Glossary
Cyber security glossary
Plain-English definitions of the cyber security terms NZ business leaders actually encounter.
- Business email compromise (BEC)
- A scam where an attacker impersonates a supplier, executive or colleague — often after accessing a real mailbox — to trigger fraudulent payments or data disclosure.
- EDR (Endpoint Detection & Response)
- Security software on devices that detects suspicious behaviour and enables investigation and response, going well beyond traditional antivirus.
- MDR (Managed Detection & Response)
- EDR combined with a team that monitors and responds to threats on your behalf, 24/7.
- MFA (Multi-factor authentication)
- Requiring a second proof of identity (like a phone approval) in addition to a password — one of the most effective controls against account takeover.
- Phishing
- Fraudulent messages designed to trick people into revealing credentials, making payments, or installing malware.
- Ransomware
- Malicious software that encrypts your data and demands payment. Tested, isolated backups are the key defence.
- Zero trust
- A security approach that never assumes trust based on network location and verifies every access request.
- Least privilege
- Giving each person or system only the access it genuinely needs, to limit the damage if an account is compromised.
- Incident response
- The process of detecting, containing and recovering from a cyber security incident.
- NZISM
- The New Zealand Information Security Manual — the government's information security controls, maintained by the NCSC.
- Privacy Act 2020
- New Zealand's core privacy law, governing how organisations handle personal information and requiring serious breaches to be reported.
- Attack surface
- The sum of all the points where an attacker could try to get in — accounts, devices, applications and services.
Related pages
Let’s talk
Every good plan starts with a conversation, and there’s no obligation in having one.