Glossary

The vocabulary of the threat.

Plain definitions of the attacks, controls and regulations that shape email and identity security, written for the person who has to explain them to a board.

Account Takeover (ATO)

Account takeover (ATO) is an attack where a criminal gains control of a legitimate user account, most damagingly email, and operates from inside it.

Read →

Agentic AI Security

Agentic AI security is about protecting and controlling AI agents that act autonomously with real permissions. Where a chatbot answers, an agent acts.

Read →

AI Governance

AI governance is the rules and controls that make AI use safe and compliant across the tools you deploy and the tools employees adopt on their own.

Read →

AI Jailbreaking

AI jailbreaking is manipulating an AI model with crafted inputs so it ignores its built-in safety rules and produces content or actions its developers intended to block.

Read →

AI-Native Security

AI-native security is a platform where AI is the core detection and decision engine, designed in from day one, not a feature added on top of a rule-based product.

Read →

AiTM Phishing

Adversary-in-the-middle (AiTM) phishing proxies the real login page to steal session tokens, defeating most MFA. It's a leading path to account takeover and BEC.

Read →

Business Email Compromise

Business Email Compromise (BEC) is fraud where attackers impersonate executives, colleagues or vendors in email to trick an organization into transferring money or sensitive data. It is consistently the costliest cybercrime category the FBI's IC3 reports.

Read →

CIS Controls

The prioritized, prescriptive set of security safeguards maintained by the Center for Internet Security, ordered to stop the most common attacks first.

Read →

Consent Phishing

Consent phishing tricks a user into granting a malicious OAuth app access to their Google Workspace or Microsoft 365 account. No password is stolen, MFA is unaffected, and the attacker holds the mailbox.

Read →

Cyber Essentials

The UK government-backed certification of basic cyber hygiene, built on five technical control themes and required in much UK public procurement.

Read →

Cyber Resilience Act

The EU regulation placing cybersecurity requirements on products with digital elements: secure by design, vulnerability handling and reporting duties for manufacturers.

Read →

Cybersäkerhetslagen

Cybersäkerhetslagen is the Swedish law implementing the EU's NIS2 directive, setting cybersecurity and incident reporting requirements for essential and important entities operating in Sweden.

Read →

Data Breach

A data breach is an incident where confidential, protected or personal data is accessed, disclosed, altered or destroyed without authorization, whether by external attack, insider action or mistake.

Read →

Deepfake

Synthetic media, video, voice or images, generated by AI to convincingly imitate a real person, increasingly used to "confirm" fraudulent payment instructions in corporate fraud.

Read →

DMARC

DMARC is a DNS-published policy that tells receiving servers what to do with mail failing SPF or DKIM alignment for your domain, and sends you reports.

Read →

DORA (Digital Operational Resilience Act)

DORA is the EU regulation on digital operational resilience for the financial sector, directly binding since 17 January 2025, built on five pillars covering ICT risk, incidents, testing, third-party risk and information sharing.

Read →

Email Spoofing

Email spoofing is the forging of email sender information so a message appears to come from someone the recipient trusts. It is the foundational technique behind phishing, BEC and whaling.

Read →

EU AI Act

The EU AI Act is the world's first comprehensive AI law, regulating AI systems by risk level and placing duties on organizations that deploy AI as well as those that build it.

Read →

GDPR

GDPR is the EU's data protection law, requiring appropriate security of personal data and notification of personal data breaches to supervisory authorities within 72 hours of awareness.

Read →

HIPAA

The US law governing privacy and security of protected health information, with breach notification duties and a leading role for email as a breach source.

Read →

HITRUST

The healthcare industry certification whose CSF harmonizes HIPAA, ISO and NIST requirements into one certifiable framework, common in US healthcare vendor deals.

Read →

Integrated Cloud Email Security (ICES)

Integrated Cloud Email Security (ICES) is the API-based email security category that works inside Microsoft 365 and Google Workspace instead of rerouting mail.

Read →

Invoice Fraud

Invoice fraud is the family of scams where organizations are tricked into paying fraudulent invoices or redirecting legitimate payments to attacker-controlled accounts.

Read →

ISO 27001

ISO 27001 is the international standard for information security management systems (ISMS), the most commonly requested security certification in European B2B procurement.

Read →

ISO 42001

ISO/IEC 42001 is the first international, certifiable standard for AI management systems, governing how organizations develop and use AI responsibly.

