{
	"glossary": {
		"#" : [
			{
				"term": "3-2-1 Rule",				
				"termCtrIdSuffix": "321rule", 
				"definition": "The 3-2-1 Rule is a backup strategy where 3 copies of data are maintained, using at least 2 types of storage media (e.g., disks and tape, as an issue specific to one form of media should not affect all copies) with 1 copy stored offsite (to prevent an on-site issue, such as a fire, destroying all copies). The 3-2-1 rule ensures the organisation will always have a copy of data that can be restored."
			}
		],
		"A": [
			{
				"term": "Air Gap",				
				"termCtrIdSuffix": "airgap", 
				"definition": "An air gapped system or device is IT infrastructure that is physically isolated from a larger network or the internet i.e., there are no cables through which malware might enter or data may be exfiltrated. <a href=\"https://blog.k7computing.com/air-gapping-for-enterprise-cybersecurity-what-why-how/\" target=\"_blank\">Air gapped devices or networks are used in very high security environments</a> that aim for zero cyberattack risk. Air gapped systems can also have cybersecurity solutions installed; the cybersecurity solutions used in such security sensitive environments, such as <a href=\"https://www.k7computing.com/business-users/endpoint-security/k7-on-premises-EPS\" target=\"_blank\">K7 Endpoint Security</a>, support offline updates to allow the solutions to receive malware definition updates without being connected to the internet."
			},
			{
				"term": "AMSI",				
				"termCtrIdSuffix": "amsi", 
				"definition": "The Antimalware Scan Interface (AMSI) is a Windows standard that allows software to integrate malware scanning capabilities from cybersecurity solutions. Threat actors may use features present in software, such as support for user scripts, to launch attacks by running malicious scripts in the software; such activity within a software or service can be examined for threats through the AMSI combined with a cybersecurity solution. AMSI scanning includes files, memory, streams, URLs, and IPs, and facilitates the identification and detection of fileless malware."
			},
			{
				"term": "Antivirus",				
				"termCtrIdSuffix": "antivirus", 
				"definition": "Antivirus is a general term used to describe a cybersecurity product that protects computing devices (and users) from digital threats. Such threats are no longer limited to computer viruses, and antivirus products do a lot more than just protect against viruses. They can also protect against Trojans, worms, ransomware, phishing, hacking, webcam spying, identity theft, and many other cyberattacks. Antivirus is not restricted to PCs and is available for, and required by, mobile phones and tablets. Antivirus may also include theft-protection features for mobile devices."
			},
			{
				"term": "ASM",
				"termCtrIdSuffix": "asm", 
				"definition": "The attack surface of an organisation is any point of entry for an attacker, including cloud assets and any parts of enterprise IT infrastructure or data that can be accessed by vendors. Attack Surface Management (ASM) is the continuous monitoring of the attack surface to identify new points of entry, evaluation of the attack surface from the perspective of an attacker, and securing all points of entry."
			}
		],
		"B": [
			{
				"term": "Backdoor",
				"termCtrIdSuffix": "backdoor", 
				"definition": "A backdoor is an attacker’s entry point into IT infrastructure. A backdoor may exist due to a vulnerability in any of the software used by the organization or individual, or may have been created by the attacker e.g., an employee may deliberately install malware that allows them to bypass the cyber defences of the organization. Backdoors may be also be installed by threat actors in legitimate software (digital supply chain attacks) by compromising the organisation that develops the software, creating a backdoor into every organisation that uses the software."
			},
			{
				"term": "Behaviour-based Analysis",
				"termCtrIdSuffix": "bbanalysis", 
				"definition": "Behaviour-based Analysis is the identification of cyberthreats by analysing the behaviour of processes rather than relying on signatures of already known threats. Behaviour-based analysis is necessary for identification and blocking of obfuscated (disguised) or unknown/zero-day attacks where no signature or patch is available."
			},
			{
				"term": "Black Hat Hacker",
				"termCtrIdSuffix": "bhhacker", 
				"definition": "A black hat hacker is the kind of individual whom the media usually refers to as a ‘hacker.’ Such hackers find flaws in digital infrastructure without obtaining the owner’s permission and use the flaws they discover for malicious purposes such as stealing data or demanding a ransom. Black hat hacking activity is always illegal."
