Skip to content
The Cyber Security Place

Reference

The words that are used to mean two things

There are enough dictionaries. What is missing is a list of the places where two people say one word, agree out loud, and walk away holding different meanings — which is where most of the expensive misunderstandings in this field begin.

Last reviewed August 25, 2026

50 terms, of which 15 are contested — used to mean different things by the party saying them and the party hearing them. Incident and breach differ by roughly a factor in survey figures and are reported under one word. Managed means enrolled, not controlled. Zero trust is an architecture that a gateway product does not deliver. An SBOM is worth having as a query and worthless as a filed document.Phishing-resistant requires that a credential cannot be replayed, which excludes codes and push approvals. End of life is three dates, and security updates stop at the earliest. Each entry states what the seller means, what the buyer hears, and what the difference costs. The pattern repeats: the reading that is easy to evidence displaces the reading that would change an outcome, and the substitution is invisible because everybody in the room agrees.

Which words are actually contested?

Filter for a term, or switch to the contested ones and read those alone. They are under half the list and they account for most of the trouble.

Reference50 terms, 15 of them contested

AttributionGovernancecontested

Naming who was responsible for an intrusion. It is the most quoted claim in this field and the one least often supported by evidence the victim holds: confident public attribution generally rests on intelligence gathered outside the incident, which is the sort of thing governments have and companies do not.

Seller A supplier naming a country within days is offering an inference assembled from tooling, infrastructure and the working hours visible in timestamps — a hypothesis wearing a flag.

Buyer The audience receives it as an established fact and repeats it as one. By the second retelling every qualifier has evaporated and the nationality has become the headline.

Cost of the gap For the defender’s actual week, nothing whatsoever changes: identical machines get rebuilt, identical regulators get notified. What shifts is the insurance posture, since a formal governmental accusation can transmute an indemnifiable loss into a protracted quarrel about a war exclusion.

State actors & espionage

UnderwritingGovernancecontested

The assessment an insurer makes before agreeing to carry a risk. Since ransomware losses erased the profit of the cyber class, it stopped being a formality and became the most effective security requirement most mid-sized organisations have ever met — multi-factor authentication on email is now, in practice, binary.

Seller A broker frames the questionnaire as administrative friction preceding a quotation.

Buyer The applicant completes it honestly, describing an unusually tidy Tuesday.

Cost of the gap The answers behave as continuing warranties. An exception granted in month seven can matter more at claim time than anything that was true when the policy was bound.

Cyber insurance

War exclusionGovernancecontested

A clause removing cover for losses caused by state-backed attacks. Modern wordings do not turn on whether a state was involved, which would be unarguable, but on scale: whether the attack had a major detrimental impact on a state, its essential services or its security.

Seller Introduced as boilerplate, of the sort marine and property contracts have carried since Victorian times.

Buyer Dismissed as inapplicable by a company that is manifestly at peace with everybody.

Cost of the gap The threshold gets adjudicated by intelligence analysts who will never glimpse your telemetry, on a calendar wholly unrelated to your renewal. Study the wording beforehand; construing it amid a crisis, with counsel billing hourly on both sides, is the expensive route.

Cyber insurance

Sub-limitGovernancecontested

A cap inside a policy that is lower than the headline figure, applying to one category of loss. Ransomware is the one that surprises people: a policy described as five million may carry a fraction of that for extortion.

Seller Advertised through the aggregate limit of indemnity — the arresting figure on the summary page.

Buyer Interpreted, reasonably, as the amount that would actually arrive.

Cost of the gap No refusal occurs and nothing is disputable. The contract disburses precisely what it promised, and the promise resided in an annex nobody opened.

Cyber insurance

PanelGovernancecontested

The list of lawyers, forensic responders and negotiators an insurer requires you to use. For a small organisation it is frequently worth more than the payout: it buys access at three in the morning to people you could not otherwise have found or afforded.

Seller Promoted as an inclusion: specialist expertise bundled with the indemnity.

