This page is dedicated to the most common terminology used in cyber security.
There is an additional section added to each term, called the ‘The Core Logic‘ that describes it in a simpler more understandable method. It is described so simple that even children can learn the term!
All terminilogy has been alphabetised.
Leave me a comment on which terminology I should add next or how helpful you find this page.
List of Definitions
A
Attacker Motive
Cybersecurity frameworks use models such as MICE (Money, Ideology, Compromise, Ego) to classify motives. Typical types include insider threats (revenge or greed), state-sponsored espionage (stealing secrets), hacktivism (ideological disruption via DDoS), and financial gain (e.g., ransomware, data theft). 1
The Core Logic – Imagine describing the motivation of an attacker to a 9-year-old who spots troublemakers on the playground: “Some bullies steal lunch money (financial gain), others trash your sandcastle to show off (ego), a few do it to protest snack rules (ideology), or spy for their team (espionage).” Building stronger forts—locks for robbers, friends for braggarts—is made possible by understanding why.
Authenticity
In cybersecurity, authenticity guarantees that information, communications, or users are real and come from reliable sources, avoiding spoofing or impersonation. It is a fundamental tenet of extended security models that goes beyond the fundamental CIA trio.
Authenticity confirms the legitimacy of an information source or action originator, frequently via digital signatures, certificates, or multi-factor authentication, according to standards and frameworks such as those extending the CIA triad (also known as the CIAAN triad). 2
The Core Logic – “It’s like checking if your friend really has legitimate cards—no fake cards from a sneaky copycat!” is how you may describe authenticity to a 7-year-old who is trading cards. To ensure that deals remain fair and you know who is authentic, we employ unique stamps (digital signatures) or secret handshakes (certificates). If you’re stuck on “what if stamps copy?” simplify to unbreakable seals, exposing gaps like the necessity for reliable checkers, until the child trades with trust and fully understands.
Availibility
According to NIST and academic frameworks, availability is ensuring operational continuity and protecting against disruptions such as denial-of-service attacks, hardware failures, or ransomware through redundancies, backups, and resilience measures. It completes the CIA triad by balancing confidentiality and integrity, emphasizing that secure data must remain useable for valid objectives. 3
The Core Logic – Consider describing availability to a 9-year-old who wants her favourite game app: “It’s like your toy box is always open and full when playtime comes—no older brother hogging it or a storm knocking it over (that means no blackouts or hacks). We add extra batteries, locks solely for bad guys, and easy fixes so you can get Teddy at any time, ensuring that the fun never ends!” If you come into the question “what about floods?”, simplify to cloud backups as magic extra toy boxes—spotting gaps until the child is joyfully playing and completely understanding.
C
Confidentiality
NIST standards define confidentiality as keeping authorised constraints on information access and disclosure while protecting data at rest, in transit, or during processing from purposeful or unintentional unauthorised reads. It is a pillar of the CIA trinity (confidentiality, integrity, and availability), with peer-reviewed publications emphasising safeguards such as encryption and access management to protect private and proprietary data. 4
The Core Logic – Picture explaining confidentiality to a 10-year-old hiding a birthday surprise note: “It’s like putting your secret message in a locked diary—only you have the key, so nosy siblings can’t peek and ruin the fun (that’s keeping it private). If someone sneaks a copy or steals it, the surprise is spoiled; locks, passwords, and codes (encryption) stop that, making sure only the right eyes see it.” Gaps show up if you forget “what if the key gets lost?”—then add backups with new locks, simplifying until the kid nods and gets it fully.
Cyber Security Attack
An intentional, malevolent attempt by threat actors to compromise, disrupt, harm, or obtain unauthorised access to systems, networks, data, or applications is known as a cybersecurity attack.
