Call NowFree Quote
Reference

IT & Cybersecurity Glossary

Plain-English definitions of the terms we get asked about most - no jargon, no vendor spin. Each one links through to a full guide if you want the detail.

Cybersecurity & Compliance

MFA (Multi-Factor Authentication)

A login process that requires a second proof of identity beyond a password - typically a code or approval on your phone - so a stolen password alone isn't enough to get in.

Read the full guide

Passkeys

A phishing-resistant replacement for passwords that ties your login to a physical device (like your phone) instead of something you type - meaning it can't be phished or guessed.

Read the full guide

MFA Fatigue / Push-Bombing

An attack where a hacker who already has your password spams your phone with MFA approval requests, hoping you'll eventually tap "approve" just to make the notifications stop.

Read the full guide

Zero Trust

A security model that assumes no user or device is automatically trustworthy - even inside the network - and verifies every access request instead of trusting anything by default.

Read the full guide

EDR (Endpoint Detection & Response)

Security software that actively monitors laptops and servers for suspicious behaviour and can isolate a compromised device automatically - a meaningful step up from traditional antivirus.

Read the full guide

MDR (Managed Detection & Response)

A service where a security team actively monitors your EDR alerts around the clock and responds to real threats - rather than software alone generating alerts nobody's watching.

Read the full guide

Essential Eight

The Australian Signals Directorate's baseline set of eight cybersecurity controls (patching, MFA, backups, application control, and more) that most Australian compliance and insurance requirements are now built around.

Read the full guide

NIST CSF (Cybersecurity Framework)

A widely used US-origin framework for structuring a cybersecurity program around five functions - Identify, Protect, Detect, Respond, Recover - often used alongside or instead of the Essential Eight.

Read the full guide

ISO 27001

An international standard for information security management systems, often required by larger clients or government contracts as proof a business takes data security seriously.

Read the full guide

APRA CPS 234

A prudential standard requiring APRA-regulated entities (and the financial services businesses that support them) to maintain specific information security capabilities.

Read the full guide

Notifiable Data Breaches (NDB) Scheme

The Australian legal requirement to notify affected individuals and the OAIC when a data breach is likely to result in serious harm.

Read the full guide

Business Email Compromise (BEC)

A scam where an attacker impersonates a trusted contact (often via a compromised or look-alike email account) to redirect a real payment to their own bank account.

Read the full guide

SPF, DKIM & DMARC

Three email authentication standards that work together to stop attackers from sending fake emails that appear to come from your own domain.

Read the full guide

Attack Surface Reduction

The practice of actively shrinking the number of ways into your systems - unused software, open ports, unnecessary admin access - so there's simply less for an attacker to target.

Read the full guide

BYOD (Bring Your Own Device)

A policy allowing staff to use their own personal phones or laptops for work, which requires its own set of security and data-separation controls to manage safely.

Read the full guide

Insider Threat

Risk to a business that originates from someone with legitimate access - a current or former staff member, or a contractor - rather than an outside attacker.

Read the full guide

Penetration Testing vs Vulnerability Scanning

A vulnerability scan is an automated check for known weaknesses; a penetration test is a human actively trying to exploit them, the way a real attacker would.

Read the full guide

DNS Filtering

A security control that blocks access to known-malicious websites at the network level, before a user's browser even loads the page.

Read the full guide

QR Code Phishing (Quishing)

A phishing attack delivered via a QR code instead of a link, designed to bypass email link-scanning security and land the victim on a fake login page from their phone.

Read the full guide

Deepfake

AI-generated audio or video convincing enough to impersonate a real person - increasingly used in scam phone calls and video calls requesting urgent payments.

Read the full guide

Shadow AI

Staff using free, unapproved AI tools (like public ChatGPT) with business or client data, outside of any policy or IT visibility.

Read the full guide

Backup & Disaster Recovery

Microsoft 365 & Cloud

Networking

Managed IT & Strategy

Can't find a term?

Ask us directly - we'll explain it in plain English, no sales pitch attached.