2FA (two-factor authentication)
A sign-in method that requires exactly two different authentication factors, such as a password plus an approval in an authenticator app. 2FA is one form of multi-factor authentication.
Discuss your IT needsPlain-English IT glossary
Clear definitions of common terms used in business IT, cybersecurity, backup, Microsoft 365, cloud services, email, domains and networking.
A useful reference
Technical language is useful when it is precise. It becomes a problem when an acronym or product term hides an important limitation.
This guide explains what each term generally means, where similar terms differ and what a business should not assume from the label alone.
Originally published 6 April 2023. Substantially reviewed and expanded 4 September 2026.
Showing all 82 terms.
A sign-in method that requires exactly two different authentication factors, such as a password plus an approval in an authenticator app. 2FA is one form of multi-factor authentication.
A network device that provides WiFi connectivity and connects wireless devices to a wired network. A router may contain an access point, but they are not the same function.
The Advanced Encryption Standard using a 256-bit key. It is a widely used form of symmetric encryption, which means the same secret key is used to encrypt and decrypt the data.
Software designed to detect, block and remove malicious software. Modern antivirus can analyse suspicious behaviour as well as known malware, but it is only one part of protecting a device.
The process of proving that a person, device or service is who or what it claims to be. Passwords, passkeys, security keys and authenticator apps are authentication methods.
The rules that determine what an authenticated person or system is allowed to access or do. Authentication confirms identity; authorisation applies permissions to that identity.
A separate copy of data kept so that information can be restored after deletion, corruption, device failure, theft or another loss event. A backup is useful only if it covers the required data and can be restored when needed.
A contracted service in which a provider supplies and usually manages part or all of the backup system. The exact scope can include software, storage, monitoring, retention and recovery assistance, and should be confirmed in the agreement.
The storage used to hold backup copies. It may be local, offsite or cloud-based, and its required capacity depends on data volume, change rate, retention and the backup method.
The amount of data a connection can carry in a given time, usually measured in bits per second. Bandwidth is capacity, while latency describes delay; both affect how a connection feels in use.
Restoring a complete computer or server, including its operating system, applications, settings and data, onto an empty or replacement machine. Hardware and driver compatibility can affect the process.
The planning and arrangements used to keep critical business activities operating during and after disruption. It includes people, communication, suppliers and workarounds as well as technology and disaster recovery.
A temporary copy of data kept closer to where it is used so pages, applications or services can load faster. A stale cache can show old content until it expires or is cleared.
Computing resources delivered from a provider's infrastructure rather than solely from equipment at your premises. Cloud services can include applications, storage, servers, databases and security services.
A backup that sends protected data to storage operated through a cloud service. Encryption, retention, data location, monitoring and restore procedures still need to be understood.
An approach that considers cloud services as the preferred option when choosing or replacing technology. It does not mean every workload must be moved to the cloud regardless of cost, risk or suitability.
Information stored or processed digitally, including documents, email, records, images, databases, configuration and logs. Different data can require different protection, access and retention rules.
A facility designed to house computing, storage and network equipment with supporting power, cooling, connectivity and physical security. The controls and resilience differ between facilities and service tiers.
Dynamic Host Configuration Protocol, which automatically gives devices network settings such as an IP address, gateway and DNS servers. Without it, those settings normally have to be entered manually.
A backup method that sends data from the protected system directly to cloud storage without first requiring a local backup appliance. Whether a local copy is also desirable depends on recovery needs and connectivity.
The planned process for restoring technology, systems and data after a serious disruption. A workable plan identifies priorities, dependencies, responsibilities, recovery targets and how recovery will be tested.
A service that provides hosted technology and assistance for recovering specified systems after disruption. Coverage, recovery targets, testing, network changes and provider responsibilities must be agreed rather than assumed.
DomainKeys Identified Mail. It adds a cryptographic signature to an email so receiving systems can check that the message is associated with the signing domain and was not altered after it was signed.
Domain-based Message Authentication, Reporting and Conformance. It uses alignment with SPF and DKIM results to support reporting and a domain owner's requested handling policy for unauthenticated mail. It does not stop every form of phishing.
The Domain Name System, which publishes records used to connect domain names with services such as websites, email and other internet resources. Incorrect DNS changes can interrupt several services at once.
