Sicra Header Logo
Offerings
Knowledge
Careers
About us
People
English
Norsk
Talk to us
Home
Knowledge
Dictionary
Not fluent in cybersecurity? We speak your language
A
B
C
D
E
F
G
H
I
J
K
L
M
N
O
P
Q
R
S
T
U
V
W
X
Y
Z
A
ABAC (Attribute Based Access Control)
ABAC grants access based on multiple attributes and context.
Read more
ADC (Application Delivery Controller)
Application Delivery Controller (ADC) ensures safe and efficient access.
Read more
Adware
Adware displays ads and may collect user data without consent.
Read more
Agentic AI
Agentic AI describes AI systems that can plan, decide, and act independently.
Read more
AI Act
The AI Act sets requirements for how organizations develop and use artificial intelligence.
Read more
Air-gapped networks
A network isolated from external connections.
Read more
AISI (AI Security Institute)
AISI evaluates the capabilities and security risks of advanced AI models.
Read more
Alert fatigue
Alert fatigue occurs with high alarm frequency.
Read more
Alpha AI
Alpha AI reduces noise and highlights critical security threats.
Read more
Antivirus
Antivirus detects, prevents, and removes malware from devices.
Read more
API (Application Programming Interface)
An API is an interface that connects systems securely.
Read more
Arctic Wolf
Arctic Wolf protects organizations from cyber threats.
Read more
Artificial general intelligence (AGI)
AGI can perform all intellectual tasks humans can.
Read more
Artificial intelligence (AI)
AI enables computers to perform human tasks.
Read more
Attack surface
An attack surface is every digital entry point an attacker can exploit.
Read more
Authentication
Authentication verifies identity and secures access.
Read more
Authorization
Authorization defines which actions and resources an identity may access.
Read more
Azure
Azure is Microsoft’s cloud platform that consists of over 200 products and cloud services.
Read more
Azure Policy
Azure Policy ensures control and compliance in cloud environments.
Read more
Azure Resource Manager
ARM enables consistent management of Azure resources with security controls.
Read more
B
Baiting
Baiting lures victims with tempting offers.
Read more
BEC (Business Email Compromise)
Learn what BEC is and how it targets businesses.
Read more
Best practice
Beste praksis streber etter høyest mulig sikkerhet
Read more
Bicep
Bicep is Azure's native declarative language for infrastructure as code.
Read more
Biometrics
Biometrics enable secure authentication without passwords.
Read more
Blackhat
A blackhat is a hacker who attacks systems without permission.
Read more
Blue team
Blue team protects systems with real-time response
Read more
Bluejacking
Bluejacking sends unsolicited messages via Bluetooth.
Read more
Bluetree
Norwegian technology company with expertise in networking, OT security, and industrial cybersecurity.
Read more
Botnet
Botnet are infected computers controlled by attackers.
Read more
Brute force attack
Brute force attack tests all password combinations.
Read more
Bug bounty
Bug bounty rewards ethical hackers for vulnerability findings.
Read more
C
Carding
Carding is fraud with stolen credit card information.
Read more
CASB (Cloud Access Security Broker)
CASB provides control and visibility over cloud usage.
Read more
Cato Networks
Cloud-native SASE platform unifying networking and security.
Read more
Certificate management
Poor certificate management can lead to outages and security risks.
Read more
CI/CD (Continuous Integration, Continuous Delivery/Deployment)
CI/CD enables secure and fast code delivery through automation.
Read more
CIS (Center for Internet Security)
CIS develops global security standards that help organizations protect systems and data.
Read more
CIS Benchmarks
CIS Benchmarks provide secure configuration baselines for systems and cloud services.
Read more
CIS Controls
CIS Controls provide organizations with a prioritized and structured path to stronger cybersecurity.
Read more
Cisco
Global leader in networking, security, and collaboration technologies.
Read more
CISO as a service
CISO as a service is outsourced security leadership without hiring a CISO.
Read more
CISO for hire
CISO-for-hire offers temporary security expertise.
