Security Glossary
Find explanations of key security terms. Stay informed and stay safe.
Cyber Threats
Malicious activities aimed at compromising systems, networks, or data—such as ransomware, phishing, DDoS attacks, or social engineering—can result in financial, operational, or privacy-related losses.
Digital Forensic Analysis
Technical investigation of security incidents that collects and analyzes digital evidence to identify the source of the attack, assess the impact, and support corrective actions.
Anti-malware
Security tools that detect, block, and remove malicious software, protecting devices from known threats and suspicious behavior.
Anti-phishing
Technologies that identify and block fake messages designed to steal personal data, credentials, or banking information.
Anti-spam
Filters that block unsolicited messages, reducing the risk of fraud, phishing, and malware infection.
Antivirus
Security software that detects and removes known viruses, Trojans, and worms, helping to protect computers and mobile devices.
Digital Signatures
A security mechanism that guarantees the authenticity, integrity, and origin of digital documents and files, ensuring that they have not been altered.
Backdoor
A covert method of accessing computer systems that bypasses security mechanisms, enabling unauthorized access.
Immutable Backup
Backups protected against modification or deletion, ensuring data recovery even after attacks such as ransomware.
Botnet
A network of devices that have been infected and are remotely controlled by attackers to carry out attacks, send spam, or commit fraud.
Cyberattack
Malicious activity intended to compromise digital systems, data, or services.
Cyber hygiene
A set of best practices that help users and organizations keep their systems, devices, and accounts more secure.
Cloud
A remote environment where data and applications are stored and processed over the internet, rather than remaining solely on the user's device.
Parental control
Tools and settings that allow you to restrict and monitor children’s internet access, block inappropriate content, and manage screen time.
Cryptography
A set of techniques that protect information by converting it into encrypted data, ensuring confidentiality, integrity, and, in some cases, authenticity.
Sensitive Data
Personal or business information whose disclosure could cause harm, such as bank details, login credentials, or confidential information.
Dark Web
The part of the internet not indexed by search engines, often associated with illegal activities or harmful content.
DDoS (Distributed Denial of Service)
An attack in which multiple devices send large volumes of traffic to a service, causing it to slow down or become unavailable to legitimate users.
Deepfake
Fake content generated using artificial intelligence, such as manipulated videos or audio clips, used in scams or to spread misinformation.
Email Security
Technologies that protect email against phishing, spam, malware, and fraud.
Email Spoofing
Falsifying the sender's address in an email to deceive the recipient and appear to be a legitimate source.
Encryption
The process of applying encryption to convert readable information into an encrypted format.
Social Engineering
Psychological manipulation that exploits people's trust to obtain sensitive information or induce dangerous actions.
Firewall
A security system that monitors network traffic, allowing legitimate communications and blocking unauthorized access.
Footprinting
The process of gathering information about an organization or system, typically from public sources, to identify potential entry points or security vulnerabilities. It is often the first step in a cybersecurity assessment or cyberattack.
Online shopping fraud
Scams when shopping online that can result in financial loss or data theft.
Hacker / Computer Hacker
A person who attempts to access systems or networks without authorization.
Hacktivism
Cyberattacks motivated by political, social, or ideological factors.
Biometric Identification
An authentication method based on physical or behavioral characteristics.
Hardware Inventory
Mapping and monitoring of an organization's physical devices, enabling more secure management.
Incident Investigation
Analysis of security incidents to identify causes and impacts and improve future responses.
Malicious Links
Fraudulent links sent via email or messages that lead to fake websites or install malware.
Malware
Malicious software designed to steal data, cause damage, or compromise systems.
DDoS Mitigation
Processes and technologies that filter out malicious traffic and keep services available during attacks.
Zero Trust Model
A security approach that assumes that no user or device is trustworthy by default.
MFA (Multi-Factor Authentication)
A security method that requires more than one factor, combining a password, mobile phone biometrics.
Phishing
An attack that uses fake messages to obtain personal data or credentials.
Active Prevention
Anticipating threats through continuous monitoring and rapid response.
Active Protection
Automatic blocking of attacks in real time.
Data Protection / GDPR
Rules for the proper and secure handling of personal data.
Quishing (QR Code Phishing)
It involves the use of manipulated QR codes to deceive users by redirecting them to pages controlled by third parties.
Ransomware
A type of malware that encrypts data and demands payment to unlock it.
Active Recovery
The ability to quickly restore systems and data following an attack or failure.
Network Redundancy
Distribution of services across multiple infrastructures to ensure availability.
RobotCalls
Automatic calls used for spam, aggressive advertising, or fraud.
Data Theft
Unauthorized access to or extraction of sensitive information.
Identity Theft
Unauthorized use of personal data to commit fraud or gain access to accounts.
Sandboxing
Analysis of suspicious files in isolated environments to identify threats.
Information Security
Practices that protect information by ensuring confidentiality, integrity, and availability.
Digital Security
Practices and technologies that protect people and devices in the online environment.
Fake Website
A page created to mimic a legitimate website with the aim of deceiving users.
Smishing
Phishing via text messages.
Spear Phishing
Highly targeted and personalized phishing.
Spoofing
Impersonating a legitimate source.
Spyware
It is a type of malicious software that installs itself on a device (mobile phone, computer, tablet) without the user's knowledge to monitor activities and collect personal information.
Threat Hunting
Proactive detection of attack indicators before they cause damage.
Threat Intelligence
Strategic information on threats, techniques, and attackers to strengthen protection.
Vishing
Phishing carried out via phone calls.
Vulnerability
A security vulnerability that can be exploited by attackers.
WAF – Web Application Firewall
Specific protection for web applications against direct attacks.
Wangiri
Telephone fraud involving very short call attempts (i.e., with no actual call duration) made from unknown numbers, usually international ones.
It works simply: you receive a call that rings only once and then hangs up, appearing as a missed call. When you decide to call back, the call is routed to a premium-rate number or value-added service, generating charges that go to the scammers. The goal is to exploit people’s curiosity or impulse to return missed calls.
Worm (Computer Worm)
Malware that automatically spreads between devices.