A cybersecurity glossary with tech terms in clear language

Your guide to understanding security speak

Attack vectors

What is business email compromise?

Business email compromise (BEC) is a cybercrime where attackers use stolen or fake credentials to send convincing emails, tricking recipients into revealing sensitive info or transferring funds.

Learn more
What is cryptojacking?

What is cryptojacking? Discover what it is, its impact, and steps to protect your devices and networks from unauthorized cryptomining.

Learn more
What is phishing in cybersecurity?

Learn about these types of cyber attacks, prevention strategies, and response protocols to protect your organization from these evolving threats.

Learn more
What is ransomware protection?

Ransomware protection involves methods and technologies to defend IT systems from ransomware—malicious software that encrypts data, blocking access until a ransom is paid.

Learn more

Auto remediation

Auto remediate: How does expert-guided automation transform threat response?

Learn how to auto remediate security threats with expert-guided automation. Discover Expel's approach to balancing speed and human oversight.

Learn more
How do visibility and context shape effective cybersecurity remediation strategies?

Learn how visibility and context drive effective cybersecurity remediation strategies, from deny lists to device preferences.

Learn more
How do you build trust in automated cybersecurity tools?

Learn the four pillars for establishing confidence in automated security tools: transparency, human oversight, testing, and granular control.

Learn more
What are some auto remediation tools that create massive impact through seemingly small actions?

Learn why the most effective auto remediation tools work through precision, not force - small actions that deliver huge security value.

Learn more
What is auto remediation? A high-level guide

What is auto remediation? Learn how this practice can automate critical actions against an attacker in the case of a cybersecurity incident.

Learn more
Why is automation in cybersecurity critical to modern threat response?

Understanding how automation in cybersecurity is transforming security operations through speed, volume management, and consistent accuracy.

Learn more

Cloud

What is cloud detection and response?

Cloud detection and response (CDR) quickly detects, analyzes, investigates, and responds to threats, similar to managed detection and response (MDR) and extended detection and response (XDR) services.

Learn more
What is cloud security?

What is cloud security? Read an in-depth definition of cloud security and discover more resources to secure your environment.

Learn more

Cybersecurity tools

What is a data lake?

Learn what is a data lake in cybersecurity, how it differs from SIEM systems, and the key benefits for security operations, including better threat detection, comprehensive data retention, and advanced analytics capabilities.

Learn more
What is SIEM in cybersecurity?

Get the answer to what is SIEM in cybersecurity, including types of SIEM solutions, architecture, implementation strategies, and alternatives.

Learn more

Endpoint

What is endpoint detection and response?

Endpoint detection and response (EDR) collects endpoint data to establish normal patterns, helping monitor for compromises and providing intelligence for containment and remediation.

Learn more

Extended detection and response (XDR)

What is XDR?

Learn how extended detection and response (XDR) unifies and automates security across multiple layers to combat modern cyber threats effectively.

Learn more

Frameworks and tools

What is NIST in cybersecurity?

Learn what is NIST in cybersecurity, its role in developing standards and frameworks, and how organizations use NIST guidelines to strengthen their security programs.

Learn more
What is the MITRE ATT&CK Framework?

Learn what MITRE ATT&CK is in cybersecurity and why it matters. Discover how this framework helps security teams like Expel's detect threats, map adversary behavior, and strengthen defenses against cyber attacks in enterprise and cloud environments.

Learn more

Identity

What is identity threat detection and response (ITDR)?

Learn what identity threat detection and response (ITDR) is in cybersecurity and why it matters. Discover how this approach protects user credentials, differs from IAM and XDR, and helps prevent identity-based attacks in today's remote work environment.

Learn more

Kubernetes

What is Kubernetes security?

Kubernetes adoption is growing, but security is a challenge. Learn how to address vulnerabilities, integrate security tools, and use automation to improve Kubernetes protection.

Learn more

Managed detection and response (MDR)

What does “good” look like for MDR service providers?

A discussion on the essential qualities that define effective MDR service providers in today's cybersecurity landscape.

Learn more
What is an MDR solution?

MDR solutions quickly detect, analyze, investigate, and respond to threats using EDR, network and cloud protection, and logs.

Learn more
What is MDR in cybersecurity?

Managed detection and response (MDR) is a cybersecurity service that provides customers with remotely delivered security operations center (SOC) functions.

Learn more

Managed security services

What are managed security services?

What are managed security services? Managed security services (MSS) are outsourced services provided by third-party companies to manage and protect an organization's cybersecurity operations.

Learn more

Network security

What is managed network detection and response?

Learn what managed network detection and response (MNDR) is and how it protects your network infrastructure.

Learn more

SecOps

What is SecOps?

Learn what is SecOps in cybersecurity, how it integrates security with IT operations, key frameworks like SOAR and DevSecOps, and best practices for implementing effective security operations in your organization.

Learn more

Security operations center (SOC)

How can SOC performance metrics be misleading?

SOC performance metrics can mislead. This article shows why surface-level analysis—like evaluating solely on MTTR—risks wrong assessments.

Learn more
How do you increase SOC performance efficiency?

Measuring SOC performance efficiency is a journey, not a destination. Learn how to measure your SOC using a "crawl, walk, run" approach.

Learn more
How does effective SOC management ensure data accuracy?

Effective SOC management avoids treating data as the end-all, as metrics alone provide incomplete stories. Learn how to verify data accuracy.

Learn more
What are some cybersecurity metrics examples for measuring automation impact?

A look at essential cybersecurity metrics examples for measuring automation impact on team productivity, burnout, and operational efficiency.

Learn more
What is a security operations center (SOC)?

A security operations center (SOC) is a centralized unit that monitors, detects, and responds to cybersecurity incidents, using people, processes, and technology to enhance security posture and manage threats.

Learn more
What is SOC-as-a-service (SOCaaS)?

SOC-as-a-Service (SOCaaS) offers 24x7 cloud-based SOC capabilities, including monitoring, alert triage, incident response, and threat remediation on a subscription basis.

Learn more

Software-as-a-service (SaaS)

What is SaaS security?

Learn about critical security measures for cloud-based applications, common threats, and essential protection strategies for your organization's SaaS environment.

Learn more

Threat intelligence

What is cyber threat intelligence?

Cyber threat intelligence gathers and analyzes data on cyber threats to help organizations prevent attacks by understanding threat actors and vulnerabilities.

Learn more
What is threat hunting in cybersecurity?

Threat hunting is a proactive approach to finding hidden or unresolved threats in a network, using digital forensics and incident response.

Learn more

Vulnerability management

What is vulnerability management?

Learn what vulnerability management is and why it matters for your organization's security posture. A clear explanation of key concepts and practices.

Learn more
expel X icon

Ready to take the next steps with Expel MDR?

The choice is yours: see Expel in action on-demand, or explore our MDR packages.