The Cybersecurity Vocabulary You Should Know (A Plain Glossary)

Published on August 10, 20269 min read
An open notebook where cybersecurity terms are paired with small clear icons: a hook, a padlock, a cloud

One morning, Sophie B. opens the report her IT provider has just sent. Three pages, and a dozen words she doesn't understand: "roll out MFA," "ransomware risk," "unpatched zero-day." She runs an accounting firm, not an IT department — and yet she is the one who has to decide what to do, and answer the client who asked her the day before: "by the way, how do you protect my data?"

This glossary is for her, and for you. Cybersecurity vocabulary isn't reserved for technicians: a dozen or so words are enough to understand what threatens a small business and what protects it. You don't need to become an expert — just to know what people are talking about.

Why cybersecurity vocabulary concerns you

In an accounting firm, there is no IT specialist down the hall. IT "is handled by the provider." The trouble is that delegating a subject you don't understand means delegating with your eyes closed. When the provider writes "you should enable MFA," should you say yes? Is it urgent? Is it expensive? Without the words, there is no way to weigh the decision.

Cybersecurity vocabulary isn't general knowledge: it's a decision-making tool. Understanding a dozen terms lets you ask the right questions, judge whether an alert is serious, and answer a client or an auditor without panicking or bluffing. Here are the words to know, sorted into three families: threats (how you are attacked), protections (how you defend yourself) and the rules (the law and standards that frame all of it).

The words of threats: how you get attacked

Phishing. A fake message — email, text, or call — that imitates a trusted contact (a bank, Microsoft, a supplier) to push you into clicking, handing over a password, or paying. It's the number-one entry point for attacks on small businesses. In plain terms: someone dangles a hook and hopes you bite.

CEO fraud (or BEC, for Business Email Compromise). A targeted variant of phishing: an email pretends to be the boss or a partner and demands an urgent, discreet transfer. In a small firm where everyone knows each other, no one dares ask for confirmation — and that is exactly what the fraudster exploits.

Ransomware. Malicious software that encrypts your files — accounts, client folders, payroll — makes them unreadable, then demands a ransom to give access back. For an accounting firm, it's the Monday morning when nothing opens anymore. Paying guarantees nothing; preparation is what saves you.

Zero-day flaw. A vulnerability in software that not even its maker knows about yet, so no fix exists on the day it is exploited. "Zero-day" means zero days of warning. You can't anticipate each one, but you can limit the damage by keeping your software up to date and your data backed up.

Data breach. The disclosure, loss, or theft of data you were meant to protect. For a firm holding tax and payroll data, it's the nightmare scenario: loss of client trust, plus a duty to notify the data protection authority (see below).

The words of protection: how you defend yourself

MFA (multi-factor authentication, or 2FA). On top of your password, a second proof of identity: a code on your phone, a notification to approve, a fingerprint. Even if an attacker steals your password, they lack this second key. It's the protection with the best effort-to-effect ratio for a small business, and often free on tools like Microsoft 365.

VPN (virtual private network). An encrypted tunnel between your device and your company that protects your traffic when you work remotely — from home, a train, or a café's Wi-Fi. In plain terms: it makes your connection unreadable to anyone trying to snoop on a public network.

Encryption. Turning data into text that is unreadable without the right key. A stolen encrypted laptop is just a paperweight for the thief; an intercepted encrypted email can't be read. It's the difference between losing a machine and losing your clients' data.

3-2-1 backup. A simple rule so you never lose everything: 3 copies of your data, on 2 different types of media, with 1 kept offline or off-site. A disconnected backup is your best insurance against ransomware — provided you have actually tested restoring it, not just left it "somewhere."

Least privilege. The principle of giving each person only the access they need, and no more. The receptionist doesn't need access to every partner's files; an intern doesn't need administrator rights. Fewer open doors mean less possible damage.

The words of the rules: the law and standards

nFADP (new Federal Act on Data Protection). The Swiss law in force since 1 September 2023. It requires any company that processes personal data to take "appropriate" security measures and to report serious breaches to the federal authority (the FDPIC). It's the first framework a Swiss SME should know.

GDPR (European regulation). The European Union's equivalent. It applies to you on top of the nFADP if you process data on people located in the EU or work with European clients. For a purely local firm, the nFADP comes first; the GDPR adds on depending on your clientele.

ISO 27001:2022. A recognized international standard describing good practices for managing information security. It's the language of large clients and supplier questionnaires. Aligning with it structures your approach — but be careful: following the standard is not "being certified." Certification is a full audit in its own right.

NCSC (National Cyber Security Centre). Switzerland's official reference for practical recommendations and alerts aimed at SMEs. When you're looking for reliable, up-to-date advice on a threat, it's the source to favour over any article found at random.

What to remember

You don't need to master everything, but three ideas really matter.

First, these words describe your daily reality, not some distant world. Phishing lands in your inbox, ransomware targets your client files, and the nFADP applies to your firm today.

Second, understanding cybersecurity vocabulary means taking back control. You stop merely enduring a technical report: you know which question to ask and which answer to expect.

Third, most basic protections — MFA, backups, least privilege — cost little and are a matter of organisation, not of a large IT budget.

How to use it day to day

A glossary is useless if it stays in a drawer. Here is how to turn it into habits this week.

1. Keep these words at hand and insist on "plain language"

Pin this list near your desk. Every time your provider or a client uses a technical term, look it up here — and if you can't find it, ask for it to be explained in one simple sentence. A good partner knows how to make things clear; the one who refuses may be hiding their own uncertainty.

2. Help your team recognise the threats

Share the four "threat" words with your staff and agree on a common reflex: at the slightest email that rushes you, frightens you, or asks for an unusual payment, you stop and verify through a known channel (a call to a number already saved). Most attacks fail against a simple second check.

3. Ask your provider three questions, in the right words

Armed with the vocabulary, open the conversation: "Is multi-factor authentication (MFA) enabled everywhere?", "Are our backups tested, and is there an offline copy?", "Are our laptops encrypted?" Three questions, three clear answers — or three projects to launch.

Where do you really stand?

Knowing cybersecurity vocabulary is the first step; knowing where your business actually stands is another. Between "we have antivirus" and "our access, our backups and our sensitive data are genuinely under control," there is a gap that only an honest stocktake can reveal.

That is what the Cyber Passport self-assessment does. It certifies nothing and never promises you'll be "compliant": it shows you, question by question, where your organisation is solid and where it still rests on trust or habit — a clear report you can share with a client or an auditor. The right time to do it is now, while you have the words to understand the answers.

Topics

  • glossary
  • vocabulary
  • SME
  • Switzerland
  • awareness

Read next