			},
			{
				"term": "Botnet",
				"termCtrIdSuffix": "botnet", 
				"definition": "A botnet (robot + network) is a group of devices that are connected to the internet and are under the remote control of a threat actor through the installation of bots on the devices. The bots may be installed through phishing emails, social media messages, or unpatched vulnerabilities. A botnet can be used for a variety of malicious activities including launching a <a href=\"javascript:void(0);\" onclick=\"scrollToSectionTerm('#section-D-dosddos')\">Distributed Denial of Service (DDoS) attack</a>, sending <a href=\"javascript:void(0);\" onclick=\"scrollToSectionTerm('#section-S-spam')\">spam email</a>, or mining cryptocurrency. The attacker may not attack the device on which the bot is installed, but use the device to launch attacks against other victims. Bots can be removed by using the <a href=\"https://www.k7computing.com/k7-bot-removal-tool\" target=\"_blank\">K7 Bot Removal Tool.</a>"
			},
			{
				"term": "Brute Force Attack",
				"termCtrIdSuffix": "bfattack",
				"definition": "A Brute Force Attack repeatedly tries different combinations of characters, or different combinations of usernames and passwords, or different combinations of targets and credentials (attacker has the username and password and tries to discover what they unlock) until the correct combination is discovered and the credentials are obtained/target compromised. A brute force attack is a trial and error approach that can be used to obtain access to a user account, device, network, system, or service; or to access a password protected file. Brute Force Attacks can be prevented by limiting the number of access attempts within a time period; implementing <a href=\"javascript:void(0);\" onclick=\"scrollToSectionTerm('#section-M-mfa')\">Multi-Factor Authentication (MFA)</a>; monitoring spikes in traffic and failed logins; and restricting IP addresses that are allowed to attempt login or blocking IP addresses from which multiple failed logins are detected."
			},
			{
				"term": "BYOD",
				"termCtrIdSuffix": "byod",
				"definition": "Bring Your Own Device (BYOD) is a policy where employees are allowed to use computing devices of their choice, such as their personal devices, rather than devices issued by their employer. BYOD has the advantage of allowing employees to use the form factor, platforms, and applications they are familiar with, and can also save capex for the organisation as device investment is avoided. Cybersecurity, however, may be compromised as the employee’s personal device will usually not be provisioned with cybersecurity (configuration, permissions, security tools) to the same extent as a device issued by the organisation."
			}
		],
		"C": [
			{
				"term": "Catfishing",
				"termCtrIdSuffix": "catfishing",
				"definition": "Catfishing is a form of social engineering where the attacker assumes a persona to deceive the victim e.g., the victim begins chatting with the attacker on a dating website, and is eventually drawn into a scam. The attacker may use photos and other personal information sourced online (or even in person) to impersonate a person to allow the victim to believe they can verify the identity of the person they believe they are interacting with. Catfishing is particularly used in romance scams."
			},
			{
				"term": "Clickjacking",
				"termCtrIdSuffix": "clickjacking",
				"definition": "Clickjacking (click + hijacking) is malicious activity where a click results in an action different from the action expected by the user e.g., the user clicks on a button in a webpage but the result is a click on a button in a different webpage that authorises an action such as payment verification or password change. Clickjacking may take different forms, such as making a cursor appear at a different location (from its actual location) on the user’s screen or by hijacking taps on mobile device screens."
			},
			{
				"term": "Cloud Deployment",
				"termCtrIdSuffix": "clouddplymnt",
				"definition": "Enterprise cybersecurity solutions require a console that syncs with individual devices and manages cybersecurity for each device. The console provides centralised control over cybersecurity across the enterprise. The console may be installed on a device in the facility where endpoints need to be protected (on-premises deployment) or in the cloud. The advantages of cloud deployment include anytime, anywhere cybersecurity management using just a browser, and support for 100% remote deployment of cybersecurity to each endpoint. Regulators in some industries may specify that the console must be on premises and cannot be in the cloud."
			},
			{
				"term": "Cross-Site Scripting",
				"termCtrIdSuffix": "ccscripting",
				"definition": "Cross-Site Scripting (abbreviated as XSS) is the injection of malicious scripts into otherwise benign and trusted websites. An attacker can use cross-site scripting to send malicious code to a different end user and the user’s browser will execute the script, allowing the attacker to steal sensitive data, hijack sessions, and perform other malicious actions on the user’s device. Cross-site scripting attacks usually occur when a web application accepts user input <a href=\"https://blog.k7computing.com/top-5-vulnerabilities-in-web-applications-and-mitigation-methods/\" target=\"_blank\">without validation or encoding.</a>"
			}
		],
		"D": [
			{
				"term": "Dark Web",
				"termCtrIdSuffix": "darkweb",
				"definition": "The dark web, also known as the darknet, is a part of the World Wide Web that is not indexable by search engines and requires a special Tor browser for access. The dark web is not inherently illegal but is favoured by threat actors, due to its emphasis on privacy and anonymity, to <a href=\"https://blog.k7computing.com/the-dark-web-what-it-is-how-hackers-use-it-and-why-it-matters/\" target=\"_blank\">host hacker websites and communicate privately</a>."