Buyer Assumed to be optional, sitting alongside whichever consultancy already knows your estate.

Cost of the gap Instructing your own firm may prejudice the claim, and whoever does arrive reports to the carrier. Their objectives overlap generously with yours without ever coinciding: containment of expenditure ranks above satisfying your curiosity about causation.

Cyber insurance

Access reviewIdentitycontested

The periodic exercise in which somebody confirms that an account still needs what it can reach. It is the control that exists specifically to catch permissions nobody can justify, and it works by asking a person who knows.

Seller Marketed as governance: documentary evidence that entitlements receive supervision.

Buyer Experienced as a spreadsheet of unfamiliar rows requiring approval before Friday.

Cost of the gap Where nobody remembers, which describes most service accounts, the exercise emits no alarm. It concludes successfully, that row ratified by whichever manager happened to countersign the batch.

Machine identity

OffboardingIdentitycontested

Removing what a departing person could reach. Every documented procedure works from a list, the list comes from the central directory, and a substantial part of a modern estate never entered the central directory.

Seller Characterised as a checklist discharged on somebody’s final afternoon.

Buyer Presumed exhaustive precisely because the checklist reached its end.

Cost of the gap Departmental subscriptions procured on somebody’s card, grants conferred individually rather than through a group, and communal passwords memorised by four colleagues all outlive the ceremony unscathed.

Insider risk

Tabletop exerciseDetectioncontested

Walking through an incident around a table, without touching any systems. Its value is entirely in what it changes afterwards: an exercise that produced no follow-up actions was a presentation.

Seller Convened as a rehearsal of the documented plan.

Buyer Endured as an unusually theatrical meeting with sandwiches.

Cost of the gap Unrehearsed plans collapse at three predictable junctures — adjudication, spokesmanship, and possession of the telephone numbers — so a session that never provoked those three verified nothing.

Incident response

Business email compromiseFraud

Persuading somebody to send money or data by impersonating a colleague, supplier or executive over email. It carries no malware and no link, which is why it defeats controls built to find both, and it is a finance-process failure wearing a security costume.

Scams against people

Egress controlArchitecture

Restricting what may leave a network rather than what may enter it. Almost every control budget goes on the inbound direction, and almost every incident that matters involves something going out — a copy of a database, a beacon to an operator, an export scheduled to look like reporting.

Malware

PrepositioningAttack

Establishing access and holding it without using it, so that the capability exists on the day it is wanted. It is deliberately quiet, produces no loss to investigate, and is therefore almost impossible to fund a response to: the finding is that nothing happened.

Critical infrastructure

Post-quantumArchitecture

Cryptography chosen to survive a computer that does not exist yet. The deadline is not the arrival of that machine: it is how long your data stays sensitive, because anything intercepted today can be stored and read later. Data with a twenty-year confidentiality requirement is already exposed.

Encryption & privacy

Account takeoverFraud

Gaining control of an account that already exists and has a history, rather than opening a new one. It is the largest category of consumer identity fraud loss because everything the fraud checks look for — an established relationship, a familiar device, ordinary transaction patterns — is inherited along with the account.

Fraud & identity theft

Attack surfaceGeneral

Everything an outsider can reach and interact with. Useful as a direction of travel and treacherous as a measurement, because nobody agrees whether it counts hosts, services, endpoints, identities or all four, and the number therefore cannot be compared between two organisations or between two years of the same one.

Blast radiusCloud

How far an intruder reaches from a single foothold. In a cloud estate this is a graph traversal rather than a network diagram, because roles can assume other roles: a credential with modest direct permissions can arrive at sensitive data in two or three hops.

Cloud security

BreachGovernancecontested

In regulation, a confirmed compromise of personal data requiring notification. In ordinary usage, almost anything bad. The distinction matters more than any other in this glossary.

Seller Any confirmed unauthorised access, quoted to establish that the problem is large.

Buyer A notifiable event with legal consequences and a public disclosure.

