Resources / Glossary

The jargon, translated

Nobody should need a dictionary to understand a quote. Here's what the terms in IT proposals, insurance forms and security questionnaires actually mean - and why each one matters to your business.

A

Antivirus

AVSecurity

Software that looks for known malicious files on a device and removes or quarantines them.

Still useful, but on its own it only catches threats someone has already catalogued. Most organisations have moved on to endpoint detection and response.

B

Backup

Backup & recovery

A separate copy of your data, held somewhere it can't be changed or deleted by whatever went wrong with the original.

A backup you've never restored from is a hope, not a plan. Ask when the last test restore happened and how long it took.

Break-fix

Support & service

A support arrangement where you pay per incident or per hour, only when something goes wrong.

Predictable for the provider, unpredictable for you. There's no commercial reason for anyone to prevent the next problem.

Business continuity

BCBackup & recovery

The plan for keeping the organisation trading while something is broken - not just the technical recovery.

It covers the people and process bits: who tells customers, how orders get taken, what happens if the office is unavailable.

C

Co-managed IT

Support & service

An arrangement where an internal IT person or team keeps ownership, and an external provider covers specific gaps.

Useful when your IT manager is stretched rather than absent. Worth agreeing in writing who owns what before you start.

Conditional access

Security

Rules in Microsoft 365 that decide whether a sign-in is allowed, based on who's asking, from where, and on what device.

It's how you block sign-ins from countries you don't operate in, or require a managed device for admin accounts, without making daily life harder.

Copilot

Microsoft 365

Microsoft's AI assistant across Microsoft 365 apps, working from the data each user can already reach.

It inherits your permissions. If access is loose today, Copilot will surface that faster than any audit.

Cyber Essentials

Compliance

A UK government-backed scheme covering five basic technical controls. Cyber Essentials Plus adds an independent technical check.

Increasingly asked for in tenders, insurance forms and public sector contracts. The controls are sensible regardless of the certificate.

D

Disaster recovery

DRBackup & recovery

The technical side of getting systems and data back after a serious incident.

Only means something when it's paired with agreed recovery targets and a test that proves them.

DMARC

Security

An email setting that tells other mail servers what to do with messages that claim to come from your domain but fail checks.

Alongside SPF and DKIM, it's what stops someone spoofing your finance team's address to your customers.

DSPT

Data Security and Protection ToolkitCompliance

An annual self-assessment for organisations handling NHS patient data.

If you work with the NHS in any capacity, someone will eventually ask whether yours is up to date.

E

EDR

Endpoint detection and responseSecurity

Software that watches for suspicious behaviour on a device, rather than only known bad files, and can isolate the device if needed.

It catches things antivirus misses, but it produces alerts. Check whether anyone is actually watching them.

Endpoint

Infrastructure

Any device a person works on - laptop, desktop, phone, tablet.

Most incidents start at an endpoint, which is why so much security spend points there.

Entra ID

formerly Azure ADMicrosoft 365

Microsoft's identity service - the list of who your people are and what they're allowed to reach.

It's the front door to almost everything. Tidy accounts and sensible sign-in rules here do more for security than most tools.

G

GDPR

Compliance

Data protection law covering how you collect, store and use personal information.

Mostly a process and governance question. Technology supports it; it doesn't deliver it on its own.

H

Hybrid

Infrastructure

A setup where some systems run in your own building and some run in the cloud.

Very common, and perfectly workable. It just means two things to keep patched, backed up and monitored instead of one.

I

Immutable backup

Backup & recovery

A backup copy that can't be edited or deleted for a set period, even by an administrator.

It's the answer to ransomware that goes looking for your backups first.

Intune

Microsoft 365

Microsoft's tool for setting up and managing company devices - settings, updates, apps and the ability to wipe a lost laptop.

It's what makes a new starter's laptop work on day one, and a leaver's laptop harmless on day two.

ISO 27001

Compliance

An international standard for running an information security management system, audited by an external body.

A bigger commitment than Cyber Essentials, and usually driven by what your customers require of you.

L

Licence optimisation

Microsoft 365

Reviewing which Microsoft licences you pay for, who holds them and whether the plan matches the use.

Most organisations pay for a fraction of what they use, and for a few people who left.

M

Managed detection and response

MDR, SOCSecurity

A team, usually external, watching security alerts around the clock and acting on the ones that matter.

Tools generate alerts; this is the bit that decides which ones deserve a phone call at 2am.

Managed IT support

Support & service

An ongoing arrangement covering help desk, device management, monitoring and maintenance for a regular fee.

The value is in the work you never see. Ask what's proactive, not just how fast tickets get answered.

MFA

Multi-factor authentication, 2FASecurity

A second proof of identity on top of a password - usually an app prompt or code.

The single most effective thing most organisations can do. Worth checking it's on for every account, including admin and shared ones.

O

On-premise

on-premInfrastructure

Servers and systems that physically live in your building.

Not automatically wrong. The question is whether the hardware is still supported and what happens if the room floods.

P

Patching

Security

Applying the updates that software vendors release to fix bugs and close security holes.

Unglamorous and consistently one of the most effective controls. Ask for evidence of coverage, not just intent.

Phishing

Security

A message designed to trick someone into handing over credentials, approving a payment or installing something.

It targets people, not systems, which is why training and a clear reporting route matter as much as filtering.

Privileged access

admin rightsSecurity

Accounts with the ability to change settings, install software or reach everyone's data.

The fewer of these, the smaller the damage when one is compromised. Everyday work shouldn't need them.

R

RPO

Recovery point objectiveBackup & recovery

How much data you can afford to lose, measured in time.

An hourly backup means up to an hour of re-keying. Agree the number before an incident, not during one.

RTO

Recovery time objectiveBackup & recovery

How long you can afford to be without a system before it really hurts.

This is the number that decides what recovery approach you actually need - and what it costs.

S

Shadow IT

Support & service

Tools and subscriptions teams buy themselves, outside anyone's view.

Usually a sign the approved tools aren't doing the job. Worth understanding before switching anything off.

SharePoint

Microsoft 365

Microsoft's document storage for teams and departments, sitting behind Teams files and company intranets.

Most sprawl and permission confusion starts here. A structure decided once is worth more than any amount of tidying later.

SLA

Service level agreementSupport & service

The written commitment for how quickly a provider will respond to and update you on issues, by priority.

Read what's promised: response time isn't resolution time, and business hours vary. Ask how performance is reported.

T

Ticket priority

Support & service

How urgent an issue is judged to be, which sets the response time it gets.

Agree what counts as critical up front. "Whole site down" and "one person's printer" shouldn't sit in the same queue.

V

Virtualisation

Infrastructure

Running several separate servers as software on one physical machine.

Standard practice for years. It matters to you mainly because it changes how backup and recovery are handled.

Vulnerability assessment

Security

A scan that lists known weaknesses across your devices, software and services.

The output is a list, not a plan. The useful version comes with an order of priority and an owner for each item.

Z

Zero trust

Security

A design principle: verify every request rather than trusting anything simply because it's inside the network.

A direction of travel, not a product. In practice it usually starts with identity, device health and access reviews.

Seen a term in a quote that isn't here?

Send it over. We'd rather explain it plainly than leave you guessing what you're being asked to buy.