A registered human-readable name, such as example.co.za, used for websites, email addresses and other internet services. Registration, DNS hosting and website hosting are related but separate services.
Endpoint Detection and Response. EDR records and analyses activity on endpoints to help detect, investigate and respond to suspicious behaviour. Its effectiveness depends on coverage, configuration, monitoring and response.
The use of a cryptographic algorithm and key to transform readable data into a protected form. Encryption can protect stored data and data in transit, but key management and access controls remain essential.
A device that connects to a network or service, commonly a desktop, laptop, phone, tablet or server. Endpoint management can cover configuration, updates, security, monitoring and support.
A control that allows or blocks network traffic according to defined rules. Firewalls can run on individual devices or at network boundaries, and they require appropriate configuration and maintenance.
A service relationship in which a provider accepts defined ongoing responsibilities for an agreed system or outcome. Fully managed does not mean unlimited or all-inclusive; the scope, exclusions and service process still matter.
A device or service that connects one network to another and passes traffic between them. In a small network, the internet router or firewall often acts as the default gateway.
The contact and workflow used to receive, record, prioritise and track support requests. A helpdesk is a process, not merely an email address or ticketing application.
A service that authenticates users and provides identity information to applications. It can centralise sign-in, multi-factor authentication and access policies across connected services.
Internet Message Access Protocol, used by email applications to read and synchronise messages held on a mail server. SMTP is normally used separately to send mail.
The organised process for identifying, containing, investigating and recovering from a security incident. It should also cover communication, evidence, decisions and lessons after the event.
A backup containing data that changed since a previous backup point. It can reduce backup time and storage use, but restore behaviour depends on the product and the chain of backup data available.
A numerical address used to identify and route traffic to a device or service on an IP network. Addresses may be public or private, and fixed or assigned dynamically.
Independent certification that a defined management system and scope conform to a particular ISO standard. A vague claim that a company is 'ISO certified' is incomplete unless the standard, scope and current certificate are identified.
Assistance with technology problems, requests, maintenance and decisions. The service may be reactive, proactive or managed, so response arrangements and included responsibilities should be confirmed.
A backup approach that records changes in sequence so recovery can use captured change history and, in some products, select a precise recovery point. The implementation and available recovery points are product-specific.
A network connecting devices within a limited area such as a home, office or building. It can include wired ethernet, WiFi and shared network services.
The delay between sending data and receiving a response, commonly measured in milliseconds. High latency can affect calls, remote sessions and interactive applications even when bandwidth is sufficient.
Storage physically attached to, or located on the same premises as, the system using it. Examples include an internal drive, external drive or local storage appliance. Local storage is not automatically a backup.
Software or code created to disrupt systems, steal information, gain unauthorised access or perform another harmful action. Ransomware, spyware, some bots and computer viruses are types of malware.
Ongoing IT work delivered under an agreed service relationship rather than only when something breaks. Scope can include support, monitoring, maintenance, security, backup and responsibility for selected systems.
Authentication using two or more different factor types, such as something you know, possess or are. Two passwords do not create MFA because they are the same type of factor.
Microsoft's subscription service family for business productivity, communication, identity, security and device management. The included products and controls depend on the licence assigned.
Collecting and reviewing system signals to identify faults, capacity issues, security events or failed jobs. Monitoring can raise an alert, but an alert still needs an appropriate response process.
A DNS record that identifies the mail servers expected to receive email for a domain. Changing MX records can redirect inbound mail and should be planned carefully.
Network-attached storage, a device that provides shared file storage over a network. A NAS can be part of a backup design, but simply storing the only copy of data on it is not a backup.
A backup copy kept in a different physical location from the source system. Separation helps protect against events that affect the primary location, but access, encryption and restore time still matter.
An application that creates and stores credentials in an encrypted vault. It helps people use strong, unique passwords while remembering one primary credential and protecting it with MFA where available.
A software update intended to correct a defect, security vulnerability or compatibility issue. Patch management includes identifying, testing, deploying and checking updates, not merely enabling automatic updates.
A deceptive message or interaction designed to make someone reveal information, approve an action, send money or run malicious content. Phishing can arrive through email, messaging, social media, websites or phone calls.
Technology that carries electrical power and network data over the same ethernet cable. It is commonly used for access points, cameras and VoIP phones when the equipment and power requirements are compatible.