			},
			{
				"term": "Deep Web",
				"termCtrIdSuffix": "deepweb",
				"definition": "The deep web is the part of the World Wide Web that is not indexable by search engines but can be accessed by the same web browsers that we use to access the <a href=\"javascript:void(0);\" onclick=\"scrollToSectionTerm('#section-S-surfaceweb')\">surface web</a>, in contrast to the <a href=\"javascript:void(0);\" onclick=\"scrollToSectionTerm('#section-D-darkweb')\">dark web</a> that can only be accessed through a special browser. Email, private social media, our bank records, and paywalled/subscription-based content are examples of deep web content; they can be accessed only after providing our credentials and are not indexed by search engines. The deep web is not inherently illegal but, similar to the surface web, can also be used for illegal purposes."
			},
			{
				"term": "DoS/DDoS",
				"termCtrIdSuffix": "dosddos",
				"definition": "A Denial of Service (DoS) attack floods a website or network with more traffic/data than it can handle, resulting in poor user experience or service unavailability. A Distributed Denial of Service (DDoS) attack floods the victim website or network by using a large number of attacking devices, such as a <a href=\"javascript:void(0);\" onclick=\"scrollToSectionTerm('#section-B-botnet')\">botnet.</a>"
			},
			{
				"term": "Drive-by Download",
				"termCtrIdSuffix": "dbd",
				"definition": "A Drive-by Download is a malicious file that downloads to the user’s device without the user’s knowledge. The file may download from a website as soon as the page loads without the user clicking or otherwise interacting with the webpage. The user may not even be aware that the webpage is open as in the case of a popup or pupunder window tab. Computer software that use a browser’s engine to generate popups may also trigger a drive-by download through the popup despite the browser not being open."
			}
		],
		"E": [
			{
				"term": "Endpoint Security",
				"termCtrIdSuffix": "endpointsec",
				"definition": "An endpoint, in the context of computing, is a device that connects to a network. Endpoint security is a cybersecurity solution that protects endpoints such as desktops, laptops, and servers."
			}
		],
		"F": [
			{
				"term": "Firewall",
				"termCtrIdSuffix": "firewall",
				"definition": "A firewall is a network security component that monitors all data traffic flowing into and out of a network or device. Allowing or blocking data is governed by rules that are configured in the firewall and the optimisation of rules and configuration for security is known as <a href='https://blog.k7computing.com/strengthening-enterprise-cybersecurity-with-firewall-hardening' target='_blank'>firewall hardening</a>. The firewall may be hardware or software and deployed in a facility (network-based), installed in a device (host-based), or hosted in the cloud (cloud firewall)."
			},
			{
				"term": "File Integrity Monitoring",
				"termCtrIdSuffix": "fileim",
				"definition": "File Integrity Monitoring protects critical files in an organisation, such as Intellectual Property, confidential information, or other data that can be considered an enterprise’s crown jewels, by monitoring file creation, modification, movement, or deletion in areas where the files are stored."
			},
			{
				"term": "Fileless Malware",
				"termCtrIdSuffix": "flmalware",
				"definition": "Fileless malware are cyberattacks that do not exist as a file on disk, and are loaded directly into the device’s memory through a malicious script running in legitimate software. Conventional malware scanning of disks cannot spot such attacks as there is no file to be scanned. Fileless malware can be defeated by using the Windows <a href=\"javascript:void(0);\" onclick=\"scrollToSectionTerm('#section-A-amsi')\">Antimalware Scan Interface (AMSI)</a> to allow cybersecurity solutions (such as <a href=\"https://www.k7computing.com/business-users/endpoint-security/k7-on-premises-EPS/graphene/request-trial\" target=\"_blank\">K7 Endpoint Security</a> or <a href=\"https://www.k7computing.com/home-users/total-security\" target=\"_blank\">K7 Total Security</a>) to scan the scripts running in software for malicious activity."
