Reference
Cybersecurity Glossary
32 terms, written by the people who run the assessments - not summarised from other websites.
A
- What is AI Red Teaming?
AI red teaming is adversarial testing of an AI system - deliberately attempting to make a model produce harmful output, leak data, or misuse its tools, in order to find failures before real users do.
Red Team & Adversary Emulation
- What is API Security?
API security is the practice of protecting the interfaces applications use to talk to each other - enforcing authentication, authorisation, input validation and rate limiting on every endpoint rather than relying on the client.
API Security
B
- What is BOLA?
BOLA (Broken Object Level Authorisation) is an API flaw where an endpoint checks that a caller is logged in but not whether they own the record they requested, letting anyone read or change other users’ data.
API Security
- What is Broken Access Control?
Broken access control is a flaw where users can act outside their intended permissions - reading, changing or deleting data belonging to others - because the application fails to enforce who is allowed to do what.
Web Application Security
C
- What is a CVE?
A CVE (Common Vulnerabilities and Exposures) is a unique public identifier assigned to a specific known security vulnerability, so that everyone referring to it means exactly the same flaw.
Vulnerability Management
- What is CSPM?
Cloud Security Posture Management is tooling that continuously inspects your cloud configuration against security benchmarks, flagging misconfigurations such as public storage, over-permissioned roles and disabled logging.
Cloud Security
- What is CSRF?
Cross-site request forgery is an attack that tricks a logged-in user’s browser into sending an unintended request to your site, performing an action as that user without their knowledge.
Web Application Security
- What is CVSS?
CVSS (Common Vulnerability Scoring System) is an open standard that rates a vulnerability’s technical severity from 0.0 to 10.0, giving a consistent way to compare issues across different systems and vendors.
Vulnerability Management
E
- What is EDR?
EDR (Endpoint Detection and Response) is an agent installed on laptops and servers that records process, file and network activity, flags malicious behaviour, and lets a responder isolate or roll back the machine remotely.
SOC Operations
I
- What is IAM?
Identity and Access Management is the cloud system that defines who or what can perform which actions on which resources - the control that decides whether a compromised component becomes a full breach.
Cloud Security
J
- What is a JWT?
A JSON Web Token is a signed, self-contained token that carries user identity and claims, letting a server verify who a request is from without looking anything up in a database.
API Security
L
- What is Lateral Movement?
Lateral movement is how an attacker travels through a network after their initial break-in, moving from the first compromised machine toward the systems that actually hold value.
Red Team & Adversary Emulation
- What is LLM Security?
LLM security is the practice of protecting applications built on large language models, covering prompt injection, data leakage, unsafe tool use, supply chain risk and the handling of model output as untrusted input.
Security Engineering
M
- What is MFA?
Multi-factor authentication requires more than one form of proof to sign in - typically a password plus a code or hardware key - so that a stolen password alone is not enough to take over an account.
Zero Trust
- What is MITRE ATT&CK?
MITRE ATT&CK is a free, structured knowledge base of the tactics and techniques attackers use in real intrusions, giving defenders a shared vocabulary for describing and measuring detection coverage.
Threat Intelligence
- What is Model Poisoning?
Model poisoning is an attack that corrupts an AI model by tampering with its training data or weights, embedding hidden behaviour that activates on a trigger the attacker controls.
Security Engineering
O
- What is the OWASP Top 10?
The OWASP Top 10 is a regularly updated list of the ten most critical web application security risks, published by the Open Worldwide Application Security Project as an awareness and baseline testing standard.
Web Application Security
P
- What is Penetration Testing?
Penetration testing is an authorised simulated attack on your systems, carried out by security professionals, to find and prove exploitable weaknesses before a real attacker does.
Vulnerability Management
- What is Prompt Injection?
Prompt injection is an attack where text supplied to an AI system is interpreted as instructions rather than data, causing the model to ignore its original directions and follow the attacker’s instead.
Security Engineering
R
- What is Red Teaming?
Red teaming is a goal-driven adversary simulation that tests whether an organisation can detect and respond to a realistic attack, rather than trying to enumerate every vulnerability.
Red Team & Adversary Emulation
S
- What is a SOC?
A Security Operations Centre is the team and tooling responsible for monitoring an organisation’s systems, triaging alerts, and responding to security incidents - either in-house or delivered as a managed service.
SOC Operations
- What is an S3 Bucket Misconfiguration?
An S3 bucket misconfiguration is a cloud storage container left readable or writable by the public, exposing whatever it holds - a recurring cause of large data breaches involving no exploitation at all.
Cloud Security
- What is SIEM?
SIEM (Security Information and Event Management) is software that collects log data from across your systems, correlates it in one place, and raises alerts when the combined picture looks like an attack.
SOC Operations
- What is SQL Injection?
SQL injection is a vulnerability where untrusted input is inserted into a database query, letting an attacker change what the query does - reading, modifying or deleting data they should never reach.
Web Application Security
- What is SSRF?
Server-side request forgery is a vulnerability where an attacker makes your server send HTTP requests to destinations of their choosing, reaching internal systems that were never meant to be reachable from outside.
Web Application Security
T
- What is Threat Hunting?
Threat hunting is the proactive search for attackers already inside your environment, driven by hypotheses about adversary behaviour rather than waiting for an alert to fire.
Blue Team & Defensive Security
V
- What is a Vulnerability Assessment?
A vulnerability assessment is a systematic scan of your systems that identifies and ranks known security weaknesses, producing an inventory of what needs fixing without attempting to exploit anything.
Vulnerability Management
- What is VAPT?
VAPT (Vulnerability Assessment and Penetration Testing) combines automated scanning for breadth with manual exploitation for depth, giving you both a full inventory of weaknesses and proof of which ones actually matter.
Vulnerability Management
X
- What is Cross-Site Scripting (XSS)?
Cross-site scripting is a vulnerability where an attacker gets their JavaScript to run in another user’s browser on your site, letting them steal session data, alter the page, or act as that user.
Web Application Security
- What is XDR?
XDR (Extended Detection and Response) is a platform that correlates security telemetry across endpoints, network, cloud and identity in one place, aiming to detect attacks that look harmless in any single source.
SOC Operations
Z
- What is a Zero-Day?
A zero-day is a vulnerability that is being exploited before the vendor has released a fix, leaving defenders with zero days of warning to patch against an attack already in progress.
Vulnerability Management
- What is Zero Trust?
Zero trust is a security model that stops treating network location as proof of trustworthiness, requiring every request to be authenticated and authorised regardless of where it originates.
Zero Trust
Next Step
Reading is not testing.
If any of this sounds like your stack, we will scope an assessment and tell you exactly what it costs.
Mutual NDA before scoping · Reply within 4 business hours