Read more
CISOaaS
CISOaaS is outsourced security leadership delivered as a flexible service.
Read more
Cloud
Cloud offers scalable IT services with shared security responsibility between customer and provider.
Read more
Compliance
Compliance ensures IT solutions meet legal requirements.
Read more
Computer virus
A computer virus is malware that infects files and systems
Read more
Computer worm
A computer worm is malware that spreads automatically between computers.
Read more
Conditional Access
Conditional Access provides context-based access control in Entra ID based on identity, device and risk.
Read more
Credential stuffing
Credential stuffing uses stolen usernames and passwords from attacks to gain access to new accounts.
Read more
Cyber insurance
Cyber insurance provides financial protection against cyberattacks.
Read more
Cyber Kill Chain
Cyber Kill Chain breaks down cyberattacks into seven phases.
Read more
Cyberattack
A cyberattack is a digital assault on systems, networks, or data.
Read more
Cybersecurity
Cybersecurity protects against digital attacks.
Read more
D
Dark web
Dark web requires special software for access.
Read more
Data breach
A data breach is when sensitive information is exposed or stolen.
Read more
Data exfiltration
Dataeksfiltrering er uautorisert overføring av data fra virksomhetens systemer.
Read more
Data lake
A data lake stores large amounts of data in its original form.
Read more
Data security
Data security protects information from loss, change, and exposure.
Read more
DDoS attack (Distributed Denial of Service)
DDoS attacks paralyze servers with heavy traffic.
Read more
Decryption
Decryption makes encrypted information readable again.
Read more
Deep web
Deep web is not indexed by search engines like Google.
Read more
DevOps (Development and Operations)
DevOps combines development and operations for better collaboration.
Read more
DevSecOps (Development, Security and Operations)
DevSecOps means security is part of the full development process
Read more
Digital forensics
Digital forensics uncovers what happened during a cyberattack.
Read more
Digital identification
Digital identification verifies identity online.
Read more
Digital security
Digital security protects systems, data, and users from cyber threats.
Read more
Digital twin security
Digital twin security protects virtual models of physical systems.
Read more
DLP (Data Loss Prevention)
DLP blocks leaks with proactive security measures.
Read more
DORA (Digital Operational Resilience Act)
DORA protects financial companies from digital threats.
Read more
DPI (Deep packet inspection)
DPI analyzes and filters network traffic at a deep level.
Read more
Dumpster diving
Dumpster diving is searching through trash for sensitive information.
Read more
E
East-west traffic
Internal traffic between systems and resources in a network.
Read more
Eavesdropping attack
Eavesdropping attacks threaten data confidentiality.
Read more
EDR (Endpoint Detection and Response)
EDR monitors and protects endpoints from modern attacks.
Read more
Encryption
Encryption protects data.
Read more
Entra ID
Entra ID, formerly Azure AD, provides central authentication with advanced security features.
Read more
Expert systems (AI)
Expert systems (AI) follow predefined rules.
Read more
Exploit kit
Exploit kits exploit vulnerabilities to infect systems with malware.
Read more
F
F5
F5 protects applications and APIs from risks and threats.
Read more
Feedback loops
Feedback loops collect and analyze information.
Read more
FIDO2 (Fast IDentity Online 2)
FIDO2 enables authentication with security keys, biometrics, or mobile devices.
Read more
Fileless malware
Fileless malware uses system processes without files.
Read more
Firewall
A firewall is a barrier between internal and external networks.
Read more
FQDN (Fully Qualified Domain Name)
FQDN is the complete name of a computer or host.
Read more
FWaaS (Firewall as a Service)
Cloud-based firewall protecting traffic across locations.
Read more
G
GDPR (General Data Protection Regulation)
GDPR gives more control over personal data.
Read more
GDPR compliance
GDPR compliance means handling personal data securely and lawfully in the EU.
Read more
GIAC (Global Information Assurance Certification)
GIAC certifications are highly recognized in cybersecurity.
