Plain English
Security and technology glossary
Short definitions for concepts used across Security e-Drift.
- AI agent
- An AI-enabled system that can plan or take actions toward a goal, often by using tools or connected services.
- Authentication
- The process of checking that a person, device, or service is who or what it claims to be.
- Blast radius
- The amount of harm a mistake or compromise can cause before it is contained.
- Botnet
- A group of compromised devices controlled together, usually without their owners knowing.
- Credential stuffing
- An attack that tries stolen username and password combinations on other services where people may have reused them.
- Encryption
- A way of transforming readable information so that only someone with the right key can read it.
- Generative AI
- AI that creates new text, images, audio, code, or other material from patterns learned during training.
- Human in the loop
- A person must review or approve a consequential action before a system completes it.
- Digital identity
- The accounts, attributes, credentials, and signals used to represent a person or organisation online.
- Multi-factor authentication
- An account check that asks for another factor beyond a password, such as an app prompt or security key.
- Phishing
- A message or interaction designed to make you reveal information, send money, or open something harmful.
- Privacy
- Your ability to understand and influence how information about you is collected, used, and shared.
- Prompt injection
- Instructions designed to make an AI system ignore its intended rules or reveal or misuse information and tools.
- Ransomware
- Malware that blocks access to systems or data, often through encryption, while demanding payment.
- Zero trust
- An approach that verifies each access request instead of trusting it only because it comes from inside a network.