Cost of the gap Survey figures for how many organisations were breached and how many had an incident differ by roughly a factor, and both get reported under the same word. Any comparison between two such figures is meaningless unless both stated which they measured.

Industry & market

Credential stuffingAttack

Trying username and password pairs from one breach against unrelated services, on the assumption that people reuse them. It requires no skill and no vulnerability, only a list, and it is the reason a breach at an unimportant service becomes your problem.

CVSSVulnerability

A scoring system for how severe a flaw could be in the abstract. It says nothing about whether the affected code is reachable in your deployment or whether anybody is exploiting it, which is why prioritising by score alone spends most of the effort on findings that cannot be reached.

Dependency confusionSupply chain

Publishing a public package with the same name as one of your internal ones, so a resolver checking both sources fetches the attacker's higher version number. The fix is configuration rather than detection: pin the source for internal names.

Supply chain risk

Dwell timeDetection

How long an intruder was present before anybody noticed. It is measured only on intrusions that were eventually found, which makes it a description of your detection rather than of their patience, and it runs long by default on equipment that cannot host an agent.

Network & infrastructure

EDRDetection

Software installed on a computer that records what processes do and can intervene. The category is mature and effective, and its defining limitation is that it must be installed — which excludes the boundary appliances now leading the intrusion figures.

End of lifeGovernancecontested

The date after which the manufacturer will publish no further fixes. On an internet-facing device this is not a warning, it is a replacement date, and roughly two fifths of exploited edge flaws in one recent analysis affected hardware already past it.

Seller End of sale, end of standard support, end of extended support — three different dates, usually quoted as one.

Buyer The date the equipment stops being safe to operate.

Cost of the gap Buyers routinely plan against the latest of the three and discover that security updates stopped at the earliest. Ask which one the date in the contract refers to.

EPSSVulnerability

A probability that a flaw will be exploited in the near term, derived from observed activity. More useful than severity alone for ordering a queue, and still no substitute for knowing whether the affected path exists in your build.

ExposureGeneral

What could actually be reached and used, as distinct from what exists. A vulnerable library present in a build is a vulnerability; the same library reachable from an internet-facing endpoint is an exposure. Most prioritisation failures come from treating the two as one.

InjectionApplication

Any attack where input is treated as instruction. In a database query the problem is solved completely by separating the command from its values. In a language model no equivalent separation exists, which is why the same word describes a closed problem in one place and an open one in the other.

AI & security

KEV catalogueVulnerability

A public list of flaws known to be exploited, published so that defenders can prioritise. It does what it says and is widely treated as the whole priority list, which it is not: of the network edge flaws seen exploited in one recent year, under a quarter appeared in it.

Network & infrastructure

Lateral movementAttack

Getting from the first machine to the one that mattered. It is the phase where most intrusions are either stopped or become expensive, and it is enabled almost entirely by shared credentials and flat networks rather than by anything sophisticated.

Least privilegeCloud

Granting each identity only what it needs. Correct and insufficient on its own: every link in a permission chain is already something needed, so trimming each grant individually does not break the chain. What breaks it is refusing to let certain hops exist at all.

Cloud security

Lethal trifectaAI

The combination of access to private data, exposure to text written by strangers, and any means of communicating outwards. Any two are containable; all three make an assistant into an exfiltration tool for whoever can put words in front of it.

AI & security

Liveness detectionIdentity

Checking that a face presented to a camera belongs to a present, living person. It defeats somebody holding a photograph and frequently fails against video injected directly through a virtual camera, because it examines content rather than provenance.

Fraud & identity theft

ManagedEndpointcontested

Enrolled in a management platform. Not the same as controlled, and the gap between those two readings is where a great deal of mobile exposure sits.

Seller The device is enrolled, policy applies to the work profile, and the console shows it.

Buyer The organisation can see and control what happens on that device.

