Glossary
The vocabulary of data security & AI governance.
70+ definitions across DSI, DLP, compliance, insider risk, and more — written for security teams and business leaders alike.
AI-Native Security
AI-native security uses machine learning at its core to detect threats through behavior and context—go beyond rules and improve accuracy in modern environments.
Alert Fatigue in Cybersecurity
Alert fatigue in cybersecurity explained. Learn why excess low-quality alerts overwhelm teams and how context-driven detection improves response.
Audit Readiness
Audit readiness is the operational state of having controls in place and evidence continuously generated so that any audit can be satisfied without a last-minute scramble. Learn what it requires and how to build it.
Audit Trail
An audit trail is an immutable, timestamped record of system and user activity that enables accountability, forensic investigation, and regulatory compliance. Learn how it works and what makes one defensible.
Automated Data Discovery
Automated data discovery continuously finds sensitive data across every environment — no manual scans, no agents, no gaps between what you know and what exists.
Behavioral Analytics in Security
Behavioral analytics in security explained: detect insider threats and anomalies using identity baselines, sequence detection, and data context. Learn how it works.
Blast Radius in Cybersecurity
Blast radius in cybersecurity explained: learn how to measure incident impact, track data spread, and reduce exposure with lineage and least privilege controls.
Breach Notification
Breach notification is the legal obligation to inform regulators and affected individuals when a personal data breach occurs. Learn the 72-hour GDPR rule, DPDP universal notification, and what timely scope determination requires.
CCPA
CCPA gives California residents rights over their personal data. Learn who must comply, what consumer rights require operationally, and how it differs from GDPR.
CNAPP
CNAPP unifies cloud security tools like CSPM, CWPP, and CIEM into one platform. Learn what it covers, how it works, and when you need it.
CSPM
CSPM (Cloud Security Posture Management) continuously monitors cloud infrastructure configurations for misconfigurations, policy violations, and compliance drift. Learn how it works, what it detects, and how it differs from DSPM.
Compliance Automation
Compliance automation replaces manual evidence collection and periodic control checks with continuous monitoring, automated framework mapping, and real-time remediation. Learn how it works and what it requires.
Continuous Security Monitoring
Continuous security monitoring is the ongoing, automated observation of systems, data, and controls to detect threats, misconfigurations, and compliance drift in real time. Learn how it works and why it differs from periodic monitoring.
DPDP
DPDP governs personal data of Indian citizens worldwide. Learn how it differs from GDPR, what consent and breach rules require, and the penalties for non-compliance.
DSAR
A DSAR (Data Subject Access Request) is a formal request by an individual to access, correct, or delete personal data held about them. Learn GDPR requirements, response timelines, and what fulfilment operationally requires.
Data Breach
Data breach explained with causes, costs, and response strategies. Learn how to detect incidents faster, limit impact, and meet compliance requirements.
Data Classification
Data classification labels drive every security decision downstream. Why accuracy here determines whether your entire security stack works.
Data Detection and Response
Data Detection and Response (DDR) identifies active data threats, analyzes behavior patterns, and triggers fast containment to prevent breaches. Learn how DDR works.
Data Discovery
Data discovery locates sensitive data across cloud, SaaS, and on-prem before you can classify, govern, or protect it. Here's what full coverage requires.
Data Exfiltration
Data exfiltration explained: how sensitive data leaves systems, why tools miss it, and how to detect risky behavior patterns before loss occurs.
Data Governance
Data governance sets the policies that data security enforces. Without it, access controls and DLP have nothing meaningful to act on.
Data Inventory
A data inventory documents what data you hold, where it sits, and what regulations apply. Learn why manual maintenance fails and what compliance actually requires.
Data Lineage
Data lineage tracks every movement, transformation, and access event across a dataset's life. See why security lineage demands more than governance tools provide.
Data Loss Prevention
Data Loss Prevention (DLP) helps stop sensitive data leaks by monitoring movement across email, cloud, and endpoints with accurate, policy-based controls.
Data Mapping
Data mapping documents how personal data flows between systems, processors, and third parties. Learn what GDPR Article 30 requires and why manual mapping fails.
Data Masking
Data masking replaces real sensitive values with realistic fakes protecting production data in dev and test environments without breaking application workflows.
Data Provenance
Data provenance documents where data came from, who handled it, and whether that history is defensible the record regulators and courts actually require.
Data Retention Policy
A data retention policy defines how long an organisation keeps different types of data and what happens when the retention period expires. Learn GDPR requirements, retention periods by data type, and what enforcement operationally requires.
Data Risk Assessment
A data risk assessment identifies, evaluates, and prioritises risks to sensitive data across an organisation's environment. Learn the key steps, how it differs from a security audit, and what makes one accurate.
Data Security Intelligence
Data Security Intelligence (DSI) is the live evidence of where sensitive data lives, who can reach it, and where exposure is growing. Here's what it means.
Data Security Platform
A data security platform unifies discovery, classification, monitoring, and protection of sensitive data across cloud, SaaS, and endpoints. Learn how it works.
Data Security Posture Management
Understand DSPM and why it matters for data security: continuous data discovery, contextual risk scoring, compliance mapping, and automated controls to reduce breach risk.
