THREAT-WATCH logo

THREAT‑WATCH

GLOSSARY

Identity & Access

Identity has quietly become the primary control plane in most breaches. Attackers rarely break encryption; they log in, using credentials that were phished, reused, or bought. That shift is why zero trust moved from marketing language to architecture, and why multi-factor authentication is now the single highest-return control most mid-market organisations can deploy. The terms in this category describe how access is granted, proven and revoked: who an account belongs to, what it may reach, how strongly that is verified, and what happens to standing privilege that nobody reviews. NIS2 Article 21 explicitly names access control and authentication among the measures in-scope entities must implement, which makes these definitions a compliance matter as well as a technical one.

Zero Trust Security

A security model that assumes no user or device should be trusted by default, even inside the network perimeter.

Traditional security models trusted anything already inside the corporate network. Zero trust assumes breach is possible at any point and requires continuous verification of identity and device health for every access request, regardless of location. In practice, this means strict identity checks, network segmentation, and least-privilege access rather than one perimeter firewall doing all the work.

Endpoint Protection (EDR)

Multi-Factor Authentication (MFA)

A login method requiring two or more independent proofs of identity, such as a password plus a code from a phone.

MFA combines something you know (password), something you have (a device or hardware key), or something you are (biometrics), so a stolen password alone isn't enough to break in. It's one of the single highest-value, lowest-cost security controls available, and its absence is a common finding after account-takeover incidents. Not all MFA is equally strong: SMS codes are weaker than authenticator apps, which are weaker than hardware security keys.

Endpoint Protection (EDR)

Identity and Access Management (IAM)

The systems and policies that control who can access what, across every application and system in an organization.

IAM covers account provisioning and deprovisioning, authentication, and authorization, ensuring people have access to exactly what their role requires, no more. Weak IAM, such as former employees retaining access, or overly broad permissions, is a recurring root cause in breach investigations. Modern IAM increasingly centers on least-privilege access and continuous verification rather than one-time login checks.

Endpoint Protection (EDR)

Privileged Access Management (PAM)

Controls specifically for accounts with elevated permissions, like administrators, since those accounts cause the most damage if compromised.

PAM tools vault and rotate privileged credentials, enforce just-in-time access (granting elevated rights only for the duration needed, not permanently), and log every privileged session for audit purposes. Attackers specifically target admin credentials because they unlock the most systems at once, making PAM a priority control for any organization with IT staff or system administrators.

Endpoint Protection (EDR)

Single Sign-On (SSO)

A login system letting users authenticate once to access multiple applications, instead of separate passwords for each.

SSO centralizes authentication through one identity provider, which improves both security (one strong login to protect and monitor, instead of dozens of weak ones) and user experience. It also makes offboarding faster and more reliable: disabling one central account cuts access to every connected application at once, rather than hunting down access across many separate systems.

Endpoint Protection (EDR)

Zero Trust Network Access (ZTNA)

A practical implementation of zero trust that grants access to specific applications, not the whole network, after verifying identity and device health each time.

ZTNA replaces traditional VPNs, which typically grant broad network access once connected, with per-application access brokered through an identity- and context-aware gateway. If a device is compromised, ZTNA limits what an attacker can reach to the specific application the user was authorized for, rather than the entire internal network a VPN would expose.

Endpoint Protection (EDR)

Password Manager

Software that generates, stores, and auto-fills strong, unique passwords for every account, encrypted behind one master password.

Password managers solve the core problem behind credential-based attacks: people reuse weak passwords across accounts because remembering dozens of strong, unique ones isn't realistic. With a password manager, only one strong master password (ideally itself protected with MFA) needs to be remembered, while every other account gets a long, random, unique password the user never has to type or recall.

Need this applied to your environment, not just defined?

We run managed cybersecurity and NIS2 compliance for Greek and EU mid-market companies. Tell us what you're dealing with.