to your network — laptops, desktops, phones — to catch suspicious activity early. Why it matters: Threats are caught and addressed before they turn into a bigger problem.

Identity threat detection and response (ITDR) — Monitoring focused specifically on user accounts and logins, designed to catch signs that someone's credentials have been stolen or misused. Why it matters: Attackers increasingly target logins directly rather than devices, so this closes a gap that device-focused security alone doesn't cover.

Least privilege access — A security principle where people are only given the access they actually need to do their job, and nothing more. Why it matters: It limits the damage if an account is ever compromised, since there's less for an attacker to reach.

Malware — Any software designed to damage, disrupt, or gain unauthorized access to your systems. Why it matters: It's the broad category that phishing, ransomware, and viruses all fall under — knowing the term helps you understand what your protection is actually guarding against.

Multi-factor authentication (MFA) — A login process that requires a second step beyond your password, like a code generated by an authenticator app on your phone. Why it matters: It's one of the simplest, most effective ways to keep someone from breaking into your accounts, even if they steal a password.

NIST (National Institute of Standards and Technology) Cybersecurity Framework — A framework developed by a U.S. government agency that outlines a structured approach to managing and reducing cybersecurity risk. Why it matters: Many industries and contracts reference NIST standards, so understanding it helps you gauge what "good security" looks like against an established, respected benchmark.

Passkey — A modern, passwordless way to log in using your device (fingerprint, face scan, or PIN) instead of typing a password. Why it matters: It's both more convenient and harder for attackers to steal or guess, since there's no password to leak in the first place.

Password manager — A secure tool that stores and generates strong, unique passwords for all your accounts. Why it matters: It removes the temptation to reuse weak passwords, which is one of the easiest ways accounts get compromised.

Phishing — A fake email, text, or message designed to look legitimate so it can trick you into clicking a bad link or sharing sensitive information. Why it matters: It's one of the most common ways businesses get compromised — and often starts with something as simple as a convincing email.

Ransomware — Malicious software that locks up your files and demands payment to get them back. Why it matters: An attack can bring your business to a standstill, which is exactly why prevention and fast recovery both matter.

Security awareness training — Ongoing education that helps your team recognize scams and risky behavior. Why it matters: Your employees are often the first line of defense — a little training goes a long way.

Security operations center (SOC) — A team (often outsourced) that monitors your systems around the clock, watching for and responding to security threats in real time. Why it matters: Threats don't wait for business hours, so having eyes on your systems continuously means issues get caught faster, no matter when they happen.

Sensitivity labels — Tags applied to documents and emails (like "Confidential" or "Public") that control how they can be shared and whether protections like encryption are automatically applied. Why it matters: It helps make sure sensitive information stays protected even as it moves between people, without your team having to think about it every time.

Social engineering — Manipulation tactics used to trick people (rather than systems) into giving up information or access. Why it matters: No amount of technology fully replaces awareness — this is why training your team matters as much as the tools you use.

Zero-day threat — A newly discovered vulnerability that attackers exploit before a fix is available. Why it matters: It's a reminder that no system is ever "finished" being protected, which is why ongoing monitoring matters more than a one-time setup.

Backup & Data Protection

3-2-1 backup rule — A best-practice approach: keep 3 copies of your data, on 2 different types of storage, with 1 copy stored offsite. Why it matters: It protects you against nearly every way data can be lost — hardware failure, theft, fire, or an attack — because you're never relying on a single point of failure.

Business continuity — The broader strategy for keeping your business operating during and after a disruption, of which disaster recovery is one part. Why it matters: It's about more than data — it's about making sure your team can keep working no matter what happens.

Cloud backup — Data backup stored securely offsite via the internet, rather than on physical hardware in your office. Why it matters: It protects you even if something happens to your physical location.

Data backup — A saved copy of your business's files and systems, kept separately so it can be restored if something goes wrong. Why it matters: It's the difference between a bad day and a business-ending event.

Data retention — How long your business keeps different types of data before it's deleted or archived. Why it matters: The right retention policy balances compliance needs with keeping your systems clean and efficient.

Disaster recovery — The plan and process for getting your systems back up and running after a major disruption. Why it matters: Having a plan in place before something happens is what turns a crisis into a manageable setback.

Email archiving — Long-term, searchable storage of your email history, separate from your regular inbox. Why it matters: It helps with compliance requirements and makes it easy to retrieve old messages when you need them.

Ransomware recovery — The process of restoring your systems and data after a ransomware attack, ideally without paying the attacker. Why it matters: Solid backups are what make it possible to recover on your own terms, rather than someone else's.

Recovery point objective (RPO) — The maximum amount of data (measured in time) your business can afford to lose in an incident. Why it matters: It shapes how often your backups run — the smaller this number, the less you stand to lose.

Recovery time objective (RTO) — The target amount of time it should take to restore your systems after an incident. Why it matters: Knowing this number helps you understand how much downtime to expect — and plan for — if something goes wrong.

General IT & Managed Services

Azure AD / Entra ID — Microsoft's cloud-based system for managing user identities and logins across your business's accounts and apps (Microsoft renamed Azure AD to Entra ID). Why it matters: It's the foundation that many other security tools, like conditional access and MFA, are built on top of.

Cloud computing — Using software and storage hosted on the internet rather than on physical servers in your office. Why it matters: It offers flexibility and accessibility, letting your team work from anywhere with the right protections in place.

Compliance — Meeting the legal, industry, or regulatory requirements that apply to how your business handles data. Why it matters: Requirements vary by industry, but falling short can carry real financial and reputational risk.

Domain controller — A server that manages logins and security permissions across your business's network. Why it matters: It's the behind-the-scenes system that keeps track of who's allowed to access what.

Downtime — Any period when your systems or services aren't available or working. Why it matters: Even short amounts of downtime can mean lost revenue and frustrated clients — minimizing it is a core part of what good IT support does.

Help desk / IT support — The team you contact when you need technical help — anything from a printer issue to a login problem. Why it matters: Quick, friendly support means less time your team spends stuck instead of working.

IT infrastructure — The combination of hardware, software, and networks that keep your business's technology running. Why it matters: Understanding the basics helps you have more informed conversations with your IT provider.

Managed IT services (MSP) — Ongoing, outsourced IT support and management, rather than calling someone only when something breaks. Why it matters: It shifts your IT from reactive firefighting to proactive care, which usually means fewer surprises.

Network security — The practices and tools that protect your business's internal network from unauthorized access. Why it matters: It's the foundation everything else — devices, data, communication — relies on to stay safe.

Patch management — The process of keeping software and systems updated with the latest security fixes. Why it matters: Outdated software is one of the most common ways businesses get compromised — staying current closes those gaps.

Proactive IT support (vs. break-fix) — An approach focused on preventing problems before they happen, rather than waiting for something to break. Why it matters: It's usually far less disruptive — and often less costly — than dealing with issues after the fact.

Remote monitoring and management (RMM) — Technology that allows your IT provider to keep an eye on your systems and fix many issues remotely, often before you notice a problem. Why it matters: Many issues get caught and resolved before they ever affect your day.

VoIP (voice over IP) — Phone service that runs over the internet rather than traditional phone lines. Why it matters: It's often more flexible and cost-effective, especially for growing or multi-location businesses.