			}
		],
		"G": [			
			{
				"term": "Grey Hat Hacker",
				"termCtrIdSuffix": "ghhacker",
				"definition": "A grey hat hacker blends elements of <a href=\"javascript:void(0);\" onclick=\"scrollToSectionTerm('#section-W-whhacker')\">white hat</a> and <a href=\"javascript:void(0);\" onclick=\"scrollToSectionTerm('#section-B-bhhacker')\">black hat</a> hacking. Similar to black hat hackers, grey hat hackers do not obtain permission before probing cyber defences for weaknesses. Similar to white hat hackers (and unlike black hat hackers) grey hat hackers do not compromise the organisation; they disclose identified gaps in defences to the organisation and may receive payment for such disclosure. Grey hat hacking is generally considered illegal, as permission was not obtained in advance for hacking, with illegality determined based on the specific laws they violated while hacking the organisation."
			},
			{
				"term": "G Suite Segmentation",
				"termCtrIdSuffix": "gsuiteseg",
				"definition": "G Suite/Google Workspace is a suite of cloud-based communication, productivity, and collaboration tools. G Suite Segmentation is the division of permissions/restrictions to permit access to a user’s enterprise Google Account for work but block access to the user’s personal Google Account, or a Google Account linked to a G Suite account hosted on any other domain, to prevent malware download and data theft."
			}
		],
		"H": [
			{
				"term": "Hacker",
				"termCtrIdSuffix": "hacker",
				"definition": "A hacker is an individual with the knowledge and skill to achieve technology objectives through unconventional means. Hackers, and hacking, need not be illegal but are often associated with illegal activity by the media. The terms White Hat Hackers, Black Hat Hackers, and Grey Hat Hackers have been coined to distinguish hackers and their hacking activities based on the legality/malice of their actions."
			},
			{
				"term": "HIDS/HIPS",
				"termCtrIdSuffix": "hidships",
				"definition": "An Intrusion Detection System monitors data traffic and helps uncover policy violations, misconfigurations, and malicious activity. An Intrusion Prevention System provides real-time analysis of data traffic and blocks known attacks. When these security components are installed on the device they are protecting (the host, such as an individual computer) they are known as Host Intrusion Detection System (HIDS) and Host Intrusion Prevention System (HIPS) to distinguish them from IDS/IPS systems that operate at the network level."
			}
		],
		"I": [
			{
				"term": "Identity Theft",
				"termCtrIdSuffix": "identitytheft",
				"definition": "Cyberattackers can impersonate an individual (steal their identity) in digital interaction to commit criminal acts. Identity Theft can range from applying for a loan in an individual’s name (which the victim will need to repay) to creating a deepfake of a CEO to persuade staff to act on the fake CEO’s instructions, such as transferring funds. The information used for successful impersonation may be obtained from data breaches or posts shared on social media. Audio and video of an individual may be used to generate deepfakes, and discarded documents and ID cards in stolen wallets may also be used for information theft."
			},
			{
				"term": "Insider Threat",
				"termCtrIdSuffix": "insiderthreat",
				"definition": "An insider threat refers to a threat that originates from a user who has authorised access to an organisation’s digital assets, such as an employee or contractor. Such threats need not be malicious, and may arise due to negligence or mistakes. Insider threats can be difficult to identify as the user is expected to be present and active in the system, and can be countered through <a href=\"javascript:void(0);\" onclick=\"scrollToSectionTerm('#section-L-lpaccess')\">Least Privilege Access</a>, <a href=\"javascript:void(0);\" onclick=\"scrollToSectionTerm('#section-U-ueba')\">User and Entity Behaviour Analytics</a>, and user training."
			}
		],
		"K": [
			{
				"term": "Keylogger",
				"termCtrIdSuffix": "keylogger",
				"definition": "An application that records a user’s keystrokes. Organisations may use keyloggers to manage security and maintain productivity, but keyloggers are often malicious software used by threat actors to steal user credentials. Modern keyloggers can go beyond recording keystrokes and may even take screenshots or record a video of a user’s activity to allow a threat actor to see exactly how the user interacts with an application or service."
			}
		],
		"L": [
			{
				"term": "Lateral Movement",
				"termCtrIdSuffix": "lmovement",
				"definition": "Lateral movement is a technique used by cyberattackers where they first gain access to a computing asset in a network and then move to other assets in the network to achieve large scale compromise. The attacker may first gain access to a computer of a user in the HR department by sending an email with a malicious attachment, move through the network until they gain access to an IT admin’s device, and eventually target the victim organisation’s data backups."
