Glossary

Cybersecurity terms,explained clearly

Plain-language definitions of the phishing, social engineering, and human-risk terms that matter, written for security teams and the people they protect.

P

Passkey

A passwordless sign-in method using cryptographic key pairs, tied to a device and biometric or PIN unlock, that resists phishing by design.

Password Manager

A tool that securely generates, stores, and autofills unique passwords for every account, so users never need to reuse or memorize them.

Password Spraying

An attack that tries a small number of common passwords against a large number of accounts, one password at a time, to avoid triggering account lockout policies.

Penetration Testing

An authorised simulated attack against systems to find exploitable weaknesses before a real attacker does.

Pharming

An attack that redirects victims from a legitimate website's correct address to a fake copy of it by tampering with DNS resolution or a local hosts file, so even a correctly typed address lands on the attacker's page.

Phish-Prone Rate

The percentage of employees who fail a simulated phishing test by clicking a link, opening an attachment, or submitting credentials.

Phishing

Phishing is a social engineering attack where criminals impersonate a trusted sender to trick people into revealing credentials, transferring money, or installing malware.

Phishing Simulation

A controlled, authorized exercise that sends realistic but harmless fake phishing messages to employees to measure how they respond and to train safer behavior.

Phishing-Resistant MFA

Multi-factor authentication cryptographically bound to the legitimate website's origin, such as FIDO2 security keys and passkeys, that cannot be phished or relayed the way SMS codes and push approvals can.

Pretexting

A social engineering tactic where an attacker invents a false scenario to trick a target into revealing information or granting access.

S

Security Awareness Training

Security awareness training is structured education that teaches employees to recognize and respond to cyber threats such as phishing, social engineering, and unsafe data handling.

Security Culture

The shared attitudes, beliefs, and everyday behaviors around security that exist across an organization, beyond formal policy and training.

Security Operations Center

The team and function responsible for monitoring, detecting and responding to security events, often around the clock.

Session Hijacking

The theft or forgery of a valid session token or cookie, letting an attacker impersonate an already logged-in user without ever needing their password.

SIEM

A platform that centralises log data from across an estate, correlates it, and raises alerts on suspicious patterns.

SIM Swapping

A social-engineering attack in which a criminal convinces or bribes a mobile carrier to transfer a victim's phone number to a SIM card the attacker controls, intercepting calls and SMS one-time passwords.

Single Sign-On (SSO)

An authentication method where one identity provider verifies a user once and that single login grants access to many connected applications, typically via SAML or OpenID Connect.

Smishing

Smishing is phishing carried out over SMS or other text messaging, where attackers send fraudulent texts to trick people into revealing data, clicking malicious links, or sending money.

Social Engineering

The manipulation of people into revealing sensitive information or taking unsafe actions by exploiting trust, emotion, and human psychology rather than technical flaws.

Spear Phishing

A targeted phishing attack that uses personalized details about a specific individual or organization to make a fraudulent message far more convincing.

Spyware

Software that secretly monitors a user's activity and collects information such as browsing habits, keystrokes, or credentials without consent.

Put the theory into practice

See how Claro turns awareness into measurable behavior change.

Request a demo