Data Sprawl
Data sprawl grows when data copies outpace governance. Learn why that gap between what exists and what's classified is where breaches actually happen.
Data Tokenization
Data tokenization replaces sensitive values with non-sensitive tokens, keeping originals in a secure vault. See how it reduces PCI DSS scope and breach impact.
Data at Rest
Data-at-rest is data stored in any persistent form — databases, file systems, cloud storage, backups, and endpoints. Learn the security controls that protect it, how encryption works, and where most organisations have gaps.
Data in Motion
Data-in-motion is data actively being transmitted across a network — between systems, to cloud storage, or over email. Learn the encryption and monitoring controls that protect it, and why approved channels are the real risk.
Data in use
Data-in-use is data actively being processed, read, or modified in memory by a running application. Learn why it's the hardest state to protect, what specific threats apply, and what controls address the in-use state.
Database Activity Monitoring
Database Activity Monitoring (DAM) tracks and analyzes database access in real time to detect misuse, insider threats, and anomalies. Learn how it works.
EDR
EDR is the security layer that monitors endpoint activity in real time, detects threats after they land, and gives teams the data to investigate fast.
End-Point DLP
Endpoint DLP protects sensitive data on devices by monitoring file activity, USB transfers, and clipboard actions to stop leaks before data leaves. Learn more.
Exfiltration Vector
Exfiltration vectors explained — why permitted channels are harder to detect than blocked ones, and why sequence-based detection is what actually catches modern data theft.
eBPF
eBPF (extended Berkeley Packet Filter) runs sandboxed programs inside the Linux kernel to observe system calls, process behaviour, and network activity with near-zero overhead. Learn how it works and why it matters for security.
GDPR
GDPR governs how organisations handle EU residents' personal data worldwide. Learn the seven principles, lawful bases, breach rules, and what compliance requires.
GRC
GRC unifies governance, risk, and compliance to cut audit fragmentation and map control evidence across regulatory frameworks like GDPR, PCI DSS, and SOC 2.
Incident Response
How incident response works: the six phases, why data incidents break standard IR frameworks, and what fast investigation actually requires.
Insider Threat Detection
Insider threat detection identifies risky user behavior across data and systems to prevent misuse, data theft, and reduce detection time effectively.
Intent Modeling
Intent modeling goes beyond access control — evaluating sequences of permitted actions to detect when legitimate access drifts into misuse before data leaves the environment.
LLM
An LLM is an AI model trained on massive text datasets to understand and generate language. Here's what that means for security teams and CISOs.
Lateral Movement
Lateral movement explained: how attackers expand access after initial compromise, why credentials make it hard to detect, and how behavioral analytics catches it.
Least Privilege
The principle of least privilege requires that every user, process, and system has only the minimum access needed to perform its function. Learn how it works, why violations accumulate, and how to implement it in practice.
Network DLP
Network DLP monitors and blocks sensitive data leaving via email, web, and file transfers—protect your perimeter and reduce exfiltration risk.
Non-Human Identity (NHI)
Non-human identities (NHIs) are service accounts, API keys, OAuth tokens, and machine credentials that access systems without a human user. Learn the security risks and why NHI governance is a critical gap in most programmes.
PCI DSS
PCI DSS governs how organisations handle payment card data. Learn the 12 requirements, compliance levels, and why scope definition determines whether you pass.
Personally Identifiable Information
PII covers more than names and ID numbers. What counts as personally identifiable information across GDPR, DPDP, and CCPA and why accuracy matters.
Policy Enforcement
Security policy enforcement is the process of translating security policies into technical controls that actively prevent or correct policy violations. Learn how automated enforcement works and why manual enforcement creates risk gaps.
Process Lineage
Process lineage is the parent-child chain of processes on an endpoint — documenting which process spawned which, what each executed, and what files and network connections each accessed. Learn how it supports security investigations.
Protected Health Information
PHI is health information linked to an individual identity and learn what HIPAA's 18 identifiers cover, who must comply, and what a breach actually requires.
SOC 2
SOC 2 is an audit report, not a certification. Learn the five Trust Service Criteria, Type I vs Type II differences, and what evidence auditors actually require.
SOX Compliance
SOX links financial reporting to IT controls. Learn what Section 404 auditors test and why evidence gaps are where most programmes fail.
Security Posture
Security posture measures your organization’s defense strength across controls, configurations, exposure, and response—continuously monitor and reduce risk.
Semantic Data Classification
Semantic data classification identifies sensitive data by meaning, not pattern matching — see why it achieves 95–98% accuracy where rule-based tools fall short.
Sensitive Data
Sensitive data spans regulated PII, business-confidential records, and technical secrets. Learn what each domain requires and why context determines classification.
Shadow AI
Shadow AI creates a data exfiltration surface that conventional DLP tools can't see. Learn what governance actually requires beyond blocking.
Shadow Data
Shadow data is sensitive data outside your governed perimeter — created by normal operations, invisible to DLP, and often the easiest path for attackers.
Ready to see Matters
in Action?
Join a specialized 30-minute walkthrough.
No sales fluff, just pure visibility and security intelligence.