			},
			{
				"term": "Least Privilege Access",
				"termCtrIdSuffix": "lpaccess",
				"definition": "Also known as the Principle of Least Privilege, Least Privilege Access refers to a user (or any entity, including machines and applications) being granted only the access rights that are essential for their tasks and removing access rights they do not, or no longer, require. This limits the damage that can be caused if the user’s credentials are compromised or if the user chooses to act maliciously."
			}
		],
		"M": [
			{
				"term": "Macros",
				"termCtrIdSuffix": "macros",
				"definition": "A macro is a mini-program that can execute a set of instructions to automate tasks e.g., macros in Excel. Macros can be created by the user or be received along with a file, and the instructions in the macro may be malicious. Macros are usually disabled by default to prevent execution of malicious instructions, and users must enable them only after verifying that enabling macros is necessary to complete their task and scanning the file for threats."
			},
			{
				"term": "MDR",
				"termCtrIdSuffix": "mdr",
				"definition": "Managed Detection and Response (MDR) is a cybersecurity service that protects enterprises with the MDR provider analysing, predicting, defending, detecting, and responding to cyberthreats. The MDR provider has the tools and knowhow to deliver expert cybersecurity services at a standard that an in-house team cannot match, and the enterprise does not need to invest in the tools, talent, and training required for 24/7 cybersecurity monitoring and response."
			},
			{
				"term": "MFA",
				"termCtrIdSuffix": "mfa",
				"definition": "Multi-Factor Authentication (MFA) is the use of more than one credential to authenticate a user or provide access to a digital resource. Requiring a password and OTP is an example of MFA. The factors can include Something You Know (e.g., passwords/PINs); Something You Have (e.g., OTP); Something You Are (e.g., biometrics); Something You Do (e.g., sequence of tasks); Somewhere You Are (location). MFA must be carefully implemented to <a href='https://blog.k7computing.com/mfa-fix-it-before-it-is-bypassed/' target='_blank'>avoid threat actors bypassing MFA.</a>"
			},
			{
				"term": "MITRE ATT&CK Framework",
				"termCtrIdSuffix": "maframework",
				"definition": "The MITRE ATT&CK Framework is a collection of the tactics and techniques used by cyberattackers. It includes 14 categories: Reconnaissance, Resource Development, Initial Access, Execution, Persistence, Privilege Escalation, Defence Evasion, Credential Access, Discovery, Lateral Movement, Collection, Command and Control, Exfiltration, and Impact. Multiple techniques and sub-techniques are listed under each category. Detailed descriptions of how cyberattackers compromise technology systems are provided for each category, technique, and sub-technique, enabling cybersecurity practitioners to develop defences and mitigation measures against each attack."
			}			
		],
		"N": [
			{
				"term": "Network Segmentation",
				"termCtrIdSuffix": "networkseg",
				"definition": "Network Segmentation is the division of a network into sub networks (segments) that can function as a small network. The network may be segmented using hardware (physical segmentation) or software (logical segmentation). Network segmentation can improve cybersecurity by preventing lateral movement i.e., malware may be unable to move from one segment to another or a threat actor who has gained unauthorised access to a network segment may not be able to access another network segment, containing the attack to the affected network segment."
			}
		],
		"O": [
			{
				"term": "On-demand Scan",
				"termCtrIdSuffix": "ondmndscan",
				"definition": "An On-demand Scan is a security scan that is initiated by the user for a specific purpose. This is distinct from a real-time scan which is automatically initiated when an event occurs, such as a file being downloaded, or a scheduled scan which is initiated at a particular time. An on-demand scan can be initiated by the end user or by an admin on an end user’s machine."
			}
		],
		"P": [
			{
				"term": "Phishing",
				"termCtrIdSuffix": "phishing",
				"definition": "Phishing is a form of social engineering where the attacker persuades the user to perform an action that isn’t in the user’s best interest, such as transferring funds or installing a malicious application. Phishing can occur through emails, phone calls, text messages, or social media. Phishing variants include whaling – targeting high value victims such as CEOs; and spear phishing – using customised methods and messages to target a specific individual. Phishing may depend purely on persuasive communication, which may include deepfakes, and not include malware, making it difficult to identify and block with purely technology-based solutions. User awareness, at the individual level, and verification processes, at an organisational level, are necessary for effective defence against phishing. An employee receiving a WhatsApp message from a person claiming to be the CFO with instructions for an emergency fund transfer is an example of a phishing message that cannot be stopped purely by technology and requires user awareness and organisational policy to prevent the fund transfer scam from succeeding."
