Reference

Cybersecurity Glossary

By the NexusSec engineering team · 9 min read · Updated July 2026
A plain-English reference to the security and networking terms businesses encounter most often. No marketing language, no unnecessary jargon — just what each term means and why it matters. Where a topic deserves more depth, we have linked to a fuller explanation.

Attacks and threats

Defences and controls

Testing and assurance

Networking

Operations

Frequently asked questions

What is the difference between a vulnerability, a threat and a risk?

A vulnerability is a weakness, such as an unpatched server. A threat is something that could exploit it, such as a ransomware group. Risk is the combination of likelihood and impact — how probable exploitation is and how badly it would hurt. Security work should prioritise risk, not just vulnerability counts.

What does CVSS score mean?

CVSS is the Common Vulnerability Scoring System, rating severity from 0 to 10 based on technical characteristics. It is useful for comparison but lacks your business context. A medium-scored vulnerability on a critical internet-facing system may matter far more than a high-scored one on an isolated test machine.

What is the 3-2-1 backup rule?

Keep three copies of your data, on two different types of media, with one copy stored offsite. Modern practice adds immutability, meaning at least one copy cannot be altered or deleted, which protects against ransomware that specifically targets backups.

What is the difference between IDS and IPS?

An Intrusion Detection System identifies suspicious traffic and raises an alert. An Intrusion Prevention System does the same but also blocks the traffic. Most modern firewalls include IPS, though it is sometimes left in detection-only mode after deployment, which we find frequently during audits.

What is a DMZ?

A DMZ, or demilitarised zone, is a network segment hosting services that must be reachable from the internet, such as a web or mail server. It is isolated from the internal network, so that compromising an internet-facing service does not automatically give an attacker access to internal systems.

Need these concepts applied to your network?

NexusSec designs, deploys and manages security infrastructure for businesses across Navi Mumbai, Mumbai and India.

Explore Our Services