Read more
Governance
Governance defines how decisions are made, controlled and followed up in IT and security.
Read more
GPAI (General-purpose AI)
GPAI supports many tasks, but requires control over data and access.
Read more
Grayhat
A grayhat finds vulnerabilities without permission but avoids harm.
Read more
GSA (Global Secure Access)
GSA combines network, identity, and endpoint security.
Read more
H
Hacking
Hacking is compromising digital devices and networks.
Read more
Hacktivism
Hacktivism uses hacking for political or social goals.
Read more
Hash
Hash turns data into a fixed-length string.
Read more
Honeytoken
Honeytoken uses fake data to reveal unauthorized access.
Read more
I
IaC (Infrastructure as Code)
IaC provides repeatable infrastructure with potential for consistent security controls.
Read more
IAM (Identity and Access Management)
IAM manages identities and access to systems, applications, and data.
Read more
Identity security
Identity security protects resources with identity management, authentication, and access.
Read more
IDS (Intrusion Detection System)
IDS detects and alerts on suspicious activity and threats in networks and systems.
Read more
IEC 62443
IEC 62443 – the standard for structured and mature OT security.
Read more
IGA (Identity Governance and Administration)
IGA ensures the right access, at the right time, with proper compliance.
Read more
IIoT (Industrial Internet of Things)
IIoT links machines to networks and introduces new risks.
Read more
IoT (Internet of Things)
IoT refers to physical devices that communicate via the internet.
Read more
IPS (Intrusion Prevention System)
IPS blocks malicious activity in real-time.
Read more
IRT (Incident Response Team)
IRT handles security incidents and limits damage.
Read more
ISO 27001 (International Organization of Standardization)
ISO/IEC27001 sets requirements for information security.
Read more
ISO 9001
Standard for quality management and continuous improvement.
Read more
IT security
IT security is about protecting data, systems, and users.
Read more
IT-GRC (IT Governance, Risk and Compliance)
IT-GRC helps organizations govern IT, manage risk, and meet regulatory requirements through a structured and integrated approach.
Read more
J
JIT (Just-in-Time)
JIT reduces risk by providing temporary access only when required.
Read more
Juice jacking
Juice jacking transfers malware via USB charging stations.
Read more
K
Kerberos
Kerberos uses tickets for secure communication.
Read more
L
Least privilege
Least privilege means users only get access to what they truly need.
Read more
Lethal Trifecta
Three weak links – when they connect, the entire security chain breaks.
Read more
LLM (Large Language Model)
LLMs are AI models capable of understanding and generating natural language.
Read more
Load balancing
Distributes traffic across servers to improve performance and availability.
Read more
Logging
Logging collects information about events and activities for monitoring, troubleshooting, and security.
Read more
M
Machine ID
Machine identities give systems and services secure access to digital resources.
Read more
Machine learning (AI)
Machine learning uses data to learn and improve.
Read more
Malware
Malware is software that harms, steals, or disrupts systems.
Read more
Man-in-the-middle (MITM) attack
MITM attacks intercept or manipulate communication.
Read more
MDR (Managed Detection and Response)
MDR protects organizations from cyber threats with technology and expertise.
Read more
MFA (Multi-factor authentication)
MFA protects against unauthorized access even when passwords are compromised.
Read more
Microsegmentation
Microsegmentation limits threats by dividing the network.
Read more
Microsoft
Microsoft is known for Windows, Office, Xbox, Azure, and Surface.
Read more
Microsoft Intune
Intune protects access and data on devices.
Read more
MITRE ATT&CK (Adversarial Tactics, Techniques, and Common Knowledge)
MITRE ATT&CK maps tactics and techniques used by adversaries during cyberattacks.
Read more
MITRE D3FEND
MITRE D3FEND describes defensive techniques that can be used against cyberattacks.
Read more
MSP+ (Managed Service Provider Plus)
MSP+ is an extended MSP model with closer customer follow-up.
