Start here · no jargon

Cyber security,
explained in plain English.

Security has a language problem. The ideas underneath it are genuinely straightforward, but they're buried under acronyms, sound-alike words and sales jargon that makes everyone feel like they've missed a meeting. This page fixes that: the core concepts with everyday analogies, a chart that finally sorts out phishing from vishing from smishing, and a glossary you can search whenever a term turns up in a quote or an insurance form.

Written for business owners and staff with no technical background. Nothing to buy, nothing to sign up for — read it, bookmark it, send it to your team.

If you read nothing else
  1. Attackers mostly log in rather than break in. Stolen and reused passwords are how the majority of incidents start, so protecting logins matters more than any single product you could buy.
  2. Almost every attack targets a person first. The technology is usually the second step. Urgency, authority and a request to skip the normal process are the constants.
  3. Nothing works alone, so you layer things. Filters miss, people click and software has bugs. Several imperfect layers beat one perfect-sounding product every time.
Core concepts

Twelve ideas that make everything else make sense.

You don't need to understand how any of the technology works. You do need these dozen ideas, because every security conversation, quote and insurance question sits on top of them. Each one comes with an analogy, because analogies are how people actually remember things.

01
Threat, vulnerability & risk

Threat, vulnerability and risk aren't the same thing

A threat is who or what might hurt you, a vulnerability is the gap they'd come through, and risk is how likely that is and how much it would cost you.

These three words get used interchangeably, and that's why security conversations often go in circles. Keeping them separate makes every other decision easier.

A threat is the thing that could cause harm: a criminal group, a disgruntled ex-employee, a flood in the server cupboard. You generally can't remove threats, they exist whether you like it or not.

A vulnerability is a weakness they could use: a staff member reusing the same password everywhere, a laptop that hasn't been updated in eight months, a backup nobody has ever tested. Vulnerabilities are the part you can actually fix.

Risk is what you get when you put the two together and add consequences. A vulnerability that a threat can easily reach, in a system that runs your whole business, is high risk. The same vulnerability on a spare laptop that holds nothing is not.

Think of it like — The house on the corner

Burglars in the neighbourhood are the threat. The window you never lock is the vulnerability. The risk is the chance someone climbs through it multiplied by what you keep in that room. You can't stop burglars existing, but you can absolutely lock the window, and you should lock the one in front of the safe first.

In your business

Good security spending follows risk, not fear. That's why we start with a review rather than a shopping list: the aim is to find the unlocked window in front of your safe, not to sell you cameras for the garden shed.

02
Attack surface

Your attack surface is every way in

Every account, device, app and connection is another door someone could try — and most businesses have far more doors than they realise.

Your attack surface is the total collection of places an attacker could try to get in. Staff email accounts, laptops, phones, the office wi-fi, your website, the accounting platform, the file sharing tool someone signed up for last year and forgot about.

Every new app, every extra account and every device that connects to your systems adds to it. That's not an argument against using technology, it's an argument for knowing what you actually have.

The accounts nobody thinks about are the dangerous ones: the ex-employee whose login was never disabled, the shared 'admin' password from the old IT provider, the free trial someone connected to your email and never revoked.

Think of it like — Doors, windows and the back gate

A shop with one front door is easy to secure. A shop with a front door, a loading dock, three fire exits, a window that doesn't quite close and a key under the mat is not — and the owner has usually forgotten about at least two of those. Security starts with walking the building and writing down every way in.

In your business

An account clean-up is one of the cheapest security wins there is. Disabling logins nobody uses removes doors instead of guarding them.

03
Defence in depth

No single tool protects you — layers do

Every control fails sometimes, so you stack several independent ones and accept that no single failure should be able to sink you.

There is no product that makes a business secure on its own, no matter what the box says. Filters miss things. People click things. Software has bugs nobody knew about yet.

Defence in depth means assuming each layer will occasionally fail and making sure the next one is there to catch it. A dodgy email gets past the filter, so the trained staff member doesn't click it. They click it anyway, so multi-factor authentication stops the login. The attacker gets in regardless, so monitoring spots the unusual behaviour and shuts the account down. Everything goes wrong at once, so the tested backup gets you trading again.

This is also why comparing security products one-against-another is the wrong question. They aren't competing, they're covering for each other.

Think of it like — Swiss cheese

Picture several slices of Swiss cheese stacked up. Each slice has holes — no slice is perfect. But the holes don't line up, so nothing gets all the way through. Remove enough slices and eventually they do.

In your business

It's why our services are grouped by what they protect — logins, devices, information, backups and people — rather than sold as one magic product.

04
Identity is the new perimeter

Most attackers don't break in, they log in

Passwords alone are no longer a lock, and identity — who can sign in to what — has become the single most important thing to protect.

It used to be that everything sat inside the office, behind the office firewall, and security meant defending the building. Now your email, files and business systems live in the cloud and your team reaches them from home, the car and the airport. The 'wall' around your business is gone.

What's left is identity: the username and password that proves someone is who they claim to be. If an attacker has those, they don't need to break anything. They walk in the front door looking exactly like your office manager.

This is why passwords on their own are no longer enough, and why multi-factor authentication — a second proof, usually a tap on your phone — is the single highest-value control most businesses can turn on.

Think of it like — The stolen staff pass

A thief who steals a staff pass doesn't smash a window. They walk through reception, nod at the person on the desk and use the lift like everyone else. Nothing looks like a break-in, because it wasn't one. Multi-factor authentication is reception asking for a second form of ID before the pass works.

In your business

If you only ever do one thing from this page: turn on multi-factor authentication everywhere, starting with email and any account that can move money.