Cost of the gap A compromise arriving through personal messages and personal applications is invisible to the console, which reports green throughout — accurately, because the work profile was never the problem.

Endpoint & mobile

MFA fatigueIdentity

Sending repeated approval prompts until somebody accepts one to make it stop. It is not an attack on the technology but on the person, and it is closed by methods that require a specific action tied to the session rather than a yes or no.

MTTD and MTTRDetection

Mean time to detect and mean time to respond. Both are averages over the incidents you found, so improvements can indicate better detection or fewer detected incidents, and neither number is comparable between organisations that define an incident differently.

Non-human identityCloud

A credential belonging to a machine: a service account, a pipeline role, an API key, a workload identity. They outnumber people by ratios from tens to one upwards, and almost none has an owner or an expiry, because nothing about a machine ever resigns.

Cloud security

PasskeyIdentity

A credential bound cryptographically to the site that issued it, held on a device and never transmitted. Presented with a convincing replica on a lookalike address, the authenticator has nothing to offer, which removes credential theft rather than reducing it.

Security awareness

Phishing-resistantIdentitycontested

An authentication method that cannot be replayed against a site other than the one it was registered with. The term is precise and frequently applied loosely to methods that merely make interception harder.

Seller Multi-factor authentication with a push notification or a one-time code.

Buyer A method a phishing site cannot defeat.

Cost of the gap Codes and push approvals are relayed in real time by proxy tooling that is widely available. A deployment described as phishing-resistant that retains a code-based fallback has kept the original weakness and added a route to it.

Prompt injectionAI

Text reaching a language system that is treated as a directive rather than as material to work on. It is a property of the architecture rather than a defect in an implementation, which is why published defences keep falling to adapted attempts.

AI & security

ReachabilityApplication

Whether execution can actually get from your code to a vulnerable function, as opposed to whether the vulnerable component is present. It is the only way of shortening a findings queue that removes non-problems rather than ignoring real ones.

Application security

RiskGovernancecontested

Strictly, the combination of how likely something is and what it would cost. Loosely, whatever the speaker is worried about.

Seller A score, usually a colour, produced by a product.

Buyer A statement about likelihood and consequence that can inform a decision.

Cost of the gap A risk register full of scored items with no likelihood, no cost and no owner cannot be used to choose between two pieces of work, which is the only thing a risk register is for.

SBOMSupply chaincontested

An inventory of the components inside a piece of software.

Seller A document, generated once, satisfying a requirement.

Buyer The ability to answer whether you are affected when a flaw is published.

Cost of the gap A list generated once and filed describes a graph that changes every build. The value is in regenerating it automatically and being able to query it in minutes; minutes against days is the whole exposure.

Supply chain risk

Security debtApplication

A known flaw left unrepaired for more than a year. The category is useful because it separates work in progress from work that has quietly become permanent, and it is now the normal condition rather than the exception.

Application security

Shift leftApplication

Moving security activity earlier in development. The durable half is about feedback latency and it works. The half that failed assumed that moving detection earlier also moves the repair work earlier, when it moves the alerts earlier to people with no authority to decide which matter.

Application security

Significant incidentGovernance

The threshold that starts a reporting clock under the essential entities regime. Like every such term it is a judgement made early with partial information, which is why classification rather than reporting is the binding activity.

Compliance & regulation

SIM swapFraud

Persuading a carrier to move a telephone number to a different device, after which every code sent to it follows. The organisation whose account is protected by those codes has no visibility into the transfer and no ability to prevent it.

Endpoint & mobile

SmishingAttack

A lure delivered by text message. Measured click rates run around forty per cent above the same material by email, because there is no sender domain to inspect, no filtering layer, and the message is read while doing something else.

Endpoint & mobile

Synthetic identityFraud

An identity assembled from parts rather than stolen whole, typically a real but unused identification number with a fabricated name and date of birth. Nobody is impersonated, so nobody complains, which is why the estimated losses exceed the measured ones.

