Glossary

The language defenders use, defined plainly.

The work recognised by the Cyber Security Awards comes wrapped in acronyms and shorthand. This glossary keeps the definitions short, accurate and free of jargon, so the terms read as clearly as the work behind them.

MITRE ATT&CK

A freely available knowledge base that catalogues how real attackers behave, organised into tactics (their goals) and techniques (how they reach them). Defenders use it as a shared language to map detections, test coverage and describe an intrusion in terms everyone in the field recognises.

Zero Trust

A security model that treats no user, device or network location as inherently trusted. Every request is verified against identity, device health and context before access is granted, and access is kept to the minimum needed. The principle is summarised as never assume, always verify, limit what each request can reach.

SOCSecurity Operations Centre

The team and function that monitors an organisation for threats around the clock, investigates alerts and coordinates the response when something is wrong. A SOC blends people, process and tooling, and much of its work is the patient triage of signals on a quiet Tuesday night shift.

EDR / XDREndpoint / Extended Detection and Response

EDR watches laptops, servers and other endpoints, recording behaviour so analysts can detect, investigate and contain threats on the device itself. XDR widens that lens, correlating signals across endpoints, email, identity and cloud so related events surface as one incident rather than scattered alerts.

SIEMSecurity Information and Event Management

A platform that collects logs and events from across an environment, normalises them and applies correlation rules to surface suspicious activity. A SIEM gives analysts one place to search, alert and build a timeline, and it underpins much of the detection work a SOC carries out each day.

Threat Intelligence

Evidence-based knowledge about adversaries, their methods and their infrastructure, gathered and analysed so defenders can act on it. Good intelligence answers who might target an organisation, how they tend to operate and what to watch for, turning scattered observations into decisions a defender can actually use.

Penetration Testing

An authorised, scoped assessment in which testers attempt to breach systems the way a real attacker might, then report what they found and how to fix it. The goal is to expose exploitable weaknesses before a genuine adversary does, within agreed rules and with the owner’s permission.

Red Team and Blue Team

The red team plays the attacker, probing defences with realistic tactics. The blue team defends, detecting and responding to that activity. Running them together tests not only whether weaknesses exist but whether defenders notice and react, which is often where the most useful lessons emerge.

Incident ResponseIR

The organised process of preparing for, detecting, containing, eradicating and recovering from a security incident, then learning from it. A practised IR plan turns a stressful event into a sequence of known steps, so the people involved act with clarity instead of improvising under pressure.

Responsible DisclosureCoordinated Vulnerability Disclosure

The practice of reporting a discovered vulnerability privately to the affected party, giving them reasonable time to fix it before any public detail appears. CVD protects users while still crediting the finder, and it depends on good faith on both sides, the reporter and the organisation receiving the report.

CVSSCommon Vulnerability Scoring System

An open standard for rating the severity of a vulnerability on a scale from zero to ten, based on how it can be exploited and what the impact would be. CVSS gives teams a shared reference for prioritising fixes, though it describes severity rather than the full business risk.

Dwell Time

The length of time an attacker remains undetected inside an environment, measured from initial compromise to discovery. Shorter dwell time limits the damage an intruder can do, which is why so much detection effort aims to shrink the gap between a breach happening and a defender noticing it.

Blast Radius

The extent of the damage a single compromise can cause, measured by how far an attacker could reach once they gain a foothold. Designing for a smaller blast radius, through segmentation and least privilege, means one breached account or system does not hand over the whole estate.

Ransomware

Malicious software that encrypts an organisation’s data, or steals it, and then demands payment to restore access or stay silent. Modern campaigns often combine encryption with the threat of leaking stolen files, which is why reliable, tested backups and quick detection matter as much as prevention.

Phishing

A social engineering attack that tricks people into revealing credentials, transferring money or running malicious code, usually through a convincing email, message or fake page. Targeted variants tailor the lure to a specific person or role, and they remain one of the most common ways intrusions begin.

MFAMulti-Factor Authentication

A login control that requires more than one type of proof, typically something you know and something you have, such as a password plus a code or a hardware key. MFA blocks many account takeovers, since a stolen password alone is no longer enough to get in.

IAMIdentity and Access Management

The discipline of managing who exists in a system, what they can do and how that is enforced over time. IAM covers provisioning, authentication, authorisation and the removal of access when it is no longer needed, and it sits at the centre of most modern security models.

DLPData Loss Prevention

Controls that detect and stop sensitive information from leaving an organisation, whether by accident or deliberate exfiltration. DLP inspects data in email, on devices and in the cloud, applying rules based on what the information is, where it is going and who is moving it.

Vulnerability Management

The continuous cycle of finding weaknesses across systems, assessing how serious they are, fixing or mitigating them and confirming the fix held. It is ongoing rather than a one-off scan, because new flaws appear constantly and the work is in prioritising what to address first with limited time.

NIST CSFCybersecurity Framework

A voluntary framework from the US National Institute of Standards and Technology that organises security work into core functions, including identify, protect, detect, respond and recover. It gives organisations of any size a common structure for describing where they are and where they want their programme to go.

ISO 27001

An international standard for an information security management system, the set of policies, processes and controls an organisation uses to manage security risk. Certification is granted after an independent audit, signalling that the organisation runs security as a managed system rather than as a collection of ad hoc measures.

CISOChief Information Security Officer

The senior leader accountable for an organisation’s security strategy, risk decisions and the team that carries them out. A CISO translates technical risk into terms the board understands, sets priorities under real constraints and answers for the programme when something goes wrong, as well as when it goes right.

Purple Team

A way of working in which attackers and defenders collaborate openly rather than competing, sharing findings in real time to improve detection and response together. Where a red team tests defences quietly, a purple exercise turns each attack step into a learning moment the blue team can act on immediately.

Attack Surface

The sum of all the points where an attacker could try to enter or extract data from a system, including exposed services, accounts, applications and people. Reducing the attack surface, by removing what is not needed and hardening what remains, gives an adversary fewer ways in to begin with.

Cyber Resilience

The ability of an organisation to keep operating and recover quickly when an attack succeeds, accepting that some incidents will get through. Resilience extends beyond prevention into detection, response, backups and rehearsal, so a serious event becomes a setback the organisation absorbs rather than one that stops it.

FAQ

About this glossary

Who is this glossary for?

Anyone reading about the work that defenders do, whether you are a finalist explaining your contribution, a judge weighing it, a journalist covering the field or someone newer to security who wants the terms in plain English.

How are the definitions written?

Each term leads with a short, self-contained definition of roughly 40 to 60 words, kept accurate and free of marketing language. Where a term has a common acronym, it is shown alongside the full name.

Do these definitions replace official standards?

No. Frameworks such as MITRE ATT&CK, the NIST Cybersecurity Framework, ISO 27001 and CVSS are maintained by their own bodies, and their published documentation is always the authoritative source. This glossary explains the terms in plain language.

Why does an awards programme publish a glossary?

Recognition only means something if people understand what is being recognised. Defining the language clearly lets a wider audience follow the work behind each nomination, rather than the jargon that usually surrounds it.