The words that show up in a proposal, a security audit, or the middle of an incident, explained clearly by the engineers who use them every day, so nothing trips you up.
No acronym soup and no fear-selling. Pick a letter, or read straight through, each definition says what the thing literally is and why it matters to a small or midsize organization.
Every point where an attacker could try to get in — internet-facing servers, logins, applications, and devices. The smaller and better-monitored it is, the less there is to defend.
A copy of your data written so it cannot be altered or deleted for a set period, not by an administrator, and not by ransomware. It guarantees a clean copy to restore from.
The plan and systems that keep you running through an outage and get you back to normal after one. Backup is part of it; BCDR is the whole recovery picture, including how fast and how recent.
A scam where an attacker poses as an executive, vendor, or coworker over email to trick someone into wiring money or sharing data. Often sent from a real, hijacked mailbox, so it looks legitimate.
A U.S. Department of Defense program requiring companies in its supply chain to meet defined cybersecurity practices before they can handle certain contract information.
A policy that decides whether a sign-in is allowed based on context — who, what device, where, and how risky the login looks, rather than just a correct password.
Security software on laptops, servers, and phones that detects suspicious behavior, not just known viruses, and can isolate a device or roll back changes when something is wrong.
Any device that connects to your network and touches your data: a laptop, desktop, server, phone, or tablet. Each one is a potential way in, which is why each one is monitored.
A barrier between your network and the internet that permits wanted traffic and blocks the rest, based on rules. A first line of defense — necessary, but not sufficient on its own.
Systematically configuring Microsoft 365 — MFA, conditional access, safe links, audit logs, sharing defaults, and anti-phishing, to minimize attack surface and close the gaps default tenants leave open.
Requiring a second proof of identity beyond a password, a code, an app prompt, or a hardware key, so a stolen password alone can't get someone in. The single highest-impact control for most organizations.
EDR technology plus a staffed security operations center that investigates and acts on alerts around the clock. The tool detects; people respond. We provide both.
An MSP runs your IT for a predictable monthly fee — monitoring, help desk, patching, security, and planning, instead of you hiring and staffing all of it in-house.
The disciplined process of testing and applying software and firmware updates that fix security holes. Unpatched systems are one of the easiest ways attackers get in.
Fraudulent messages, usually email, designed to trick you into clicking a malicious link, opening a bad attachment, or handing over credentials. The most common way breaches start.
Malware that encrypts your files and demands payment to unlock them, often after stealing a copy first to extort you. Tested, immutable backups are the reliable way out.
How much data, measured in time, you can afford to lose in an outage. An RPO of one hour means backups must be recent enough that you'd lose at most an hour of work.
How quickly a system must be back after an outage. An RTO of four hours means you've committed to restoring service within four hours of going down.
The team and tooling that monitors your environment for threats around the clock and coordinates the response when something is found. Not to be confused with SOC 2, below.
A system that collects logs and security events from across your environment, correlates them, and raises alerts, the data backbone a SOC works from.
An independent attestation that a service provider's security controls were in place and operating effectively over a period of time, typically six to twelve months. It's an attestation report, the correct phrasing is "SOC 2 Type II compliant," never "certified."
One secure login that grants access to many applications, so users juggle fewer passwords and IT has one place to enforce policy and cut off access when someone leaves.
An encrypted tunnel that lets remote users reach internal systems as if they were in the office, keeping traffic private over the public internet.
A weakness in software, configuration, or process that an attacker can exploit. Finding and fixing them before attackers do is what vulnerability management is for.
A glossary is more useful when you know where you'll meet the term. Here's where each cluster lands, and where to go when you'd rather have a person walk you through it.
MFA, EDR, MDR, and SOC show up when you're comparing providers. Now you can read the line items and know what you're actually buying.
See how we defend you→HIPAA, CMMC, NIST CSF, and SOC 2 Type II are the frameworks your clients and insurer ask about. We map controls to each and keep the evidence ready.
Compliance & risk→Ransomware, RPO, RTO, and immutable backups stop being abstract fast. Knowing them before the bad day is how recovery stays calm.
Backup & recovery→No. SOC 2 Type II is an independent attestation, an auditor examines whether your security controls were in place and operating effectively over a period of time and issues a report. There's no certificate and no pass/fail badge, so the accurate phrasing is "SOC 2 Type II compliant," not "SOC 2 certified."
EDR is the endpoint detection technology, the software that spots suspicious behavior on a device. MDR is that technology plus a staffed security operations center that investigates and acts on what it finds. The tool detects; the SOC responds. We provide both.
RPO is about data: how much you can afford to lose, measured in time (an RPO of one hour means backups every hour or better). RTO is about downtime: how fast a system has to be back (an RTO of four hours means restored within four hours). Point equals data lost; Time equals time down.
Not at all — that's our job. This glossary exists so the language in our reports and proposals is never a black box, but you're never expected to become the expert. Ask us anything, and we'll translate it into a plain business decision.
Because two vendors can use the same acronym and deliver very different things — "managed EDR" with a real SOC behind it is not the same as a tool nobody watches. Knowing the term lets you ask the follow-up question that separates them.
If a word in a proposal or report has you second-guessing, we'll define it, and if it turns out to be a gap, we'll help you close it.