Back to Learning Hub

Cybersecurity Awareness Glossary

Last updated: 2026-08-136 min read

Plain-English definitions of the phishing, social engineering, email authentication and awareness-programme terms security teams actually use.

Plain-English definitions of the terms that come up in phishing awareness and security training. Grouped by what they describe: the attacks, the techniques behind them, the defences, and the numbers a programme is measured by.


Attack types

Phishing. A fraudulent message that impersonates a trusted organisation or person to make the recipient click a link, open an attachment, hand over credentials, or move money. The umbrella term for everything below. See what is phishing.

Spear phishing. Phishing aimed at one specific person, written using real details about them — their manager's name, a live project, a recent company announcement. Far rarer than bulk phishing and far more successful. See what is spear phishing and how enterprises defend against it.

Whaling. Spear phishing aimed at senior executives, or impersonating them. The name reflects the value of the target rather than a different technique.

Business email compromise (BEC). A scam that uses a compromised or convincingly faked business mailbox to redirect payments — fake invoices, changed bank details, urgent wire requests. Usually carries no malware at all. See BEC explained.

CEO fraud. A BEC variant in which the attacker poses as a senior executive and asks finance for an urgent, confidential transfer.

Vendor email compromise. A BEC variant in which a supplier's mailbox is compromised and their genuine clients receive fraudulent invoices.

Vishing. Voice phishing — the attack arrives as a phone call, often impersonating IT support, a bank's fraud team, or a senior colleague.

Smishing. Phishing delivered by SMS text message. See what is smishing and vishing and smishing simulations.

Quishing. Phishing that hides the malicious link inside a QR code, so the destination cannot be inspected before scanning and the victim usually moves to a personal phone outside corporate controls.

Deepfake phishing. Social engineering using AI-cloned voice or video to impersonate someone the target knows, typically on a call or video meeting. See what is deepfake phishing.

Clone phishing. A copy of a genuine message the recipient already received, resent with the link or attachment swapped for a malicious one.

Watering hole attack. Compromising a legitimate website that a target group is known to visit, rather than contacting the targets directly.

Pharming. Redirecting traffic from a legitimate address to a fraudulent one by tampering with DNS, so the victim reaches the fake site without clicking anything.


Techniques and concepts

Social engineering. Manipulating people into revealing information or taking risky actions, rather than attacking technology. The discipline all phishing belongs to. See what is social engineering.

Pretext. The cover story a message uses — a delivery notification, a payroll update, a legal deadline. The more it fits the target's real context, the better it works.

Lure. The specific bait inside the pretext: the link, the attachment, the request for a reply.

Payload. What the attack is actually trying to deliver or obtain — malware, a credential-harvesting page, or a payment.

Credential harvesting. Stealing usernames and passwords through a fake login page that mirrors a service the victim genuinely uses.

Account takeover. The result of successful credential harvesting: an attacker operating a real account, which is why their later messages pass every technical check.

MFA fatigue. Bombarding a user with repeated multi-factor approval prompts until they approve one to stop the noise. Also called push bombing.

Domain spoofing. Forging the sender address so a message appears to come from a domain the attacker does not control.

Lookalike domain. A registered domain that reads as a legitimate one at a glance — examp1e.com for example.com. Unlike spoofing, the attacker genuinely owns it, so it passes authentication checks.

Typosquatting. Registering common misspellings of a domain to catch mistyped traffic or lend credibility to a lure.

Pretexting, baiting, tailgating. Three classic social engineering plays: inventing a scenario to extract information; leaving infected media or an enticing offer to be picked up; and following an authorised person through a secure door.


Defences

Multi-factor authentication (MFA). Requiring a second proof of identity beyond a password. It raises the cost of account takeover substantially but is not absolute — MFA fatigue and code phishing both defeat it.

Passkey. A phishing-resistant replacement for passwords, bound cryptographically to the real site, so a lookalike login page has nothing to steal.

SPF (Sender Policy Framework). A DNS record listing which mail servers are allowed to send on behalf of your domain.

DKIM (DomainKeys Identified Mail). A cryptographic signature added to outbound mail, verified by the recipient against a public key published in your DNS.

DMARC. A published policy telling receiving mail servers what to do when SPF or DKIM fail — monitor, quarantine, or reject — plus reporting on who is sending as your domain. The three together make your domain harder to spoof; none of them stop a lookalike domain. You can test your own domain for email spoofing free.

Secure email gateway. A filtering layer that scans inbound mail for known malicious senders, links, and attachments. Effective against bulk attacks, weaker against text-only social engineering.

Out-of-band verification. Confirming a sensitive request through a different channel than the one it arrived on — phoning a number you already hold, never the number in the message. The single most effective control against BEC and deepfake fraud.

Zero trust. A security model that verifies every request rather than trusting anything by virtue of being inside the network.


Awareness programmes

Security awareness training. The educational layer that teaches employees to recognise and report threats. See what is security awareness training.

Phishing simulation. An authorised fake phishing message sent to your own employees to measure how they respond. See what is a phishing simulation and how to run one.

Baseline test. The first simulation, run before any training, establishing the numbers every later campaign is compared against.

Landing page. The page a simulated link leads to. In a well-designed programme it teaches rather than scolds.

Just-in-time training. A short lesson delivered at the moment someone clicks a simulated link, when the correction is most likely to stick.

Human risk management. Treating human-driven risk as something measured and managed per person over time, rather than a training box ticked annually. See what is human risk management.

Human firewall. Shorthand for a workforce that reliably recognises and reports threats.


Metrics

Click rate. The share of recipients who clicked the link in a simulation. The headline number, and the one most easily flattered by easy simulations.

Reporting rate. The share who reported the message to security. The better indicator of a mature programme: low clicks and low reports can simply mean people ignore their email.

Time to report. How quickly the first report arrives — the number that decides whether security can contain a real campaign while it is still running.

Repeat clicker. Someone who clicks across multiple campaigns. A small group usually accounts for a disproportionate share of risk, and is where targeted intervention pays.

Phishing resilience score. A composite measure of how well an organisation resists phishing, combining click, report and repeat behaviour over time. See phishing resilience score and how it is calculated.

Dwell time. How long an attacker remains undetected inside an environment after a successful compromise.


Related Learning

Ready to stop phishing attacks?

Run realistic phishing simulations and high-impact security awareness training with PhishSkill's automated platform.