cybee

Menu

Start freeDeutsch

Security terms.
Plain language.

A client’s questionnaire. An app asking for access. A warning on your Mac. Find out what the words mean, with examples from everyday work.

Find a term
The words change.
The work is familiar.
Endpoint
The Mac you work on
Permission
What a tool may do
Evidence
A fact you can show

A

AI agent

AI & connections

An AI application that can use tools to carry out tasks, rather than only return text. What it can do depends on the tools and access it has.

At workA coding assistant edits a project file and runs a test.

B

Backup

Devices & software

A separate copy of information that can be used to recover after loss or damage. A backup is only useful if you can restore what you need.

At workYou restore a client’s project after its working folder is accidentally deleted.

C

Credential

Accounts & access

Information used to prove an identity or obtain access, such as a password, token or certificate. Different credentials can grant different levels of access.

At workA contractor’s personal login and a shared automation key are separate credentials.

CVE

Devices & software

A common identifier for a publicly disclosed security vulnerability. The identifier helps you find the same issue across vendor notices and security tools.

At workAn update notice lists a CVE so you can check which software versions are affected.

Cybersecurity

Risks & daily habits

Protecting digital systems, information and the work that depends on them. It includes devices, accounts and people’s decisions, as well as responding when something goes wrong.

At workKeeping project files safe means protecting both the laptop and the account that shares them.

D

E

EDR

Devices & software

Endpoint detection and response: software that observes activity on computers to help identify and respond to suspicious behaviour. Its detection and response abilities vary by product.

At workA security tool flags an unusual process and gives you a way to investigate it.

Endpoint

Devices & software

A device at the edge of a network where someone works or a service runs. In a small team’s security questionnaire, it often means the work computers.

At workThe Mac a designer uses for client work is an endpoint.

F

FileVault

Devices & software

The macOS feature that protects access to encrypted data on the startup disk. Access depends on an authorised user’s credentials or a recovery method.

At workA departing teammate hands over the agreed recovery information before returning the Mac.

H

Hardening

Devices & software

Changing settings to reduce unnecessary access and make a system harder to misuse. It can include disabling unused services and tightening security settings.

At workYou disable sharing you do not use and require a password after the screen locks.

I

Incident

Risks & daily habits

An event that compromises, or threatens to compromise, the security of systems or information. An alert is a reason to investigate; it is not automatically a confirmed incident.

At workSomeone uses a stolen work account to download client files.

Incident response

Risks & daily habits

The organised steps taken to understand, contain and recover from a security incident. A plan should make clear who acts and who needs to be told.

At workYou pause an affected account, preserve the logs and contact the person responsible.

K

Key rotation

Accounts & access

Replacing an access key and retiring the old one. The applications using it must be updated too; creating a new key alone may leave the old key usable.

At workAfter a contractor leaves, you replace their automation key and revoke the old one.

L

Log

Proof & requirements

A record of events reported by a system. Logs can help reconstruct what happened, but they only contain the events that system captured and retained.

At workAn activity log records when a tool tried to run a command.

M

Malware

Risks & daily habits

Software designed to harm systems, steal information or perform other unwanted actions. It may arrive disguised as a useful application or document.

At workA fake download installs a program that steals saved account information.

MCP

AI & connections

Model Context Protocol: a shared way for AI applications to connect to tools and information. The connection itself does not prove a tool was used or that the connection is safe.

At workA coding assistant connects to a tool that can search your project documentation.

MCP server

AI & connections

A program that makes tools, information or prompts available to an AI application through MCP. It can run on your computer or at a remote address.

At workTwo assistants are configured to use the same server for a project’s files.

MFA

Accounts & access

Multi-factor authentication: signing in with more than one type of proof, such as a password and a security key. Two passwords are still the same type of factor.

At workA stolen password alone is not enough to sign in when a second factor is required.

N

Notarization

Devices & software

Apple’s automated check of submitted Mac software for known malicious content and certain signing issues. It is not an endorsement of every product claim or an independent security audit.

At workA notarized app can still need permissions and careful review before your team uses it.

O

OAuth

Accounts & access

A standard for granting an application limited access to a service without handing it your account password. The approved permissions still need to be reviewed.

At workYou allow a scheduling app to read your calendar, then later remove that access.

Offboarding

Accounts & access

The steps taken when someone leaves a company or project. They include removing relevant access, recovering devices and transferring ownership of shared work.

At workA freelancer finishes; you review their account, shared folders and automation keys.

P

Passkey

Accounts & access

A sign-in credential that uses a cryptographic key pair instead of a shared password. It is bound to the intended service, which helps resist phishing.