			},
			{
				"term": "PII",
				"termCtrIdSuffix": "pii",
				"definition": "Personally Identifiable Information (PII) is any data related to an individual that is specific to an individual and can be used to identify or locate them. An Aadhaar Number or Social Security Number is PII. Direct personal identifiers can identify an individual without addition information (e.g., a phone number) while indirect personal identifiers can be used in combination to identify an individual (e.g., address and first name). Stolen PII can be used to steal an individual’s identity (e.g., a threat actor can impersonate a victim and obtain a bank loan that the victim will have to repay) and are highly targeted in data breaches; businesses should, therefore, ensure additional protection for customers’ PII."
			}
		],
		"Q": [
			{
				"term": "QR Code",
				"termCtrIdSuffix": "qrcode",
				"definition": "A QR code (quick-response code) is used to lead the user to information and is often used to link URLs for promotional campaigns that users can easily access by scanning the code with their mobile phone’s camera. They are also increasingly used to link to payment recipients. QR codes present a cybersecurity risk as the user is not immediately aware of the underlying URL and the code can be used to link to a malicious web asset. Cyberattackers may also use QR codes to launch attacks by exploiting vulnerabilities in the application (such as the camera app on a phone) used to read the QR code."
			}
		],
		"R": [
			{
				"term": "Real-time Scan",
				"termCtrIdSuffix": "rtscan",
				"definition": "Real-time scanning is used by cybersecurity solutions to identify a cyberthreat at the moment of access e.g., an email attachment is scanned after the user clicks on the attachment but before the file opens, or a file is scanned as soon as it downloads. These scans ensure that a malicious payload cannot be activated by inadvertent user action. Real-time scanning is restricted to files that are used, in contrast to <a href=\"javascript:void(0);\" onclick=\"scrollToSectionTerm('#section-S-schscan')\">scheduled scanning</a>."
			},
			{
				"term": "Ransomware",
				"termCtrIdSuffix": "ransomware",
				"definition": "Ransomware is a type of cyberattack where files on a device are encrypted and the attacker demands a ransom, usually in cryptocurrency, for the decryption key. In double extortion ransomware, the attacker steals data, such as customers’ Personally Identifiable Information (PII), and threatens to expose the data if the ransom is not paid. In triple extortion ransomware, the stakeholders whose data has been stolen are approached by the attacker and a ransom is demanded to prevent their data being leaked."
			}
		],
		"S": [
			{
				"term": "Scheduled Scan",
				"termCtrIdSuffix": "schscan",
				"definition": "A scheduled scan is used by a cybersecurity solution to scan all files, irrespective of whether they are being used or not. Such scans enable the identification of dormant malware, i.e., malware that has not been activated yet but could activate on a certain date or due to user action. They can also spot malware that avoided being identified when downloaded because the downloaded file did not contain a malicious component and acquired it later. Scheduled scans may take time to complete, and support scheduling to avoid interfering with the user’s normal use of the device."
			},
			{
				"term": "SD-WAN",
				"termCtrIdSuffix": "sdwan",
				"definition": "Software Defined WAN (<a href='https://blog.k7computing.com/creating-secure-branch-connectivity-with-sd-wan/' target='_blank'>SD-WAN</a>) is a cost-effective and reliable method to provide connectivity between the head offices, branches, data centres, cloud services, and remote employees, by using conventional internet to avoid the cost and complexity of using private WAN/dedicated carrier channels. SD-WAN such as <a href='https://www.k7computing.com/business-users/network-security/k7-sd-wan' target='_blank'>K7 SD-WAN</a> can use multiple connectivity options to balance the load or switch between connectivity lines to improve reliability and uptime, and integrate VPN to enhance security."
			},
			{
				"term": "SIEM",
				"termCtrIdSuffix": "siem",
				"definition": "Security Information and Event Management (SIEM) is a cybersecurity solution used by enterprises to collect security data from across the organisation and analyse the data to predict and prevent attacks. Security analysts use SIEM to quickly make sense of the large amounts of security event data generated by the vast number of devices, applications, and services used by the enterprise. In addition to anticipating and responding to security events, SIEMs can also help organisations maintain regulatory compliance. Modern SIEMs can be hosted in the cloud for quick access from anywhere, and incorporate AI to identify trends and anomalies that security analysts should pay immediate attention to."
