173 key terms covering NIS2 compliance, vCISO services, cyber insurance, AI threats, incident response, and practical security — written for Irish business owners, not IT specialists.
Plain-English definitions of key cybersecurity terms, covering NIS2 compliance, vCISO services, cyber insurance, AI threats, incident response, and practical security for Irish SMEs.
Use the search box or A–Z index to find any term instantly.
Browse by Category
Every term is tagged with one of the site's topic clusters:
- AI & Emerging Threats
- Cyber Insurance
- Incident Response & Business Continuity
- NIS2 Compliance
- Pragmatic Security
- Remote & Hybrid Work Security
- Risk Management
- Security Awareness & Human Factors
- vCISO & Security Leadership
Cybersecurity Terms, A–Z
Access Control
A security mechanism that restricts who can view or use resources in a computing environment. Access control policies define which users, devices, or systems are permitted to access specific data or applications, and under what conditions. For Irish SMEs, strong access control — including role-based permissions and the principle of least privilege — is one of the most effective ways to limit the blast radius of a breach.
Advanced Persistent Threat (APT)
A sophisticated, long-term cyberattack in which an intruder gains access to a network and remains undetected for an extended period. APT actors — often nation-state groups or well-funded criminal organisations — are patient, methodical, and focused on high-value targets. While APTs typically target large enterprises and critical infrastructure, supply-chain attacks mean SMEs can be used as stepping stones into bigger organisations.
AI-Generated Malware
Malicious software created or enhanced using artificial intelligence tools, enabling attackers to produce novel variants faster than traditional signature-based defences can detect them. AI lowers the technical barrier for writing functional malware, meaning less-skilled threat actors can now produce sophisticated attacks. Endpoint Detection and Response (EDR) tools that use behavioural analysis are better equipped to catch AI-generated threats than legacy antivirus.
AI-Powered Phishing
Phishing attacks that use large language models (LLMs) to craft highly personalised, grammatically perfect lure emails at scale. Unlike traditional phishing, which is often identifiable by poor spelling or generic greetings, AI-powered phishing can mimic a colleague's writing style, reference real recent events, and pass basic human scrutiny. Security awareness training must evolve to account for the fact that employees can no longer rely on spotting obvious errors.
Asset Inventory
A complete, up-to-date register of all hardware, software, data, and services that an organisation owns or relies upon. You cannot protect what you do not know you have — asset inventory is the foundation of every effective security programme. NCSC Ireland's 12 Steps to Cyber Security lists asset management as the first and most critical control.
Attack Surface
The total set of points — hardware, software, network interfaces, user accounts, and third-party integrations — through which an attacker could potentially gain unauthorised access to a system. Reducing your attack surface by disabling unused services, removing unnecessary software, and enforcing least-privilege access is a core principle of good security hygiene.
Audit Log
A chronological record of events within a system, capturing who did what, when, and from where. Audit logs are essential for detecting suspicious activity, investigating incidents, and demonstrating compliance with regulations such as NIS2 and GDPR. Logs should be stored securely, retained for an appropriate period, and reviewed regularly — not just after an incident.
Authentication
The process of verifying that a user, device, or system is who or what it claims to be. Passwords alone are the weakest form of authentication; multi-factor authentication (MFA) adds one or more additional verification steps — such as a one-time code or biometric check — to significantly reduce the risk of unauthorised access.
Backup Strategy
A documented plan for creating, storing, and testing copies of critical data so that it can be recovered following a ransomware attack, hardware failure, or accidental deletion. The industry-standard approach is the 3-2-1-1-0 rule: three copies of data, on two different media types, with one copy offsite, one copy offline or immutable, and zero unverified backups.
BEC (Business Email Compromise)
A type of fraud in which an attacker impersonates a senior executive, supplier, or trusted contact via email to trick employees into transferring money or sensitive data. BEC attacks cost businesses billions globally each year and are often carried out without any malware — making them difficult for technical controls alone to catch. Staff training and payment verification procedures are the most effective defences.
Breach Notification
The legal obligation to inform regulators and, in some cases, affected individuals when a personal data breach occurs. Under GDPR, Irish businesses must notify the Data Protection Commission (DPC) within 72 hours of becoming aware of a qualifying breach. NIS2 introduces separate, stricter incident reporting timelines for in-scope organisations — including a 24-hour early warning, a 72-hour incident notification, and a 30-day final report.
BYOD (Bring Your Own Device)
A policy that allows employees to use their personal smartphones, laptops, or tablets for work purposes. BYOD increases flexibility and can reduce hardware costs, but it also introduces significant security risks — personal devices may lack corporate security controls, run outdated software, or be shared with family members. A formal BYOD policy should define acceptable use, minimum security requirements, and the organisation's right to remotely wipe corporate data.
CISA (Certified Information Systems Auditor)
A globally recognised professional certification awarded by ISACA, validating expertise in auditing, controlling, and monitoring information systems. CISA-certified professionals are qualified to assess whether an organisation's IT controls are adequate, functioning correctly, and aligned with business objectives. It is one of the most respected credentials in the information security and IT audit profession.
CISM (Certified Information Security Manager)
A management-focused certification from ISACA that validates expertise in information security governance, risk management, incident management, and programme development. CISM is designed for practitioners who design and manage enterprise security programmes rather than those focused on technical implementation. It is widely recognised by employers and regulators as a mark of security leadership competence.
CISSP (Certified Information Systems Security Professional)
Widely regarded as the gold standard of cybersecurity certifications, the CISSP is awarded by ISC2 and covers eight domains of security knowledge — from security architecture and engineering to identity management and software development security. It requires a minimum of five years of professional experience and is recognised globally as a mark of senior security expertise.
CISO (Chief Information Security Officer)
The senior executive responsible for an organisation's information security strategy, governance, and risk management. The CISO reports to the board or CEO, translates technical risk into business language, and ensures that security investment is aligned with organisational objectives. Many SMEs cannot justify a full-time CISO — which is why the virtual CISO (vCISO) model has become increasingly popular.
Cloud Security
The set of policies, controls, and technologies designed to protect data, applications, and infrastructure hosted in cloud environments such as Microsoft Azure, AWS, or Google Cloud. Cloud security is a shared responsibility — the cloud provider secures the underlying infrastructure, while the customer is responsible for securing their data, access controls, and configurations. Misconfigured cloud storage is one of the most common causes of data breaches.
COBIT (Control Objectives for Information and Related Technologies)
A governance and management framework for enterprise IT, developed by ISACA. COBIT provides a comprehensive set of controls and best practices for aligning IT activities with business goals, managing risk, and ensuring compliance. It is widely used by auditors and security professionals to design and assess IT governance programmes.
Compliance
The state of adhering to laws, regulations, standards, or contractual obligations relevant to an organisation's operations. In the cybersecurity context, compliance typically refers to meeting the requirements of frameworks such as NIS2, GDPR, ISO 27001, or sector-specific regulations. Compliance is a floor, not a ceiling — it establishes minimum acceptable standards but does not guarantee that an organisation is genuinely secure.
Cyber Essentials
A UK government-backed certification scheme that helps organisations protect themselves against the most common cyber threats. It covers five technical controls: firewalls, secure configuration, user access control, malware protection, and patch management. While not yet mandatory in Ireland, Cyber Essentials is increasingly referenced in procurement requirements and provides a useful baseline for SMEs starting their security journey.
