MFA / 2FA
Stops many account takeovers, even when passwords leak.
To enhanceCommon cybersecurity, compliance, cloud, AI, networking, email, software and procurement acronyms explained for UK SMEs.
Version 1.0 | Reviewed 5 August 2026 | Copyright (c) 2026 Aldermere Systems. All rights reserved.
This is a practical reference, not legal advice, certification, audit work, or a managed security service. It is designed to help non-technical business owners understand what suppliers, insurers, tenders and software platforms are talking about.
You do not need to become a cybersecurity expert. These are the terms most likely to appear in ordinary SME conversations.
Stops many account takeovers, even when passwords leak.
Practical UK baseline for basic business cybersecurity.
Applies when handling personal data.
UK regulator for data protection and information rights.
Helps reduce fake email pretending to come from your domain.
Helps prove outgoing email has not been tampered with.
Tells mail systems what to do when email authentication fails.
Helps recover files and systems after mistakes, failure, or attack.
Helps businesses understand what their IT provider actually does.
Important when using AI tools, integrations, and connected software safely.
Use this as a fast lookup when someone sends you an acronym and assumes everybody knows what it means.
Care labels are a simple guide only: Essential, Useful, Advanced, or Sector-specific.
Business As Usual
Normal day-to-day business operations.
Business Continuity Plan
A plan for keeping the business running during disruption.
Bring Your Own Device
Staff using their own phones, tablets or laptops for work.
Customer Relationship Management
Software used to manage customers, leads, sales and communication history.
Disaster Recovery
How a business restores systems and data after a major failure.
Enterprise Resource Planning
Software that manages major business processes like stock, accounts and operations.
Human Resources
The people, payroll, hiring and staff management side of a business.
Key Performance Indicator
A number used to measure whether something is working well.
Managed Service Provider
An outsourced IT company that looks after computers, networks, updates and support.
Managed Security Service Provider
Like an MSP, but focused on cybersecurity monitoring and protection.
Original Equipment Manufacturer
A company that makes original parts, devices or software used in another company's product.
Point of Sale
A till, checkout or payment system.
Return on Investment
Whether the money spent on a product or service gives enough value back.
Recovery Point Objective
How much data loss is acceptable after a failure.
Recovery Time Objective
How quickly a system needs to be restored after an outage.
Service Level Agreement
A promise about support response times, uptime or service quality.
Small and Medium-sized Business
Another way of saying SME, often used in software and IT sales.
Small and Medium-sized Enterprise
A small or medium-sized business. Usually not a huge corporation, but big enough to need proper systems and security.
Standard Operating Procedure
A written step-by-step process for doing a task properly.
Total Cost of Ownership
The full cost of something over time, including setup, support, licences and maintenance.
Two-Factor Authentication
A type of MFA using two login checks.
Advanced Persistent Threat
A skilled attacker or group that stays hidden and targets organisations over time.
Antivirus
Software that detects and blocks known malware.
Not an acronym
Copies of important files and systems that can be restored after mistakes, failure, theft, or attack.
Cloud Access Security Broker
Security controls placed between users and cloud services.
Common Vulnerabilities and Exposures
A public reference number for a known software security weakness.
Common Vulnerability Scoring System
A score showing how serious a vulnerability is.
Data Loss Prevention
Tools and rules that stop sensitive data being leaked or sent to the wrong place.
Endpoint Detection and Response
Security software that watches laptops, desktops and servers for suspicious activity.
Firewall
A barrier that controls what network traffic is allowed in or out.
Identity and Access Management
Controlling who can log in, what they can access and what they can change.
Intrusion Detection System
A system that spots possible attacks.
Indicator of Compromise
A clue that a system may have been attacked, such as a bad IP address or suspicious file.
Intrusion Prevention System
A system that can block possible attacks.
Managed Detection and Response
A managed service where security experts monitor and respond to threats for you.
Multi-Factor Authentication
Logging in with more than just a password, such as a code, app prompt or security key.
Next-Generation Firewall
A more advanced firewall with deeper inspection and security features.
Privileged Access Management
Extra control over powerful admin accounts.
Role-Based Access Control
Giving people access based on their job role.
Security Information and Event Management
A system that collects security logs and helps spot suspicious behaviour.
Security Orchestration, Automation and Response
Tools that automate parts of security investigation and response.
Security Operations Centre
A team or service that monitors security alerts and incidents.
Single Sign-On
One login used to access multiple systems.
Tactics, Techniques and Procedures
The methods attackers use.
