IT & Cybersecurity Glossary
Plain-English definitions of the terms we get asked about most - no jargon, no vendor spin. Each one links through to a full guide if you want the detail.
Cybersecurity & Compliance
MFA (Multi-Factor Authentication)
A login process that requires a second proof of identity beyond a password - typically a code or approval on your phone - so a stolen password alone isn't enough to get in.
Read the full guidePasskeys
A phishing-resistant replacement for passwords that ties your login to a physical device (like your phone) instead of something you type - meaning it can't be phished or guessed.
Read the full guideMFA Fatigue / Push-Bombing
An attack where a hacker who already has your password spams your phone with MFA approval requests, hoping you'll eventually tap "approve" just to make the notifications stop.
Read the full guideZero Trust
A security model that assumes no user or device is automatically trustworthy - even inside the network - and verifies every access request instead of trusting anything by default.
Read the full guideEDR (Endpoint Detection & Response)
Security software that actively monitors laptops and servers for suspicious behaviour and can isolate a compromised device automatically - a meaningful step up from traditional antivirus.
Read the full guideMDR (Managed Detection & Response)
A service where a security team actively monitors your EDR alerts around the clock and responds to real threats - rather than software alone generating alerts nobody's watching.
Read the full guideEssential Eight
The Australian Signals Directorate's baseline set of eight cybersecurity controls (patching, MFA, backups, application control, and more) that most Australian compliance and insurance requirements are now built around.
Read the full guideNIST CSF (Cybersecurity Framework)
A widely used US-origin framework for structuring a cybersecurity program around five functions - Identify, Protect, Detect, Respond, Recover - often used alongside or instead of the Essential Eight.
Read the full guideISO 27001
An international standard for information security management systems, often required by larger clients or government contracts as proof a business takes data security seriously.
Read the full guideAPRA CPS 234
A prudential standard requiring APRA-regulated entities (and the financial services businesses that support them) to maintain specific information security capabilities.
Read the full guideNotifiable Data Breaches (NDB) Scheme
The Australian legal requirement to notify affected individuals and the OAIC when a data breach is likely to result in serious harm.
Read the full guideBusiness Email Compromise (BEC)
A scam where an attacker impersonates a trusted contact (often via a compromised or look-alike email account) to redirect a real payment to their own bank account.
Read the full guideSPF, DKIM & DMARC
Three email authentication standards that work together to stop attackers from sending fake emails that appear to come from your own domain.
Read the full guideAttack Surface Reduction
The practice of actively shrinking the number of ways into your systems - unused software, open ports, unnecessary admin access - so there's simply less for an attacker to target.
Read the full guideBYOD (Bring Your Own Device)
A policy allowing staff to use their own personal phones or laptops for work, which requires its own set of security and data-separation controls to manage safely.
Read the full guideInsider Threat
Risk to a business that originates from someone with legitimate access - a current or former staff member, or a contractor - rather than an outside attacker.
Read the full guidePenetration Testing vs Vulnerability Scanning
A vulnerability scan is an automated check for known weaknesses; a penetration test is a human actively trying to exploit them, the way a real attacker would.
Read the full guideDNS Filtering
A security control that blocks access to known-malicious websites at the network level, before a user's browser even loads the page.
Read the full guideQR Code Phishing (Quishing)
A phishing attack delivered via a QR code instead of a link, designed to bypass email link-scanning security and land the victim on a fake login page from their phone.
Read the full guideDeepfake
AI-generated audio or video convincing enough to impersonate a real person - increasingly used in scam phone calls and video calls requesting urgent payments.
Read the full guideShadow AI
Staff using free, unapproved AI tools (like public ChatGPT) with business or client data, outside of any policy or IT visibility.
Read the full guideBackup & Disaster Recovery
RTO & RPO
RTO (Recovery Time Objective) is how long you can afford to be down; RPO (Recovery Point Objective) is how much data you can afford to lose. Together they define what "good enough" recovery actually means.
Read the full guide3-2-1 Backup Rule
A backup best practice: keep three copies of your data, on two different types of media, with one copy stored offsite - so no single failure can wipe out every copy at once.
Read the full guideImmutable Backups
Backup copies that can't be altered or deleted - by anyone, including an attacker with admin credentials - for a set retention period, which is what actually stops ransomware from destroying your backups too.
Read the full guideBusiness Continuity vs Disaster Recovery
Business continuity is the plan for keeping the business running during a disruption; disaster recovery is the narrower technical plan for restoring IT systems after one.
Read the full guideMicrosoft 365 & Cloud
Conditional Access
A Microsoft 365 feature that applies login rules based on context - blocking or challenging sign-ins from unusual countries, devices, or risk levels - rather than treating every login the same.
Read the full guideMicrosoft Entra ID
Microsoft's cloud identity platform (formerly Azure Active Directory) that manages who can sign in to your business's Microsoft 365 apps and what they can access once they're in.
Read the full guideMicrosoft Purview DLP (Data Loss Prevention)
A Microsoft 365 feature that automatically detects and blocks sensitive information - like credit card numbers - from being emailed or shared outside the business.
Read the full guideWindows 365 Cloud PC
A full Windows desktop that runs in Microsoft's cloud and streams to any device, so a business can hand out a complete, managed PC without buying physical hardware.
Read the full guideData Sovereignty & Data Residency
Data sovereignty is which country's laws govern your data; data residency is simply which physical country it's stored in - two related but distinct questions when choosing cloud services.
Read the full guideNetworking
SD-WAN
A networking approach that intelligently manages traffic across multiple internet connections (like NBN plus a 4G backup), automatically routing around outages instead of going fully offline.
Read the full guideVLAN Segmentation
Splitting one physical network into separate logical networks - for example, keeping guest Wi-Fi, staff devices, and point-of-sale systems apart - so a breach in one area can't spread freely to the rest.
Read the full guideManaged IT & Strategy
vCIO (Virtual CIO)
Part-time, outsourced strategic technology leadership - roadmaps, budgeting, vendor management - for businesses that need CIO-level thinking without a full-time executive hire.
Read the full guideCo-Managed IT
An arrangement where an external provider works alongside an existing internal IT person or team, rather than replacing them - typically covering overflow support, specialist security work, or after-hours coverage.
Read the full guideCan't find a term?
Ask us directly - we'll explain it in plain English, no sales pitch attached.