Read more
N
NAC (Network Access Control)
Network Access Control controls who and what can access a network.
Read more
Network
A network enables communication between users, devices, systems and services.
Read more
Network segmentation
Segmentation divides the network into secure zones that limit the spread of threats.
Read more
Network telemetry
Collection of data to understand network state and activity.
Read more
Neural networks and deep learning (AI)
Neural networks and deep learning mimic brain functions.
Read more
NHI (non-human identities)
NHI are digital identities used by applications, services, and machines that need secure access to an organization’s systems and data.
Read more
NIS2 (Network and Information Systems Directive 2)
NIS2 strengthens information security in the EU and EEA.
Read more
NIST SP 800-162
Guidance for implementing attribute-based and context-aware access control.
Read more
NOC (Network Operation Center)
A NOC ensures stable operations, rapid troubleshooting and continuous network monitoring.
Read more
North-south traffic
Traffic between internal systems and external services.
Read more
NSM (Norwegian National Security Authority)
NSM strengthens Norway’s digital and national security.
Read more
NTLM (New Technology LAN Manager)
NTLM vulnerabilities in Windows are serious and require immediate response.
Read more
O
O3 Cyber
O3 Cyber protects and enhances cloud infrastructure.
Read more
OT (Operational technology)
Operational technology (OT) digitally controls machines and processes.
Read more
OT security
OT security ensures the operation of critical infrastructure.
Read more
P
Palo Alto Networks
Palo Alto Networks launched next-generation firewalls.
Read more
PAM (Privileged Access Management)
PAM controls and monitors privileged accounts and administrative access.
Read more
Password spraying
Password spraying uses common passwords to access accounts.
Read more
Passwordless
Passwordless enables secure access without passwords.
Read more
PBAC (Policy-Based Access Control)
PBAC governs access through policies and context.
Read more
Pentesting
Pentesting finds weak points in computer systems.
Read more
Phishing
Phishing tricks the victim into giving up sensitive information.
Read more
PLC (Programmable Logic Controller)
PLC automates operations and needs protection from sabotage.
Read more
PQC (Post-quantum cryptography)
PQC protects data against attacks from future quantum computers.
Read more
Pre-authentication
Pre-authentication confirms identity before access – seamless with SSO.
Read more
Pretexting
Pretexting creates a false story to obtain sensitive information.
Read more
Prompt injection
Prompt injection can manipulate AI systems into following unwanted instructions.
Read more
Purdue
Purdue enables control and clarity in OT security.
Read more
Purple team
Purple team improves security through collaboration between blue and red team.
Read more
Q
Quishing
Quishing uses malicious QR codes to steal information.
Read more
R
Ransomware
Ransomware encrypts data and demands ransom.
Read more
RBAC (Role-Based Access Control)
RBAC provides access management based on roles to implement least privilege.
Read more
Red team
Red team reveals weaknesses through realistic attacks.
Read more
Response time
Response time is key to limiting the impact of security incidents
Read more
Risk detection
Risk detection identifies suspicious activity before security breaches.
Read more
River Security
River Security maps vulnerabilities to protect against digital attacks.
Read more
Rootkit
Rootkits hide access and conceal other malicious activities.
Read more
S
SANS (SysAdmin, Audit, Network, and Security Institute)
SANS is a global leader in cybersecurity training, certification, and threat research.
Read more
SASE (Secure Access Service Edge)
SASE unifies networking and security into a single cloud-based model for secure access anywhere.
Read more
SD-WAN (Software-Defined Wide Area Network)
SD-WAN optimizes and secures traffic between locations and cloud services.
Read more
Secure by design
Secure by Design builds security into digital solutions from the start.
Read more
Security audits
Security audits assess risk and increase leadership focus.
Read more
Security classification
Security classification controls access to sensitive information based on potential harm.
Read more
Security consultant
A security consultant works to protect systems and sensitive data.
Read more
Security management
Security management is the governance of information security.
Read more
Security training
Security training builds awareness and reduces human error.