Unified Threat Management
A security appliance or service combining several protections in one place.
Virtual Private Network
A secure connection used to access systems remotely or protect network traffic.
Web Application Firewall
Protection for websites and web apps against common attacks.
Extended Detection and Response
Security monitoring across multiple areas, such as devices, email, cloud and network.
Zero-day Vulnerability
A security flaw that is being used before a fix is available.
Business Email Compromise
A scam where criminals use email to trick staff into paying money or sharing information.
Chief Executive Officer Fraud
A scam where an attacker pretends to be the boss and asks for urgent payment or action.
Cross-Site Request Forgery
An attack that tricks a logged-in user's browser into performing an unwanted action.
Distributed Denial of Service
A larger DoS attack using many devices at once.
Denial of Service
An attack that tries to make a website or system unavailable.
Man-in-the-Middle
An attack where someone secretly intercepts communication between two parties.
MITRE Adversarial Tactics, Techniques and Common Knowledge
A knowledge base describing how cyber attackers operate.
Open Source Intelligence
Information gathered from public sources such as websites, social media, records and search engines.
Remote Access Trojan
Malware that lets an attacker control a device remotely.
Remote Code Execution
A serious flaw that lets an attacker run commands on a system from elsewhere.
SQL Injection
An attack where database commands are inserted into website forms or requests.
Cross-Site Scripting
A website attack where malicious script runs in a user's browser.
Cyber Assessment Framework
A framework used to assess cyber resilience, especially in regulated or essential services.
Cyber Essentials
A UK government-backed cybersecurity certification covering basic protective controls.
Cyber Essentials Plus
Cyber Essentials with independent technical testing.
Cyber Security and Resilience Bill
UK legislation intended to update and strengthen cyber resilience rules.
Data Protection Act
UK data protection legislation that works alongside UK GDPR.
Data Protection Impact Assessment
A risk assessment for projects that may affect people's privacy.
Data Protection Officer
A person responsible for advising on and monitoring data protection compliance.
Data Subject Access Request
Another name for a Subject Access Request.
Department for Science, Innovation and Technology
UK government department responsible for areas including digital, technology and cyber policy.
Digital Service Provider
A provider of digital services such as cloud, search or online marketplaces.
Freedom of Information
Rules allowing access to certain public authority information.
General Data Protection Regulation
Data protection law covering how personal data is handled.
Information Assurance for Small and Medium Enterprises
Organisation involved in Cyber Essentials delivery and SME-focused assurance.
Information Commissioner's Office
The UK regulator for data protection and information rights.
Information Security Management System
The policies, processes and controls used to manage information security.
International Organization for Standardization
An organisation that publishes international standards.
Information Security Management Standard
A recognised standard for managing information security properly.
National Cyber Security Centre
The UK's national technical authority for cybersecurity.
Network and Information Systems
UK/EU rules focused on security and resilience for important digital and essential services.
Operator of Essential Services
An organisation providing important services such as energy, transport, water or healthcare.
Payment Card Industry Data Security Standard
Security rules for organisations that handle card payments.
Privacy and Electronic Communications Regulations
UK rules covering electronic marketing, cookies and similar communications.
Protected Health Information
Health-related personal information, mainly used in healthcare contexts.
Personally Identifiable Information
Information that can identify a person, directly or indirectly.
Procurement Policy Note
UK government procurement guidance for public sector buying.
Record of Processing Activities
A record of what personal data an organisation processes and why.
Subject Access Request
A request from an individual asking what personal data an organisation holds about them.
United Kingdom General Data Protection Regulation
The UK version of GDPR after Brexit.
Dynamic Host Configuration Protocol
The system that automatically gives devices their network settings.
Domain Name System
The system that turns website names into IP addresses.
File Transfer Protocol
An older method for moving files between systems.
HyperText Transfer Protocol
The basic protocol used by websites.
HyperText Transfer Protocol Secure
The secure version of HTTP, using encryption.
Internet Protocol
The system used to send data across networks.
Internet Protocol Address
A number that identifies a device on a network or the internet.
Local Area Network
A network inside a building or site.
Media Access Control Address
A hardware address used to identify a network device.
Network Address Translation
A method that lets many devices share one public internet address.
Quality of Service
Network settings that prioritise important traffic such as voice or video.
Remote Desktop Protocol
A way to remotely control a Windows computer.
Secure File Transfer Protocol
A secure method for transferring files.
Secure Shell
A secure way to log in to and manage remote systems.
