Plain-English IT glossary

IT terminology, explained without the jargon

Clear definitions of common terms used in business IT, cybersecurity, backup, Microsoft 365, cloud services, email, domains and networking.

A useful reference

Understand the words before making the decision

Technical language is useful when it is precise. It becomes a problem when an acronym or product term hides an important limitation.

This guide explains what each term generally means, where similar terms differ and what a business should not assume from the label alone.

Originally published 6 April 2023. Substantially reviewed and expanded 4 September 2026.

Showing all 82 terms.

0-9

2FA (two-factor authentication)

A sign-in method that requires exactly two different authentication factors, such as a password plus an approval in an authenticator app. 2FA is one form of multi-factor authentication.

A

Access point

A network device that provides WiFi connectivity and connects wireless devices to a wired network. A router may contain an access point, but they are not the same function.

AES-256

The Advanced Encryption Standard using a 256-bit key. It is a widely used form of symmetric encryption, which means the same secret key is used to encrypt and decrypt the data.

Antivirus

Software designed to detect, block and remove malicious software. Modern antivirus can analyse suspicious behaviour as well as known malware, but it is only one part of protecting a device.

Authentication

The process of proving that a person, device or service is who or what it claims to be. Passwords, passkeys, security keys and authenticator apps are authentication methods.

Authorisation

The rules that determine what an authenticated person or system is allowed to access or do. Authentication confirms identity; authorisation applies permissions to that identity.

B

Backup

A separate copy of data kept so that information can be restored after deletion, corruption, device failure, theft or another loss event. A backup is useful only if it covers the required data and can be restored when needed.

Backup as a Service (BaaS)

A contracted service in which a provider supplies and usually manages part or all of the backup system. The exact scope can include software, storage, monitoring, retention and recovery assistance, and should be confirmed in the agreement.

Backup storage

The storage used to hold backup copies. It may be local, offsite or cloud-based, and its required capacity depends on data volume, change rate, retention and the backup method.

Bandwidth

The amount of data a connection can carry in a given time, usually measured in bits per second. Bandwidth is capacity, while latency describes delay; both affect how a connection feels in use.

Bare-metal restore

Restoring a complete computer or server, including its operating system, applications, settings and data, onto an empty or replacement machine. Hardware and driver compatibility can affect the process.

Business continuity

The planning and arrangements used to keep critical business activities operating during and after disruption. It includes people, communication, suppliers and workarounds as well as technology and disaster recovery.

C

Cache

A temporary copy of data kept closer to where it is used so pages, applications or services can load faster. A stale cache can show old content until it expires or is cleared.

Cloud

Computing resources delivered from a provider's infrastructure rather than solely from equipment at your premises. Cloud services can include applications, storage, servers, databases and security services.

Cloud backup

A backup that sends protected data to storage operated through a cloud service. Encryption, retention, data location, monitoring and restore procedures still need to be understood.

Cloud-first

An approach that considers cloud services as the preferred option when choosing or replacing technology. It does not mean every workload must be moved to the cloud regardless of cost, risk or suitability.

D

Data

Information stored or processed digitally, including documents, email, records, images, databases, configuration and logs. Different data can require different protection, access and retention rules.

Data centre

A facility designed to house computing, storage and network equipment with supporting power, cooling, connectivity and physical security. The controls and resilience differ between facilities and service tiers.

DHCP

Dynamic Host Configuration Protocol, which automatically gives devices network settings such as an IP address, gateway and DNS servers. Without it, those settings normally have to be entered manually.

Direct-to-cloud backup

A backup method that sends data from the protected system directly to cloud storage without first requiring a local backup appliance. Whether a local copy is also desirable depends on recovery needs and connectivity.

Disaster recovery

The planned process for restoring technology, systems and data after a serious disruption. A workable plan identifies priorities, dependencies, responsibilities, recovery targets and how recovery will be tested.

Disaster Recovery as a Service (DRaaS)

A service that provides hosted technology and assistance for recovering specified systems after disruption. Coverage, recovery targets, testing, network changes and provider responsibilities must be agreed rather than assumed.

DKIM

DomainKeys Identified Mail. It adds a cryptographic signature to an email so receiving systems can check that the message is associated with the signing domain and was not altered after it was signed.

DMARC

Domain-based Message Authentication, Reporting and Conformance. It uses alignment with SPF and DKIM results to support reporting and a domain owner's requested handling policy for unauthenticated mail. It does not stop every form of phishing.

DNS

The Domain Name System, which publishes records used to connect domain names with services such as websites, email and other internet resources. Incorrect DNS changes can interrupt several services at once.

Domain name

A registered human-readable name, such as example.co.za, used for websites, email addresses and other internet services. Registration, DNS hosting and website hosting are related but separate services.