Cyber Insurance
A specialist insurance product that covers financial losses arising from cyberattacks, data breaches, and related incidents. Policies typically cover costs such as incident response, legal fees, regulatory fines, business interruption, and customer notification. Insurers are increasingly requiring policyholders to demonstrate minimum security controls — such as MFA and tested backups — before issuing or renewing coverage.
Cyber Kill Chain
A framework developed by Lockheed Martin that describes the stages of a cyberattack: reconnaissance, weaponisation, delivery, exploitation, installation, command and control, and actions on objectives. Understanding the kill chain helps defenders identify where they can interrupt an attack before it reaches its goal. Disrupting an attack at the early stages — such as blocking delivery — is far less costly than responding after exploitation.
Cyber Resilience
The ability of an organisation to anticipate, withstand, recover from, and adapt to cyberattacks and security incidents. Resilience goes beyond prevention — it acknowledges that breaches will happen and focuses on minimising their impact and restoring normal operations quickly. NIS2 explicitly requires in-scope organisations to demonstrate cyber resilience, not just compliance with technical controls.
Dark Web Monitoring
A service that continuously scans dark web forums, marketplaces, and data dumps for an organisation's compromised credentials, stolen data, or mentions of their brand. When employee passwords or customer data appear on the dark web, it is often the first indicator that a breach has occurred — sometimes months before the organisation discovers it internally.
Data Breach
An incident in which sensitive, protected, or confidential data is accessed, disclosed, or stolen without authorisation. Data breaches can result from cyberattacks, accidental disclosure, insider threats, or lost/stolen devices. Under GDPR, Irish businesses must report qualifying breaches to the Data Protection Commission within 72 hours and may face significant fines for failures in data protection.
Data Protection Commission (DPC)
Ireland's national data protection supervisory authority, responsible for enforcing the General Data Protection Regulation (GDPR) and the Data Protection Act 2018. The DPC investigates complaints, conducts audits, and can impose fines of up to €20 million or 4% of global annual turnover for serious GDPR violations. Irish businesses that handle personal data must comply with DPC guidance and report qualifying data breaches within 72 hours.
Deepfake
Synthetic media — video, audio, or images — generated by artificial intelligence to convincingly portray a real person saying or doing something they did not. Deepfakes are increasingly being used in fraud, including CEO impersonation attacks where a fake audio or video call is used to authorise fraudulent payments. Verification procedures that do not rely solely on voice or video recognition are essential defences.
Defence in Depth
A security strategy that layers multiple independent controls so that if one fails, others remain in place. Rather than relying on a single firewall or antivirus product, defence in depth combines network controls, endpoint security, identity management, encryption, monitoring, and user training. No single control is perfect — layering them significantly raises the cost and complexity of a successful attack.
DDoS (Distributed Denial of Service)
An attack that overwhelms a website, server, or network with traffic from thousands of compromised machines simultaneously, making it unavailable to legitimate users. DDoS attacks are often used as a distraction while attackers carry out other malicious activity, or as a form of extortion. Cloud-based DDoS mitigation services can absorb large-scale attacks before they reach an organisation's infrastructure.
DMARC (Domain-based Message Authentication, Reporting and Conformance)
An email authentication protocol that prevents attackers from sending emails that appear to come from your domain — a technique known as email spoofing. DMARC builds on SPF and DKIM to tell receiving mail servers what to do with messages that fail authentication checks. Implementing DMARC is one of the most impactful and cost-effective email security controls available to Irish SMEs.
DORA (Digital Operational Resilience Act)
An EU regulation that establishes binding requirements for the digital operational resilience of financial entities — including banks, insurance companies, investment firms, and their critical ICT service providers. DORA came into force in January 2025 and requires in-scope organisations to implement robust ICT risk management, incident reporting, resilience testing, and third-party risk oversight. It operates alongside NIS2 but with sector-specific requirements.
EDR (Endpoint Detection and Response)
A security technology that continuously monitors endpoint devices — laptops, desktops, servers, and mobile devices — for signs of malicious activity, and provides tools to investigate and respond to threats. Unlike traditional antivirus, which relies on known malware signatures, EDR uses behavioural analysis to detect novel threats. EDR is now considered the minimum standard for endpoint protection in any organisation handling sensitive data.
Encryption
The process of converting data into an unreadable format using a cryptographic algorithm, so that only authorised parties with the correct decryption key can access it. Encryption protects data both at rest (stored on devices or servers) and in transit (moving across networks). Full-disk encryption on laptops and mobile devices is a critical control — if a device is lost or stolen, encrypted data remains inaccessible to the finder.
EU AI Act
The world's first comprehensive legal framework for artificial intelligence, adopted by the European Union in 2024. The EU AI Act classifies AI systems by risk level — from minimal to unacceptable — and imposes obligations on developers and deployers of high-risk AI. Irish businesses that use AI tools in hiring, credit scoring, critical infrastructure, or law enforcement contexts will need to assess their obligations under the Act.
Exposure Management
A continuous process of identifying, prioritising, and reducing the vulnerabilities and misconfigurations that could be exploited by an attacker. Exposure management goes beyond traditional vulnerability scanning by considering the business context and exploitability of each weakness — helping organisations focus remediation effort where it matters most.
Firewall
A network security device or software that monitors and controls incoming and outgoing network traffic based on predefined security rules. Firewalls act as a barrier between trusted internal networks and untrusted external networks such as the internet. Modern next-generation firewalls (NGFW) go beyond port and protocol filtering to inspect application-layer traffic and detect threats in real time.
Forensic Investigation
The systematic collection, preservation, and analysis of digital evidence following a security incident, with the goal of understanding what happened, how, and by whom. Digital forensics is critical for incident response, insurance claims, and potential legal proceedings. Evidence must be handled in a way that preserves its integrity and chain of custody — which is why engaging a qualified forensics professional is important.
Fractional CISO
Another term for a virtual CISO (vCISO) — a senior security professional engaged on a part-time or retainer basis rather than as a full-time employee. The fractional model gives SMEs access to board-level security leadership at a fraction of the cost of a full-time hire. The engagement can be structured as a fixed monthly retainer, a project-based arrangement, or a hybrid of both.
GDPR (General Data Protection Regulation)
The European Union's primary data protection law, which came into force in May 2018. GDPR grants individuals rights over their personal data and imposes obligations on organisations that collect, store, or process it — including requirements for lawful basis, data minimisation, security, and breach notification. Irish businesses are subject to GDPR and supervised by the Data Protection Commission (DPC).
Governance (Security Governance)
The framework of policies, processes, roles, and accountability structures through which an organisation directs and controls its information security activities. Good security governance ensures that security decisions are made at the right level, aligned with business objectives, and subject to appropriate oversight. It is a core component of the vCISO role and a key requirement under NIS2.
Human Firewall
The concept of employees as an active layer of security defence — able to recognise, resist, and report social engineering attacks, phishing emails, and suspicious activity. Building a human firewall requires ongoing security awareness training, clear reporting channels, and a culture where employees feel safe raising concerns without fear of blame.
