Our Cybersecurity Glossary

Malware, phishing, backup… When it comes to cybersecurity, it is not always easy to navigate the many terms and abbreviations used by experts. Would you like to better understand the terminology used by cybersecurity professionals, or simply find the right words to describe your needs in the event of a cyberattack? MCG has compiled 30 essential cybersecurity terms that are commonly used in the industry.

Cybersecurity terms explained in just a few minutes

Ransomware

Ransomware is a type of malicious software designed to prevent a company from accessing its data or IT systems. Its purpose is simple: to disrupt the victim’s operations and demand a ransom payment in exchange for a key that, in theory, allows the affected files to be recovered.

More information

NIS2 Directive

The NIS2 Directive (short for “Network and Information Security 2”) is a European directive designed to strengthen the cybersecurity of organisations considered essential or important to the economy and society. It succeeds the first NIS Directive, adopted in 2016, and significantly broadens its scope to better address evolving cyber threats.

More information

Cybersecurity terms explained in just a few minutes

Phishing

Phishing is a cyberattack technique that involves deceiving someone by impersonating a trusted organisation in order to persuade them to disclose sensitive information, such as passwords, bank card details or business data.

More information

CRA (Cyber Resilience Act)

The Cyber Resilience Act is European legislation requiring manufacturers of digital products, such as software and connected devices, to improve the security of their products throughout their entire lifecycle.

More information

Malware

Malware, short for “malicious software”, is a program designed to infiltrate an IT system in order to cause damage, steal information or allow a cybercriminal to take control of a device.

More information

Cyberattack

A cyberattack is a malicious action carried out by an individual or group of hackers with the aim of compromising an IT system, network or data.

More information

Firewall

A firewall is a security system that protects a computer, server or network against unauthorised access.

More information

VPN

A VPN, or Virtual Private Network, is a technology that creates a secure, encrypted connection between a user and an IT network over the Internet.

More information

Multi-Factor Authentication (MFA)

Multi-factor authentication (MFA), sometimes referred to as two-factor authentication or 2FA, is a security method that requires at least two forms of verification before access to an account or application is granted.

More information

Zero Trust

Zero Trust is a cybersecurity approach based on a simple principle: no user, device or application is considered trustworthy by default, even when it is located within the company’s network. Every access request must be verified before it is authorised.

More information

EDR

EDR, or Endpoint Detection and Response, is a cybersecurity solution that, unlike traditional antivirus software, continuously analyses the behaviour of devices and applications in order to identify suspicious activity, including previously unseen attacks.

More information

XDR

XDR, or Extended Detection and Response, is a cybersecurity solution that helps detect, analyse and respond to cyberattacks by centralising information from multiple security systems.

More information

SOC

A SOC, or Security Operations Centre, is a team of experts responsible for continuously monitoring a company’s IT systems in order to detect, analyse and respond quickly to cyber threats.

More information

SIEM

SIEM, or Security Information and Event Management, is a solution that centralises and analyses activity logs from across a company’s IT systems.

More information

Backup

A backup is a secure copy of a company’s data. Backups are one of the key pillars of any cybersecurity and business continuity strategy.

More information

Data Encryption

Data encryption is a security technique that makes information unreadable to unauthorised individuals. Using an encryption algorithm, data is transformed into an unintelligible format that can only be decrypted using a specific key.

More information

Vulnerability

A vulnerability is a weakness in software, a system or an IT device. It can be exploited by a cybercriminal to access data, install malware or compromise a system. Security updates and patches help reduce this risk.

More information

Security Patch

A security patch is an update released to fix a vulnerability in software, a system or an IT device. Its purpose is to prevent a known weakness from being exploited by a cybercriminal. Security patches help reduce the risk of cyberattacks and maintain the protection of a company’s systems.

More information

Exploit

An exploit is a technique or piece of software used to take advantage of a security vulnerability. It allows a cybercriminal to exploit a weakness in order to access a system, steal data, install malware or carry out other malicious actions.

More information

CVE

A CVE, or Common Vulnerabilities and Exposures, is a unique identifier assigned to a known, publicly disclosed cybersecurity vulnerability. It allows companies, software vendors and cybersecurity experts to identify a specific vulnerability and track available patches or fixes.

More information

Penetration Testing (Pentest)

A penetration test, or pentest, is a controlled cyberattack simulated by cybersecurity experts. Its purpose is to identify vulnerabilities in an IT system before they can be discovered and exploited by real cybercriminals.

More information

Social Engineering

Social engineering is a cyberattack technique that involves manipulating someone into revealing sensitive information or carrying out a risky action. Rather than attacking an IT system directly, the cybercriminal exploits trust, urgency or fear to deceive the victim.

More information

DDoS

A DDoS (Distributed Denial of Service) attack is a cyberattack that sends an extremely large number of requests to a website, server or online service in order to overwhelm it and make it unavailable to legitimate users.

More information

Domain Spoofing

Domain spoofing is a fraud technique that involves imitating or falsifying the domain name of a trusted company or organisation. The aim is to deceive the victim into disclosing sensitive information, clicking on a malicious link or making a payment.

More information

Zero-Day Vulnerability

A zero-day vulnerability is a software vulnerability that is unknown to the software vendor or for which no patch is yet available. It poses a significant risk because cybercriminals may exploit it before companies have had the opportunity to install a security update.

More information

Active Directory

Active Directory (AD) is a Microsoft system that allows companies to centralise the management of users, computers and security groups, which are used to define access permissions to IT resources.

More information

Identity and Access Management (IAM)

Identity and Access Management (IAM) encompasses the tools and processes used to control who can access a company’s IT resources. It helps ensure that each user only has access to the resources they genuinely need.

More information

Shadow IT

Shadow IT refers to employees using software, applications, cloud services or devices without the authorisation or supervision of the IT department.

More information

Data Loss Prevention (DLP)

Data Loss Prevention (DLP) refers to a set of solutions designed to detect and prevent sensitive data from leaving an organisation, whether accidentally or deliberately. DLP solutions can, for example, control the sharing, sending or transfer of confidential information.

More information

Disaster Recovery Plan (DRP)

A Disaster Recovery Plan (DRP) defines the procedures to be followed to restore IT systems and data following a major incident, such as a cyberattack, IT failure or disaster. Its purpose is to enable the company to return to normal operations as quickly as possible.

More information

Business Continuity Plan (BCP)

A Business Continuity Plan (BCP) sets out the measures required to enable a company to continue carrying out its essential activities despite a major incident, such as a cyberattack, IT failure or disaster.

More information

CyFun

CyFun, short for CyberFundamentals Framework, is a cybersecurity framework developed by the Centre for Cybersecurity Belgium (CCB). It is designed to help organisations strengthen their level of cybersecurity by implementing a set of practical measures tailored to their size and level of maturity.

More information

25+ years

25+ years

Expertise

100+

100+

Secured companies

10.000

10.000

Users protected

The cybersecurity partner for ambitious businesses

MCG brings more than 25 years of cybersecurity expertise and a proven methodology covering every stage of IT security, supporting your business or IT department.

We are also a team of recognised experts who assist you with the analysis, implementation and maintenance of your IT infrastructure.

The cybersecurity partner for ambitious businesses
...

Tell us about your cybersecurity needs

Thank you for your message, we’ll contact you very soon! Fill all fields Error when creating request. Please try again
6Lcp1CAbAAAAAM-4iEYkG33vfIaUYODi6YEXTTqi