E

EDR

Endpoint Detection and Response. EDR records and analyses activity on endpoints to help detect, investigate and respond to suspicious behaviour. Its effectiveness depends on coverage, configuration, monitoring and response.

Encryption

The use of a cryptographic algorithm and key to transform readable data into a protected form. Encryption can protect stored data and data in transit, but key management and access controls remain essential.

Endpoint

A device that connects to a network or service, commonly a desktop, laptop, phone, tablet or server. Endpoint management can cover configuration, updates, security, monitoring and support.

F

Firewall

A control that allows or blocks network traffic according to defined rules. Firewalls can run on individual devices or at network boundaries, and they require appropriate configuration and maintenance.

Fully managed service

A service relationship in which a provider accepts defined ongoing responsibilities for an agreed system or outcome. Fully managed does not mean unlimited or all-inclusive; the scope, exclusions and service process still matter.

G

Gateway

A device or service that connects one network to another and passes traffic between them. In a small network, the internet router or firewall often acts as the default gateway.

H

Helpdesk

The contact and workflow used to receive, record, prioritise and track support requests. A helpdesk is a process, not merely an email address or ticketing application.

I

Identity provider (IdP)

A service that authenticates users and provides identity information to applications. It can centralise sign-in, multi-factor authentication and access policies across connected services.

IMAP

Internet Message Access Protocol, used by email applications to read and synchronise messages held on a mail server. SMTP is normally used separately to send mail.

Incident response

The organised process for identifying, containing, investigating and recovering from a security incident. It should also cover communication, evidence, decisions and lessons after the event.

Incremental backup

A backup containing data that changed since a previous backup point. It can reduce backup time and storage use, but restore behaviour depends on the product and the chain of backup data available.

IP address

A numerical address used to identify and route traffic to a device or service on an IP network. Addresses may be public or private, and fixed or assigned dynamically.

ISO certification

Independent certification that a defined management system and scope conform to a particular ISO standard. A vague claim that a company is 'ISO certified' is incomplete unless the standard, scope and current certificate are identified.

IT support

Assistance with technology problems, requests, maintenance and decisions. The service may be reactive, proactive or managed, so response arrangements and included responsibilities should be confirmed.

J

Journal-based backup

A backup approach that records changes in sequence so recovery can use captured change history and, in some products, select a precise recovery point. The implementation and available recovery points are product-specific.

L

LAN (local area network)

A network connecting devices within a limited area such as a home, office or building. It can include wired ethernet, WiFi and shared network services.

Latency

The delay between sending data and receiving a response, commonly measured in milliseconds. High latency can affect calls, remote sessions and interactive applications even when bandwidth is sufficient.

Local storage

Storage physically attached to, or located on the same premises as, the system using it. Examples include an internal drive, external drive or local storage appliance. Local storage is not automatically a backup.

M

Malware

Software or code created to disrupt systems, steal information, gain unauthorised access or perform another harmful action. Ransomware, spyware, some bots and computer viruses are types of malware.

Managed IT services

Ongoing IT work delivered under an agreed service relationship rather than only when something breaks. Scope can include support, monitoring, maintenance, security, backup and responsibility for selected systems.

MFA (multi-factor authentication)

Authentication using two or more different factor types, such as something you know, possess or are. Two passwords do not create MFA because they are the same type of factor.

Microsoft 365

Microsoft's subscription service family for business productivity, communication, identity, security and device management. The included products and controls depend on the licence assigned.

Monitoring

Collecting and reviewing system signals to identify faults, capacity issues, security events or failed jobs. Monitoring can raise an alert, but an alert still needs an appropriate response process.

MX record

A DNS record that identifies the mail servers expected to receive email for a domain. Changing MX records can redirect inbound mail and should be planned carefully.

N

NAS

Network-attached storage, a device that provides shared file storage over a network. A NAS can be part of a backup design, but simply storing the only copy of data on it is not a backup.

O

Offsite backup

A backup copy kept in a different physical location from the source system. Separation helps protect against events that affect the primary location, but access, encryption and restore time still matter.

P

Password manager

An application that creates and stores credentials in an encrypted vault. It helps people use strong, unique passwords while remembering one primary credential and protecting it with MFA where available.

Patch

A software update intended to correct a defect, security vulnerability or compatibility issue. Patch management includes identifying, testing, deploying and checking updates, not merely enabling automatic updates.

Phishing

A deceptive message or interaction designed to make someone reveal information, approve an action, send money or run malicious content. Phishing can arrive through email, messaging, social media, websites or phone calls.

PoE (Power over Ethernet)

Technology that carries electrical power and network data over the same ethernet cable. It is commonly used for access points, cameras and VoIP phones when the equipment and power requirements are compatible.