IAM (Identity and Access Management)
A framework of policies and technologies that ensures the right individuals have access to the right resources at the right times, for the right reasons. IAM encompasses user provisioning, authentication, authorisation, single sign-on (SSO), and privileged access management (PAM). Weak IAM — such as shared accounts, excessive permissions, or no MFA — is one of the most common root causes of security breaches.
Incident Response
The organised approach to addressing and managing the aftermath of a security breach or cyberattack. An effective incident response plan defines roles and responsibilities, communication procedures, containment steps, eradication processes, and recovery actions. Having a tested plan in place before an incident occurs dramatically reduces the time to recovery and the overall cost of a breach.
Incident Response Retainer
A pre-arranged agreement with a cybersecurity firm to provide rapid incident response services when needed, typically at a pre-negotiated rate. Having a retainer in place means you are not scrambling to find qualified help in the middle of a crisis. Some cyber insurance policies require or incentivise the use of pre-approved incident response providers.
Insider Threat
A security risk that originates from within an organisation — typically a current or former employee, contractor, or business partner who misuses their authorised access. Insider threats can be malicious (deliberate sabotage or data theft) or unintentional (accidental data disclosure or falling for a phishing attack). Monitoring user behaviour, enforcing least-privilege access, and conducting offboarding procedures are key controls.
ISO 27001
The international standard for information security management systems (ISMS), published by the International Organisation for Standardisation. ISO 27001 provides a systematic framework for managing sensitive information, covering risk assessment, security controls, and continual improvement. Certification to ISO 27001 demonstrates to customers, partners, and regulators that an organisation takes information security seriously.
Least Privilege
A security principle that states users, applications, and systems should be granted only the minimum level of access required to perform their function — nothing more. Enforcing least privilege limits the damage that can be caused by a compromised account or a malicious insider. It is a foundational control in Zero Trust architecture and a key requirement of NIS2.
LLM (Large Language Model)
A type of artificial intelligence trained on vast quantities of text data, capable of generating human-like text, answering questions, writing code, and performing a wide range of language tasks. LLMs such as GPT-4 and Claude underpin tools like ChatGPT and Microsoft Copilot. From a security perspective, LLMs introduce risks including data leakage (employees sharing sensitive information with AI tools) and their use by attackers to craft more convincing phishing and social engineering attacks.
Malware
A broad term for any software intentionally designed to cause harm to a computer, network, or user. Malware includes viruses, worms, trojans, ransomware, spyware, and adware. It is typically delivered via phishing emails, malicious downloads, compromised websites, or infected USB drives. Endpoint protection, email filtering, and user awareness training are the primary defences.
MFA (Multi-Factor Authentication)
An authentication method that requires users to verify their identity using two or more independent factors: something they know (password), something they have (authenticator app or hardware token), or something they are (biometric). MFA is one of the single most effective controls against account takeover — it blocks the vast majority of credential-based attacks even when passwords have been compromised.
MSSP (Managed Security Services Provider)
A third-party company that provides outsourced monitoring and management of security systems and functions. MSSPs typically offer services such as 24/7 security operations centre (SOC) monitoring, threat detection, firewall management, and vulnerability scanning. Unlike a vCISO, an MSSP focuses on operational security delivery rather than strategic leadership and governance.
NCSC Ireland (National Cyber Security Centre)
Ireland's national authority for cybersecurity, operating under the Department of the Environment, Climate and Communications. The NCSC provides guidance, incident response support, and threat intelligence to Irish organisations. It publishes practical resources for SMEs — including the 12 Steps to Cyber Security framework — and is the designated national authority for NIS2 implementation in Ireland.
Network Segmentation
The practice of dividing a computer network into smaller, isolated zones to limit the spread of an attack. If an attacker compromises one segment — such as a guest Wi-Fi network or a workstation — segmentation prevents them from moving laterally to more sensitive systems such as financial databases or operational technology. It is a key control in Zero Trust architecture.
NIS2 Directive
The EU's Network and Information Security Directive 2 (NIS2) is the primary European legislation governing cybersecurity for critical and important sectors. It replaces the original NIS Directive and significantly expands its scope, covering sectors including energy, transport, health, digital infrastructure, manufacturing, food, and waste management. In Ireland, NIS2 was transposed into national law in October 2024, with enforcement by the NCSC.
NIS2 Penalties
The sanctions available to national authorities for non-compliance with NIS2. For essential entities, fines can reach €10 million or 2% of global annual turnover (whichever is higher). For important entities, the maximum is €7 million or 1.4% of global annual turnover. Senior management can also be held personally liable, and temporary bans on executives are possible in serious cases.
OSINT (Open Source Intelligence)
Information gathered from publicly available sources — websites, social media, company filings, job postings, and more — and used to build a picture of a target organisation or individual. Attackers use OSINT extensively during the reconnaissance phase of an attack to identify employees, technologies in use, and potential vulnerabilities. Organisations should periodically review their own digital footprint to understand what an attacker could learn about them.
Patch Management
The process of identifying, acquiring, testing, and applying software updates (patches) to fix security vulnerabilities and improve functionality. Unpatched software is one of the most common entry points for attackers — many major breaches exploit vulnerabilities for which patches were available months or years before the attack. A formal patch management process should define timelines for applying critical, high, and medium-severity patches.
Penetration Testing
A simulated cyberattack conducted by authorised security professionals to identify exploitable vulnerabilities in systems, networks, or applications before real attackers do. Penetration tests can be black-box (no prior knowledge), white-box (full knowledge), or grey-box (partial knowledge). Results should be used to prioritise remediation, not just to generate a compliance report.
Phishing
A social engineering attack in which an attacker sends a fraudulent message — typically by email — designed to trick the recipient into revealing sensitive information, clicking a malicious link, or downloading malware. Phishing is the most common initial attack vector in cybercrime. Variants include spear phishing (targeted at a specific individual), whaling (targeting executives), vishing (voice phishing), and quishing (QR code phishing).
Phishing Simulation
A controlled exercise in which an organisation sends realistic but harmless fake phishing emails to its own employees to test their awareness and identify who is most susceptible to social engineering. Phishing simulations are most effective when combined with immediate, non-punitive training for those who click, and when results are used to improve the overall security awareness programme.
Privileged Access Management (PAM)
A security discipline focused on controlling, monitoring, and auditing the use of privileged accounts — those with elevated permissions such as system administrators, database administrators, and root accounts. Privileged accounts are high-value targets for attackers because compromising one can provide unrestricted access to critical systems. PAM solutions enforce just-in-time access, session recording, and credential vaulting.
Quishing
A phishing attack that uses QR codes instead of traditional hyperlinks to direct victims to malicious websites. Because QR codes are opaque — the destination URL is not visible until scanned — they bypass many email security filters and exploit the trust users place in physical or digital QR codes. Quishing attacks are increasingly common in Ireland, particularly targeting business owners and employees via email and printed materials.
Ransomware
A type of malware that encrypts a victim's files and demands a ransom payment — typically in cryptocurrency — in exchange for the decryption key. Modern ransomware attacks often involve double extortion: attackers exfiltrate data before encrypting it, threatening to publish it publicly if the ransom is not paid. Offline, tested backups are the most effective defence against ransomware, alongside EDR, MFA, and network segmentation.
