Threat Glossary — Cybersecurity Terms Explained
The terms your board will ask about, in plain language. Definitions for the techniques, frameworks and tools that come up in security operations. Concise, sourced, and aligned with how regulators use them. 26 terms.
Agentic AI — AI systems that plan, decide and act toward a goal, used in SOCs to investigate and contain alerts end-to-end rather than just classifying them.
Alert fatigue — The reduced effectiveness of analysts when alert volume exceeds reviewable capacity. The dominant operational risk in modern SOCs.
ATT&CK — MITRE's adversary-tactics-and-techniques framework. The de facto vocabulary for describing what attackers do.
Audit trail — A tamper-evident log of every action taken on a system, required by most financial and healthcare regulators.
BNM RMiT — Bank Negara Malaysia's Risk Management in Technology framework for financial institutions.
Containment — The action of stopping an attack from progressing, typically host isolation, token revocation or binary quarantine.
Detection rule — A signal pattern that triggers an alert. SQUDO AI® reads them as input rather than relying on them alone.
Dwell time — How long an attacker is in the environment before detection. Lower is better; agentic AI compresses this dramatically.
EDR — Endpoint Detection and Response, software that watches what happens on laptops, servers and workloads.
Explainability — Whether an AI decision can be traced back to the evidence and rules that produced it. Non-negotiable for regulated SOCs.
False positive — An alert that turns out to be benign. The majority of alert volume in unfiltered SOCs.
IdP — Identity Provider, the system that authenticates users (Okta, Entra ID, Ping).
Lateral movement — An attacker moving from one host to another inside the network.
MAS TRM — Monetary Authority of Singapore's Technology Risk Management guidelines.
MTTC — Mean Time To Contain, from first signal to the attacker being stopped. The headline operational metric.
MTTR — Mean Time To Respond, broader than MTTC; includes investigation and remediation.
OJK — Otoritas Jasa Keuangan, Indonesia's financial services authority.
PDPA — Personal Data Protection Act, the data protection regime in Singapore, Malaysia and Thailand.
Residency — Where data physically lives and is processed. The core sovereignty question.
SIEM — Security Information and Event Management, the central log store and correlation engine of most SOCs.
SOAR — Security Orchestration, Automation and Response, playbook engines that automate response actions.
SOC — Security Operations Center, the team and platform watching for and responding to incidents.
Sovereignty — Operational control over where data lives, who can access it and how it is processed, by you, not your vendor.
Tier 1 — The first line of human alert review in a SOC. The work SQUDO AI® automates.
XDR — Extended Detection and Response, EDR plus identity, email and cloud signal.
Zero trust — An architectural posture that assumes no implicit trust based on network location.
Get a demo · Visit NEXULIS