In short
Cyber security is full of jargon. This glossary explains the terms London businesses hear most often, from phishing and ransomware to MFA, EDR and penetration testing, in one or two plain-English sentences each.
A to Z
- Breach
- An incident where information is accessed, changed or lost without permission.
- Cyber Essentials
- A UK government-backed certification covering five basic technical controls that protect against common attacks. Cyber Essentials
- Cyber Essentials Plus
- The same five controls as Cyber Essentials, verified by hands-on technical testing. Cyber Essentials
- Dark web monitoring
- A service that watches breach data and criminal markets for your company's details, such as staff passwords. Dark Web Monitoring
- EDR
- Endpoint detection and response: software on laptops and servers that spots and stops suspicious behaviour. 24/7 Monitoring (SOC)
- Encryption
- Scrambling data so only someone with the right key can read it.
- Firewall
- A barrier that controls which network traffic is allowed in and out.
- Incident response
- The planned steps an organisation takes to contain, investigate and recover from a security incident. Incident Response
- ISO 27001
- The international standard for managing information security, which organisations can be certified against. ISO 27001
- Malware
- Malicious software, such as viruses, spyware or ransomware.
- MDR
- Managed detection and response: EDR plus a team that watches and responds to alerts 24/7. 24/7 Monitoring (SOC)
- MFA
- Multi-factor authentication: a second check, such as a code on your phone, on top of a password.
- Patch
- A software update that fixes a security weakness.
- Penetration test
- An authorised, simulated attack carried out by a person to find and prove weaknesses. Penetration Testing
- Phishing
- Emails or messages that trick people into clicking a link, opening a file or handing over details. Security Awareness Training
- PCI DSS
- The security standard for organisations that take card payments. PCI DSS
- Ransomware
- Malware that locks or steals your data and demands payment to release it.
- Risk assessment
- A structured review of what could go wrong, how likely it is and how much harm it would cause. Cyber Security Assessments
- SOC
- Security operations centre: a team that monitors systems and responds to threats. 24/7 Monitoring (SOC)
- SOC 2
- A US attestation report on how a service organisation protects customer data.
- UK GDPR
- The UK's main data protection law, covering how organisations handle personal data. GDPR & Data Protection
- Vulnerability
- A weakness in software, hardware or a process that an attacker could use.
- Vulnerability scan
- An automated check for known weaknesses across your systems. Vulnerability Management
- Zero-day
- A weakness that attackers know about before a fix is available.
Frequently asked questions
Information security protects all of an organisation's information, digital or not. Cyber security is the part focused on digital systems, networks and data.
Phishing. The UK government's Cyber Security Breaches Survey 2025 found it was experienced by 85% of businesses that identified a breach or attack.