Read →

Malvertising

The use of legitimate online advertising networks to deliver malware or route victims to phishing pages, including search ads impersonating trusted software brands.

Read →

MFA Fatigue

MFA fatigue (push bombing) floods a user with authentication prompts until they approve one. It turns MFA's one-tap convenience into the weak point.

Read →

NIS2 Directive

NIS2 is the EU cybersecurity directive requiring essential and important entities across 18 sectors to manage cyber risk, secure supply chains and report significant incidents on strict deadlines, with personal accountability for management.

Read →

NIST Cybersecurity Framework

The voluntary US framework for organizing cybersecurity work, structured in CSF 2.0 around six functions from Govern to Recover.

Read →

PCI DSS

The contractual security standard for organizations handling payment card data, maintained by the PCI Security Standards Council, with 12 requirement areas.

Read →

Phishing

Phishing is the fraudulent message, most often email, that starts most breaches. Attackers impersonate a trusted party to trick recipients into revealing credentials, paying money, granting access or installing malware.

Read →

Pretexting

Pretexting is a social engineering technique where an attacker invents a believable scenario to justify asking for information, access or money. It powers most business email compromise attacks.

Read →

Prompt Injection

Prompt injection hides malicious instructions in content an AI system processes, hijacking what it does. It's widely regarded as the top security risk for LLM applications.

Read →

Quishing

Phishing where the malicious link is delivered as a QR code, evading text-based email scanners and moving the attack to the user's phone.

Read →

Ransomware

Ransomware encrypts your data (and increasingly steals it first) to extort payment. Most attacks start with a phishing email or a stolen credential, days before encryption.

Read →

Ransomware-as-a-Service

A criminal business model where ransomware developers lease their malware to affiliates who carry out attacks, splitting the ransom. Phishing is the model's main entry point.

Read →

Secure Email Gateway (SEG)

A secure email gateway (SEG) is a mail security layer deployed in front of an email platform via MX rerouting to filter spam, malware and known threats before delivery.

Read →

Shadow AI

Shadow AI is the use of AI tools, models or AI-powered integrations inside an organization without IT or security team approval.

Read →

Shadow IT

Shadow IT is any software, hardware, cloud service or integration used inside an organization without IT department approval or oversight.

Read →

Smishing

Phishing delivered by SMS text message. For companies the danger is the channel hop: attacks that start in email and move to unmonitored phones.

Read →

SOC 2

SOC 2 is an AICPA attestation standard where an independent auditor examines how a service organization protects customer data against the Trust Services Criteria.

Read →

Social Engineering

Social engineering is the manipulation of people, rather than systems, to gain access, information or money. It is the human layer nearly every modern cyberattack relies on.

Read →

Spear Phishing

Spear phishing is a phishing attack crafted for one specific, researched person: the message references your real projects, colleagues and context so that acting on it feels natural.

Read →

Supply Chain Attack

A supply chain attack compromises an organization through a trusted supplier, software or service provider. Regulators now mandate supply chain security explicitly.

Read →

Thread Hijacking

Thread hijacking injects malicious replies into real, ongoing email conversations, borrowing their trust and context to defeat normal suspicion.

Read →

TISAX

The automotive industry's shared information security assessment, based on the VDA ISA catalog and required by many OEMs before sharing sensitive data.

Read →

Typosquatting

Typosquatting registers domains that resemble legitimate ones to deceive users, a foundation of phishing and BEC that DMARC cannot stop.

Read →

Vendor Email Compromise (VEC)

Vendor email compromise (VEC) is business email compromise where attackers hijack or imitate a supplier's mailbox to redirect payments inside genuine invoice threads.

Read →

Vishing

Vishing is phishing over phone calls, now supercharged by AI voice cloning. It exploits the immediacy and authority of a live voice, and increasingly pairs with email fraud.

Read →

Whaling Attack

Whaling is a highly targeted phishing attack aimed at senior executives (CEOs, CFOs) whose authority can move money and unlock data. It is the executive tier of spear phishing and a core BEC technique.

Read →

Zero Day Attacks

Attacks exploiting a vulnerability the vendor has not yet patched. Signatures fail by definition; most zero-days arrive by email.

Read →

Know the words. Then stop the thing.

Free for one account. Four minutes to connect.