Cybersecurity glossary
Plain-language definitions of the cybersecurity terms SMB owners actually run into.
- Sauvegarde 3-2-1
- The universally recommended backup rule: 3 copies of your data, on 2 different media, with 1 off-site.
- BEC (Business Email Compromise)
- A type of fraud where an attacker compromises or impersonates a legitimate mailbox to validate a fraudulent transfer or bank-account change.
- Cyberassurance
- An insurance policy covering all or part of the costs related to a cyber incident: remediation, business interruption, ransom, legal fees.
- DMARC, SPF & DKIM
- Three complementary standards that prove an email actually comes from your domain and prevent attackers from impersonating you.
- ISO 27001
- International standard that certifies the implementation of an information security management system.
- Authentification à deux facteurs (2FA / MFA)
- A mechanism that requires a second factor (code, app, physical key) on top of the password to log in.
- NIS2
- European directive (effective 2024) that extends cybersecurity obligations to tens of thousands of companies, including SMBs.
- Test d'intrusion (pentest)
- An offensive audit where a consultant simulates an attack on your infrastructure, under contract, to identify exploitable vulnerabilities.
- Phishing
- An identity-spoofing attempt via email, SMS, or message, designed to make you click a booby-trapped link or reveal credentials.
- Ransomware
- Malicious software that encrypts your files and demands a ransom in exchange for the decryption key.
- RGPD
- European regulation (effective 2018) governing the collection and processing of personal data, with fines up to 4% of revenue.