Secure Sockets Layer
Older term still commonly used for website security certificates.
Transmission Control Protocol
A reliable method for sending data over networks.
Transport Layer Security
The modern security technology behind HTTPS.
User Datagram Protocol
A faster, less strict method for sending network data.
Virtual Local Area Network
A separated network created inside a larger network.
Voice over Internet Protocol
Phone calls carried over the internet.
Wide Area Network
A network spread across multiple locations or the internet.
Wireless Local Area Network
A Wi-Fi network.
Address Record
A DNS record pointing a domain to an IPv4 address.
IPv6 Address Record
A DNS record pointing a domain to an IPv6 address.
Content Delivery Network
A network that helps websites load faster and can add protection.
Content Management System
Website software such as WordPress, Shopify or similar platforms.
Canonical Name
A DNS alias pointing one name to another.
Call To Action
A button or message asking the visitor to do something, such as "Buy Now" or "Contact Us".
DomainKeys Identified Mail
A system that digitally signs email to prove it was not altered.
Domain-based Message Authentication, Reporting and Conformance
A policy that tells mail systems what to do if SPF or DKIM checks fail.
Mail Exchange
DNS records that tell the internet where email for a domain should go.
Search Engine Optimisation
Improving a website so search engines can understand and rank it.
Search Engine Results Page
The results page shown by a search engine.
Sender Policy Framework
A DNS record that says which servers are allowed to send email for a domain.
Text Record
A DNS record often used for verification and email security settings.
User Interface
The visible buttons, menus, screens and controls a user interacts with.
User Experience
How easy and pleasant a website, app or system is to use.
Application Programming Interface
A way for software systems to talk to each other.
Continuous Delivery or Continuous Deployment
Automatically preparing or releasing software updates.
Continuous Integration
Automatically testing code when changes are made.
Command Line Interface
A text-based way to control software using commands.
Cascading Style Sheets
The styling language used for web pages.
Comma-Separated Values
A simple spreadsheet-style text file.
Database
A structured place where information is stored.
Development and Operations
A way of working that connects software development, deployment and operations.
Development, Security and Operations
DevOps with security built into the process.
Container Platform
A tool for packaging software so it runs consistently.
Git Version Control
A system for tracking changes in code and files.
Git Hosting Platform
A platform used to store, review and collaborate on code.
Graphical User Interface
A visual interface with windows, buttons and menus.
HyperText Markup Language
The structure language used for web pages.
Infrastructure as a Service
Cloud servers, storage and networking rented instead of owned.
Integrated Development Environment
Software used to write, test and manage code.
JavaScript
A programming language commonly used for websites and apps.
JavaScript Object Notation
A common data format used by software and APIs.
Container Orchestration Platform
A system for managing lots of containers.
Minimum Viable Product
The simplest working version of a product that proves the idea.
Platform as a Service
A cloud platform for building or running applications.
Software as a Service
Software used online, usually by subscription.
Software Development Kit
Tools and code that help developers build with a platform.
Structured Query Language
A language used to work with databases.
Virtual Machine
A software-based computer running inside another computer.
Virtual Private Server
A rented virtual server, usually hosted in a data centre.
Extensible Markup Language
An older structured data format still used by many systems.
YAML Ain't Markup Language
A human-readable configuration file format.
AI Agent
An AI system that can take steps toward a task, not just answer one question.
Artificial Intelligence
Software that can perform tasks normally associated with human intelligence.
Application Programming Interface Key
A secret code that lets software access an online service.
Bring Your Own Key
A setup where the user supplies their own API key instead of the provider holding it.
Generative Pre-trained Transformer
A type of AI language model used for text, chat and content generation.
Graphics Processing Unit
A chip used for graphics and heavy AI processing.
AI Hallucination
When AI produces something that sounds confident but is wrong or unsupported.
Large Language Model
An AI model trained to understand and generate text.
Machine Learning
A type of AI where systems learn patterns from data.
Natural Language Processing
Technology that helps computers understand human language.
Neural Processing Unit
A chip designed to run AI tasks efficiently.
Optical Character Recognition
Technology that reads text from images, scans or photos.
AI Instruction
The instruction or question given to an AI system.
Retrieval-Augmented Generation
AI that looks up information from documents or databases before answering.
Speech-to-Text
Technology that turns speech into written text.
Text-to-Speech
Technology that turns written text into spoken audio.
Bring Your Own Device
Staff using personal devices for work.
Corporate-Owned, Personally Enabled
A company-owned device that staff can also use personally.
