
| Most common attack vector | Phishing emails (Verizon Data Breach Investigations Report, 2023) |
| Average cost of a data breach (US) | $9.48 million (IBM Cost of a Data Breach Report, 2023) |
| Recommended password length | At least 16 characters (NIST Digital Identity Guidelines) |
| Share of breaches involving stolen credentials | ~49% (Verizon Data Breach Investigations Report, 2023) |
| 2FA effectiveness against automated attacks | Blocks ~99.9% of attacks (Microsoft Security research findings) |
| Time to exploit a zero-day after disclosure | Often under 15 days (Google Project Zero research) |
Why Cybersecurity Vocabulary Matters
When your email provider warns about a phishing attempt, or a news story reports a zero-day exploit, the terminology can feel like a foreign language. That gap matters — unfamiliar language slows down your ability to respond, and in cybersecurity, response time counts.
This glossary gives everyday US internet users a practical, plain-English reference for the terms they're most likely to encounter in security alerts, app settings, and news coverage. It is not exhaustive — the field is vast — but it covers the vocabulary that directly affects how you protect your accounts, devices, and personal data.
For a broader introduction to staying safe online, see our beginner's guide to online security. If you'd like a similar reference in another domain, our investing glossary for US beginners follows the same plain-language approach.
This Is a Reference Guide, Not a Security Plan
Understanding these terms helps you navigate security settings, breach notifications, and news stories more confidently. However, every individual's threat environment is different. For a thorough security posture, consult resources from organizations such as CISA (Cybersecurity and Infrastructure Security Agency) or a qualified IT security professional.
Core Terms: Threats and Attacks
Understanding what attackers actually do is the foundation of any security literacy. The terms below describe the most common categories of threats you're likely to encounter.
Malware
Short for malicious software, malware is any program designed to damage, disrupt, or gain unauthorized access to a computer or network. It includes viruses, ransomware, spyware, and trojans.
Phishing
A social engineering attack in which a criminal impersonates a trusted entity—such as a bank or tech company—via email, text, or fake website to trick users into revealing passwords or financial details.
Two-Factor Authentication (2FA)
A login security method requiring two forms of verification: something you know (a password) and something you have or are (a code sent to your phone, or a fingerprint). It significantly reduces unauthorized access risk.
Encryption
The process of scrambling data so only an authorized party with the correct key can read it. Websites using HTTPS and messaging apps with end-to-end encryption both rely on this technology.
Firewall
A security system—either hardware or software—that monitors and filters incoming and outgoing network traffic based on established rules, blocking unauthorized access while allowing legitimate connections.
VPN (Virtual Private Network)
A service that creates an encrypted tunnel for your internet traffic, masking your IP address and making it harder for third parties to monitor your online activity, especially on public Wi-Fi.
Zero-Day Vulnerability
A software flaw that is unknown to the vendor and therefore unpatched. Attackers who discover it can exploit it before a fix is available, making it particularly dangerous.
Ransomware
A type of malware that encrypts a victim's files or locks their system, then demands payment—usually in cryptocurrency—in exchange for restoring access. It affects both individuals and organizations.
Data Breach
An incident in which unauthorized individuals gain access to sensitive, protected, or confidential information held by an organization. Exposed data may include usernames, passwords, or financial records.
Social Engineering
Manipulation tactics that exploit human psychology rather than technical weaknesses to gain unauthorized access or information. Phishing is the most common example.
Patch
A software update released by a developer to fix security vulnerabilities, bugs, or other issues. Applying patches promptly is one of the most effective ways to reduce exposure to known threats.
Multi-Factor Authentication (MFA)
An expanded form of 2FA that may require more than two verification factors. It is widely used by businesses and increasingly recommended for personal accounts to strengthen login security.
Many of these threats rely less on sophisticated code than on human error. Social engineering — the manipulation of people rather than systems — underlies the majority of successful attacks. Our companion article on the human side of cybersecurity attacks explores those psychological tactics in depth.
Key Numbers Behind Everyday Threats
Raw statistics help illustrate why these terms aren't abstract — they reflect real-world consequences at scale.
~49%
Of breaches involve stolen or weak credentials
According to the Verizon Data Breach Investigations Report 2023, credential theft remains the leading cause of unauthorized access.
$9.48M
Average US data breach cost
IBM's 2023 Cost of a Data Breach Report identifies the United States as consistently having the highest average breach cost globally.
15 days
Typical window to exploit a disclosed zero-day
Google Project Zero research found attackers frequently weaponize known vulnerabilities within two weeks of public disclosure.
| Most common attack vector | Phishing emails (Verizon Data Breach Investigations Report, 2023) |
| Average cost of a data breach (US) | $9.48 million (IBM Cost of a Data Breach Report, 2023) |
| Recommended password length | At least 16 characters (NIST Digital Identity Guidelines) |
| Share of breaches involving stolen credentials | ~49% (Verizon Data Breach Investigations Report, 2023) |
| 2FA effectiveness against automated attacks | Blocks ~99.9% of attacks (Microsoft Security research findings) |
| Time to exploit a zero-day after disclosure | Often under 15 days (Google Project Zero research) |
These figures reinforce a consistent message from security researchers: the most impactful protective steps are often the simplest ones, such as enabling two-factor authentication and applying software patches without delay.
Protective Concepts You'll See in Settings and News
Beyond threat vocabulary, many security terms describe the tools and practices that defend against attacks. You'll encounter these in app permission screens, router settings, and account security dashboards.
- Encryption: Look for HTTPS in browser address bars and end-to-end encryption labels in messaging apps. These indicate your data is scrambled in transit.
- VPN: Useful for masking your IP address on public Wi-Fi, though it does not make you anonymous online or protect against all threats.
- Firewall: Built into most modern operating systems; keep it enabled unless a qualified technician advises otherwise.
- MFA/2FA: Available on most major platforms — email, banking, social media. Enabling it is one of the highest-impact steps an everyday user can take.
- Patch/Update: Software updates frequently close known security gaps. Delaying them leaves you exposed to vulnerabilities that attackers are already exploiting.
For guidance on how these concepts apply specifically within mobile and desktop apps, see the complete picture on app security for everyday users. The Apps hub also contains practical guides on safe download habits and permissions management.