Risk Assessment
A structured process for identifying, analysing, and evaluating the cybersecurity risks facing an organisation. A risk assessment considers the likelihood and potential impact of various threat scenarios, the effectiveness of existing controls, and the organisation's risk appetite. It is the foundation of any security programme and a core requirement under NIS2, ISO 27001, and GDPR.
Risk Appetite
The level of risk an organisation is willing to accept in pursuit of its objectives. Risk appetite is not a fixed number — it varies by risk type, business context, and regulatory environment. Defining risk appetite is a board-level responsibility and is essential for making proportionate security investment decisions. A vCISO helps translate technical risk into business terms so that leadership can make informed choices.
Risk Register
A document that records identified risks, their likelihood and impact scores, the controls in place to mitigate them, and the residual risk remaining after those controls are applied. A well-maintained risk register is a living document — reviewed and updated regularly — and is a key artefact for demonstrating governance maturity to regulators, insurers, and board members.
SASE (Secure Access Service Edge)
A cloud-delivered security architecture that combines network security functions — such as secure web gateway, cloud access security broker (CASB), and Zero Trust Network Access (ZTNA) — with wide-area networking (WAN) capabilities. SASE is designed for distributed workforces and cloud-first organisations, providing consistent security regardless of where users are located.
Security Audit
A systematic evaluation of an organisation's security posture, policies, and controls against a defined standard or framework. Security audits can be internal (conducted by the organisation's own team) or external (conducted by an independent third party). Regular audits help identify gaps, validate the effectiveness of controls, and provide evidence of due diligence to regulators and insurers.
Security Awareness Training
Structured education programmes designed to improve employees' understanding of cybersecurity threats, safe behaviours, and their role in protecting the organisation. Effective security awareness training goes beyond annual compliance tick-boxes — it uses engaging formats, real-world examples, and regular reinforcement to build lasting behavioural change. It is the most cost-effective security investment available to most SMEs.
Security Operations Centre (SOC)
A centralised team — internal or outsourced — responsible for continuously monitoring an organisation's IT environment for security threats, analysing alerts, and responding to incidents. A SOC typically operates 24/7 and uses a combination of SIEM tools, threat intelligence, and human analysis. For most Irish SMEs, a managed SOC provided by an MSSP is more cost-effective than building an internal capability.
Security Policy
A formal document that defines an organisation's security objectives, the rules governing the use of its systems and data, and the responsibilities of employees and management. Security policies provide the governance foundation for all security activities and are a requirement under NIS2, ISO 27001, and most cyber insurance policies. Policies must be communicated clearly, reviewed regularly, and enforced consistently.
Security Posture
The overall strength of an organisation's cybersecurity defences — encompassing its policies, controls, processes, and culture. Security posture is not a binary state but a spectrum, and it changes continuously as new threats emerge, technology evolves, and the business grows. A vCISO's primary role is to assess, improve, and maintain an organisation's security posture over time.
Security Roadmap
A prioritised, time-bound plan for improving an organisation's security posture. A security roadmap translates the findings of a risk assessment into a sequence of actionable initiatives, with clear owners, timelines, and success metrics. It is a key deliverable from a vCISO engagement and provides the board with visibility of where security investment is going and what outcomes it is delivering.
Shadow IT
Technology — applications, services, or devices — used within an organisation without the knowledge or approval of the IT or security team. Shadow IT is particularly prevalent in remote and hybrid work environments, where employees use personal tools to work around perceived friction. It creates security blind spots because unsanctioned tools are not subject to the organisation's security controls, patching, or data governance policies.
SIEM (Security Information and Event Management)
A technology platform that aggregates and analyses log data from across an organisation's IT environment — firewalls, servers, endpoints, applications — to detect patterns indicative of a security incident. SIEM provides the visibility needed to identify attacks that span multiple systems and is a core component of a mature security operations capability. Cloud-based SIEM solutions have made this technology more accessible to mid-market organisations.
SME (Small and Medium-Sized Enterprise)
In the EU context, an SME is defined as a business with fewer than 250 employees and either an annual turnover not exceeding €50 million or a balance sheet total not exceeding €43 million. SMEs make up over 99% of businesses in Ireland and face a disproportionate cybersecurity burden — they are targeted by attackers who assume they have weaker defences, but often lack the resources of larger organisations.
Social Engineering
The use of psychological manipulation to trick people into divulging confidential information or performing actions that compromise security. Social engineering exploits human tendencies such as trust, urgency, authority, and fear rather than technical vulnerabilities. It underpins the majority of successful cyberattacks — including phishing, vishing, pretexting, and BEC fraud.
Software Supply Chain Attack
An attack that targets the software development or distribution pipeline to inject malicious code into legitimate software before it reaches end users. The SolarWinds attack of 2020 — in which malicious code was inserted into a trusted IT management tool and distributed to thousands of organisations — is the most prominent example. Supply chain attacks are particularly dangerous because victims trust the compromised software.
SPF (Sender Policy Framework)
An email authentication protocol that allows domain owners to specify which mail servers are authorised to send email on their behalf. SPF helps prevent email spoofing by enabling receiving mail servers to verify that an incoming message from a domain was sent from an authorised source. SPF works alongside DKIM and DMARC to form a comprehensive email authentication framework.
Threat Intelligence
Evidence-based knowledge about existing or emerging threats — including the tactics, techniques, and procedures (TTPs) of threat actors — that can be used to inform security decisions. Threat intelligence helps organisations understand who is likely to target them, how, and why, enabling more targeted and effective defences. It is consumed by SOC teams, incident responders, and security leadership.
Third-Party Risk Management
The process of identifying, assessing, and mitigating the cybersecurity risks introduced by vendors, suppliers, and other third parties that have access to an organisation's systems or data. Supply chain attacks and third-party breaches are a growing threat — attackers increasingly target smaller, less-secure suppliers as a route into their larger customers. NIS2 explicitly requires in-scope organisations to manage supply chain security.
Threat Modelling
A structured process for identifying potential threats to a system, understanding how they could be exploited, and prioritising mitigations. Threat modelling is typically conducted during the design phase of new systems or applications, but it is equally valuable for assessing existing environments. It helps organisations move from reactive security to a proactive, risk-informed approach.
vCISO (Virtual Chief Information Security Officer)
A senior cybersecurity professional engaged on a part-time, fractional, or retainer basis to provide strategic security leadership to an organisation that does not have — or need — a full-time CISO. A vCISO brings board-level security expertise, builds and oversees the security programme, manages risk, ensures regulatory compliance, and reports to leadership. For Irish SMEs, the vCISO model delivers enterprise-grade security governance at a proportionate cost.
Vulnerability
A weakness in a system, application, network, or process that could be exploited by a threat actor to gain unauthorised access or cause harm. Vulnerabilities can be technical (unpatched software, misconfigured systems) or procedural (weak password policies, lack of security training). Identifying and remediating vulnerabilities before attackers exploit them is the goal of vulnerability management programmes.
Vulnerability Scanning
An automated process that probes systems, networks, and applications for known security weaknesses. Vulnerability scanners compare the configuration and software versions of target systems against databases of known vulnerabilities, producing a prioritised list of findings for remediation. Regular scanning — at least quarterly, and after significant changes — is a baseline security practice and a requirement under many compliance frameworks.