05
Least privilege

Everyone should have exactly the access they need — and no more

Limiting what each account can reach means one compromised login opens one room, not the whole building.

Least privilege means each person's account can reach what their job requires and nothing else. Not because you don't trust your team, but because accounts get stolen and mistakes get made.

The most common version of this problem is administrator access. Admin accounts can change anything: create users, disable security settings, read every mailbox. When everyday work happens on an admin account, a single unlucky click hands over the keys to everything at once.

The same applies to shared logins. If four people use one account, nobody can tell who did what, and offboarding one of them means changing the password for everyone — which is exactly why it usually doesn't happen.

Think of it like — The master key

A cleaner needs a key to the office, not a master key to the safe, the server room and the payroll cabinet. Handing everyone a master key makes the day easier right up until one goes missing, and then every lock in the building has to change.

In your business

Separate admin accounts, no shared logins, and an offboarding checklist that actually gets followed. Unglamorous, and it stops more damage than most security products.

06
Zero trust

Zero trust: verify every time, trust nothing by default

Instead of trusting anything inside the network, every request gets checked on its own merits — who, on what device, from where.

The old model was a hard shell around a soft centre: get past the office firewall and you were trusted. That falls apart the moment work happens from home, on phones and in cloud platforms.

Zero trust flips the assumption. Nothing is trusted just because of where it is. Every sign-in is assessed on its own: is this the right person, on a device we manage, from a plausible location, doing something normal for their role?

In practice it's much less dramatic than it sounds. For staff it usually means a phone tap on a new device, and nothing at all on the laptop they use every day.

Think of it like — The airport, not the gated suburb

In a gated suburb, the gate is the only check — once you're inside, nobody asks again. An airport checks you at the door, at security, at the gate and at the aircraft, every single time, regardless of how you got there. Zero trust is the airport.

In your business

Sign-in rules that quietly allow the familiar and challenge the unusual: a login from your office at 9am is invisible, the same login from overseas at 3am is blocked and investigated.

07
Social engineering

The easiest system to hack is a person

Most attacks don't defeat technology, they persuade a human being to open the door — usually by creating urgency.

Social engineering is manipulation aimed at people rather than software. Phishing is the best-known form, but it also covers phone calls, text messages, fake invoices, and someone in a hi-vis vest walking into your office because nobody questions a hi-vis vest.

The techniques barely change because they don't need to. Urgency ('this must be paid today'), authority ('it's the director, I'm in a meeting'), fear ('your account will be closed'), and helpfulness ('sorry, I've just locked myself out, can you reset it?').

The tell is almost always the same: something wants you to act quickly, quietly, and outside your normal process. Real business rarely needs all three at once.

Think of it like — The confidence trick

A con artist doesn't pick the lock on your front door. They knock, hold up a clipboard, mention a burst water main and ask to check the taps. Everything they do is designed to make helping them feel more natural than questioning them.

In your business

A rule that never changes: any request to pay someone new, change bank details or send account codes gets verified by phone on a number you already had — never the number in the message.

08
Updates & patching

Updates are security work, not housekeeping

Most successful attacks use a known flaw that was fixed months ago on machines that were never updated.

When a software company finds a security flaw, they release a fix — a patch. The moment that patch is public, the flaw is public too, and attackers start scanning the internet for anyone who hasn't applied it.

That's why 'we'll do the updates later' is a security decision, not an admin one. The gap between a patch being released and it being installed is the window attackers work in, and automated scanning means being small is no protection at all.

The awkward corner is old software and old hardware. Once something is out of support it stops getting patches entirely, so the holes just accumulate. At that point the only real fix is replacing it.

Think of it like — The recall notice

A car maker announces a faulty lock and offers a free fix. Now every thief in the country knows exactly which model to try. Booking the repair isn't maintenance any more, it's the whole point.

In your business

Patching is two of the eight controls in the Australian Government's Essential Eight, which is a fair signal of how much it matters. Managed devices update on a schedule instead of when someone gets around to it.

09
Encryption

Encryption makes stolen data useless

Scrambling data so it can only be read with the right key means losing a device isn't the same as losing the information on it.

Encryption converts readable information into scrambled nonsense that can only be unscrambled with the correct key. It protects data in two situations: at rest, meaning sitting on a hard drive or in cloud storage, and in transit, meaning while it travels across the internet.

You already rely on it constantly. The padlock in your browser means the connection is encrypted, so the café wi-fi can't read your banking session. Device encryption — FileVault on Mac, BitLocker on Windows — means a stolen laptop is a lost asset rather than a data breach.

The catch is that encryption only protects data someone else has taken. It does nothing about an attacker who logs in as a real user, because to the system they simply are a real user, and it hands them the readable version.

Think of it like — The shredded document

Encryption is a document written in a code only you and the recipient can read. Someone can steal the page, photograph it, keep it for a decade — without the key it's gibberish. But if they've stolen your identity badge and asked the filing clerk politely, they get the plain-English copy handed straight to them.

In your business

Encryption on every laptop and phone, so a device left in a taxi is a replacement cost rather than a notifiable data breach.

10
Backups & recovery

A backup you've never restored is a hope, not a backup

Backups are the last line of defence, and the only way to know one works is to have actually restored from it.

Backups are what stand between a bad day and a business-ending one. Ransomware, a deleted folder, a failed drive, an employee tidying up — all of them end the same way if there's a good copy to restore.

The classic rule is 3-2-1: three copies of your data, on two different types of storage, with one kept somewhere else entirely. The offsite copy matters because fire, flood and theft don't respect the fact that your backup drive sits next to the computer it backs up.

