Plain definitions of the attacks, controls and regulations that shape email and identity security, written for the person who has to explain them to a board.
Account takeover (ATO) is an attack where a criminal gains control of a legitimate user account, most damagingly email, and operates from inside it.
Read →Agentic AI security is about protecting and controlling AI agents that act autonomously with real permissions. Where a chatbot answers, an agent acts.
Read →AI governance is the rules and controls that make AI use safe and compliant across the tools you deploy and the tools employees adopt on their own.
Read →AI jailbreaking is manipulating an AI model with crafted inputs so it ignores its built-in safety rules and produces content or actions its developers intended to block.
Read →AI-native security is a platform where AI is the core detection and decision engine, designed in from day one, not a feature added on top of a rule-based product.
Read →Adversary-in-the-middle (AiTM) phishing proxies the real login page to steal session tokens, defeating most MFA. It's a leading path to account takeover and BEC.
Read →Business Email Compromise (BEC) is fraud where attackers impersonate executives, colleagues or vendors in email to trick an organization into transferring money or sensitive data. It is consistently the costliest cybercrime category the FBI's IC3 reports.
Read →The prioritized, prescriptive set of security safeguards maintained by the Center for Internet Security, ordered to stop the most common attacks first.
Read →Consent phishing tricks a user into granting a malicious OAuth app access to their Google Workspace or Microsoft 365 account. No password is stolen, MFA is unaffected, and the attacker holds the mailbox.
Read →The UK government-backed certification of basic cyber hygiene, built on five technical control themes and required in much UK public procurement.
Read →The EU regulation placing cybersecurity requirements on products with digital elements: secure by design, vulnerability handling and reporting duties for manufacturers.
Read →Cybersäkerhetslagen is the Swedish law implementing the EU's NIS2 directive, setting cybersecurity and incident reporting requirements for essential and important entities operating in Sweden.
Read →A data breach is an incident where confidential, protected or personal data is accessed, disclosed, altered or destroyed without authorization, whether by external attack, insider action or mistake.
Read →Synthetic media, video, voice or images, generated by AI to convincingly imitate a real person, increasingly used to "confirm" fraudulent payment instructions in corporate fraud.
Read →DMARC is a DNS-published policy that tells receiving servers what to do with mail failing SPF or DKIM alignment for your domain, and sends you reports.
Read →DORA is the EU regulation on digital operational resilience for the financial sector, directly binding since 17 January 2025, built on five pillars covering ICT risk, incidents, testing, third-party risk and information sharing.
Read →Email spoofing is the forging of email sender information so a message appears to come from someone the recipient trusts. It is the foundational technique behind phishing, BEC and whaling.
Read →The EU AI Act is the world's first comprehensive AI law, regulating AI systems by risk level and placing duties on organizations that deploy AI as well as those that build it.
Read →GDPR is the EU's data protection law, requiring appropriate security of personal data and notification of personal data breaches to supervisory authorities within 72 hours of awareness.
Read →The US law governing privacy and security of protected health information, with breach notification duties and a leading role for email as a breach source.
Read →The healthcare industry certification whose CSF harmonizes HIPAA, ISO and NIST requirements into one certifiable framework, common in US healthcare vendor deals.
Read →Integrated Cloud Email Security (ICES) is the API-based email security category that works inside Microsoft 365 and Google Workspace instead of rerouting mail.
Read →Invoice fraud is the family of scams where organizations are tricked into paying fraudulent invoices or redirecting legitimate payments to attacker-controlled accounts.
Read →ISO 27001 is the international standard for information security management systems (ISMS), the most commonly requested security certification in European B2B procurement.
Read →ISO/IEC 42001 is the first international, certifiable standard for AI management systems, governing how organizations develop and use AI responsibly.
Read →The use of legitimate online advertising networks to deliver malware or route victims to phishing pages, including search ads impersonating trusted software brands.
Read →MFA fatigue (push bombing) floods a user with authentication prompts until they approve one. It turns MFA's one-tap convenience into the weak point.
Read →NIS2 is the EU cybersecurity directive requiring essential and important entities across 18 sectors to manage cyber risk, secure supply chains and report significant incidents on strict deadlines, with personal accountability for management.
Read →The voluntary US framework for organizing cybersecurity work, structured in CSF 2.0 around six functions from Govern to Recover.
Read →The contractual security standard for organizations handling payment card data, maintained by the PCI Security Standards Council, with 12 requirement areas.
Read →Phishing is the fraudulent message, most often email, that starts most breaches. Attackers impersonate a trusted party to trick recipients into revealing credentials, paying money, granting access or installing malware.
Read →Pretexting is a social engineering technique where an attacker invents a believable scenario to justify asking for information, access or money. It powers most business email compromise attacks.
Read →Prompt injection hides malicious instructions in content an AI system processes, hijacking what it does. It's widely regarded as the top security risk for LLM applications.
Read →Phishing where the malicious link is delivered as a QR code, evading text-based email scanners and moving the attack to the user's phone.
Read →Ransomware encrypts your data (and increasingly steals it first) to extort payment. Most attacks start with a phishing email or a stolen credential, days before encryption.
Read →A criminal business model where ransomware developers lease their malware to affiliates who carry out attacks, splitting the ransom. Phishing is the model's main entry point.
Read →A secure email gateway (SEG) is a mail security layer deployed in front of an email platform via MX rerouting to filter spam, malware and known threats before delivery.
Read →Shadow AI is the use of AI tools, models or AI-powered integrations inside an organization without IT or security team approval.
Read →Shadow IT is any software, hardware, cloud service or integration used inside an organization without IT department approval or oversight.
Read →Phishing delivered by SMS text message. For companies the danger is the channel hop: attacks that start in email and move to unmonitored phones.
Read →SOC 2 is an AICPA attestation standard where an independent auditor examines how a service organization protects customer data against the Trust Services Criteria.
Read →Social engineering is the manipulation of people, rather than systems, to gain access, information or money. It is the human layer nearly every modern cyberattack relies on.
Read →Spear phishing is a phishing attack crafted for one specific, researched person: the message references your real projects, colleagues and context so that acting on it feels natural.
Read →A supply chain attack compromises an organization through a trusted supplier, software or service provider. Regulators now mandate supply chain security explicitly.
Read →Thread hijacking injects malicious replies into real, ongoing email conversations, borrowing their trust and context to defeat normal suspicion.
Read →The automotive industry's shared information security assessment, based on the VDA ISA catalog and required by many OEMs before sharing sensitive data.
Read →Typosquatting registers domains that resemble legitimate ones to deceive users, a foundation of phishing and BEC that DMARC cannot stop.
Read →Vendor email compromise (VEC) is business email compromise where attackers hijack or imitate a supplier's mailbox to redirect payments inside genuine invoice threads.
Read →Vishing is phishing over phone calls, now supercharged by AI voice cloning. It exploits the immediacy and authority of a live voice, and increasingly pairs with email fraud.
Read →Whaling is a highly targeted phishing attack aimed at senior executives (CEOs, CFOs) whose authority can move money and unlock data. It is the executive tier of spear phishing and a core BEC technique.
Read →Attacks exploiting a vulnerability the vendor has not yet patched. Signatures fail by definition; most zero-days arrive by email.
Read →Free for one account. Four minutes to connect.