You are sitting with a vendor, an insurance agent, or the new IT person, and about ninety seconds in you realize you have quietly stopped understanding the words. Somebody says “we will push the patch to your endpoints after hours” and everyone nods. You nod too, because you are the owner and nodding is part of the job, and because stopping the meeting to ask what an endpoint is feels like admitting something you would rather not admit.

That is not your failure. Our industry has a bad habit of using shorthand in rooms where nobody else shares it, then treating the confusion that follows as a customer problem. You should not have to learn a second language to buy a service. So we are starting a series to fix it, ten terms at a time, translated into the language you actually run your business in. This is Part One. There will be more, and each one takes another ten words off the pile.

How This Glossary Works

Every entry gets two things: what the word means in plain English, and the question you can ask to find out whether it is being handled well. That second part is the point. A definition you cannot act on is trivia. A definition that hands you one good question to ask your IT provider is leverage.

These are not the ten most technically important terms in computing. They are the ten that come up most often in real conversations with owners here in Denton County, in the kind of meeting where a decision is about to get made and everyone is pretending to follow along.

Terms One Through Three: The Stuff You Own

  • Endpoint. An endpoint is any device a human being uses to touch your business data. Laptops, desktops, phones, the tablet at the front counter, the laptop your bookkeeper uses from home. When someone says “we secure your endpoints,” they mean “we put protection on your computers and phones.” The useful question: which of my devices are actually covered, and can you show me the list? The gap between the devices you think are covered and the devices actually covered is where most trouble starts.
  • Patch. A patch is a small update from a software company that fixes something broken or closes a security hole they found after they shipped the product. Patching is applying those updates on purpose instead of clicking “remind me tomorrow” for eight months. The Cybersecurity and Infrastructure Security Agency, the federal agency known as CISA, keeps a public catalog of software flaws criminals are actively exploiting, which exists precisely because unpatched software is such a reliable way in. The useful question: how do we know every machine got last month’s updates, and what happens to the ones that failed?
  • Software as a service, or SaaS. Software you rent by the month and use through a web browser instead of installing it and owning it forever. Microsoft 365, QuickBooks Online, your scheduling tool. The mental model that keeps owners out of trouble: the cloud is just someone else’s computer. That is not a criticism, their computer is usually better run than yours would be, but it means their outage becomes your outage. The useful question: if this vendor went dark for three days, what would we do?

Terms Four and Five: The Stuff That Goes Wrong

  • Phishing. A fake message designed to get a real person to hand over something valuable, usually a password or a payment. It arrives as an email, a text, or a call, and the good ones do not look fake. They look like your bank, your vendor, or your own controller. Phishing is the front door for most business fraud because it skips your technology and goes straight at your people. The useful question: what actually happens when one of my employees clicks a bad link, and would I find out?
  • Ransomware. Software that scrambles your files so you cannot read them, then demands payment for the key to unscramble them. Modern versions also copy your data out first, so paying does not necessarily end it. This is not a large company issue. Verizon’s 2025 Data Breach Investigations Report found ransomware present in eighty-eight percent of breaches at small and medium businesses, compared with thirty-nine percent at large organizations. The useful question: if every file we own were locked tomorrow morning, how many hours until we are back to work?

Terms Six and Seven: The Stuff That Keeps It From Going Wrong

  • Multi-factor authentication, or MFA. Requiring a second proof of identity beyond the password, usually a code from an app on your phone or a tap on a physical key. It exists because passwords get stolen constantly, and a stolen password is worthless if it is not enough by itself. The FBI lists enabling two-factor or multi-factor authentication among its core recommendations for avoiding business email fraud. If you do one thing after reading this, make it this one. The useful question: is MFA on for every single account, including the owner’s, the bookkeeper’s, and the ones nobody uses anymore?
  • Least privilege. The practice of giving each person exactly the access their job requires and nothing more. Your warehouse lead does not need the ability to change payroll. This sounds bureaucratic until you remember that when an account gets taken over, whoever took it inherits everything that account could reach. Least privilege shrinks the damage. The useful question: if my most junior employee’s account were taken over tonight, what could the person on the other end actually get to?

Terms Eight Through Ten: The Stuff That Happens After

  • Backup versus sync. These are not the same thing, and the difference has cost people their businesses. A sync service, like the shared drive everyone saves to, copies changes everywhere immediately. That is convenient, and it also means a file that gets encrypted gets encrypted everywhere, immediately. A backup is a separate copy from a specific moment in time that a bad event cannot reach into and ruin. The useful question: is our backup something an attacker who owns an employee’s login could delete?
  • Recovery time objective and recovery point objective, RTO and RPO. Two numbers that turn “we have backups” into a plan. RTO is how long you can be down before it really hurts. RPO is how much work you can afford to redo, measured in time. If your RPO is one hour, you need backups running at least hourly. Most owners have never been asked for these numbers, which is a shame, because they are business decisions, not technical ones. The useful question: what are our two numbers, and does the current setup actually meet them?
  • Service level agreement, or SLA. The written promise about how fast a provider responds and resolves things, with the categories defined. A real SLA distinguishes between “the whole office is down” and “my mouse is acting weird,” with a different response time for each. A weak one says “we respond promptly.” The useful question: what is the promised response time for a total outage, and what happens if it is missed?

The Bottom Line

You do not need to become technical. You need enough vocabulary to tell whether the person across the table is answering your question or steering around it, and these ten words cover a lot of tables.

Part Two covers the next ten, including the networking terms and the insurance vocabulary that shows up on cyber policy applications. In the meantime, if you hit a definition here and realized you do not know the answer to the question underneath it, that is worth a conversation. We work with small and mid-sized businesses across Denton County and the wider DFW area, and we are glad to walk the list with you and tell you honestly where you stand. Reach us at https://harrisonward.com/contact/.


Sources

Comments are closed

This website uses cookies and asks your personal data to enhance your browsing experience. We are committed to protecting your privacy and ensuring your data is handled in compliance with the General Data Protection Regulation (GDPR).