Cloud infrastructure dedicated to one organisation rather than shared as a public multi-tenant service. It may be hosted on the organisation's premises or by a provider, and it is not automatically more secure.
The secret half of an asymmetric cryptographic key pair. It can be used to create digital signatures or decrypt information intended for its matching public key, and must not be shared or exposed.
Malware used to deny access to systems or data and demand payment. Modern incidents may also involve data theft and extortion, so backups are important but do not address every consequence.
The broader work of returning data, systems and business operations to an acceptable state after loss or disruption. Recovery can involve restores, rebuilding, validation, communication and temporary workarounds.
Administering devices, servers or network equipment without being physically present. It can improve support and monitoring, but access should be authenticated, limited, logged and maintained securely.
The action of copying data or a system back from a backup to a usable location. A successful backup job does not prove that every required restore will work, which is why restore testing matters.
The length of time a backup, record or other data is kept before expiry or deletion. Retention should reflect recovery needs, legal obligations, business requirements and storage constraints.
A device or service that directs traffic between different IP networks. A typical small-business router connects the local network to an internet service, but firewall, WiFi and switching functions may be separate.
The target maximum amount of data loss measured in time. An RPO of four hours means the recovery design aims to restore data no more than four hours old, subject to the agreed system and circumstances.
The target time for restoring an agreed service after disruption. It is a planning objective, not automatically a guarantee, and depends on the recovery design, dependencies and service agreement.
Software operated by a provider and accessed as a service, usually through a browser or application. The provider runs the platform, while the customer still has responsibilities such as access control, configuration and data governance.
Protected against defined threats to an appropriate level. Secure is not an absolute state; the controls, risks, assumptions and remaining exposure should be understood in context.
The overall design of security controls, trust boundaries, identities, systems and processes. It describes how controls work together rather than treating each product as an isolated protection.
A service or product that the customer configures, monitors and maintains. Provider support may still exist, but ongoing operation remains primarily the customer's responsibility.
A computer system or software service that provides resources to other devices or applications. A server can be physical, virtual or cloud-hosted and may provide files, applications, identity, databases or websites.
Simple Mail Transfer Protocol, used to submit and relay email between clients and mail servers. It handles sending, while protocols such as IMAP are commonly used to read and synchronise mailboxes.
Sender Policy Framework, a DNS-based mechanism that lets a domain publish which systems may send mail for it. SPF checks the envelope sender, can be affected by forwarding and must align appropriately to contribute to DMARC.
A sign-in arrangement that lets one authenticated identity access multiple connected applications. SSO reduces separate passwords but makes protection and recovery of the central identity especially important.
A network device that connects wired devices on the same local network and forwards traffic to the correct port. Managed switches can also provide features such as VLANs, monitoring and Power over Ethernet.
A logically separated customer environment within a shared cloud service. A Microsoft 365 tenant, for example, contains an organisation's identities, domains, settings and subscribed services.
A recovery approach that starts protected workloads as virtual machines in alternate infrastructure. Recovery speed still depends on current backups, configuration, networking, capacity and testing.
An encrypted connection between a device or network and a VPN endpoint. It can protect traffic across untrusted networks or provide private remote access, but it does not make every activity anonymous or safe.
A network connecting locations across a larger geographic area. Businesses use WAN services, internet links or encrypted tunnels to connect branches, data centres and cloud environments.
Wireless local networking based on the IEEE 802.11 family of standards. Coverage and performance depend on access-point placement, interference, building materials, channel use and device capabilities.
The WiFi generation based on IEEE 802.11ax. It can improve efficiency and capacity, especially with many compatible devices, but real performance still depends on the network design and client hardware.
A security approach that does not grant trust solely because a user or device is inside a network. Access decisions use verified identity, device state, policy, context and least-privilege principles.
Try a shorter word or ask Kwik Support what the term means in your situation.
Context still matters
Technology providers can use the same term for services with very different coverage. “Managed”, “secure”, “backup” and “cloud” do not by themselves confirm what is included, monitored or recoverable.
When comparing a proposal, ask what systems are covered, who responds, what is excluded and how the claimed outcome is checked.
Start with a conversation
Tell us what you are considering or what a provider has proposed, and we can help you work through the practical meaning.