At workYou approve sign-in with your device’s fingerprint check instead of typing a password.

Password manager

Accounts & access

A tool that stores and helps create passwords so each account can have its own strong password. Protect the manager’s own account carefully.

At workYour team shares an approved service login through a vault instead of a chat message.

Patch

Devices & software

A software change that fixes a problem, sometimes a security weakness. Not every update is a security patch, and installing an update is different from changing settings.

At workA browser update fixes a vulnerability in the version installed on your Mac.

Phishing

Risks & daily habits

A deceptive message or website designed to make someone reveal information or take a harmful action. It often borrows the name of a familiar person or service.

At workAn email posing as a client asks you to sign in to a fake document-sharing page.

Policy

Proof & requirements

A rule that states how your organisation expects something to be handled. A written policy describes the requirement; separate evidence shows whether it was followed.

At workYour policy requires a screen lock; a device check shows whether that setting is enabled.

Prompt injection

AI & connections

Instructions in content that try to redirect an AI application away from its intended task. The risk grows when the application can act on tools or sensitive information.

At workA webpage tells an assistant to ignore its task and send project data elsewhere.

Q

Quarantine

Devices & software

Separating a suspicious file or item so it is less able to cause harm while it is reviewed. What quarantine prevents depends on the security tool and the item.

At workA suspicious download is moved out of normal use while someone checks it.

R

Ransomware

Risks & daily habits

Malicious software used to extort payment, often by locking or encrypting files. An attack may also involve stolen information and threats to publish it.

At workA team cannot open its project files and receives a payment demand.

Risk

Risks & daily habits

The possibility of harm, considering both how likely an event is and how much it could affect your work. A finding matters more when valuable data or important access is involved.

At workAn unused tool with access to every client folder deserves more attention than one with no access.

S

Scope

Proof & requirements

The boundary of what a check, permission or report covers. For evidence, always ask which devices, accounts, dates and controls were included.

At workA report about three Macs does not also prove that every cloud account uses MFA.

Security alert

Risks & daily habits

A notification that something may need investigation. It can point to a real problem, expected activity or an error in detection; the alert needs context.

At workA script running on a Mac triggers an alert; you check who started it and why.

Security control

Proof & requirements

A measure used to reduce security risk. It can be technical, such as disk encryption, or organisational, such as an agreed process for removing access.

At workA required screen lock is one control; checking that it stays enabled is another task.

Security questionnaire

Proof & requirements

A set of questions a customer, partner or insurer uses to understand your security practices. Answers should describe what you actually do and name the evidence that supports them.

At workA new client asks how work laptops are protected before signing the contract.

Security training

Risks & daily habits

Practical learning that helps people make safer decisions at work. Completion records show participation; they do not guarantee every future decision will be safe.

At workA short lesson helps a teammate recognise a suspicious request for client files.

Session

Accounts & access

A period of authenticated interaction with a service, often maintained by a cookie or token. Closing a tab may not end the account’s signed-in session.

At workYou sign out of a shared computer so the next person cannot use your open account.

Shadow AI

AI & connections

AI tools used for work without the organisation knowing enough about them or approving their use. The concern is missing visibility into data, access and responsibility.

At workA teammate tests a new assistant with client files and keeps using it after the trial.

SSO

Accounts & access

Single sign-on: using one identity service to sign in to multiple applications. It simplifies account access but does not replace MFA or careful app permissions.

At workA teammate uses their work identity to open both the project tool and the file service.

Startup item

Devices & software

An app or background task configured to run when a computer starts, a person signs in or another launch condition is met. Some are useful; others may be forgotten or unwanted.

At workA tool you stopped using still starts a background helper each time you sign in.

T

Threat

Risks & daily habits

Something that could harm your systems, information or work. A threat might exploit a weakness; risk considers how likely that is and what the consequences would be.

At workA criminal group trying stolen passwords is a threat to your work accounts.

Tool call

AI & connections

A request from an AI application to run a tool, such as reading a file or executing a command. A request, an attempt and a completed action are different stages.

At workAn assistant requests a file read; its activity record shows whether the tool completed it.

V

Vulnerability

Devices & software

A weakness that could be used to compromise a system or information. It might be a software defect, an unsafe setting or a gap in a process.

At workAn outdated application has a known flaw that a newer release fixes.

W

Simple words.
Careful definitions.

Written by cybee for people who run small teams. We use the references below to check technical meanings, then explain them in our own words. Examples are illustrative.

Reviewed 21 September 2026. A definition describes a concept, not necessarily a feature offered by cybee.

Now put it in context.

Understand a warning, review your team’s tools or prepare for a client’s questions.