VPN (Virtual Private Network)
A technology that creates an encrypted tunnel between a user's device and a corporate network, protecting data in transit from interception. VPNs are widely used to secure remote access for employees working from home or public locations. However, traditional VPNs have limitations — they grant broad network access once connected, which is why Zero Trust Network Access (ZTNA) is increasingly preferred for modern remote work environments.
Whaling
A highly targeted form of spear phishing that specifically targets senior executives — CEOs, CFOs, and board members — who have authority to authorise large financial transactions or access to sensitive information. Whaling attacks are carefully researched and personalised, often referencing real business relationships, upcoming events, or financial transactions to appear legitimate.
Zero Day
A software vulnerability that is unknown to the vendor and for which no patch exists. Zero-day vulnerabilities are highly valuable to attackers because there is no available fix — organisations cannot patch what has not yet been disclosed. Defence against zero-days relies on layered controls such as EDR, network segmentation, and behaviour-based detection rather than signature-based patching.
Zero Trust
A security model based on the principle of 'never trust, always verify' — every user, device, and connection must be authenticated and authorised before being granted access to resources, regardless of whether they are inside or outside the corporate network. Zero Trust replaces the traditional 'castle and moat' approach, which assumed that anything inside the network perimeter could be trusted. It is the recommended architecture for modern, distributed organisations.
ZTNA (Zero Trust Network Access)
A technology that implements Zero Trust principles for remote access — granting users access only to the specific applications they need, rather than broad network access. Unlike traditional VPNs, ZTNA continuously verifies user identity and device health before granting access, and limits lateral movement if a device is compromised. It is the preferred remote access architecture for organisations with distributed workforces.
DKIM (DomainKeys Identified Mail)
An email authentication method that attaches a digital signature to every outgoing email, allowing the receiving mail server to verify that the message genuinely came from your domain and has not been tampered with in transit. DKIM works alongside SPF and DMARC to form a complete email authentication framework. Without DKIM, attackers can intercept and modify emails without detection. Microsoft 365 and Google Workspace both support DKIM and it should be enabled on every business email domain.
HTTPS (HyperText Transfer Protocol Secure)
The secure version of HTTP — the protocol that governs how data is transferred between a browser and a website. HTTPS encrypts all communication using TLS, protecting data from being intercepted or modified by attackers, particularly on public Wi-Fi networks. Any website that collects personal data, processes payments, or requires login must use HTTPS. Browsers mark HTTP sites as 'Not Secure', which damages both user trust and search engine rankings. HTTPS is a baseline requirement, not an optional extra.
TLS (Transport Layer Security)
The cryptographic protocol that underpins HTTPS and secures data in transit across the internet. TLS replaced the older SSL protocol and establishes an encrypted tunnel between a browser and a server so that data cannot be read or altered by third parties. TLS version 1.2 and 1.3 are the current secure standards; older versions (TLS 1.0 and 1.1) are deprecated and should be disabled on all servers. TLS is also used to secure email transmission between mail servers.
HSTS (HTTP Strict Transport Security)
An HTTP security header that instructs browsers to only ever connect to a website over HTTPS, even if the user types 'http://' in the address bar. HSTS prevents a class of attack called SSL stripping, where an attacker downgrades a connection from HTTPS to HTTP to intercept traffic. Once a browser has seen an HSTS header, it will refuse to connect to that domain over plain HTTP for the duration specified in the policy. HSTS is a simple, high-value security header that every HTTPS website should implement.
Content Security Policy (CSP)
An HTTP security header that tells a browser which sources of content — scripts, stylesheets, images, fonts, and frames — are permitted to load on a webpage. CSP is the primary defence against Cross-Site Scripting (XSS) attacks, where attackers inject malicious scripts into a trusted website to steal data or hijack user sessions. A well-configured CSP prevents injected scripts from executing, even if an attacker manages to insert them into the page. CSP requires careful configuration and testing, as an overly strict policy can break legitimate site functionality.
DNSSEC (Domain Name System Security Extensions)
A set of extensions to the DNS protocol that add cryptographic authentication to DNS responses, preventing DNS cache poisoning attacks where an attacker redirects a domain name to a malicious IP address. Without DNSSEC, an attacker who compromises a DNS resolver can silently redirect users from your legitimate website to a fake one. DNSSEC requires configuration at both the DNS hosting provider (to sign the zone) and the domain registrar (to publish the DS record). It is particularly important for organisations in regulated sectors and those handling sensitive data.
CAA Record (Certification Authority Authorisation)
A DNS record that specifies which Certificate Authorities (CAs) are permitted to issue SSL/TLS certificates for a domain. Without a CAA record, any CA in the world could theoretically issue a certificate for your domain — which could be exploited if a CA is compromised or acts negligently. Adding a CAA record restricts certificate issuance to only the CAs you trust (for example, Let's Encrypt or DigiCert), and notifies you if an unauthorised issuance attempt is made. CAA records are a quick DNS addition that meaningfully reduces the risk of fraudulent certificates being issued for your domain.
Board Liability
The legal responsibility that company directors carry for the decisions they make — or fail to make — on behalf of the organisation. Under NIS2, board members of in-scope organisations can be held personally liable for cybersecurity failures, with consequences including fines and temporary bans from holding management positions. Board liability is not theoretical — it is an enforceable legal obligation.
Director Liability
The personal legal exposure that individual directors face when an organisation they govern fails to meet its regulatory obligations. Under NIS2 and Ireland's transposing legislation, directors can face personal fines, temporary disqualification from management roles, and reputational damage if their organisation suffers a significant cybersecurity incident and cannot demonstrate adequate governance. Director liability makes cybersecurity a boardroom issue, not just an IT issue.
Personal Liability
The principle that an individual — not just the organisation they work for — can be held legally responsible for failures in their area of responsibility. NIS2 Article 20 introduces personal liability for members of management bodies who fail to ensure their organisation complies with cybersecurity risk management obligations. This means a director's personal assets, reputation, and career are at stake.
Board Oversight
The duty of a board of directors to actively supervise and take responsibility for an organisation's cybersecurity risk management. Under NIS2, boards must approve cybersecurity risk management measures, oversee their implementation, and undergo regular cybersecurity training. Passive delegation to the IT department is no longer sufficient — boards must demonstrate informed, active engagement.
Board Responsibility
The collective obligation of a board of directors to ensure that cybersecurity is treated as a strategic business risk, not a technical afterthought. NIS2 makes board responsibility explicit: management bodies must approve risk management measures, ensure adequate resources, and be accountable for non-compliance. Board responsibility cannot be fully delegated — it remains with the directors.
Board Accountability
The principle that directors must answer for the cybersecurity decisions and outcomes of the organisations they govern. Under NIS2, accountability is not just moral — it is legal. Directors must be able to demonstrate that they understood the risks, approved appropriate measures, and monitored their effectiveness. If they cannot, they face personal consequences.
Due Diligence
The reasonable steps that a director or organisation takes to understand, assess, and manage risk before making decisions. In cybersecurity, due diligence means conducting risk assessments, implementing proportionate controls, monitoring their effectiveness, and documenting everything. Under NIS2, demonstrating due diligence is the primary defence against personal liability for directors.
Corporate Governance
The system of rules, practices, and processes by which a company is directed and controlled. Good corporate governance ensures that the interests of shareholders, employees, customers, and regulators are balanced. Cybersecurity governance is now a core component of corporate governance — NIS2 makes it explicit that boards must treat cybersecurity as a governance responsibility, not a technical function.
