
Your guide to social engineering, AI threats and security awareness.
A data breach is an incident in which personal or confidential data is accessed, disclosed, altered or lost without authorisation.
Generative AI is artificial intelligence that creates new content such as text, images, audio, video or code based on patterns learned from data.
Impersonation is the act of pretending to be a trusted person or organisation to deceive someone into sharing information, money or access.
ISO/IEC 27001 is the international standard for establishing, operating and continually improving an information security management system (ISMS).
Just-in-time training delivers a short security lesson at the moment it is most relevant, such as right after an employee interacts with a simulated attack.
Malware is malicious software designed to damage systems, steal data or give attackers unauthorised control, including viruses, trojans, spyware and ransomware.
MFA fatigue is an attack in which criminals flood a victim with MFA push requests until the victim approves one out of annoyance or confusion.
Microlearning is a training approach that delivers short, focused lessons of a few minutes each, designed to be completed frequently and remembered easily.
Multi-factor authentication (MFA) is a login method that requires two or more different types of proof of identity, such as a password plus a phone or security key.
Phishing is a social engineering attack in which criminals send deceptive messages that imitate a trusted sender to steal credentials, money or data, or to install malware.
A quid pro quo attack is a social engineering technique in which attackers offer a service or reward in exchange for information or system access.
Quishing is QR code phishing: attackers use QR codes to lead victims to fake login or payment pages, often bypassing email link filters.
Ransomware is malware that encrypts data or systems and demands a ransom, often combined with data theft and the threat of publication.
The report rate is the percentage of employees who report a simulated or real phishing attack, used as a key indicator of security awareness.
Security culture is the shared values, attitudes and everyday behaviours that determine how people in an organisation handle security.
Smishing (SMS phishing) is a phishing attack delivered via text message or messaging apps that tricks recipients into clicking links, sharing data or sending money.
Spam bombing floods a victim's inbox with thousands of emails, often as the first step of an attack in which criminals then pose as IT support to gain remote access.
Tailgating is a physical social engineering attack in which an unauthorised person follows an authorised employee into a restricted area.
Threat intelligence is analysed information about current cyber threats, attackers and their techniques that helps organisations prepare and respond.
Whaling is a highly targeted phishing attack aimed at senior executives such as CEOs and CFOs.