			},
			{
				"term": "SOAR",
				"termCtrIdSuffix": "soar",
				"definition": "Security Orchestration, Automation, and Response (SOAR) automates cybersecurity tasks and reduces the security team’s effort and stress. Predefined workflows are triggered when specific events occur or a pattern is noticed in security data. SOAR improves speed of response and allows security teams to focus attention on tasks and events that require human intervention."
			},
			{
				"term": "SOC",
				"termCtrIdSuffix": "soc",
				"definition": "A Security Operations Centre (SOC) is a centralised unit in an organisation (or even a nation) that has the tools and team to monitor security event data and respond to activity that is malicious or initiate investigation into activity that is suspicious. SOCs enable coordinated and efficient cybersecurity operations. In addition to maintaining cybersecurity, SOCs can also ensure compliance with internal and external standards and regulations."
			},
			{
				"term": "Spam",
				"termCtrIdSuffix": "spam",
				"definition": "Spam is bulk messages that have not been requested or are not wanted by users. The messages may be advertising/commercial messages, or attacks such as phishing campaigns. Spam messages may be sent through email, text messages, or social media, and can involve the use of comments or tags. Spam messages that are not malicious can still affect users due to lost productivity and cost of computing resources (storage, bandwidth, AI tokens, etc.) consumed."
			},
			{
				"term": "SQL Injection",
				"termCtrIdSuffix": "sqlinjection",
				"definition": "Structured Query Language (SQL) is a language used to interact with databases. <a href=\"https://blog.k7computing.com/top-5-vulnerabilities-in-web-applications-and-mitigation-methods/\" target=\"_blank\">SQL Injection is a web application vulnerability</a> that permits SQL code to be included as valid user input (e.g., in web forms), allowing threat actors to trick the database server into executing unintended actions such as accessing, modifying, or deleting data."
			},
			{
				"term": "Surface Web",
				"termCtrIdSuffix": "surfaceweb",
				"definition": "The surface web is the part of the World Wide Web that we are most familiar with. It is the part of the WWW that is indexable and accessible through a search engine using a conventional browser, in contrast to the <a href=\"javascript:void(0);\" onclick=\"scrollToSectionTerm('#section-D-deepweb')\">deep web</a> that is accessible through conventional browsers but not indexable by search engines and the <a href=\"javascript:void(0);\" onclick=\"scrollToSectionTerm('#section-D-darkweb')\">dark web</a> that is not indexable by search engines and needs a special browser for access. News, ecommerce, and corporate websites are examples of websites on the surface web. Using the surface web is legal, but it can also be used for illegal activities."
			}
			
		],
		"T": [
			{
				"term": "Threat Intelligence",
				"termCtrIdSuffix": "tintel",
				"definition": "Threat Intelligence, in the context of cybersecurity, is gathering information on cyberthreats from around the world, providing context, and abstracting information on malicious digital activity to proactively prevent cyberattacks. It eliminates the noise and emphasises the signal, provides a big picture view from which analysts can drill down to specific instances, and therefore provides much more value than a feed of Indicators of Compromise (IoCs). Threat intelligence is provided by a threat lab, such as K7 Labs, which gathers threat samples through multiple mechanisms from around the world and then analyses the threat samples to generate threat intelligence. The threat intelligence is used by security products and services vendors, or provided as a feed that can integrate with a Security Operations Centre (SOC), Security Information and Event Management (SIEM) solution, or a network security solution."
			}
		],
		"U": [
			{
				"term": "UEBA",
				"termCtrIdSuffix": "ueba",
				"definition": "User and Entity Behaviour Analytics (UEBA) establishes normal or expected behaviour for an organisation’s users and digital assets, and identifies deviations from such behaviour to flag potential malicious activity. UEBA can be particularly effective in identifying insider attacks which may be otherwise difficult to spot as the user has legitimate access privileges to the organisation’s systems."