Two things catch businesses out. First, cloud platforms like Microsoft 365 and Google Workspace keep the service running, but your data is still your responsibility, and deleted items only stay recoverable for a limited window. Second, ransomware crews specifically hunt for backups before they encrypt anything, which is why an immutable backup — one that can't be altered or deleted even by an administrator — is worth having.

And the part everyone skips: restore testing. Backups fail silently for months. The only proof is pulling something back.

Think of it like — The spare key you've never tried

Everyone has a spare key somewhere. Almost nobody has checked it turns the current lock. You find out on the night you're locked out in the rain, which is the worst possible moment to discover the lock was changed in 2019.

In your business

Backups that cover email, files, chats and device settings, kept beyond the platform's own retention window, and regularly restored to prove they work.

11
Detection & response

Assume something will get through, and be ready to catch it

Prevention stops most attacks; detection and response are what stop the ones that get past — usually measured in minutes versus months.

No sensible security plan assumes nothing will ever get through. The useful question is how quickly you notice and how fast you can contain it.

Detection means something is watching for the signals: a sign-in from a country nobody's in, a mailbox rule quietly forwarding everything to an outside address, a laptop encrypting files at a rate no human types at. Response means acting on it — isolating that device, disabling that account, shutting the mail rule down — while it's still one machine and one account.

This is why 24/7 matters rather than being a sales line. Attacks are deliberately launched overnight, on weekends and over the Christmas break, precisely because that's when nobody is looking.

Think of it like — The smoke alarm and the fire brigade

Fireproof materials are prevention. The smoke alarm is detection. The fire brigade is response. You want all three, and an alarm that wakes a house with nobody trained to act on it is only slightly better than no alarm at all.

In your business

A security operations centre watching your accounts and devices around the clock, with your local EduCom IT team handling the follow-up in business hours.

12
Your people

Trained staff are a control, not a weak link

The team blamed for clicking is also the only layer that can spot a scam no filter has seen before.

Staff get described as the weakest link so often that it's become an excuse. In reality, they're the only layer that can recognise something genuinely new — a supplier who suddenly writes differently, an invoice for a job that never happened, a request from the boss that doesn't sound like the boss.

That instinct only exists if people have practised. Short, regular training and safe simulated phishing emails give staff harmless reps at spotting the real thing, and turn a vague 'be careful' into a reflex.

The other half is culture. If reporting a mistake is embarrassing, people hide it, and an hour of silence is the difference between one locked account and a full incident. The businesses that recover well are the ones where telling someone quickly is normal and blame-free.

Think of it like — The fire drill

Nobody reads the evacuation diagram on the back of the door. Everybody knows what to do anyway, because they've walked out of the building twice a year for their whole working life. Practice beats posters.

In your business

Plain-language training that fits around real work, simulated phishing for practice, and a standing rule that reporting a click never gets anyone in trouble.

One analogy for the whole thing

Your business is a building. Security is how you look after it.

Every digital control has a physical equivalent you already understand and already pay for without thinking twice. Nobody argues about whether the shop needs a lock. The chart below is the translation.

Physical security measures and their digital equivalents
In a buildingIn your business systemsWhy it matters
The lock on the front doorPasswordsNecessary, but a lock alone is picked, copied or guessed — and most people use the same key everywhere.
Showing ID as well as using the keyMulti-factor authentication (MFA)A stolen key on its own stops working. The single highest-value thing most businesses can switch on.
Keys that only open the rooms you work inLeast privilege accessOne lost key opens one room instead of the whole building, including the safe.
Checking ID at every door, not just the gateZero trust and conditional accessBeing inside the building no longer proves anything, because most staff aren't in the building.
Deadbolts and window locks on every entranceEndpoint protection on every deviceEvery laptop and phone is its own entrance, wherever it happens to be that day.
Fixing the broken latch when the letter arrivesUpdates and patchingOnce a flaw is public, everyone knows which model of latch to try.
The safe in the back roomEncryptionIf someone gets in and takes the box, they still can't read what's inside.
Copies of the records kept at another siteOffsite, tested backupsFire, flood and theft take everything in one building — including the backup drive next to the computer.
The alarm and the cameras24/7 monitoring and threat detectionSomething is watching at 3am on a Sunday, which is exactly when attacks are launched.
The monitoring company that actually turns upManaged detection and response (MDR)An alarm nobody responds to is just a noise. Detection without response is the same idea.
Staff trained not to hold the door for strangersSecurity awareness trainingMost break-ins start with someone being helpful to a person who looked like they belonged.
The evacuation plan on the wallIncident response planWritten before the emergency, when everyone can still think clearly.
The fire drill twice a yearRestore testing and tabletop exercisesThe plan you've never rehearsed is a document, not a plan.
Building insuranceCyber insuranceCovers what's left after everything else. Insurers now expect the locks and alarms to already be in place.
The confusing one

Phishing, vishing, smishing, quishing — what's the difference?

Here's the shortcut nobody tells you: they're all the same con. Someone pretends to be a person or business you trust, manufactures a reason to hurry, and gets you to click, pay or hand something over. The silly names only describe how it reaches you — email, phone, text, QR code — not a different kind of trick.

Which is genuinely good news. You don't need fourteen defences, you need one habit: when a message asks you to act, verify it through a channel you chose. Ring the number you already had. Open the app yourself. That single reflex beats every row in this chart.

