A living reference for the terms you’ll come across on CyberWalk and elsewhere. This page gets updated as new terms come up. Bookmark it, and check back if you hit a word you don’t recognize in one of our guides.
GENERAL TERMS
CIA Triad (Confidentiality, Integrity, Availability): A model for thinking about security in three parts: keeping information secret (confidentiality), making sure it isn’t tampered with (integrity), and making sure it’s accessible when needed (availability).
Cloud security: Protecting data and services stored in cloud platforms (like Google Drive or AWS), including making sure only the right people can access what’s stored there.
Compliance: Following required rules and regulations, both internal (company policy) and external (laws), to avoid legal trouble and security gaps.
Encryption: Scrambling data so that only someone with the correct key can read it. Used to protect information in transit (like messages) and at rest (like stored files).
Internal threat: A security risk that originates from within an organization, such as an employee, vendor, or partner, whether by accident (clicking a bad link) or intentionally (misusing access).
Malware: Short for “malicious software.” Any program designed to damage a device, steal data, or gain unauthorized access. Includes viruses, spyware, and ransomware.
Multi-factor authentication (MFA) / Two-factor authentication (2FA): A login method that requires more than just a password, usually a code sent to your phone or generated by an app, to prove it’s really you.
Network security: Protecting the systems and pathways that connect devices and data, so only authorized people and traffic get through.
One-Time Password (OTP): A single-use code sent to verify your identity or authorize a transaction. Legitimate services never ask you to read an OTP back to them over a phone call.
Phishing: A scam that tricks you into giving up sensitive information (passwords, OTPs, card details) by impersonating a trusted source, usually via email, SMS, or a fake website.
Privacy protection: Practices and safeguards that keep personal data from being accessed or used without authorization.
Programming: Writing instructions that tell a computer what to do. In a security context, often used to automate tasks like monitoring traffic or detecting suspicious activity.
Ransomware: A type of malware that locks or encrypts your files and demands payment to restore access.
Security architecture: The overall design (tools, processes, and structure) that an organization uses to defend against threats.
Security controls: Specific safeguards (technical, physical, or procedural) put in place to reduce a particular security risk.
Security ethics: The principles that guide responsible, appropriate decision-making for security professionals.
Security framework: A structured, step-by-step model organizations follow to build and maintain their security practices (e.g. NIST, ISO 27001).
Security governance: The leadership and oversight structure that sets direction and accountability for an organization’s security efforts.
Technical skills: Practical, hands-on ability to use security tools and follow procedures effectively.
Threat: Anything with the potential to cause harm to a system, network, or data.
Threat actor: A person or group responsible for carrying out (or attempting) a cyberattack.
VPN (Virtual Private Network): A tool that encrypts your internet connection and masks your location, often used to browse more securely on public Wi-Fi.
PAKISTAN-SPECIFIC TERMS
CNIC: Computerized National Identity Card, Pakistan’s national ID, often requested (legitimately or fraudulently) during identity verification.
NCCIA: National Cyber Crime Investigation Agency, the current authority responsible for investigating and responding to cybercrime complaints in Pakistan. See our full guide to NCCIA.
PECA: Prevention of Electronic Crimes Act, 2016, Pakistan’s primary legislation covering cybercrime and electronic offenses.
PISF: Pakistan Information Security Framework, a national framework introduced by PKCERT aimed at strengthening cybersecurity practices across public and private institutions.
PKCERT: Pakistan’s National Cyber Emergency Response Team, responsible for national-level threat monitoring, advisories, and coordination.
PTA: Pakistan Telecommunication Authority, regulates telecom services and frequently issues public advisories on scams and fraud.
