Monitoring live · incident line answered 24×7 info@xoopie.com +91 74199-74199

The vocabulary, without the mystique.

Our industry uses acronyms as a moat. These are the terms that appear in most proposals you will receive — including ours — explained so you can hold your own in the conversation.

16 termsUpdated August 2026

  • RTO · Recovery time objective

    How long until you are operating again after a failure. If a supplier quotes an RTO without saying when it was last measured, it is an aspiration rather than a commitment.

  • RPO · Recovery point objective

    How much work you could lose, expressed as time. A 24-hour RPO means a failure at 4pm could cost you everything since the previous night's backup.

  • Immutable · WORM · Object Lock

    Write once, read many. Data that cannot be altered or deleted until a retention period expires — not by an administrator, not by the provider, not by ransomware. This single property is what separates a backup that survives an attack from one that does not.

  • Air gap

    A copy with no network path from production, so an attacker who owns your entire environment still cannot reach it. Slower to recover from, and occasionally the only thing left.

  • 3-2-1-1-0

    Three copies of data, on two media types, one held offsite, one immutable or air-gapped, and zero errors on a verified restore test. The last digit is the one most organisations skip.

  • SIEM · Log correlation

    Security information and event management. Collecting logs from every system into one place and joining them, so events that look harmless individually can be recognised as an attack collectively.

  • EDR · XDR

    Endpoint, or extended, detection and response. Software that watches behaviour on a device rather than matching known-bad signatures — which is why it can stop an attack it has never seen before.

  • UEBA · Behavioural baselining

    User and entity behaviour analytics. Learning what normal looks like for each account, so abnormal becomes visible without anyone writing a rule for it in advance.

  • MITRE ATT&CK

    A public catalogue of the techniques attackers actually use. Mapping detection coverage to it is how you find out which stages of an attack you would currently miss.

  • Zero trust

    Designing on the assumption that being inside the network proves nothing. Every request is authenticated and authorised on its own merits.

  • BEC · Business email compromise

    An attacker with access to a mailbox, or a convincing imitation of one, redirecting a legitimate payment. Rarely technically sophisticated, frequently the most expensive incident a mid-sized firm suffers.

  • DPDPA 2023

    India's Digital Personal Data Protection Act. Governs how personal data is collected, retained and handled, with obligations around consent, purpose limitation, data principal rights and breach notification.

  • Data residency · localisation

    Where your data physically sits. A regulatory question more often than a technical one, and easier to answer with evidence than with assurance.

  • Reverse engineering

    Determining how a system works without its source code or documentation — by observing behaviour, inspecting binaries and mapping data structures. Used both to secure software and to rescue businesses from software nobody can maintain.

  • Chain of custody

    The documented record of who handled evidence, when, and what they did with it. Without it, forensic findings may be technically correct and still fail to be useful in a dispute.

  • Blast radius

    How far an incident reached — which systems, which accounts, which data. Establishing it accurately is usually harder, and more important, than identifying the initial entry point.

← Back to xoopie.com