Resources
IT glossary
Every acronym, in one sentence.
Plain-English definitions of the IT and cybersecurity terms you are most likely to be handed by a vendor, an insurer or an auditor. Each one opens with a single sentence that answers the question, then explains why it matters to you.
-
BYOD Bring Your Own Device
BYOD, or bring your own device, is letting staff use their own phones and laptops for work, under rules about what company data may go on them.
-
Co-managed IT Co-managed information technology
Co-managed IT is an arrangement where your internal IT person keeps running things day to day and an outside provider works alongside them, not instead.
-
Cyber insurance
Cyber insurance covers part of the cost of a security incident, investigation, recovery, legal help, lost trade, if you had the controls you claimed.
-
Dark web monitoring
Dark web monitoring searches leaked and stolen data for your company's email addresses and passwords, and tells you when one turns up in a breach dump.
-
Disaster recovery plan
A disaster recovery plan is a written, tested document saying how your organization gets its systems and data back after an outage, and who does what.
-
EDR Endpoint Detection and Response
EDR, or endpoint detection and response, is security software on laptops and servers that watches for suspicious behaviour and can isolate the machine.
-
MFA Multi-factor authentication
MFA, or multi-factor authentication, means proving who you are with more than one thing, usually a password plus a code or approval on your phone.
-
MSP Managed Services Provider
An MSP, or managed services provider, is a company you pay a fixed monthly fee to run your technology: the helpdesk, servers, networks and updates.
-
MSSP Managed Security Services Provider
An MSSP, or managed security services provider, runs your cybersecurity monitoring and response, watching for suspicious activity and acting on it.
-
Patch management
Patch management is the routine of keeping software updated, tracking which updates exist, testing them, installing them, and confirming they landed.
-
Penetration testing
A penetration test is an exercise where a security specialist is paid to break into your systems the way an attacker would, then writes up what they found.
-
Phishing
Phishing is a message, usually email, sometimes a text or a call, made to look like it comes from someone you trust, so you hand over a password or money.
-
Ransomware
Ransomware is software that encrypts an organization's files so they cannot be opened, after which whoever placed it there asks for payment to unlock them.
-
RTO and RPO Recovery Time Objective and Recovery Point Objective
RTO is how long you can be down before it really hurts. RPO is how much data you can afford to lose. Together they decide what your backups have to do.
-
Shadow IT
Shadow IT is any software, account or device your team uses for work that the IT function does not know about, a free file-sharing tool, an unapproved app.
-
SIEM Security Information and Event Management
A SIEM, or security information and event management, is software that collects logs from across your systems and flags the patterns that look like an attack.
-
SLA Service Level Agreement
An SLA, or service level agreement, is the part of an IT contract stating how quickly your provider responds to a problem, and what happens if they miss.
-
SOC Security Operations Centre
A SOC, or security operations centre, is the team that watches an organization's systems for signs of attack and decides what to do when an alert fires.
-
vCIO Virtual Chief Information Officer
A vCIO, or virtual chief information officer, is a senior technology advisor you share rather than employ, planning your spending, roadmap and risks with you.
-
Zero trust
Zero trust designs security around the idea that no user, device or connection is trusted just because it is inside your network, everything gets checked.
Six terms in the pilot. The full glossary, every term from happier IT's existing IT terminology list, one page each, lands with the full build.
Handed a document full of these and unsure what to do?
Send it over. A 30-minute call is usually enough to tell you which parts genuinely apply to you.