Central Processing Unit
The main processor in a computer.
Choose Your Own Device
Staff choosing from approved company devices.
Hard Disk Drive
Older-style spinning disk storage.
High-Definition Multimedia Interface
A connection for video and audio to screens.
Mobile Device Management
Software used to manage company phones, tablets and laptops.
Near Field Communication
Short-range wireless communication, often used for contactless payments.
Quick Response Code
A square barcode scanned by a phone.
Random Access Memory
Short-term working memory used while a device is running.
Solid State Drive
Fast storage used in modern computers.
Unified Endpoint Management
Managing many types of devices from one system.
Universal Serial Bus
A common connection for devices, charging and data.
Universal Serial Bus Type-C
A modern reversible USB connector.
Anti-Money Laundering
Rules and checks designed to prevent criminal money movement.
Electronic Point of Sale
A digital till and sales system.
His Majesty's Revenue and Customs
The UK tax authority.
Know Your Customer
Checks used to confirm a customer's identity.
Making Tax Digital
UK tax rules requiring digital records and submissions for some businesses.
Payment Card Industry
The card payment security ecosystem.
Payment Card Industry Data Security Standard
Security rules for handling payment card data.
Point of Sale
The system where a customer pays.
Payment Service Provider
A company that processes payments, such as card or online payments.
Value Added Tax
A tax added to many goods and services.
Short cards for the terms most likely to matter in SME email, supplier, insurance and compliance conversations.
Multi-Factor Authentication / Two-Factor Authentication
MFA means logging in with more than just a password. For example, you enter your password and then approve the login using an app, code, fingerprint or security key.
Cyber Essentials
Cyber Essentials is a UK cybersecurity certification that checks whether your business has basic protections in place.
Cyber Essentials Plus
Cyber Essentials Plus is the stronger version of Cyber Essentials because it includes independent technical testing.
General Data Protection Regulation / United Kingdom GDPR
UK GDPR is the law covering how organisations collect, store, use, share and protect personal information.
Information Commissioner's Office
The ICO is the UK regulator for data protection and information rights.
Data Protection Impact Assessment
A DPIA is a risk assessment for privacy. It helps you think through whether a project could create risks for people's personal data.
Subject Access Request / Data Subject Access Request
A SAR is when someone asks to see what personal data your business holds about them.
Sender Policy Framework
SPF is a domain setting that says which mail servers are allowed to send email for your business.
DomainKeys Identified Mail
DKIM adds a digital signature to outgoing email so receiving systems can check that the message has not been tampered with.
Domain-based Message Authentication, Reporting and Conformance
DMARC tells receiving mail systems what to do when an email fails SPF or DKIM checks.
Endpoint Detection and Response
EDR watches devices for suspicious activity and helps detect attacks that basic antivirus may miss.
Virtual Private Network
A VPN creates a secure connection between a device and another network or service.
Business Continuity Plan
A BCP explains how the business keeps going during disruption.
Disaster Recovery
Disaster recovery is how you restore systems, files and data after a serious failure.
Recovery Time Objective
RTO means how quickly you need a system back after it fails.
Recovery Point Objective
RPO means how much data you can afford to lose.
Managed Service Provider
An MSP is an external company that manages IT support, devices, updates, users, networks and systems.
Managed Security Service Provider
An MSSP is a provider focused specifically on cybersecurity services.
Application Programming Interface Key
An API key is a secret code that lets one piece of software access another service.
Bring Your Own Key
BYOK means the user supplies their own API key instead of the software provider holding or reselling access.
Open Source Intelligence
OSINT means information gathered from public sources such as websites, company records, search engines, social media and public documents.
Security Information and Event Management
A SIEM collects logs from systems and helps identify suspicious activity.
Security Operations Centre
A SOC is a team that monitors security alerts and responds to cyber incidents.
Network and Information Systems
NIS rules focus on the cyber resilience of important services and digital infrastructure.
Cyber Security and Resilience Bill
This is UK legislation intended to update cyber resilience rules and strengthen protection for important services.
Good cybersecurity is not about scaring people. It is about putting sensible protections in place before something goes wrong.
This free giveaway may be downloaded and shared as an unmodified Aldermere Systems resource. It may not be resold, rebranded, or presented as another organisation's work.
Checked against public guidance from NCSC, ICO, IASME and GOV.UK at time of publication. Guidance and scheme wording can change, so use current official sources for formal decisions.
Copyright (c) 2026 Aldermere Systems. All rights reserved.