Harp Cybersecurity — Glossary

Security has a lot of acronyms. Here's what the terms on this site actually mean, in plain English.

Harp Services & Plans

Cybersecurity as a Service (CaaS)

Outsourced security on a subscription — expert monitoring, tools, and incident response for a predictable monthly fee, without building any of it in-house.

Fully Managed

Harp installs it, watches it, tunes it, and responds when something happens. You don't need anyone on staff who knows how the tools work.

Endpoint

Any device someone uses to do work — a laptop, desktop, or server. Harp prices by endpoint, so your cost is based on how many devices you're protecting, not how many features you turn on.

EDR — Endpoint Detection & Response

Security software that lives on each device and watches how it behaves. When it spots something malicious, it can stop the program and cut the device off from your network before the problem spreads. Think of a smoke detector that can also close the door on the fire.

ITDR — Identity Threat Detection & Response

Protection for your accounts and logins rather than your devices. It catches things like a stolen password being used, a sign-in from a country nobody works in, or someone quietly adding themselves to an account they shouldn't have.

SIEM — Security Information & Event Management

A system that gathers activity records from all your devices and services into one place and looks for patterns. One device on its own tells you very little; all of them together tell the story.

SOC — Security Operations Center

A team of human security analysts watching alerts and deciding what's real. “24/7 SOC” means someone is awake and looking at 3 a.m. when an alert fires, not just a tool sending an email nobody reads until Monday.

MDR — Managed Detection & Response

The industry's term for outsourced monitoring plus human response. It's what Harp's Elite plan delivers — included in the plan rather than sold as a separate add-on the way it often is elsewhere.

Vulnerability Assessment

A structured review that finds known weak points in your systems — missing updates, risky settings, services exposed to the internet — so they can be fixed before someone exploits them.

Security Awareness Training

Short, practical training that teaches your staff to recognize scam emails and unsafe requests. It matters because the large majority of breaches start with a person, not a machine.

Threat Intelligence

Ongoing information about what attackers are doing right now, worldwide. It's used to recognize the same tactics in your environment early.

Incident Response

The plan and the actions taken once something has actually happened — containing it, investigating it, and getting you back to normal.

Onboarding

The setup phase after you sign: connecting Harp to your environment, deploying protection to your devices, and confirming everything is reporting correctly. Service starts once this is complete.

Threats & Attacks

Incident

Any confirmed or suspected unauthorized access to your systems or data. It's the formal term used in your agreement, and it's what starts the clock on Harp's response commitments.

Breach

An incident where an attacker actually got in and reached data or systems they shouldn't have.

Malware

Malicious software. A catch-all term for any program built to damage, steal, spy, or take control.

Ransomware

Malware that locks up your files and demands payment to unlock them. It's the attack most likely to stop a small business from operating entirely.

Phishing

A fake email, text, or message designed to look legitimate so you'll click a link, open an attachment, or hand over a password.

Social Engineering

Manipulating a person rather than hacking a machine — the fake invoice, the urgent request from the “CEO,” the caller pretending to be IT. Phishing is the most common form.

DDoS — Distributed Denial of Service

Flooding your website or systems with so much fake traffic that real customers can't get through. The goal is to knock you offline, not to steal data.

Botnet

A network of infected computers an attacker controls remotely, often used to send spam or power a DDoS attack. Machines in a botnet are usually owned by people who have no idea.

Intrusion

An attacker successfully getting into a system they aren't supposed to be in.

Scanner

An automated probe that sweeps the internet looking for unprotected or out-of-date systems. It's the reconnaissance step — attackers scan first, then target what they find.

Credential Theft

Stolen usernames and passwords. Because stolen credentials let an attacker simply log in, this is often quieter and harder to catch than a technical break-in.

Security Basics You'll Hear About

MFA — Multi-Factor Authentication

Requiring a second proof of identity beyond a password, usually a code or a prompt on your phone. It's one of the single most effective protections against stolen passwords.

Patching

Installing the security updates vendors release for their software. Unpatched systems are one of the most common ways attackers get in.

Backups

Copies of your data stored separately so you can recover if data is destroyed, encrypted by ransomware, or deleted by mistake.

Security Hygiene

The everyday basics your business stays responsible for: patching, MFA, backups, and staff training. Harp's services reduce risk on top of these, not instead of them.

Credentials

Usernames, passwords, keys, and other information used to log in.

Microsoft Tenant

Your own private space within Microsoft's cloud, where your accounts, email, and licenses live. Your licenses stay in your tenant and belong to you.

License / Seat

Permission for one person to use a piece of software, billed per person per month.

Microsoft 365 Business Premium

Microsoft's business plan that bundles Office apps, email, device management, and core security features. It's designed for organizations up to 300 employees.

Microsoft Defender for Endpoint P2

The add-on license that unlocks Microsoft's advanced device protection — the EDR capability Harp monitors and manages on your behalf.

Compliance & Standards

Compliance

Meeting the security rules that apply to your industry, your customers, or your contracts — and being able to prove it.

HIPAA

The U.S. law governing how patient health information must be protected. It applies to healthcare organizations and the vendors that handle their data.

PCI DSS — Payment Card Industry Data Security Standard

The security rules required of any business that accepts, processes, or stores credit card payments.

SOC 2

An independent audit that verifies a company actually does what it claims to protect customer data. Enterprise customers often require it before signing with a vendor.

Worth knowing: SOC 2 and SOC (Security Operations Center) are unrelated despite the shared letters. One is an audit report; the other is a team of analysts.

NIST

A U.S. government agency whose cybersecurity frameworks are widely used as a blueprint for building a security program. Being “aligned to NIST” means following that structure.

ISO 27001

An international standard for managing information security, and the certification that goes with it. Frequently requested by customers and partners outside the U.S.

Risk Assessment

A review that identifies what could go wrong in your environment, how likely it is, and how much it would hurt — so you can spend on the risks that matter most.

Compliance Readiness

Preparing your business to pass an audit or meet a standard: closing gaps, documenting what you do, and getting evidence in order.

Billing & Contract Terms

SMB — Small and Medium-Sized Business

Generally a business under a few hundred employees. Harp is built specifically for this size, along with mid-market companies.

Per-Endpoint Pricing

Your monthly cost is the plan price multiplied by the number of devices you protect. Nothing is priced per feature, so the number is easy to predict.

Tier

The plan level you choose — Essential, Advanced, or Elite. Each tier adds capability on top of the one below it.

SLA — Service Level Agreement

The written commitment on how quickly Harp responds when something happens. Your plan determines your response times.

Auto-Renewal

Your term renews automatically at the end of each cycle unless either side gives 30 days' notice. It keeps protection from lapsing by accident.

Early Termination Charge

The amount owed if you end service before your committed term is up. It applies to committed terms, not month-to-month plans.

Portal

Harp's online account system. Billing, plan changes, and cancellations all run through it.

ROI — Return on Investment

What you get back compared to what you spend. In security, it's usually framed as the cost of prevention measured against the cost of a breach you avoided.

Don't see a term?

Ask us and we'll add it to the glossary.

Talk to an Expert →