Skip to content

A Technology Innovation Partners Inc. company.

Resources

Cybersecurity Glossary

Plain-English definitions of the cybersecurity terms business leaders actually need — no jargon, no fluff.

CMMC (Cybersecurity Maturity Model Certification)

A U.S. Department of Defense program that verifies contractors have implemented required cybersecurity practices to protect government information. Level 1 covers Federal Contract Information; Level 2 aligns to NIST 800-171 for Controlled Unclassified Information.

CMMC & NIST Compliance »

CUI (Controlled Unclassified Information)

Sensitive but unclassified information the U.S. government requires to be safeguarded, such as technical data on defense contracts. Handling CUI generally triggers CMMC Level 2 requirements.

NIST 800-171

A catalog of 110 security requirements published by the National Institute of Standards and Technology for protecting Controlled Unclassified Information in non-federal systems. Meeting it is the foundation of CMMC Level 2.

Penetration Test

An authorized, simulated cyber attack that actively exploits weaknesses to demonstrate what a real attacker could achieve — going beyond identifying vulnerabilities to proving their impact.

Penetration Testing »

Vulnerability Assessment

A systematic review that identifies and prioritizes security weaknesses across systems and applications. Unlike a penetration test, it identifies weaknesses without necessarily exploiting them.

Vulnerability Assessments »

Red Team

An objective-based, stealthy engagement that emulates a real adversary over an extended period to test not only technical controls but an organization’s ability to detect and respond.

Ransomware

Malicious software that encrypts an organization’s data and demands payment for its release. Modern ransomware often also steals data to pressure victims. Tested backups, segmentation, and MFA are the core defenses.

Multi-Factor Authentication (MFA)

A security control requiring two or more forms of verification to log in — typically a password plus a code or device. MFA is one of the highest-return controls for preventing account compromise.

MDR (Managed Detection & Response)

A service that provides continuous monitoring, expert threat detection, and rapid response across an organization’s environment — catching and containing attacks that preventive tools miss.

Managed Detection & Response »

vCISO (Virtual CISO)

An experienced security executive who leads an organization’s security program on a fractional, ongoing basis — providing strategy, board reporting, and compliance leadership without a full-time hire.

Virtual CISO Services »

Zero Trust

A security model that assumes no user or device is trusted by default, requiring continuous verification for every access request rather than trusting anything inside the network perimeter.

Phishing

A social-engineering attack that tricks people into revealing credentials or taking harmful actions, usually through deceptive email. It is the starting point for the majority of breaches.

Security Awareness Training »

Business Email Compromise (BEC)

A targeted scam in which attackers impersonate an executive or vendor to trick staff into transferring money or changing payment details. Out-of-band verification of payment requests is the key defense.

HIPAA Security Rule

The U.S. regulation requiring healthcare organizations and their business associates to protect electronic protected health information, including a documented security risk analysis.

Healthcare Cybersecurity »

Incident Response

The organized process of preparing for, containing, investigating, and recovering from a cyber incident. A tested plan is what separates a manageable event from a catastrophe.

Incident Response »

Attack Surface

The total set of points where an attacker could try to enter or extract data from an environment — internet-facing systems, applications, accounts, and third-party connections.

Have a Question These Did Not Answer?

Talk with our team about your specific security goals — in plain language, always.

Get Started