Skip to content
All resources

Fundamentals

Glossary: the cybersecurity terms worth understanding

A clear, jargon-free dictionary of the terms that come up when protecting your company.

Exposure and surface

  • External attack surface: everything your company leaves visible from the internet.
  • Exposed host: a unique asset reachable from the internet (a server, service or address).
  • Subdomain: an address within your domain (store.yourcompany.com, mail.yourcompany.com).
  • Port: a “door” a service listens on; some shouldn't be open to the internet.
  • TLS/SSL certificate: what makes your site “https”; expired or misconfigured, it's a risk.
  • OSINT: open-source intelligence — public information an attacker gathers about you.

Threats

  • Vulnerability: a flaw that can be exploited to compromise a system.
  • CVE: the public identifier of a known vulnerability (attackers look for unpatched CVEs).
  • Phishing: deception to steal credentials or data, usually by email or message.
  • Ransomware: malware that encrypts your data and demands a ransom.
  • Breach or leak: when data that should be protected is exposed or stolen.

Defense

  • Pentest: a deep, one-off test where a specialist tries to break into your systems.
  • Continuous monitoring (EASM): permanent surveillance of your internet-facing surface.
  • Hardening: strengthening a system's configuration to reduce its exposure.
  • Minimal surface: the principle of exposing to the internet only what's strictly necessary.

Where to start?

With the first thing an attacker sees: your surface. Enter your domain and NEO shows you your exposed hosts, free.

See what your company exposes — free

Analyze your domain