OSINTDFIRRoadmapsToolsCareer

The Complete Cybersecurity Acronyms Stack 2026: 50+ Terms Every Beginner Must Know

The Complete Cybersecurity Acronyms Stack 2026: 50+ Terms Every Beginner Must Know

If you’re new to cybersecurity, all the acronyms feel like another language.

SOC? SIEM? RCE? CVE?

Don’t worry. I’ve organized the 50+ most important cybersecurity acronyms

into a simple "stack" so you can learn them fast.

FUNDAMENTALS - THE BASICS

These are the foundations. If you don’t know these, you won’t get hired.

  • CIA Confidentiality, Integrity & Availability

The 3 core goals of security. Keep data secret, accurate, and accessible.

  • AAA Authentication, Authorization & Accounting

Who are you? What can you do? What did you do? That’s AAA.

  • MFA Multi-Factor Authentication

Password + Phone code. Stops 99% of account takeovers.

  • IAM Identity & Access Management

Managing who has access to what. Ex: Okta, Azure AD

  • PAM Privileged Access Management

Controlling admin/root accounts. Stops hackers from going "god mode"

  • ZT Zero Trust

"Never trust, always verify". Don’t trust anyone inside the network.

SOC & DETECTION - WHERE THE JOBS ARE

This is what SOC Analysts use daily. $60k-$100k roles.

  • SOC Security Operations Center

The team that watches for hackers 24/7

  • SIEM Security Information & Event Management

Tool that collects all logs. Ex: Splunk, QRadar, Elastic

  • SOAR Security Orchestration, Automation & Response

Makes SIEM automatically block threats

  • EDR Endpoint Detection & Response

Antivirus on steroids. Watches your laptop for malware

  • XDR Extended Detection & Response

EDR but for Email + Network + Cloud too

  • NDR Network Detection & Response

Watches network traffic for hackers

THREAT INTELLIGENCE

Think like the attacker.

  • IOC Indicator of Compromise

Evidence you were hacked. Ex: Bad IP, malware hash

  • IOA Indicator of Attack

The behavior of an attack. Ex: "brute force login attempts"

  • TTP Tactics, Techniques & Procedures

HOW hackers attack. Used by MITRE ATT&CK

  • CTI Cyber Threat Intelligence

Info about current hacker groups

  • APT Advanced Persistent Threat

Nation-state hackers. Ex: Russia, China hacking groups

  • OSINT Open-Source Intelligence

Finding hacker info from Google, LinkedIn, Twitter

VULNERABILITIES - HOW SITES GET HACKED

  • CVE Common Vulnerabilities & Exposures

ID for every bug. Ex: CVE-2024-1234

  • CVSS Common Vulnerability Scoring System

Scores how bad a CVE is. 1-10

  • CWE Common Weakness Enumeration

Types of coding mistakes that cause CVEs

  • RCE Remote Code Execution

Worst bug. Hacker can run any command on your server

  • PoC Proof of Concept

Demo code that proves a bug works

NETWORK SECURITY

  • IDS Intrusion Detection System

Alarm system. Detects hackers but doesn’t block

  • IPS Intrusion Prevention System

IDS that also blocks the hacker

  • WAF Web Application Firewall

Protects websites from XSS and SQLi

  • VPN Virtual Private Network

Encrypts your internet.

  • DDoS Distributed Denial of Service

Overloading a website with traffic

  • MITM Man-in-the-Middle

Hacker sits between you and the website

  • WEB SECURITY - BUG BOUNTY TERMS
  • XSS Cross-Site Scripting

Injecting JavaScript into a website

  • SQLi SQL Injection

Hacking databases with ' OR 1=1

  • CSRF Cross-Site Request Forgery

Trick user into clicking a bad link

  • SSRF Server-Side Request Forgery

Trick server into attacking itself

  • IDOR Insecure Direct Object Reference

Changing "user=123" to "user=124" to see other people’s data

CRYPTOGRAPHY

  • PKI Public Key Infrastructure

System for SSL certificates

  • TLS Transport Layer Security

The "S" in HTTPS

  • AES Advanced Encryption Standard

The encryption the US government uses

  • RSA Rivest–Shamir–Adleman

Old but common encryption for keys

  • SHA Secure Hash Algorithm

Used to check if files were changed

INCIDENT RESPONSE

  • IR Incident Response

The plan when you get hacked

  • DFIR Digital Forensics & Incident Response

Finding evidence after an attack

  • RCA Root Cause Analysis

"Why did this happen?"

  • RTO Recovery Time Objective

"How fast must we be back online?"

  • RPO Recovery Point Objective

"How much data can we afford to lose?"

HOW TO MEMORIZE THIS FAST

SOC Job? Learn section 2 + 3 first

Bug Bounty? Learn section 4 + 5 + 6

Interview? Learn section 1 + 8

1 Comment

TITTLEDMAN · 25d ago
What a helpful enlightenment

Leave a comment

Funded seats · Limited intake

Scholarship Courses Registration

Mentor-led tracks in OSINT, DFIR, and offensive security — with funded seats for qualifying students.