IT & Cybersecurity Glossary | IP Consulting
Knowledge Hub Plain-language guides from the engineers who do this every day. All articles →
Glossary

IT, security, and AI terms, in plain English

Every acronym and buzzword you are likely to hear from an IT partner, defined without the jargon. Search or scroll the full list.

57 terms
Back to Knowledge Hub →
Access control
Rules that decide who can open which files, apps, and systems, and what they can do once inside.
Agentic AI
AI that does not just answer questions but takes multi-step action toward a goal on your behalf, choosing tools as it goes.
Anti-malware / Antivirus
Software that detects and removes malicious programs before they can do damage.
Attack surface
Every device, account, and app an attacker could try to get into. The smaller it is, the safer you are.
Backup
A separate copy of your data you can restore from if the original is lost, corrupted, or encrypted.
Bandwidth
How much data your internet connection can carry at once. Too little causes slowdowns.
BCDR
Business Continuity and Disaster Recovery. Your plan for keeping the business running, and getting back up fast, after an outage.
BEC
Business Email Compromise. A scam where an attacker poses as a trusted person over email to trick staff into sending money or data.
BYOD
Bring Your Own Device. Letting staff use personal phones or laptops for work, which calls for extra security rules.
CJIS
The FBI security policy that governs how criminal justice data is handled. Required for many police and municipal systems.
Cloud
Computing you rent instead of own. It can be public, private, or a hybrid of both.
Cloud migration
Moving your systems, data, or apps from on-site servers into cloud services.
CMMC
Cybersecurity Maturity Model Certification. The security standard defense contractors must meet to keep federal contracts.
Co-managed IT
A model where we work alongside your in-house IT team instead of replacing it.
Compliance
Meeting the security and privacy rules a law, framework, or contract requires of you.
CUI
Controlled Unclassified Information. Sensitive government data that is not classified but still must be protected. Central to CMMC.
Dark web monitoring
Watching underground marketplaces for your stolen credentials or data so you can react before they are used.
Data breach
An incident where sensitive data is accessed, stolen, or exposed to people who should not have it.
DNS
The internet's address book. It translates website names into the numeric addresses computers actually use.
EDR / XDR
Endpoint and extended detection and response. Tools that catch and stop threats on your devices automatically.
Encryption
Scrambling data so only someone with the key can read it, protecting it both in transit and at rest.
Endpoint
Any device that connects to your network: laptops, desktops, phones, and servers.
Firewall
A control point that decides what network traffic is allowed in and out.
GRC
Governance, Risk, and Compliance. Running security and compliance as an ongoing program rather than a one-time task.
Help desk
The team you contact when something is broken or you need IT support. Also called a service desk.
HIPAA
The U.S. law that sets rules for protecting patient health information.
IaaS / PaaS / SaaS
Three ways to buy cloud: raw infrastructure, a platform to build on, or ready-to-use software.
Immutable backup
A backup copy that cannot be altered or deleted, even by an attacker or by ransomware.
Incident response
The planned steps an organization takes to contain, investigate, and recover from a security incident.
Least privilege
Giving each person and system only the access they need to do their job, and nothing more.
LLM
Large Language Model. The kind of AI behind chatbots, trained to understand and generate human language.
MDR
Managed Detection and Response. A service where a team watches your environment and responds to threats for you, around the clock.
MFA
Multi-Factor Authentication. A second step at login, like a code on your phone, that blocks most account takeovers.
MSP
Managed Service Provider. A partner that runs your IT day to day for a predictable monthly fee.
Network segmentation
Splitting a network into zones so a problem in one area cannot spread freely to the rest.
NIST
A U.S. agency whose cybersecurity frameworks are a common baseline for good security practice.
Password manager
An app that creates and stores strong, unique passwords so people do not have to remember them.
Patch management
Keeping software and systems updated so known security holes get closed before they are exploited.
Penetration test
An authorized, simulated attack on your systems to find weaknesses before a real attacker does.
Phishing
Fake emails or messages designed to trick someone into giving up a password or clicking a bad link.
Ransomware
Malware that encrypts your files and demands payment to unlock them.
RMM
Remote Monitoring and Management. The tooling an MSP uses to watch and maintain your systems remotely.
RPO / RTO
Recovery Point and Recovery Time Objectives. How much data, and how much time, you can afford to lose in an outage.
Server
A powerful computer that stores data or runs services that other devices rely on.
Shadow AI
Employees using AI tools that IT has not approved or does not know about, creating hidden data risk.
SIEM
Security Information and Event Management. A system that collects logs from across your environment to spot threats.
SLA
Service Level Agreement. A written promise of response times and uptime you can hold a provider to.
SOC
Security Operations Center. The team and tooling that monitors your environment 24/7.
Social engineering
Manipulating people, rather than hacking machines, to gain access or information.
Spam filtering
Automatically screening out junk and malicious email before it reaches inboxes.
SSO
Single Sign-On. One secure login that gets a user into many apps, with less password sprawl.
Threat actor
The person or group behind a cyberattack.
Uptime
The percentage of time a system is running and available. Higher is better.
VoIP
Voice over IP. Phone service delivered over the internet instead of traditional phone lines.
VPN
Virtual Private Network. An encrypted tunnel that lets remote users connect to a network securely.
Vulnerability
A weakness in software or configuration that an attacker could exploit.
Zero Trust
A security approach that verifies every user and device every time, instead of trusting anything by default.

Still have a question? Let's talk it through.

A 30-minute Navigate Clarity Conversation with a real IPC engineer. No obligation, no jargon.

Start with a Navigate Clarity Conversation