The phishing family — how each variant is delivered, what it looks like and how to spot it
NameArrives byWhat it actually isWhat it looks likeThe dead giveaway
PhishingFISH-ingCommon in AU businessEmailThe parent term. A fake message pretending to be someone you trust, designed to make you click a link, open an attachment or hand over a password. Usually sent to thousands of people at once."Your Microsoft 365 password expires today — click here to keep your account active." The link leads to a perfect copy of the sign-in page that quietly records what you type.The link's real destination doesn't match the brand. Hover over it before you click, or on a phone, press and hold to preview.
Spear phishingSPEAR FISH-ingCommon in AU businessEmailPhishing aimed at you specifically. The attacker has researched your name, role, colleagues and current projects, usually from your website and LinkedIn, so the message fits your actual working life.An email to your bookkeeper referencing the real supplier you used last month, the real project name, and a genuine-looking invoice with different bank details.It's plausible, but it arrives outside your normal process — new bank details, a new urgency, or a request to keep it quiet.
WhalingWAY-lingEmailSpear phishing aimed at the big fish: directors, owners, finance managers. The people who can approve payments without a second signature, or who nobody feels comfortable questioning.A legal-sounding notice to the managing director about a confidential acquisition, asking them to authorise a transfer before it becomes public.Secrecy plus authority plus a deadline. Genuine deals survive a phone call to verify.
Business email compromiseB-E-CCommon in AU businessEmail (a real, hijacked account)The most expensive of the lot. Rather than faking an address, the attacker has genuinely broken into a real mailbox — yours, a supplier's or a client's — and sends from it. Every technical check passes, because the email really is from that account.Your supplier's compromised mailbox replies in the middle of a real invoice thread: same signature, same tone, same history — with updated bank details for this payment only.Bank details that change mid-conversation. Nothing in the email itself looks wrong, because nothing in it is fake. Verify by phone on the number you already had.
Clone phishingCLONE FISH-ingEmailA copy of a genuine email you've already received, resent with the link or attachment swapped for a malicious one."Resending — the previous attachment was corrupted." It's last week's real quote, word for word, with a new file attached.You've seen this exact email before. A second copy of something you already dealt with is worth a moment's suspicion.
VishingVISH-ing (voice + phishing)Common in AU businessPhone callThe same con delivered by voice. Often paired with an email or text first, so the call feels like a follow-up to something you were already half-expecting."This is the fraud team at your bank. We've stopped a suspicious payment — I just need the code we've sent to your phone to cancel it."Nobody legitimate ever needs the code from your phone. Hang up and ring back on the number from your own records, never one they gave you.
SmishingSMISH-ing (SMS + phishing)Common in AU businessText messagePhishing by SMS or messaging app. Short, urgent and stripped of the clues you'd normally use, since a phone hides most of a link and there's no signature block to check."AusPost: your parcel is held pending a $3.95 fee." Or a message from an unknown number opening with "Hi Mum, this is my new number."Any link in an unexpected text. Open the company's real app or type the address yourself instead of tapping through.
QuishingKWISH-ing (QR code + phishing)QR codeA malicious QR code, printed on a sticker over a real one or embedded in an email as an image. Because it's a picture, it slips past filters that only read text — and phones don't show you the destination until it's too late.A sticker on a car park meter, or an email QR code claiming to be a multi-factor authentication setup you need to scan today.You can't read a QR code with your eyes. Treat any unexpected one as an unexpected link, and check the address before the page loads.
PharmingFARM-ingWebsite redirectionNo message at all. The attacker interferes with the address book of the internet so that typing the correct web address still takes you to their copy of the site.You type your bank's address exactly as always and land on a flawless replica that records your login.Rare but nasty, and the hardest to spot. Certificate warnings and a missing padlock are the visible signs; DNS filtering is the practical defence.
Angler phishingANG-luh FISH-ingSocial mediaFake support accounts lurking under a company's social posts, jumping in on public complaints and offering to help — then asking for account details in direct messages.You complain publicly about a telco. Within minutes '@Telco_Support_Help' messages you asking to verify your account to fast-track a fix.Real support won't ask for passwords or codes over social media. Check the verified handle, and note that they messaged you first.
Callback phishingAlso called TOADEmail, then phoneAn email with no link and no attachment at all — just a phone number and an alarming invoice or renewal notice. Nothing for a filter to catch, so it lands, and you make the call yourself."Your subscription auto-renews today for $749. To cancel, call 1800…" The person who answers walks you through installing remote access software to 'process the refund'.An unexpected bill with a phone number instead of any detail. Check the charge with your own bank or accounts team first.
Consent phishingOAuth phishingApp permission promptInstead of stealing your password, the attacker asks you to approve their app's access to your account. You click Accept on a genuine Microsoft or Google prompt, and they keep access even after a password change.A shared document prompts you to grant "Doc Viewer Pro" permission to read your mail and files. The prompt is real — the app is not.Read what the permission actually asks for. A document viewer has no reason to want to read all your email or sign in on your behalf.
MFA fatiguePush bombingAuthenticator appThe attacker already has your password and simply triggers approval prompts over and over, at 2am, until you tap Approve to make your phone stop.Fifteen sign-in requests in a row, then a call from 'IT support' apologising for the glitch and asking you to accept the next one.Never approve a prompt you didn't personally trigger. If they keep coming, your password is already out — change it and tell someone.
Deepfake fraudDEEP-fakeVoice call or videoAI-generated audio or video impersonating a real person. A few seconds of someone's voice from a podcast, webinar or voicemail greeting is enough to clone it convincingly.A voice note from the director, on the right number, asking for an urgent transfer while they're 'stuck in a meeting overseas'.Verify through a different channel entirely. Ring the person back on their known number, or ask something only they would know.

Scroll the chart sideways on a phone. Every row is a variation on the same three moves: impersonate someone trusted, create urgency, ask you to skip your normal process.