Fraud & identity theft

ThreatGovernance

Somebody or something with the capability and intent to cause harm. Distinct from a vulnerability, which is the weakness they would use, and from a risk, which is what it would cost you. The three words are used interchangeably in most conversations and mean three different things.

TyposquattingSupply chain

Publishing a package whose name differs from a popular one by a character, and waiting. It compromises nothing, costs nothing per attempt, and accounts for most malicious packages on public registries — which is why most of them have very low download counts.

Supply chain risk

VulnerabilityApplication

A weakness that could be used to cause harm. The word describes a property of software; whether it matters to you depends on reachability and exposure, neither of which is contained in the vulnerability itself.

Zero trustArchitecturecontested

The principle that arriving inside a network confers nothing, and that every request must prove itself to the service it reaches.

Seller A gateway product that terminates connections and mediates access.

Buyer An architecture in which internal services stop trusting the network.

Cost of the gap A device that terminates every connection is architecturally the same object as the concentrator it replaced, sold with newer vocabulary. What reduces exposure is internal services authenticating each request, which is a multi-year programme rather than a purchase.

Network & infrastructure

One word, two meanings, no argument

Set out side by side, the contested entries all have the same shape.

what is meantwhat is heardany confirmed accessa notifiable eventBreachenrolledcontrolledManageda gatewayan architectureZero trusta documenta querySBOMstrong authenticationunreplayablePhishing-resistanta coloured scorelikelihood × costRiskone datethree datesEnd of lifethe gap is the same gap in every row

None of these is a trick or a lie. In each row both readings are defensible, both are in common use, and the person using the word usually has no idea the other reading exists. That is what makes the failure mode so durable: nobody is being misled, so nobody checks.

What the rows share is a direction. The left-hand reading is consistently the one that is easier to demonstrate — a device is enrolled, a document exists, a product is installed, a score is amber. The right-hand reading is consistently the one that would change an outcome, and it is consistently harder to evidence. Words drift towards the meaning that can be shown, and the meaning that mattered is quietly left behind.

Incident, breach, and the factor between them

This is the most consequential pair in the field, and the confusion is worth setting out precisely because it corrupts almost every statistic anybody quotes.

In surveys the two are interchangeable. A questionnaire asking about a security incident returns a figure several times larger than one asking about a breach, because the first counts a suspicious message somebody reported. Both appear under headlines about how many organisations were breached, and both are then cited in one sentence as though they measured a single quantity.

The practical consequence is that any figure of the form N per cent of organisations were breached last year is uninterpretable without the question wording, and the question wording is almost never published. It is worth being blunt about the direction of the incentive: the larger number is the more useful one for whoever commissioned the research, and the larger number comes from the looser definition.

Internally the fix is small and unpopular. Pick one word for the regulated thing and one for everything else, write both into the incident procedure, and correct people who blur them — including when the blurring makes the numbers look better.

Why do definitions decide budgets?

Because a decision needs a comparison, a comparison needs numbers, and in this field the numbers are constituted by their definitions rather than merely described by them.

Take the simplest example available. Ask how many security tools an organisation runs and the honest answer ranges from about fourteen to about a hundred and thirty for one unchanged estate, depending on whether you count suite modules separately, include capabilities licensed and never enabled, count agents or consoles, and include what other teams bought. Every one of those rules is defensible. None is usually stated.

Now put that figure to work. It appears in a board paper as evidence of complexity, in a consolidation proposal as the size of the problem, and in vendor material as the reason to buy a platform. Whoever picked the counting rule picked the conclusion, and because the rule was never written down, nobody in the room can see that a choice was made at all.

The same structure recurs with dwell time, which depends on which intrusions you found; with mean time to respond, which improves when you detect fewer things; with breach cost, which varies by an order of magnitude depending on whether lost business and staff time are included. In each case the disagreement looks empirical and is definitional.

The test that cuts through all of it is a single question, worth asking out loud in any meeting where a figure is presented: what would somebody else have to do to get this same number? If that cannot be answered, the figure is a claim rather than a measurement, and it should carry the weight of one.

