Threats & attacks
The attacks and attacker techniques a small firm is actually likely to face.
19 terms
The attack types and attacker techniques most likely to actually reach a small firm — not a theoretical catalogue, but the ones worth planning for.
Showing 19 of 19
Advanced persistent threat (APT)
A patient, well-resourced attacker that stays hidden in a network over time.
Brute force attack
Systematically guessing passwords or keys until one works.
Business email compromise (BEC)
An attacker impersonates an executive or vendor's email to redirect a payment.
Credential stuffing
Trying leaked username/password pairs against other sites, betting on reuse.
Cross-site scripting (XSS)
Injecting malicious script into a site so it runs in another visitor's browser.
Deepfake fraud
Using AI-generated audio or video to convincingly impersonate someone.
Distributed denial-of-service (DDoS)
Flooding a system with traffic until it can't serve real users.
Insider threat
Harm caused by someone with legitimate access, malicious or careless.
Malware
Software built to damage, disrupt, or gain unauthorized access to a system.
Man-in-the-middle attack (MITM)
An attacker secretly intercepts communication between two parties.
Phishing
A fake message designed to trick someone into handing over credentials or money.
Ransomware
Malware that encrypts your files and demands payment to unlock them.
Session hijacking
Stealing a valid login session to act as an already-authenticated user.
Smishing & vishing
Phishing delivered by text message or phone call instead of email.
Social engineering
Manipulating a person, not a system, into breaking security procedure.
Spear phishing
Phishing aimed at one specific person using details that make it believable.
SQL injection (SQLi)
Sneaking database commands into a web form to run them against the database.
Supply chain attack
Compromising a trusted vendor to reach their downstream customers.
Zero-day
A vulnerability being exploited before the vendor has released a fix.
No terms match your search.