Glossary

Cyber security glossary

Plain-English definitions of the cyber security terms NZ business leaders actually encounter.

Business email compromise (BEC)
A scam where an attacker impersonates a supplier, executive or colleague — often after accessing a real mailbox — to trigger fraudulent payments or data disclosure.
EDR (Endpoint Detection & Response)
Security software on devices that detects suspicious behaviour and enables investigation and response, going well beyond traditional antivirus.
MDR (Managed Detection & Response)
EDR combined with a team that monitors and responds to threats on your behalf, 24/7.
MFA (Multi-factor authentication)
Requiring a second proof of identity (like a phone approval) in addition to a password — one of the most effective controls against account takeover.
Phishing
Fraudulent messages designed to trick people into revealing credentials, making payments, or installing malware.
Ransomware
Malicious software that encrypts your data and demands payment. Tested, isolated backups are the key defence.
Zero trust
A security approach that never assumes trust based on network location and verifies every access request.
Least privilege
Giving each person or system only the access it genuinely needs, to limit the damage if an account is compromised.
Incident response
The process of detecting, containing and recovering from a cyber security incident.
NZISM
The New Zealand Information Security Manual — the government's information security controls, maintained by the NCSC.
Privacy Act 2020
New Zealand's core privacy law, governing how organisations handle personal information and requiring serious breaches to be reported.
Attack surface
The sum of all the points where an attacker could try to get in — accounts, devices, applications and services.

Let’s talk

Every good plan starts with a conversation, and there’s no obligation in having one.