Print this one out

Eight red flags in any message.

One of these on its own might be nothing. Two together is worth a phone call before you do anything at all.

01

It's urgent, and it's today

Deadlines, threats of account closure, a payment that must go out this afternoon. Urgency exists to stop you checking.

02

Bank details have changed

The single most expensive red flag in Australian business. Always verify by phone on a number you already had, never the one in the message.

03

Someone wants a code from your phone

No bank, no supplier and no IT provider will ever ask for your multi-factor code. Anyone who does is trying to get into your account right now.

04

The address is almost right

educomlT.com.au, micros0ft-support.com, a real supplier name on a Gmail address. Read the bit after the @ character carefully.

05

You weren't expecting it

An invoice for a job you don't recognise, a parcel you didn't order, a password reset you didn't request. Unexpected plus a link is the classic combination.

06

The tone is subtly off

A colleague who never says 'kindly' now says it twice. A supplier who always signs off with their first name suddenly uses their full title.

07

It asks you to break the process

Skip the approval, don't mention it to the team, use this new payment method just this once. Process exists precisely for this moment.

08

The attachment wants permissions

A document asking you to enable macros or editing to 'view content properly' is asking permission to run code on your machine.

If you think you've clicked something

Speed beats certainty, so report it before you're sure. Disconnect the device from the network but leave it switched on, change the password from a different device, and tell your IT provider straight away. If money has moved, ring your bank immediately and ask for a recall. Report it at cyber.gov.au/report and, if personal information is involved, call IDCARE on 1800 595 160. Nobody should ever be in trouble for reporting a click — the hour lost to embarrassment is the hour the attacker uses.

Sound similar, mean different things

The ones people mix up.

These come up in quotes and insurance questionnaires constantly, and the differences matter when someone's telling you that you're already covered.

Types of malicious software

Virus
Attaches itself to a file or program and spreads when someone opens or shares it. Needs a person to set it off.
Worm
Spreads by itself across a network, no clicking required. One infected machine can become the whole office overnight.
Trojan
Pretends to be something useful — a free tool, an invoice, a game — and does its real job once you run it.
Ransomware
Scrambles your files and demands payment for the key. Modern versions also steal a copy first and threaten to publish it.
Spyware
Sits quietly and watches: keystrokes, screenshots, passwords. Success for spyware is never being noticed at all.

Antivirus vs EDR vs MDR

Antivirus (AV)
Checks files against a list of known bad things. Fine for yesterday's threats, blind to anything new or fileless.
EDR
Endpoint detection and response. Watches behaviour rather than matching a list, so it catches an unknown program doing something suspicious — and can isolate the device.
MDR / SOC
Managed detection and response, run by a security operations centre. The same technology, but with real analysts watching around the clock and acting on it. Tools raise alerts; people close them.

Firewall vs VPN vs DNS filtering

Firewall
Controls what traffic is allowed in and out of a network. The bouncer on the door deciding what gets through.
VPN
A private, encrypted tunnel across the public internet. It hides traffic in transit — it does not scan it for anything malicious.
DNS / web filtering
Blocks known-bad websites before the browser ever loads them. Stops a lot of phishing at the moment somebody clicks.

Who's actually attacking you

Opportunistic criminals
The overwhelming majority. Automated scanning for any business with a gap — they've never heard of you and don't care who you are.
Organised crime groups
Ransomware run as a business, complete with support desks and affiliate programs. They pick targets that look like they can pay.
Insiders
Current or former staff, usually careless rather than malicious — but a departing employee with live access is a real risk.
Nation-state actors
Well-funded, patient and mostly aimed at government, defence and critical infrastructure. Rarely your problem directly, though supply chains can pull you in.
Reference chart

The glossary. 79 terms, in plain English.

Every term you're likely to meet in a security quote, a cyber-insurance questionnaire or a client's supplier form — with what it means and something to picture. Search it, or filter by category.

