SECURITY JARGON, TRANSLATED
ACSC
The Australian Cyber Security Centre — the Australian Government's lead agency for cybersecurity advice and incident reporting, part of the Australian Signals Directorate (ASD). Publisher of the Essential Eight.
Business Email Compromise (BEC)
A scam where attackers take over or convincingly impersonate a business email account to redirect payments or steal data. One of the largest sources of SMB losses in Australia — often triggered by a single phished password.
EDR (Endpoint Detection & Response)
Modern protection software for computers and servers that doesn't just block known viruses, but detects suspicious behaviour and lets analysts investigate and contain threats remotely. The successor to traditional antivirus, and now a standard cyber-insurance requirement.
Essential Eight
The ACSC's eight baseline mitigation strategies: patch applications, patch operating systems, MFA, restrict admin privileges, application control, restrict Office macros, harden user applications, and regular backups. Measured in maturity levels 0–3.
Incident Response (IR)
The organised process of handling a cyber attack: containing it, removing the attacker, recovering systems, preserving evidence and meeting notification obligations. Having a plan before you need it is half the battle.
MDR (Managed Detection & Response)
A service where a specialist provider runs EDR tooling for you and staffs it with analysts 24/7 — detection, investigation and response as a monthly service instead of an in-house team.
MFA (Multi-Factor Authentication)
Requiring a second proof of identity (an app prompt, code or security key) in addition to a password. The single most effective control against account takeover — and the first question on every insurance form.
Notifiable Data Breaches (NDB) scheme
The Privacy Act scheme requiring organisations to notify affected individuals and the OAIC when a data breach is likely to result in serious harm. Applies to most businesses with turnover above $3M, and to many smaller ones (e.g. health providers).
OAIC
The Office of the Australian Information Commissioner — the regulator for privacy and data protection in Australia, and the body you notify under the NDB scheme.
Patching
Applying security updates to software and operating systems. Most successful attacks exploit vulnerabilities for which a patch already existed — often for months.
Penetration Test
An authorised simulated attack on your systems by security professionals, designed to find exploitable weaknesses before criminals do. Delivered with a report of findings and fixes.
Phishing
Fraudulent messages (email, SMS, voice) designed to steal credentials or trigger payments. The starting point of most real-world breaches. Its SMS variant is "smishing"; targeted phishing of executives is "spear phishing" or "whaling".
Ransomware
Malware that encrypts your files and demands payment for their return — increasingly paired with data theft and threats to publish ("double extortion"). Recovery without paying depends almost entirely on backup quality.
SIEM
Security Information and Event Management — a platform that collects logs from across your systems so threats can be detected and investigated. Usually operated for SMBs by an MDR provider rather than in-house.
Social Engineering
Manipulating people rather than technology — impersonating the CEO, a supplier or IT support to get someone to hand over access or money. Countered by training, process and healthy scepticism.
Zero Trust
A security approach that assumes no user or device is trustworthy by default — every access is verified. Less a product than a design principle behind modern controls like MFA and conditional access.
Met a term that isn't here, or want to know what it means for your business specifically?
Talk to Us