Fundamentals
Glossary: the cybersecurity terms worth understanding
A clear, jargon-free dictionary of the terms that come up when protecting your company.
Exposure and surface
- External attack surface: everything your company leaves visible from the internet.
- Exposed host: a unique asset reachable from the internet (a server, service or address).
- Subdomain: an address within your domain (store.yourcompany.com, mail.yourcompany.com).
- Port: a “door” a service listens on; some shouldn't be open to the internet.
- TLS/SSL certificate: what makes your site “https”; expired or misconfigured, it's a risk.
- OSINT: open-source intelligence — public information an attacker gathers about you.
Threats
- Vulnerability: a flaw that can be exploited to compromise a system.
- CVE: the public identifier of a known vulnerability (attackers look for unpatched CVEs).
- Phishing: deception to steal credentials or data, usually by email or message.
- Ransomware: malware that encrypts your data and demands a ransom.
- Breach or leak: when data that should be protected is exposed or stolen.
Defense
- Pentest: a deep, one-off test where a specialist tries to break into your systems.
- Continuous monitoring (EASM): permanent surveillance of your internet-facing surface.
- Hardening: strengthening a system's configuration to reduce its exposure.
- Minimal surface: the principle of exposing to the internet only what's strictly necessary.
Where to start?
With the first thing an attacker sees: your surface. Enter your domain and NEO shows you your exposed hosts, free.
See what your company exposes — free
Analyze your domain