Showing 79 of 79 terms

Plain-English cyber security glossary with everyday analogies
TermWhat it meansThink of it like
ACSCAustralian Cyber Security CentreRules & frameworksThe federal body providing cyber security advice to Australian organisations, part of the Australian Signals Directorate. It publishes the Essential Eight and runs ReportCyber.The national safety authority — guidance, alerts and the place you report an incident.
AdwareAttacks & scamsSoftware that forces unwanted advertising onto a device, often bundled with something free. Usually more annoying than dangerous, but it shows something got installed that shouldn't have.Junk mail that comes with a key to your letterbox.
Air gapProtection & toolsKeeping a copy of data completely disconnected, so ransomware spreading through the network simply can't reach it.The records in the safe deposit box across town, with no phone line to your office.
AntivirusAVProtection & toolsSoftware that spots known malicious files by matching them against a list. Still useful, no longer sufficient on its own.A guard with a book of mugshots. Great for known faces, blind to new ones.
Application allow-listingProtection & toolsOnly approved programs are permitted to run. Everything else is blocked by default, including malware that's never been seen before.A guest list instead of a bouncer trying to recognise troublemakers.
Attack surfaceEveryday jargonEvery account, device, app and connection an attacker could try. Each new tool or login adds to it.Every door, window and vent on the building.
AuthenticationLogins & identityProving you are who you say you are. Passwords, codes, fingerprints and passkeys are all forms of it.Showing your driver's licence at the door.
AuthorisationLogins & identityWhat you're allowed to do once you're in. Different from authentication — being let into the building doesn't mean you can open the safe.Which rooms your pass actually unlocks.
BackupProtection & toolsA separate copy of your data you can restore from. The rule of thumb is 3-2-1: three copies, two types of storage, one kept offsite.A spare set of records in another building.
BiometricsLogins & identityUsing a physical trait — fingerprint, face — to unlock a device. Convenient and hard to steal remotely, though it usually protects the device rather than the account.A lock that only opens for your thumb.
BotnetAttacks & scamsA network of hijacked computers controlled remotely by an attacker. Owners rarely notice; their machines are quietly rented out to send spam or attack other targets.A crowd of unwitting people all posting the same letter, hired by someone they've never met.
Brute force attackAttacks & scamsTrying enormous numbers of passwords until one works. Automated tools test billions of combinations, which is why length matters more than special characters.Trying every key on a giant keyring, very fast, all night.
Business email compromiseBECAttacks & scamsAn attacker gets into a genuine mailbox and uses it to redirect payments or harvest more access. Because the email really is from that account, technical checks don't flag it.A thief who doesn't forge the letterhead — they've taken over the actual office.
CIS ControlsRules & frameworksAn internationally used, prioritised list of security controls. Practical and ordered so you can work down it rather than doing everything at once.A checklist written in the order the jobs should actually be done.
CloudEveryday jargonSoftware and storage running on someone else's servers, reached over the internet. The provider keeps the service running; your data and access remain your responsibility.Renting a serviced office instead of owning the building.
Conditional accessLogins & identityRules that decide how much proof a sign-in needs based on context: who, what device, where from, how risky. Normal logins stay invisible; odd ones get challenged or blocked.Security waving through the regulars and stopping the person nobody recognises.
Credential stuffingAttacks & scamsTaking usernames and passwords leaked from one website and trying them automatically on hundreds of others. It works because most people reuse passwords.Finding a key in the street and trying it on every door in the suburb.
CredentialsLogins & identityThe username and password combination that gets someone into an account.The name on the pass and the key that comes with it.
Cyber insuranceRules & frameworksInsurance covering the costs of an incident. Insurers now ask detailed questions about MFA, backups and monitoring, and answers affect both premium and payout.Building insurance where the insurer wants to see the locks before they write the policy.
Data breachData & privacyInformation being accessed, taken or disclosed without authorisation. In Australia, serious breaches involving personal information must be reported.The filing cabinet was opened by someone who shouldn't have opened it.
Data sovereigntyData & privacyWhich country your data physically sits in, and therefore whose laws apply to it. It comes up in government, health and education contracts constantly.Which country's rules apply depends on which country the warehouse is in.
DeepfakeAttacks & scamsAI-generated audio or video imitating a real person. A few seconds of recorded speech is enough to clone a voice well enough to fool a colleague.A very good impersonator who has studied one specific person.
Defence in depthEveryday jargonLayering several independent controls so no single failure gets an attacker all the way through.Slices of Swiss cheese stacked so the holes don't line up.
Denial of serviceDoS / DDoSAttacks & scamsFlooding a website or system with so much traffic that real customers can't get through. Nothing is stolen; you simply stop trading.A thousand people queueing at your counter with no intention of buying anything.
DLPData loss preventionData & privacyRules that stop sensitive information — card numbers, bank details, customer records — leaving the business by email or file sharing.A mailroom that opens outgoing post and stops anything confidential going out.
DMARC, SPF & DKIMEveryday jargonThree settings on your domain that let other mail servers verify email really came from you. Without them, anyone can send mail that appears to be from your business.A verified letterhead other people's mailrooms can actually check.
DNS filteringWeb filteringProtection & toolsBlocking known-malicious websites before a browser can load them, which stops a lot of phishing at the moment of the click.A road closed before you can drive down it.
DomainEveryday jargonYour business's address on the internet — the part after the @ in your email. Losing control of it means losing email and website at once.Your street address, and the deed that says it's yours.
EDREndpoint detection & responseProtection & toolsWatches how programs behave on a device rather than matching a list, and can isolate a machine automatically when something looks wrong.A guard who notices someone acting strangely, not just someone on the wanted list.
Email filteringProtection & toolsScanning inbound mail for phishing, malware and impersonation before it reaches an inbox — and flagging mail that comes from outside the business.Sorting the post before it reaches anyone's desk.
EncryptionData & privacyScrambling data so only someone with the key can read it. Protects information at rest on a device and in transit across the internet.Writing in a code only you and the recipient can read.
EndpointProtection & toolsAny device a person uses to reach your systems: laptop, desktop, phone, tablet. The word covers all of them at once.Every door and window on the building, wherever it happens to be parked.
Essential EightRules & frameworksEight baseline strategies recommended by the Australian Government — including patching, MFA, restricting admin rights and backups — with maturity levels from zero to three.The national road rules of business security: not everything, but the bit everyone's expected to know.
ExploitAttacks & scamsA piece of code that takes advantage of a specific flaw in software. Patching removes the flaw, which makes the exploit useless.The particular jiggle that opens a faulty latch.
FirewallProtection & toolsControls what network traffic is allowed in and out based on a set of rules.The bouncer deciding who gets through the door.
HardeningEveryday jargonChanging default settings to a secure configuration and turning off what you don't use. Most break-ins exploit defaults nobody changed.Changing the locks and codes the builder left set when you moved in.
HTTPS & TLSEveryday jargonThe padlock in your browser. It means the connection is encrypted — it does not mean the site is honest, and scam sites have padlocks too.A sealed envelope. Nobody read it in transit; that says nothing about who sent it.
Identity providerIdP / SSOLogins & identityOne central account that signs you in to many services — signing into apps 'with Microsoft', for example. Fewer passwords to manage, and one place to shut everything off when someone leaves.One building pass that works across every office, issued and cancelled from reception.
Immutable backupProtection & toolsA backup that can't be changed or deleted for a set period, even by an administrator. Specifically defeats ransomware crews who hunt for backups first.Records in a time-locked vault that won't open early for anyone, including you.
Incident response planRules & frameworksA written plan for what happens when something goes wrong: who does what, who to call, how to contain it, what to tell customers.The evacuation plan on the wall, written while everyone was calm.
