Glossary
Security awareness terms, in plain language
The same terms used throughout our training modules, defined simply so anyone on your team can look one up.
- Phishing
- A fraudulent email, message, or website designed to trick someone into revealing credentials, payment details, or other sensitive information.
- Smishing
- Phishing delivered by SMS text message, often impersonating a bank, delivery company, or government agency.
- Vishing
- Phishing delivered by phone call, often using a spoofed caller ID or an urgent, scripted pretext.
- Quishing
- Phishing delivered through a malicious QR code, which should be treated with the same caution as an unknown link.
- Business Email Compromise (BEC)
- An attack where a criminal impersonates an executive, vendor, or colleague by email to redirect a payment or extract sensitive data.
- Social engineering
- Manipulating a person, rather than a system, into breaking normal security procedure, often using urgency, authority, or familiarity.
- Pretexting
- Inventing a believable scenario or false identity to gain someone's trust and extract information or access.
- Multi-factor authentication (MFA)
- A login method that requires a second proof of identity beyond a password, such as a one-time code or push approval.
- MFA fatigue (push bombing)
- An attack that sends repeated MFA push notifications hoping a tired or distracted user will approve one by mistake.
- Deepfake
- AI-generated synthetic audio or video designed to impersonate a real person's voice or face, increasingly used in fraud calls.
- SIM swap
- A fraud where a criminal convinces a mobile carrier to move a victim's phone number to a new SIM, intercepting calls and OTP codes.
- BVN
- Bank Verification Number, a unique identifier for Nigerian bank customers. It should never be shared with anyone who contacts you asking for it.
- NIN
- National Identification Number, Nigeria's unique personal identifier. Treat requests for it from unsolicited callers as a red flag.
- One-time password (OTP)
- A single-use code sent to verify identity or authorize a transaction. A real bank or platform will never ask you to read an OTP back to them.
- Ransomware
- Malicious software that encrypts files and demands payment for their release, often spread through phishing or exposed remote access.
- Whaling
- A phishing or social-engineering attack specifically targeting senior executives, who have greater authority and access.
- Insider threat
- Risk of harm from someone with legitimate access, whether through malicious intent, negligence, or a compromised account.
- Data subject
- Under data protection law, the individual whose personal data is being collected or processed.
- Data controller
- The organization that decides why and how personal data is processed, and carries the primary compliance responsibility.
- Protected Health Information (PHI)
- Individually identifiable health information protected under HIPAA, covering medical, billing, and related records.
- Personally Identifiable Information (PII)
- Any information that can identify a specific individual, such as a name combined with a phone number or ID.
- Security awareness training
- Ongoing education that teaches staff to recognize and respond to cybersecurity threats as part of daily work, rather than a one-time event.
- Micro-learning
- Short, focused training delivered in a few minutes at a time, shown to improve retention over long annual sessions.
- Phishing simulation
- A safe, controlled test email, text, or call that mimics a real attack to measure and improve staff readiness, with immediate teachable feedback.
- Callback verification
- Confirming an unusual request, such as a payment or bank-detail change, by calling a known, previously verified number rather than replying to the message.