Fiduciary Duty
The legal obligation of directors to act in the best interests of the organisation and its stakeholders. Fiduciary duty includes the duty of care (acting with reasonable skill and diligence) and the duty of loyalty (putting the organisation's interests above personal interests). Failing to address known cybersecurity risks can constitute a breach of fiduciary duty.
Duty of Care
The legal standard requiring directors to exercise the same level of care, skill, and diligence that a reasonably prudent person would exercise in similar circumstances. In the context of cybersecurity, duty of care means directors must stay informed about cyber risks, ensure appropriate security measures are in place, and act on expert advice. Ignorance of cybersecurity is not a defence.
Management Body
The term used in NIS2 to refer to the board of directors, executive committee, or equivalent governing body of an organisation. NIS2 Article 20 requires management bodies to approve cybersecurity risk management measures, oversee their implementation, and undergo cybersecurity training. The term is deliberately broad to capture all forms of corporate governance structure across EU member states.
Board Ban
A regulatory sanction under NIS2 that temporarily prohibits an individual from holding management positions in essential or important entities. Board bans can be imposed on directors who are found personally responsible for cybersecurity non-compliance. This is one of the most severe personal consequences under NIS2 and represents a significant career and reputational risk for directors.
Disqualification
The legal process by which a director is prohibited from serving as a company director for a specified period. Under Ireland's Companies Act 2014, directors can be disqualified for various forms of misconduct. NIS2 adds cybersecurity non-compliance as a potential trigger for temporary disqualification from management roles in essential entities.
Essential Entity
An organisation classified under NIS2 as operating in a sector critical to the functioning of society and the economy — including energy, transport, banking, health, water, digital infrastructure, and public administration. Essential entities face the strictest NIS2 requirements: proactive regulatory supervision, higher fines (up to €10 million or 2% of global annual turnover), and the possibility of board bans for non-compliant directors.
Important Entity
An organisation classified under NIS2 as operating in a sector that, while not critical infrastructure, is nonetheless important to the economy — including postal services, waste management, food production, manufacturing, and digital providers. Important entities face lighter supervision (reactive rather than proactive) but still face significant fines (up to €7 million or 1.4% of global annual turnover) and the same board accountability requirements.
NIS2 Scope
The range of organisations and sectors that fall under the NIS2 Directive's requirements. NIS2 significantly expanded scope compared to the original NIS Directive, bringing in 18 sectors and applying a size-cap rule: generally, any organisation with 50+ employees or €10M+ turnover operating in a covered sector is in scope. Supply chain dependencies can also bring smaller organisations into scope.
Competent Authority
The national body designated by each EU member state to oversee and enforce NIS2 compliance within its jurisdiction. In Ireland, the competent authority will be designated under the National Cyber Security Bill. Competent authorities have powers to conduct audits, issue binding instructions, impose fines, and — for essential entities — temporarily suspend management from their duties.
CSIRT (Computer Security Incident Response Team)
A specialised team responsible for receiving, analysing, and responding to cybersecurity incidents. Under NIS2, each EU member state must designate at least one CSIRT. In Ireland, the NCSC Ireland operates the national CSIRT. In-scope organisations must report significant incidents to their national CSIRT within strict timelines — 24 hours for an early warning, 72 hours for a full notification.
Incident Reporting
The formal process of notifying regulators and relevant authorities when a significant cybersecurity incident occurs. NIS2 introduces a three-stage reporting obligation: a 24-hour early warning, a 72-hour incident notification with an initial assessment, and a one-month final report with root cause analysis and remediation measures. Failure to report within these timelines is itself a compliance violation.
Supply Chain Security
The practice of identifying and managing cybersecurity risks that arise from an organisation's relationships with suppliers, vendors, and service providers. NIS2 explicitly requires in-scope organisations to address supply chain security, including assessing the security practices of direct suppliers and ensuring contractual security requirements are in place. A breach at a supplier can be just as damaging as a direct attack.
Proportionality
The principle that cybersecurity measures should be appropriate to the size, risk exposure, and criticality of the organisation. NIS2 does not require every organisation to implement the same controls — it requires measures that are proportionate to the risks faced. A 50-person food manufacturer does not need the same security infrastructure as a national energy provider, but it must demonstrate that its measures are reasonable for its context.
Risk Tolerance
The specific, measurable level of risk variation that an organisation is willing to accept around its risk appetite for a particular risk category. While risk appetite is a broad statement of willingness to accept risk, risk tolerance defines the acceptable boundaries. For example, a board might accept a risk appetite of 'moderate' for operational disruption, but set a tolerance of 'no more than 4 hours of downtime'.
Residual Risk
The level of risk that remains after all controls and mitigations have been applied. No security programme eliminates all risk — residual risk is what the organisation accepts and monitors. Understanding residual risk is essential for board-level decision-making: it tells directors what exposure remains despite the investment in security controls.
Inherent Risk
The level of risk that exists before any controls or mitigations are applied. Inherent risk represents the raw exposure an organisation faces from a particular threat. Comparing inherent risk to residual risk shows the effectiveness of existing controls and helps prioritise where further investment is needed.
Risk Treatment
The process of selecting and implementing measures to modify risk. There are four standard risk treatment options: mitigate (reduce the likelihood or impact), transfer (shift the risk to a third party, such as an insurer), accept (acknowledge the risk and monitor it), or avoid (stop the activity that creates the risk). Every identified risk should have a documented treatment decision.
Risk Matrix
A visual tool that plots risks on a grid based on their likelihood of occurring and the severity of their potential impact. Risk matrices help boards and management teams quickly understand which risks are most critical and where to focus resources. They are a standard output of cybersecurity risk assessments and a useful communication tool for non-technical stakeholders.
Risk Owner
The individual accountable for managing a specific risk — including ensuring that appropriate controls are in place, monitoring the risk over time, and escalating changes to the board. Under NIS2, risk ownership cannot be vague — every significant cybersecurity risk should have a named owner with the authority and resources to manage it.
Cyber Insurance Policy
A specialised insurance product designed to cover financial losses arising from cybersecurity incidents — including data breaches, ransomware attacks, business interruption, regulatory fines, and third-party claims. Cyber insurance is not a substitute for good security practices; insurers increasingly require evidence of baseline controls (MFA, backups, EDR, patching) before they will offer coverage or pay claims.
First-Party Coverage
The component of a cyber insurance policy that covers the policyholder's own direct losses from a cybersecurity incident. This typically includes costs such as incident response, forensic investigation, data recovery, business interruption losses, ransomware payments (where legal), customer notification, and crisis communications. First-party coverage protects your business; third-party coverage protects you from claims by others.
Third-Party Coverage
The component of a cyber insurance policy that covers claims made against the policyholder by external parties — such as customers, partners, or regulators — as a result of a cybersecurity incident. This includes legal defence costs, regulatory fines (where insurable), settlements, and damages awarded to affected third parties. Third-party coverage is particularly important for organisations that hold customer data or provide digital services.
Business Interruption Insurance
Coverage within a cyber insurance policy that compensates for lost income and additional expenses incurred when a cybersecurity incident disrupts normal business operations. Business interruption coverage typically kicks in after a waiting period and continues for a defined indemnity period. It is one of the most valuable components of a cyber policy for SMEs, where even a few days of downtime can threaten the business.