Insider threatAttacks & scamsRisk from someone who already has legitimate access — usually careless rather than malicious, but a departing employee with live logins is a genuine problem.The ex-tenant who never handed back their key.
ISO 27001Rules & frameworksAn international standard for managing information security, certified by an external auditor. Larger clients and tenders increasingly ask for it.A formal building certification, signed off by an inspector, not a self-assessment.
KeyloggerAttacks & scamsSoftware or hardware that records every keystroke, capturing passwords and card numbers as they're typed.Someone reading over your shoulder every time you type, permanently.
Least privilegeLogins & identityGiving each account only the access its job needs. Limits the blast radius when a login is compromised.Keys to your own office, not the master key to the building.
MalwareAttacks & scamsThe umbrella word for malicious software: viruses, worms, trojans, ransomware, spyware. Anything installed to cause harm or make money at your expense.'Pest' — accurate, but it doesn't tell you if it's mice or termites.
Man-in-the-middleAttacks & scamsIntercepting communication between two parties who believe they're talking directly. Public wi-fi is the classic setting.A postman steaming open every letter, reading it, then sealing it and delivering it on time.
Maturity levelRules & frameworksA score for how thoroughly a control is applied — Essential Eight uses zero to three. It measures consistency, not effort.The difference between locking most doors most nights and locking every door every night.
MDMMobile device managementProtection & toolsCentral control of company laptops and phones: enforcing settings, pushing updates, and locking or wiping a device remotely if it goes missing.Being able to change the locks on a company car from the office.
MDR / SOCManaged detection & responseProtection & toolsA team of analysts in a security operations centre watching your alerts 24/7 and acting on the real ones, so tools don't just generate noise nobody reads.The monitoring company that actually sends someone when the alarm goes off.
Multi-factor authenticationMFA / 2FALogins & identityRequiring a second proof beyond the password — usually a tap or code on your phone. Blocks the overwhelming majority of password-based attacks.Needing both the key and your ID to get through the door.
Notifiable Data Breaches schemeNDBData & privacyAustralian law requiring organisations covered by the Privacy Act to notify affected individuals and the OAIC when a breach is likely to cause serious harm.A legal duty to tell people their records were in the cabinet that got opened.
On-premisesOn-premEveryday jargonServers and systems physically in your building rather than in the cloud. Fully your responsibility to patch, back up and secure.Owning the warehouse rather than renting space in one.
PasskeyLogins & identityA password replacement built into your device, unlocked with your face or fingerprint. There's nothing to type, so there's nothing to phish, and it only works on the real website.A car key that only starts your car and can't be described over the phone.
Password managerLogins & identityAn encrypted vault that creates and stores a different strong password for every account, so nobody has to remember or reuse them.A locked keyring where every key is different and you only remember the one that opens the ring.
Password sprayingAttacks & scamsTrying a handful of very common passwords against many accounts, rather than many passwords against one. It avoids lockouts, which trigger on repeated failures for a single user.Trying the same obvious key on a thousand doors instead of a thousand keys on one.
PatchProtection & toolsAn update that fixes a flaw. Once released, the flaw is public knowledge, so unpatched systems become easier targets immediately.The recall repair. Free, quick, and now every thief knows which model to try.
Penetration testPen testProtection & toolsHiring specialists to attack your systems with permission, to find what a real attacker would find. Deeper and more manual than an automated scan.Paying a locksmith to break into your own building and write down how they did it.
Personal informationPIIData & privacyAnything that identifies a person — name, address, date of birth, Medicare or licence numbers. It carries the strictest handling obligations.The details on someone's licence, which you're now responsible for.
Privacy Act & APPsRules & frameworksAustralian law governing how organisations handle personal information, via the Australian Privacy Principles. Obligations increasingly reach smaller businesses too.The rules about what you may do with information people trusted you with.
Privileged accountAdmin accountLogins & identityAn account that can change settings, create users or read anyone's mail. Should be separate from the account used for everyday work and email.The master key. Useful, and not something to carry to lunch.
RansomwareAttacks & scamsMalware that encrypts your files and demands payment for the key. Most groups now steal a copy first and threaten to publish it, so backups alone no longer end the problem.Someone changing every lock in your building and selling you the new keys — after photographing the files.
RetentionData & privacyHow long data is kept before it's deleted. Cloud platforms only hold deleted items for a limited window — often far shorter than businesses assume.How long the archive keeps a box before it goes to the tip.
Risk registerRules & frameworksA simple list of the things that could go wrong, how likely and serious each is, and who's dealing with it. Turns vague worry into a plan.A written list of everything that could go wrong, with a name next to each one.
RTO & RPORules & frameworksRecovery time objective — how long you can afford to be down. Recovery point objective — how much recent work you can afford to lose. They decide what your backup design needs to be.'How long can the shop stay shut' and 'how many hours of takings can we lose'.
SandboxEveryday jargonOpening something suspicious in an isolated environment to see what it does, without letting it touch anything real.Opening a suspicious parcel inside a blast box.
ScarewareAttacks & scamsAlarming pop-ups claiming your device is infected, pushing you to install a 'fix' that's the actual infection or to ring a fake support line.A stranger banging on your door shouting that your house is on fire, while holding a bucket for sale.
Session tokenCookieLogins & identityThe 'you're already signed in' pass your browser holds after login. Attackers who steal one can skip the password and the MFA prompt entirely.A wristband from the door — once you have it, nobody checks your ID again.
Shadow ITData & privacyApps and services staff sign up for without telling anyone — free file converters, AI tools, personal cloud storage. Business data ends up somewhere nobody can see or secure.A filing cabinet someone bought and put in their own garage.
SIEMProtection & toolsA system that collects logs from across your environment and correlates them, so separate small oddities can be spotted as one connected attack.One control room with every camera feed on the wall, instead of tapes in each room.
SIM swappingAttacks & scamsConvincing a phone company to move your number to the attacker's SIM, so verification codes sent by SMS go to them. It's why app-based codes beat text messages.Redirecting your mail to someone else's address without you knowing.
Social engineeringAttacks & scamsManipulating people rather than technology. Phishing, phone scams, fake tradespeople — anything that persuades a human to open the door.The con artist who knocks and talks their way in, rather than picking the lock.
Supply chain attackAttacks & scamsAttacking you through a supplier, contractor or piece of software you trust. Their access becomes the attacker's access.Tampering with the delivery before it reaches your loading dock.
TenantEveryday jargonYour organisation's own private space inside a cloud platform like Microsoft 365 — your users, data and settings, separate from every other customer.Your suite in a shared building: same address, your own locked door.
TrojanAttacks & scamsMalware disguised as something legitimate. You install it deliberately, believing it's useful.The wooden horse. Wheeled in willingly, full of trouble.
TyposquattingAttacks & scamsRegistering domains that look almost right — a swapped letter, a hyphen, .co instead of .com.au — to catch mistyped addresses and unread email senders.A shopfront next door with a near-identical sign, hoping you don't look twice.
VPNVirtual private networkProtection & toolsAn encrypted tunnel across the public internet. It protects traffic in transit; it does not inspect that traffic for anything harmful.An armoured van. Safe in transit, and it doesn't care what's in the boxes.
Vulnerability scanProtection & toolsAn automated check for known weaknesses — missing patches, weak settings, exposed services — usually run on a schedule.Walking the building each month rattling every door handle.
Zero trustLogins & identityA model where nothing is trusted just because it's inside the network. Every request is verified on its own merits, every time.Airport-style checks at every gate, not one gate at the entrance to the suburb.
Zero-dayAttacks & scamsA flaw attackers know about before the vendor does, so no patch exists yet. Rare, valuable and the reason detection matters as well as patching.A design fault in the lock that the maker hasn't discovered — but the burglars have.
FAQ