Read more
Session hijacking
Session hijacking involves stealing the session ID to access sensitive information.
Read more
SIEM (Security Information and Event Management)
SIEM detects and responds to threats with centralized security overview.
Read more
SLA (Service-Level Agreement)
SLA defines service quality and responsibilities.
Read more
SMB (Server Message Block)
SMB shares files, printers, and series between computers.
Read more
SOAR (Security Orchestration, Automation and Response)
SOAR automates security processes and helps security teams respond to incidents faster and more efficiently.
Read more
SOC (Security Operations Center)
A SOC detects, analyzes, and responds to threats in real-time.
Read more
Social engineering
Social engineering exploits human psychology to access sensitive information.
Read more
Splunk
Splunk allows organizations to collect, monitor, and analyze data in real-time.
Read more
Spoofing
Spoofing involves falsifying identity to trick the victim into believing it's genuine.
Read more
Spyware
Spyware monitors and steals information without consent.
Read more
SSO (Single Sign-On)
SSO provides access to multiple applications with one login.
Read more
Stuxnet
Stuxnet disrupted Iran's nuclear program and is one of the most advanced cyberweapons.
Read more
Supply chain
The supply chain includes external parties that impact cybersecurity.
Read more
SWG (Secure Web Gateway)
SWG protects users from internet threats.
Read more
Synthetic identity theft
Synthetic identity theft combines real and fake information for financial fraud.
Read more
T
Terraform
Terraform enables secure and versioned cloud infrastructure.
Read more
The Aurora platform
Aurora enables fast threat detection and response.
Read more
Threat hunting
Threat hunting uncovers cyber threats that security tools may have missed.
Read more
Threat intelligence
Threat intelligence helps organizations defend against attacks.
Read more
Threat modeling
Threat modeling identifies security threats before attacks occur.
Read more
Token
Tokens are used for authentication, authorization, and access to digital resources.
Read more
TOTP (Time-based One-Time Password)
TOTP enables secure logins with one-time codes.
Read more
Trojan horses
A trojan horse pretends to be safe but hides malicious code.
Read more
U
UPS (Uninterruptible power supply)
A UPS provides temporary power and protects critical systems during power outages and unstable power conditions.
Read more
UTC (Coordinated universal time)
UTC provides a common time reference for logs and security incidents.
Read more
V
Virtual patching
Virtual patching protects vulnerable systems until a permanent fix is available.
Read more
Vishing
Vishing tricks victims into revealing sensitive information over the phone.
Read more
VPN (Virtual Private Network)
VPN secures communication with an encrypted tunnel.
Read more
Vulnerability management
Vulnerability management identifies and prioritizes vulnerabilities to reduce risk.
Read more
W
WAF (Web Application Firewall)
A WAF protects web applications by detecting and blocking malicious web traffic.
Read more
Whaling
Whaling is targeted phishing attacks on executives to reveal sensitive information.
Read more
Whitehat
A whitehat is an ethical hacker who tests security with permission.
Read more
Windows Hello for Business
Windows Hello for Business offers safe login without passwords.
Read more
X
XDR (Extended Detection and Response)
XDR provides unified insight and faster response across systems and devices.
Read more
Y
YubiKey
YubiKey protects users from phishing and account compromise through physical MFA.
Read more
Z
Zeek
Zeek monitors networks and detects threats early.
Read more
Zero Trust
Zero Trust recognizes that security threats can come from inside and outside.
Read more
Zero Trust architecture
Zero Trust enforces access through continuous verification.
Read more
Zero-Day vulnerability
A Zero-Day vulnerability is a hidden security gap that attackers can exploit before it's identified.
Read more
Zscaler
Leading provider of cloud-based security and Zero Trust architecture.
Read more
ZTNA (Zero Trust Network Access)
ZTNA grants access to specific applications, not the full network.
Read more
Tailored cybersecurity for institutions and enterprises that allows for innovation, growth, and fearless performance.
Get in touch
Call us +47 648 08 488