Cyber Liability Insurance
A broad term for insurance coverage that protects organisations against financial losses resulting from cybersecurity incidents, data breaches, and privacy violations. Cyber liability insurance typically combines first-party coverage (your own losses) and third-party coverage (claims from others). It is increasingly considered essential for any organisation that stores personal data, processes payments, or relies on digital systems.
Exclusion Clause
A provision in an insurance policy that specifies circumstances, events, or types of loss that are not covered. In cyber insurance, common exclusions include acts of war (including state-sponsored attacks), known but unpatched vulnerabilities, failure to maintain minimum security controls, and losses arising from the policyholder's own criminal acts. Reading and understanding exclusion clauses is critical before purchasing a policy.
Subrogation
The legal right of an insurer, after paying a claim, to pursue recovery of the loss from the third party that caused it. In cyber insurance, subrogation might involve the insurer suing a negligent vendor whose software vulnerability led to the breach. Subrogation clauses can also affect relationships with suppliers, so organisations should understand how their policy handles this.
Retroactive Date
The date in a cyber insurance policy before which incidents are not covered, even if they are discovered during the policy period. If a breach occurred before the retroactive date but is only discovered after the policy starts, the claim may be denied. This is particularly important when switching insurers — ensure there are no gaps in retroactive coverage.
Waiting Period
The time that must elapse after a cybersecurity incident before business interruption coverage begins to pay out. Waiting periods in cyber insurance typically range from 8 to 24 hours. The waiting period is effectively a time-based deductible — the organisation bears the cost of the first hours of downtime before the insurer's coverage kicks in.
Aggregate Limit
The maximum total amount an insurer will pay for all claims during a single policy period, regardless of how many separate incidents occur. If an organisation suffers multiple cyber incidents in one year, the aggregate limit caps the insurer's total exposure. Understanding the aggregate limit is essential for assessing whether a policy provides adequate protection.
Deductible
The amount the policyholder must pay out of pocket before the insurance coverage begins to pay. In cyber insurance, deductibles can be fixed amounts or percentages of the claim. Higher deductibles typically result in lower premiums but increase the organisation's financial exposure in the event of an incident.
CyFUN (Cyber Fundamentals Framework)
Ireland's national cybersecurity baseline framework, published by the NCSC Ireland. CyFUN provides a structured, proportionate approach to cybersecurity organised around six functions: Govern, Identify, Protect, Detect, Respond, and Recover. It is designed specifically for Irish organisations and aligns with international standards including NIST CSF and ISO 27001. CyFUN is the recommended starting point for any Irish SME building a security programme.
Essential 8
A set of eight prioritised cybersecurity mitigation strategies originally developed by the Australian Cyber Security Centre (ACSC) to help organisations protect against the most common cyber threats. The Essential 8 covers application whitelisting, patching applications, configuring Microsoft Office macros, user application hardening, restricting admin privileges, patching operating systems, MFA, and daily backups. While Australian in origin, the Essential 8 is widely referenced as a practical baseline for SMEs globally.
NIST CSF (Cybersecurity Framework)
A voluntary cybersecurity framework published by the US National Institute of Standards and Technology, organised around six core functions: Govern, Identify, Protect, Detect, Respond, and Recover. NIST CSF is widely adopted internationally as a common language for managing cybersecurity risk. Ireland's CyFUN framework is aligned with NIST CSF, making it a useful reference for Irish organisations seeking international best practice.
Maturity Model
A framework for measuring how advanced an organisation's cybersecurity capabilities are, typically on a scale from 'initial' (ad hoc, reactive) to 'optimised' (proactive, continuously improving). Maturity models help boards understand where the organisation stands today, set realistic improvement targets, and track progress over time. They are a key tool for vCISO engagements and board reporting.
Security Maturity
The degree to which an organisation's cybersecurity practices are formalised, repeatable, measured, and continuously improved. A mature security programme is not one that has eliminated all risk — it is one that understands its risks, has proportionate controls in place, monitors their effectiveness, and improves systematically. Security maturity is what regulators, insurers, and boards should be measuring.
Compliance Framework
A structured set of guidelines, controls, and best practices that an organisation follows to meet regulatory or industry requirements. Examples include NIS2, ISO 27001, SOC 2, PCI DSS, and GDPR. A compliance framework provides the 'what' — the requirements that must be met — while the organisation determines the 'how' based on its specific context and risk profile.
Regulatory Framework
The body of laws, regulations, directives, and standards that govern how organisations must manage cybersecurity and data protection. For Irish businesses, the key regulatory frameworks include NIS2, GDPR, the Companies Act 2014, and sector-specific regulations. Understanding which frameworks apply to your organisation is the first step in any compliance programme.
Controls Framework
A catalogue of specific security controls — technical, administrative, and physical — that an organisation can implement to manage cybersecurity risk. Examples include CIS Controls, NIST 800-53, and ISO 27001 Annex A. Controls frameworks provide the detailed 'how' that complements the high-level requirements of compliance frameworks.
Baseline Controls
The minimum set of cybersecurity controls that every organisation should have in place, regardless of size or sector. Baseline controls typically include MFA on all accounts, regular patching, tested backups, endpoint protection, email filtering, and security awareness training. They represent the foundation upon which more advanced security measures are built.
Spear Phishing
A targeted form of phishing that is directed at a specific individual or organisation, using personalised information to make the attack more convincing. Unlike mass phishing campaigns, spear phishing emails reference the target's name, role, company, or recent activities. Spear phishing is the most common initial attack vector for data breaches and is particularly effective against senior executives.
Vishing
Voice phishing — a social engineering attack conducted over the phone, where the attacker impersonates a trusted entity (such as a bank, IT support, or government agency) to trick the victim into revealing sensitive information or taking a harmful action. Vishing attacks have become more sophisticated with AI voice cloning technology, making it harder to distinguish real calls from fraudulent ones.
Smishing
SMS phishing — a social engineering attack delivered via text message, typically containing a malicious link or a request to call a fraudulent number. Smishing exploits the trust people place in text messages and the tendency to act quickly on mobile notifications. Common smishing lures include fake delivery notifications, bank alerts, and revenue notices.
Pretexting
A social engineering technique in which an attacker creates a fabricated scenario — a pretext — to manipulate a victim into providing information or performing an action. The attacker might impersonate an IT technician, a supplier, or a colleague, using a plausible story to build trust. Pretexting often precedes other attacks such as BEC fraud or credential theft.
Credential Stuffing
An automated attack in which stolen username and password combinations — typically obtained from previous data breaches — are systematically tested against other websites and services. Credential stuffing exploits the widespread habit of password reuse. It is one of the most common attack techniques and is the primary reason why MFA and unique passwords (via a password manager) are essential.
Brute Force Attack
An attack method that systematically tries every possible combination of characters to crack a password or encryption key. While simple brute force is slow against strong passwords, variants such as dictionary attacks and hybrid attacks are more efficient. Account lockout policies, rate limiting, and MFA are effective defences against brute force attacks.
Password Spraying
An attack technique that tries a small number of commonly used passwords against a large number of user accounts, rather than trying many passwords against a single account. Password spraying avoids triggering account lockout policies and is particularly effective against organisations that do not enforce strong password policies or MFA. It is a common technique used against cloud services such as Microsoft 365.