			}
		],
		"V": [
			{
				"term": "VAPT",
				"termCtrIdSuffix": "vapt",
				"definition": "Vulnerability Assessment and Penetration Testing (<a href='https://blog.k7computing.com/using-vapt-to-strengthen-enterprise-cybersecurity/' target='_blank'>VAPT</a>) involves scanning an organisation’s IT resources (devices, applications, networks, and services) for vulnerabilities (Vulnerability Assessment); and performing ethical hacking to attempt to exploit an identified vulnerability (Penetration Testing). VAPT like <a href='https://www.k7computing.com/business-users/services/k7-vapt' target='_blank'>K7 VAPT</a> includes both software-based assessment and forensic investigation by experts who perform white hat hacker attacks on systems from both within and outside the enterprise for a comprehensive security evaluation."
			},
			{
				"term": "VPN",
				"termCtrIdSuffix": "vpn",
				"definition": "A Virtual Private Network (VPN) overcomes the risks in using public internet to transmit confidential information by creating an encrypted connection through which the information is transmitted. The encryption creates a secure tunnel between the user/device and the network or digital asset they wish to connect to, such as a website or a file server in an organisation. VPNs have several practical real-world uses including keeping individuals safe when using free Wi-Fi networks in coffee shops and other public spaces, and allowing remote workers to securely connect to enterprise networks."
			}
		],
		"W": [
			{
				"term": "Watering Hole Attack",
				"termCtrIdSuffix": "whattack",
				"definition": "In the natural world, predators lurk near watering holes to target their prey when they arrive at the waterbody to drink water. In the digital world, cyberattackers use Watering Hole Attacks where they compromise websites that they know their targets are likely to use, with the goal of downloading malware to the users’ computers or otherwise compromising users. Cybersecurity/antivirus solutions cannot block the compromised website as it is a legitimate website the user needs access to, and must use techniques like real-time scanning and blocking of drive-by downloads to protect the end user."
			},
			{
				"term": "White Hat Hacker",
				"termCtrIdSuffix": "whhacker",
				"definition": "A white hat hacker, or an ethical hacker, uses their hacking skills to improve the security of digital infrastructure. They evaluate digital assets, after being invited by or obtaining permission from the owner, and disclose any flaws they find to the owner to be fixed. White hat hacking is legal and is widely used to identify and fix flaws in cyber defences before they are discovered by <a href=\"javascript:void(0);\" onclick=\"scrollToSectionTerm('#section-B-bhhacker')\">black hat hackers</a>. K7’s Vulnerability Assessment and Penetration Testing (<a href=\"https://www.k7computing.com/business-users/services/k7-vapt\" target=\"_blank\">K7 VAPT</a>) service includes white hat hacking to identify vulnerabilities in enterprise digital infrastructure."
			}
		],
		"X": [
			{
				"term": "XDR",
				"termCtrIdSuffix": "xdr",
				"definition": "Extended Detection and Response (XDR) solutions overcome the fragmentation of enterprise cybersecurity by providing a unified solution that can integrate other cybersecurity products. Security analysts will not need to view the dashboards of different cybersecurity solutions for endpoints, networks, cloud, email, etc., and can instead view a single dashboard that receives inputs from the individual cybersecurity products and enriches them with correlation and analysis to help cyber defenders quickly understand cybersecurity across the organisation and proactively initiate defensive measures before a cyberattack can commence."
			}
		],
		"Z": [
			{
				"term": "Zero-day Attack",
				"termCtrIdSuffix": "zdattack",
				"definition": "A zero-day attack is a cyberattack that exploits a vulnerability for which no patch is available from the developer of the application, operating system, or device. The developer may not even be aware of the existence of the vulnerability. The ‘zero’ in ‘zero-day’ represents the number of safe days before the vulnerability is exploited i.e., there are no safe days. As the vulnerability is unknown, cybersecurity solutions cannot rely on an attack signature to defend against a zero-day attack and will instead use behaviour-based analysis to identify malicious activity. Security solution testers verify the effectiveness of cybersecurity solutions against zero-day attacks by <a href='https://blog.k7computing.com/k7s-perfect-anti-ransomware-score-and-why-it-matters/' target='_blank'>turning off signature-based analysis and using only the behaviour-based analysis of the solution</a> against malware samples."
			},
			{
				"term": "Zero Trust",
				"termCtrIdSuffix": "ztrust",
				"definition": "Zero Trust is an architecture that follows the ‘never trust, always verify’ model to provide access. Verification is always required to confirm authenticity, for both users and devices, for access attempts from both within and outside the network. This is distinct from other security models that may assume that access attempts from within the enterprise network are genuine and not require verification."
			}
		]
	}
}