The questions people are too polite to ask.

I don't understand any of this. Where should I start?

Three things, in order. Turn on multi-factor authentication everywhere, starting with email and anything that can move money. Get a password manager so nobody is reusing the same password across sites. Make sure you have a backup someone has actually restored from.

That covers the ways the large majority of small business incidents begin. Everything else builds on top of those three.

Why are there so many words for phishing?

Because each one describes the channel it arrives through, not a different kind of trick. Email is phishing, a phone call is vishing, a text is smishing, a QR code is quishing. The con underneath is identical every time: pretend to be someone you trust, create urgency, get you to act before you check.

That's genuinely good news, because you don't need to learn fourteen defences. You need one habit — verify unexpected requests through a channel you chose yourself — and it works against all of them.

Aren't we too small to be worth attacking?

Almost all attacks are automated and indiscriminate. Software scans the entire internet looking for any business with a weak spot, and it has no idea who you are or how big you are. You aren't picked, you're found.

Smaller businesses are often hit harder, because there's less slack to absorb a week of downtime and fewer people to manage the recovery.

Is a password manager really safer than remembering passwords?

Yes, comfortably. Human-memorable passwords get reused, and one breach at any website then exposes every account using it. A password manager gives every account its own long random password, and you only remember the one that opens the vault.

The vault itself is encrypted so the provider can't read it, and losing the master password is the real risk — which is why we set up recovery properly during rollout.

Does antivirus mean we're covered?

Not on its own. Antivirus recognises known bad files, but most incidents now involve someone signing in with a stolen password — nothing malicious is ever installed, so there's nothing for antivirus to find.

Modern protection combines identity controls, behaviour-based detection on devices, email filtering, backups and people who respond when something is flagged.

What should we do if we think we've been caught out?

Speed matters far more than certainty, so report it before you're sure. Disconnect the device from the network but leave it switched on, change the password from a different device, and tell your IT provider immediately.

If money has moved, ring your bank straight away and ask for a recall. Report the incident to ReportCyber via cyber.gov.au, and contact IDCARE on 1800 595 160 if personal information is involved.

Nobody should ever be in trouble for reporting a click. The hour you lose to embarrassment is the hour an attacker uses.

How is this different from what our current IT provider does?

General IT support keeps things working; managed security assumes someone is actively trying to break in. The differences show up in the unglamorous parts: patching on a schedule, restore testing, 24/7 monitoring with someone rostered to act at 3am, and evidence you can hand to an insurer.

Plenty of businesses keep their existing support and add security alongside it. Both arrangements work.

Do we need to understand all of this ourselves?

No. You need enough to ask sensible questions and make good calls about money and risk — which is exactly what this page is for.

If a provider can't explain what something does in plain English, that's a reflection on the provider, not on you.

Still not sure what applies to you?

That's a completely reasonable place to be, and it's what the free security review is for. We'll look at where your business actually stands, explain what we find in the same plain English as this page, and tell you the smallest set of changes that would make the biggest difference. No jargon, no pressure to over-buy.