Plain English

Security and technology glossary

Short definitions for concepts used across Security e-Drift.

AI agent
An AI-enabled system that can plan or take actions toward a goal, often by using tools or connected services.
Authentication
The process of checking that a person, device, or service is who or what it claims to be.
Blast radius
The amount of harm a mistake or compromise can cause before it is contained.
Botnet
A group of compromised devices controlled together, usually without their owners knowing.
Credential stuffing
An attack that tries stolen username and password combinations on other services where people may have reused them.
Encryption
A way of transforming readable information so that only someone with the right key can read it.
Generative AI
AI that creates new text, images, audio, code, or other material from patterns learned during training.
Human in the loop
A person must review or approve a consequential action before a system completes it.
Digital identity
The accounts, attributes, credentials, and signals used to represent a person or organisation online.
Multi-factor authentication
An account check that asks for another factor beyond a password, such as an app prompt or security key.
Phishing
A message or interaction designed to make you reveal information, send money, or open something harmful.
Privacy
Your ability to understand and influence how information about you is collected, used, and shared.
Prompt injection
Instructions designed to make an AI system ignore its intended rules or reveal or misuse information and tools.
Ransomware
Malware that blocks access to systems or data, often through encryption, while demanding payment.
Zero trust
An approach that verifies each access request instead of trusting it only because it comes from inside a network.