Which terms changed meaning underneath us?

A few words in this field have moved far enough that reading older material requires translation, and the direction of the drift is instructive.

Endpoint meant a desktop computer. It now includes a handset that the organisation does not own, cannot inspect and did not buy, which changes what any sentence containing the word actually commits you to.

Perimeter meant a boundary you defended against traffic pushing at it. The equipment at that boundary is now the most attacked machine in most estates, and it is walked through rather than pushed against — the same word, opposite direction.

Artificial intelligence in this archive's earlier years names a category of detection product you procure and evaluate. It now names something you deploy, which reads your correspondence and can act. A sentence about buying it and a sentence about defending it use identical words.

Supply chain meant logistics and third-party vendors. It now primarily means the software components inside your own build, arriving from people you have never evaluated.

The pattern in all four is that the word stayed while the referent moved, which is the most expensive kind of drift. A word that visibly changes gets renegotiated. A word that quietly acquires a new referent carries old assumptions into a situation where they no longer hold.

Risk, threat, vulnerability, exposure

Four words used interchangeably in most conversations, describing four different things, and keeping them separate is the cheapest analytical improvement available to anybody working in this field.

The four are defined separately above. What the definitions cannot convey is which one goes missing: exposure, almost always. Dropping it is why a critical-rated flaw on an unreachable path outranks a moderate one on an internet-facing endpoint in most queues, and why registers fill with weaknesses wearing colours instead of consequences.

The practical test for whether a register is doing its job: pick two entries and ask which should be done first. If the register cannot answer, it is recording vulnerabilities and calling them risks, which is the commonest failure in governance documentation and follows entirely from the vocabulary.

Is 'zero trust' still a useful term?

The principle is sound and the phrase has been worn thin by being attached to products that do not deliver it. Both halves of that sentence need saying.

The difficulty is commercial rather than intellectual. Delivering the principle is a multi-year programme touching every internal service, and a programme is hard to sell. A gateway carrying the same vocabulary is easy to sell, and it reproduces the object it replaced.

So the term remains useful and requires a follow-up question. When somebody says they are doing zero trust, ask which internal services now authenticate every request. If the answer is a product name, the conversation is about a purchase. If the answer is a list of services, it is about an architecture, and the two have almost nothing in common.

Which words are worth refusing?

A shorter list, included because what a glossary omits is as informative as what it defines.

Next-generation and advanced describe when a product was marketed rather than what it does. Every category has had a next generation for fifteen years, and the phrase has never once distinguished two products in a shortlist.

Military-grade and bank-grade refer to no standard that exists. The underlying claim is usually about a specific encryption algorithm that is also used by everybody else, including the free tools.

Unhackable and 100% protection are claims no engineer would make, and their presence in material is a reliable indicator that no engineer reviewed it.

Cyber as a standalone noun — as in doing cyber — is worth avoiding for a narrower reason. It reliably signals a conversation in which nobody is going to name a specific control, and it is the vocabulary a subject acquires when it is being discussed by people who have decided not to look inside it.

The rule underneath these omissions is that a word earns its place by narrowing what could be true. If a sentence means the same thing with the adjective removed, the adjective was doing decoration rather than work.

How to write a definition into a contract

Four habits, each of which prevents a specific argument that otherwise arrives eighteen months later with lawyers attached.

Name the counting rule, not the word. Not the supplier will report all security incidents, but a statement of what qualifies: which categories, at what threshold, confirmed by whom. A term defined by example will be argued about.

Say which clock, from which event. Every reporting deadline counts from something, and the something differs between regimes. Write down the trigger alongside the number of hours, because the trigger is where the disputes are.

Pin the dates that have several versions. Support commitments in particular: specify which of end of sale, end of standard support and end of extended support the obligation attaches to, and what happens to security fixes after each.