Attacks are acts that take advantage of vulnerabilities using vectors like malware, phishing, or denial-of-service in order to steal data, harm people, or extort them; these include ransomware, DDoS, SQL injection, and botnets and more. 5
The Core Logic – “It’s like a playground bully tricking you into giving your secret clubhouse key (phishing), then messing up your toys inside (malware) or locking everyone out (DDoS) to steal your points or crash the fun,” said to a 10-year-old protecting her video game account. They are prevented by strong locks, passwords, and buddy checks, maintaining the security and fairness of your games.”
I
Information Security
According to NIST guidelines and academic papers, information security is the process of protecting data and systems from attacks through risk management, which includes technical, organisational, and human elements. The ISO/IEC 27000 standard emphasises confidentiality, integrity, and availability, which might often include authenticity and non-repudiation. A philosophical analysis suggests the “Appropriate Access” approach, in which security entails providing only legitimate access to information, bridging technological and socio-ethical concerns. 6
The Core Logic – Imagine explaining information security to a curious 8-year-old guarding her sticker collection: “Your stickers are special secrets—security means locking the box so only you and Mom can peek (that’s private, or confidential), keeping them from getting torn or swapped (that’s whole and true, or integrity), and making sure you can grab them anytime you want to trade (that’s ready when needed, or availability). Bad guys like sneaky cousins might try to steal or mess them up, so we use alarms, strong locks, and rules to stop them!”
Integrity
Peer-reviewed and standards-based sources, such as NIST and academic analyses, describe integrity as preserving information from unauthorised change, ensuring its trustworthiness, accuracy, and non-repudiation, and allowing for authorised adjustments. It combats dangers like unauthorised alterations or deletions by using controls like hashing, digital signatures, and checksums to ensure data consistency. 3
The Core Logic – Imagine explaining a 7-year-old about integrity while baking cookies: “Your recipe calls for 2 cups flour—integrity ensures that it is exactly that, with no sneaky brother adding salt to ruin the batch.” We use a scale or taste-test proof (such as hashes) to ensure that the cookies are always excellent and delicious, so they stay faithful to the recipe.” If the child is concerned about spills, simplify: erase authorised messes but report them—revealing gaps such as missing backups, until the story strikes crystal obvious.
N
Non-Repudiation
In cybersecurity, non-repudiation guarantees that a person cannot deny having carried out a particular operation, sent a message, or approved a transaction, offering cryptographic proof of origin and integrity.
By promoting integrity and accountability, which are essential for legal and forensic purposes in e-commerce, emails, and secure transfers, it enhances the CIA triad and authenticity. 7
The Core Logic – “You sign a deal with your magic marker stamp—no backing out later saying ‘I didn’t trade that Charizard!’” was spoken to an 8-year-old who was trading Pokémon cards. There are no lies or crafty take-backs because the stamp, like a video of the trade, verifies you did it.” If you’re unsure about “what if stamp are fakes?” reduce it to unbreakable parent-checked ink and identify any holes, such as the need for a witnesses, until the child confidently closes deals and takes ownership of the idea.
T
TTP’s (Tactics, Techniques & Procedures)
In cybersecurity, TTPs, or tactics, techniques, and procedures, provide a framework for characterising how adversaries plan and execute attacks, allowing defenders to effectively model and counter threats.
TTPs are divided into three categories in frameworks such as MITRE ATT&CK and NIST: tactics (the “why” or high-level goals, like initial access or lateral movement), techniques (the “how” or general methods, like phishing or credential dumping), and procedures (the particular “steps” or tools/scripts used, like a custom PowerShell script for execution). With tactics remaining fixed, as methods and procedures evolve, this behavioural model aids in tracking threat actors beyond signs of compromise. 8
The Core Logic – Consider describing TTPs to a 10-year-old who is organising a surprise party prank: “Tactics are your big goal—like sneaking into the kitchen (why).” Techniques are your tricks, like making a joke to divert Mom (how). Procedures are precise actions, such as tiptoeing to the left, quickly grabbing sweets, and whispering to pals.

Leave a Reply