Private cloud

Cloud infrastructure dedicated to one organisation rather than shared as a public multi-tenant service. It may be hosted on the organisation's premises or by a provider, and it is not automatically more secure.

Private key

The secret half of an asymmetric cryptographic key pair. It can be used to create digital signatures or decrypt information intended for its matching public key, and must not be shared or exposed.

R

Ransomware

Malware used to deny access to systems or data and demand payment. Modern incidents may also involve data theft and extortion, so backups are important but do not address every consequence.

Recovery

The broader work of returning data, systems and business operations to an acceptable state after loss or disruption. Recovery can involve restores, rebuilding, validation, communication and temporary workarounds.

Remote management

Administering devices, servers or network equipment without being physically present. It can improve support and monitoring, but access should be authenticated, limited, logged and maintained securely.

Restore

The action of copying data or a system back from a backup to a usable location. A successful backup job does not prove that every required restore will work, which is why restore testing matters.

Retention period

The length of time a backup, record or other data is kept before expiry or deletion. Retention should reflect recovery needs, legal obligations, business requirements and storage constraints.

Router

A device or service that directs traffic between different IP networks. A typical small-business router connects the local network to an internet service, but firewall, WiFi and switching functions may be separate.

RPO (recovery point objective)

The target maximum amount of data loss measured in time. An RPO of four hours means the recovery design aims to restore data no more than four hours old, subject to the agreed system and circumstances.

RTO (recovery time objective)

The target time for restoring an agreed service after disruption. It is a planning objective, not automatically a guarantee, and depends on the recovery design, dependencies and service agreement.

S

SaaS (Software as a Service)

Software operated by a provider and accessed as a service, usually through a browser or application. The provider runs the platform, while the customer still has responsibilities such as access control, configuration and data governance.

Secure

Protected against defined threats to an appropriate level. Secure is not an absolute state; the controls, risks, assumptions and remaining exposure should be understood in context.

Security architecture

The overall design of security controls, trust boundaries, identities, systems and processes. It describes how controls work together rather than treating each product as an isolated protection.

Self-managed service

A service or product that the customer configures, monitors and maintains. Provider support may still exist, but ongoing operation remains primarily the customer's responsibility.

Server

A computer system or software service that provides resources to other devices or applications. A server can be physical, virtual or cloud-hosted and may provide files, applications, identity, databases or websites.

SMTP

Simple Mail Transfer Protocol, used to submit and relay email between clients and mail servers. It handles sending, while protocols such as IMAP are commonly used to read and synchronise mailboxes.

SPF

Sender Policy Framework, a DNS-based mechanism that lets a domain publish which systems may send mail for it. SPF checks the envelope sender, can be affected by forwarding and must align appropriately to contribute to DMARC.

SSO (single sign-on)

A sign-in arrangement that lets one authenticated identity access multiple connected applications. SSO reduces separate passwords but makes protection and recovery of the central identity especially important.

Switch

A network device that connects wired devices on the same local network and forwards traffic to the correct port. Managed switches can also provide features such as VLANs, monitoring and Power over Ethernet.

T

Tenant

A logically separated customer environment within a shared cloud service. A Microsoft 365 tenant, for example, contains an organisation's identities, domains, settings and subscribed services.

V

Virtual disaster recovery

A recovery approach that starts protected workloads as virtual machines in alternate infrastructure. Recovery speed still depends on current backups, configuration, networking, capacity and testing.

VPN (virtual private network)

An encrypted connection between a device or network and a VPN endpoint. It can protect traffic across untrusted networks or provide private remote access, but it does not make every activity anonymous or safe.

W

WAN (wide area network)

A network connecting locations across a larger geographic area. Businesses use WAN services, internet links or encrypted tunnels to connect branches, data centres and cloud environments.

WiFi

Wireless local networking based on the IEEE 802.11 family of standards. Coverage and performance depend on access-point placement, interference, building materials, channel use and device capabilities.

WiFi 6

The WiFi generation based on IEEE 802.11ax. It can improve efficiency and capacity, especially with many compatible devices, but real performance still depends on the network design and client hardware.

Z

Zero trust

A security approach that does not grant trust solely because a user or device is inside a network. Access decisions use verified identity, device state, policy, context and least-privilege principles.

Context still matters

A definition is not a service scope

Technology providers can use the same term for services with very different coverage. “Managed”, “secure”, “backup” and “cloud” do not by themselves confirm what is included, monitored or recoverable.

When comparing a proposal, ask what systems are covered, who responds, what is excluded and how the claimed outcome is checked.

Start with a conversation

Need the terminology applied to your own setup?

Tell us what you are considering or what a provider has proposed, and we can help you work through the practical meaning.