Lateral Movement
The technique an attacker uses to move through a network after gaining initial access, escalating privileges and accessing additional systems and data. Lateral movement is how a single compromised endpoint can lead to a full network breach. Network segmentation, least-privilege access, and EDR are the primary defences against lateral movement.
Privilege Escalation
The process by which an attacker gains higher-level permissions than they were initially granted — moving from a standard user account to an administrator account, for example. Privilege escalation can be achieved by exploiting software vulnerabilities, misconfigurations, or weak access controls. Privileged Access Management (PAM) and the principle of least privilege are the primary defences.
Command and Control (C2)
The infrastructure and communication channels that an attacker uses to remotely control compromised systems within a victim's network. After gaining initial access, malware typically establishes a C2 connection back to the attacker's server, allowing them to issue commands, exfiltrate data, and deploy additional tools. Detecting and blocking C2 communications is a key focus of network security monitoring.
Data Exfiltration
The unauthorised transfer of data from an organisation's systems to an external destination controlled by an attacker. Data exfiltration is often the primary objective of a cyberattack — whether for financial gain, espionage, or extortion (as in double-extortion ransomware). Data Loss Prevention (DLP) tools, network monitoring, and access controls are the primary defences.
Data Loss Prevention (DLP)
A set of tools and policies designed to detect and prevent the unauthorised transmission of sensitive data outside the organisation. DLP solutions monitor data in use (on endpoints), data in motion (on the network), and data at rest (in storage) to enforce policies that prevent accidental or malicious data leakage. DLP is particularly important for organisations handling personal data, financial information, or intellectual property.
Endpoint Security
The practice of securing the devices — laptops, desktops, smartphones, tablets, and servers — that connect to an organisation's network. Modern endpoint security goes beyond traditional antivirus to include Endpoint Detection and Response (EDR), application control, device encryption, and patch management. Endpoints are the most common entry point for cyberattacks, making endpoint security a critical baseline control.
Multi-Factor Authentication (MFA)
A security mechanism that requires users to provide two or more independent forms of verification before being granted access to a system or account. The three factors are: something you know (password), something you have (phone, security key), and something you are (fingerprint, face). MFA is the single most effective control for preventing unauthorised access and is a baseline requirement under NIS2, most cyber insurance policies, and Cyber Essentials.
Single Sign-On (SSO)
An authentication method that allows users to log in once and gain access to multiple related applications without re-entering credentials. SSO improves user experience and reduces password fatigue, but it also creates a single point of failure — if the SSO account is compromised, the attacker gains access to all connected applications. SSO should always be paired with strong MFA.
Password Manager
A software tool that generates, stores, and auto-fills strong, unique passwords for every account. Password managers eliminate the need to remember multiple passwords and prevent the dangerous habit of password reuse. They are one of the simplest and most effective security tools available — every employee should use one, and organisations should provide a business-grade password manager as standard.
Tabletop Exercise
A discussion-based exercise in which key stakeholders walk through a simulated cybersecurity incident scenario to test their organisation's response plans, decision-making processes, and communication procedures. Tabletop exercises do not involve live systems — they are conducted around a table (or video call) and focus on identifying gaps in plans, roles, and coordination. They are one of the most cost-effective ways to improve incident readiness.
Business Continuity Plan (BCP)
A documented plan that outlines how an organisation will continue to operate during and after a disruptive event — such as a cyberattack, natural disaster, or major system failure. A BCP identifies critical business functions, the resources required to maintain them, and the steps to restore normal operations. It is broader than an incident response plan, covering all aspects of business survival, not just the technical response.
Disaster Recovery (DR)
The process and procedures for restoring IT systems, data, and infrastructure after a catastrophic event. Disaster recovery is a subset of business continuity planning and focuses specifically on the technical recovery of systems. A DR plan defines Recovery Time Objectives (how quickly systems must be restored) and Recovery Point Objectives (how much data loss is acceptable).
Recovery Time Objective (RTO)
The maximum acceptable amount of time that a system, application, or business function can be offline after an incident before the impact becomes unacceptable. RTO drives decisions about backup infrastructure, redundancy, and disaster recovery architecture. A 4-hour RTO requires very different (and more expensive) infrastructure than a 48-hour RTO.
Recovery Point Objective (RPO)
The maximum acceptable amount of data loss, measured in time, that an organisation can tolerate after an incident. An RPO of 1 hour means the organisation must be able to restore data to a point no more than 1 hour before the incident occurred. RPO drives backup frequency — a 1-hour RPO requires at least hourly backups.
Cyber Hygiene
The set of routine practices and precautions that individuals and organisations follow to maintain the health and security of their digital systems. Cyber hygiene includes keeping software updated, using strong unique passwords with MFA, being cautious with email attachments and links, and maintaining regular backups. Like personal hygiene prevents illness, cyber hygiene prevents the majority of common cyberattacks.
Security Baseline
A defined minimum standard of security controls that must be implemented across all systems in an organisation. A security baseline ensures consistent protection and provides a measurable standard against which compliance can be assessed. Baselines are typically derived from frameworks such as CIS Benchmarks, NCSC guidelines, or industry-specific standards.
Security Framework
A structured set of guidelines, best practices, and standards that provides a systematic approach to managing cybersecurity risk. Security frameworks — such as NIST CSF, ISO 27001, CyFUN, and CIS Controls — give organisations a common language and methodology for building, assessing, and improving their security programmes. Choosing the right framework depends on the organisation's size, sector, and regulatory requirements.
Information Security
The practice of protecting information — in all its forms (digital, physical, verbal) — from unauthorised access, use, disclosure, disruption, modification, or destruction. Information security is broader than cybersecurity: it encompasses physical security, personnel security, and procedural controls as well as technical measures. The goal is to preserve the confidentiality, integrity, and availability of information.
Cybersecurity
The practice of protecting computer systems, networks, and data from digital attacks, unauthorised access, and damage. Cybersecurity encompasses technology, processes, and people — it is not just about firewalls and antivirus, but about governance, risk management, awareness, and resilience. For Irish SMEs, cybersecurity is now a board-level responsibility under NIS2.
Data Classification
The process of categorising data based on its sensitivity and the impact that unauthorised disclosure would have on the organisation. Common classification levels include public, internal, confidential, and restricted. Data classification is the foundation of effective data protection — you cannot apply proportionate controls if you do not know which data is most sensitive and where it is stored.
Acceptable Use Policy (AUP)
A document that defines the rules and guidelines for how employees may use the organisation's IT systems, networks, and data. An AUP typically covers internet usage, email, personal devices, social media, software installation, and data handling. It sets clear expectations, reduces the risk of accidental security incidents, and provides a basis for disciplinary action if rules are violated.
Change Management
A structured process for planning, approving, implementing, and reviewing changes to IT systems and infrastructure. Change management reduces the risk of outages and security incidents caused by uncontrolled modifications. It ensures that changes are tested, documented, and reversible — and that security implications are assessed before changes are made, not after.
Know the terms. Now take action.
Understanding the language of cybersecurity is the first step. The second is knowing how it applies to your business. Book a free 20-minute call with our vCISO team and we will tell you exactly where you stand.