A living reference for the terms you’ll come across on CyberWalk and elsewhere. This page gets updated as new terms come up. Bookmark it, and check back if you hit a word you don’t recognize in one of our guides.

GENERAL TERMS

CIA Triad (Confidentiality, Integrity, Availability): A model for thinking about security in three parts: keeping information secret (confidentiality), making sure it isn’t tampered with (integrity), and making sure it’s accessible when needed (availability).

Cloud security: Protecting data and services stored in cloud platforms (like Google Drive or AWS), including making sure only the right people can access what’s stored there.

Compliance: Following required rules and regulations, both internal (company policy) and external (laws), to avoid legal trouble and security gaps.

Encryption: Scrambling data so that only someone with the correct key can read it. Used to protect information in transit (like messages) and at rest (like stored files).

Internal threat: A security risk that originates from within an organization, such as an employee, vendor, or partner, whether by accident (clicking a bad link) or intentionally (misusing access).

Malware: Short for “malicious software.” Any program designed to damage a device, steal data, or gain unauthorized access. Includes viruses, spyware, and ransomware.

Multi-factor authentication (MFA) / Two-factor authentication (2FA): A login method that requires more than just a password, usually a code sent to your phone or generated by an app, to prove it’s really you.

Network security: Protecting the systems and pathways that connect devices and data, so only authorized people and traffic get through.

One-Time Password (OTP): A single-use code sent to verify your identity or authorize a transaction. Legitimate services never ask you to read an OTP back to them over a phone call.

Phishing: A scam that tricks you into giving up sensitive information (passwords, OTPs, card details) by impersonating a trusted source, usually via email, SMS, or a fake website.

Privacy protection: Practices and safeguards that keep personal data from being accessed or used without authorization.

Programming: Writing instructions that tell a computer what to do. In a security context, often used to automate tasks like monitoring traffic or detecting suspicious activity.

Ransomware: A type of malware that locks or encrypts your files and demands payment to restore access.

Security architecture: The overall design (tools, processes, and structure) that an organization uses to defend against threats.

Security controls: Specific safeguards (technical, physical, or procedural) put in place to reduce a particular security risk.

Security ethics: The principles that guide responsible, appropriate decision-making for security professionals.

Security framework: A structured, step-by-step model organizations follow to build and maintain their security practices (e.g. NIST, ISO 27001).

Security governance: The leadership and oversight structure that sets direction and accountability for an organization’s security efforts.

Technical skills: Practical, hands-on ability to use security tools and follow procedures effectively.

Threat: Anything with the potential to cause harm to a system, network, or data.

Threat actor: A person or group responsible for carrying out (or attempting) a cyberattack.

VPN (Virtual Private Network): A tool that encrypts your internet connection and masks your location, often used to browse more securely on public Wi-Fi.

PAKISTAN-SPECIFIC TERMS

CNIC: Computerized National Identity Card, Pakistan’s national ID, often requested (legitimately or fraudulently) during identity verification.

NCCIA: National Cyber Crime Investigation Agency, the current authority responsible for investigating and responding to cybercrime complaints in Pakistan. See our full guide to NCCIA.

PECA: Prevention of Electronic Crimes Act, 2016, Pakistan’s primary legislation covering cybercrime and electronic offenses.

PISF: Pakistan Information Security Framework, a national framework introduced by PKCERT aimed at strengthening cybersecurity practices across public and private institutions.

PKCERT: Pakistan’s National Cyber Emergency Response Team, responsible for national-level threat monitoring, advisories, and coordination.

PTA: Pakistan Telecommunication Authority, regulates telecom services and frequently issues public advisories on scams and fraud.