Cybersecurity Glossary
A comprehensive guide to cybersecurity terminology. Learn the language of security with 45+ terms explained in plain English.
A sophisticated, long-term cyberattack where an intruder gains access to a network and remains undetected for an extended period. APTs are typically state-sponsored and target high-value organizations.
API Security
Security PracticesThe practice of protecting Application Programming Interfaces (APIs) from attacks and misuse. Includes authentication, authorization, input validation, and rate limiting.
Attack Surface
ConceptsThe sum of all potential entry points where an unauthorized user can access a system. Includes network interfaces, software, hardware, and human factors.
Authentication
Access ControlThe process of verifying the identity of a user, device, or system. Common methods include passwords, biometrics, tokens, and multi-factor authentication.
Black Box Testing
Penetration TestingA penetration testing approach where the tester has no prior knowledge of the target system. Simulates an external attacker with no inside information.
Brute Force Attack
Attack TypesAn attack method that uses trial-and-error to guess login credentials, encryption keys, or hidden web pages by systematically trying all possible combinations.
Bug Bounty
Security ProgramsA program offered by organizations that rewards security researchers for discovering and responsibly disclosing vulnerabilities in their systems.
General guidelines issued by Bank Negara Malaysia outlining expectations for risk management, infrastructure controls, and operational safety for financial institutions.
CREST Certification
CertificationsCouncil for Registered Ethical Security Testers. An international certification body that provides assurance of penetration testing quality, security methodologies, and ethical standards.
Cross-Site Scripting (XSS)
Web VulnerabilitiesA web security vulnerability that allows attackers to inject malicious scripts into web pages viewed by other users. Can steal session cookies, credentials, or perform actions on behalf of victims.
A standardized naming system for publicly known security vulnerabilities, each assigned a unique identifier (e.g., CVE-2026-1234).
A standardized framework for rating the severity of security vulnerabilities on a scale of 0-10 based on exploitability, impact, and complexity metrics.
Data Breach
IncidentsAn incident where sensitive, protected, or confidential data is accessed, copied, transmitted, or stolen by an unauthorized party.
DDoS Attack
Attack TypesDistributed Denial of Service. An attack that overwhelms a target with traffic from multiple sources, making services unavailable to legitimate users.
Defense in Depth
Security PracticesA security strategy that employs multiple layers of security controls throughout an IT system. If one layer fails, others continue to provide protection.
Encryption
CryptographyThe process of converting data into a coded format to prevent unauthorized access. Can be symmetric (same key) or asymmetric (public/private key pairs).
Endpoint Detection and Response (EDR)
Security ToolsSecurity solutions that continuously monitor and collect data from endpoints (laptops, servers, mobile devices) to detect, investigate, and respond to cyber threats.
Ethical Hacking
Penetration TestingAuthorized testing of computer systems to identify security vulnerabilities. Also known as penetration testing or white-hat hacking.
Firewall
Security ToolsA network security device that monitors and controls incoming and outgoing network traffic based on predetermined security rules.
Incident Response
Security PracticesThe organized approach to addressing and managing a security breach or cyberattack. Includes preparation, detection, containment, eradication, and recovery phases.
Intrusion Detection System (IDS)
Security ToolsA device or software that monitors network traffic for suspicious activity and alerts security teams when potential threats are detected.
Malware
ThreatsMalicious software designed to harm, exploit, or otherwise compromise computer systems. Includes viruses, worms, trojans, ransomware, and spyware.
Multi-Factor Authentication (MFA)
Access ControlAn authentication method requiring users to provide two or more verification factors (something you know, have, or are) to access a system.
NACSA (National Cyber Security Agency)
ComplianceMalaysia's lead government agency responsible for national cybersecurity strategy, threat intelligence, critical infrastructure protection, and policy coordination.
NACSA License
ComplianceA regulatory license issued by NACSA under the Cybersecurity Act to certify and regulate companies providing cybersecurity services in Malaysia.
OSCP
CertificationsOffensive Security Certified Professional. A hands-on penetration testing certification that requires passing a 24-hour practical exam focused on manual exploit development and system intrusion.
OWASP Top 10
StandardsA standard awareness document representing the most critical security risks to web applications, updated periodically by the Open Web Application Security Project.
Penetration Testing
Penetration TestingAn authorized simulated cyberattack performed to evaluate the security of a system by actively exploiting vulnerabilities. Identifies security gaps and validates control effectiveness.
Phishing
Attack TypesA social engineering attack using fraudulent communications (emails, messages) that appear legitimate to trick users into revealing sensitive information.
Privilege Escalation
Attack TypesAn attack technique where an attacker gains elevated access to resources that are normally protected from an application or user.
Purple Teaming
Penetration TestingA collaborative security methodology where offensive attackers (Red Team) and active defenders (Blue Team) work closely together in real-time to optimize detection capabilities.
Malaysia's Personal Data Protection Act 2010 (Act 709) regulating the processing of personal data in commercial transactions to safeguard individuals' privacy rights.
Ransomware
ThreatsMalware that encrypts a victim's files and demands payment for the decryption key. Often spreads through phishing emails or exploiting vulnerabilities.
Red Teaming
Penetration TestingA group of security professionals that simulate multi-vector real-world attacks to test an organization's physical, social, and technological defenses.
RMiT (Risk Management in Technology)
ComplianceBank Negara Malaysia's (BNM) mandatory policy document outlining requirements for technology risk management, cybersecurity resilience, and IT governance for financial institutions.
Security Operations Center (SOC)
Security OperationsA centralized unit that monitors, detects, analyzes, and responds to cybersecurity incidents using people, processes, and technology.
SIEM
Security ToolsSecurity Information and Event Management. Technology that aggregates and analyzes security data from across an organization to detect threats.
SQL Injection
Web VulnerabilitiesA code injection technique that exploits security vulnerabilities in an application's database layer by inserting malicious SQL statements.
Threat Actor
ThreatsAny individual or group that poses a threat to cybersecurity. Includes hacktivists, cybercriminals, nation-states, and insider threats.
Vulnerability
ConceptsA weakness in a system that can be exploited by a threat actor to gain unauthorized access or cause harm.
Vulnerability Assessment
Penetration TestingA systematic process of identifying, quantifying, and prioritizing security vulnerabilities in a system without attempting exploitation.
Web Application Firewall (WAF)
Security ToolsA security solution that monitors, filters, and blocks HTTP traffic to and from a web application to protect against web-based attacks.
Zero-Day Vulnerability
ThreatsA software security flaw unknown to the vendor and without a patch. Called 'zero-day' because developers have had zero days to fix it.
Zero Trust
Security PracticesA security framework requiring all users to be authenticated, authorized, and continuously validated before accessing applications and data.
Need Help With Your Security?
Understanding the terminology is just the first step. Let our experts help you implement proper security controls for your organization.
Not sure what you need?
Tell us what needs testing and we come back with a fixed fee within 48 hours — no hourly estimates.