Define the negative. State what does not count, explicitly. Most definitional arguments are about the boundary rather than the centre, and a clause naming three things that are excluded is worth more than a paragraph describing what is included.

What to do when two teams use one word differently

This is the everyday version of everything above, and it has a reliable signature: a meeting in which everybody agrees and nothing subsequently happens the way anybody expected.

The signature is worth learning because agreement is the symptom. When two people use a word with different meanings, the conversation runs more smoothly than it should — each hears their own reading confirmed, nobody has a reason to probe, and the divergence surfaces weeks later when one of them acts on a commitment the other did not make.

The remedy is small and slightly awkward. When a word is carrying weight in a decision, ask the other person to say what would be true if it were the case.What would we see, specifically, if this fleet were managed? The answers diverge immediately, and they diverge in the room rather than in an incident.

Where the divergence is structural rather than accidental — the security team means one thing by an incident and the service desk means another, and both are right for their purposes — the answer is not to force one meaning. It is to stop using the bare word in shared documents and qualify it every time, which is clumsy prose and cheaper than the alternative.

The whole of this page reduces to a single working habit. When a word is doing important work, make somebody say what it excludes. Everything in the list above was discovered that way, by people who asked once and found out that two of them had been agreeing for a year about different things.

Common questions

What is the difference between an incident and a breach?

In regulation a breach is a confirmed compromise of personal data that triggers notification duties; an incident is anything that required a response. Survey figures for the two differ by roughly a factor and both get reported under the same word, which makes any comparison meaningless unless each source stated which it counted.

Why does a glossary matter more than it used to?

Because most of the field's figures are definitional rather than empirical. How many tools you run, how many incidents you had, whether your fleet is managed — each answer moves by a factor depending on a counting rule that is almost never published.

What does 'managed' mean for a device?

Usually that it is enrolled in a management platform, which controls the work profile and its data. It does not mean the organisation can see personal applications, personal messages or personal browsing, which is where most mobile exposure sits.

Is zero trust a product or an architecture?

An architecture. The principle is that internal services stop trusting the network and authenticate every request. A gateway that terminates every connection is architecturally the same object as the concentrator it replaced, and buying one does not deliver the principle.

What is the difference between risk, threat and vulnerability?

A vulnerability is a weakness, a threat is somebody with the capability and intent to use it, and risk is what it would cost you weighted by how likely it is. The three are used interchangeably in most conversations and describe three different things.

What does phishing-resistant actually require?

That the credential cannot be replayed against any site other than the one it was registered with. Codes and push approvals are relayed in real time by widely available tooling, so a deployment retaining a code-based fallback has kept the original weakness.

Does an SBOM mean a document or a capability?

It should mean a capability. A list generated once and filed describes a graph that changes every build. What has value is regenerating it automatically and being able to query it in minutes when a flaw is published.

Why is 'end of life' three dates?

End of sale, end of standard support and end of extended support are separate, and vendor material frequently quotes whichever is furthest away. Security updates typically stop at the earliest of the three, so ask which one a contractual date refers to.

What is the lethal trifecta?

Access to private data, exposure to text written by strangers, and any means of communicating outwards. Any two are containable; all three make an assistant into an exfiltration tool for anybody who can put words in front of it.

Why is prompt injection not just another injection flaw?

Because the fix that closed database injection — separating the command from its values along different paths — has no equivalent here. A language model reads one stream and has no channel marking which portion was authorised.

How should a definition be written into a contract?

Name the counting rule, not the word. Specify what an incident includes, what managed covers, which of the three end-of-life dates applies, and what has to be true for a report to be produced. A term defined by example is a term that will be argued about.

What should happen when two teams use one word differently?

Stop using it until both have written down what they mean. The usual failure is a meeting where everybody agrees, because the word carried agreement while the meanings diverged, and the disagreement surfaces months later as a missed obligation.

Where each of these is worked through

The entries above are summaries. Each subject area is covered at length elsewhere on the site, across 13 fields.