Plain Language · No Jargon
Glossary: Security & AI, in plain English
Every acronym we use in our free small-business guides, explained without assuming you already know it. If a guide linked you here, the term you wanted is below.
- AI — Artificial Intelligence
- Software that performs tasks that normally need human judgment — writing, answering questions, recognizing patterns. In these guides it usually means a chat assistant like ChatGPT, Gemini, Copilot, or Claude.
- LLM — Large Language Model
- The kind of AI behind chat assistants. It's trained on huge amounts of text to predict and generate language. "The AI" and "the LLM" usually mean the same thing in everyday use.
- MFA — Multi-Factor Authentication
- A second step beyond your password to log in — a code from an app, a tap on your phone. It stops a stolen password from being enough on its own. The single highest-value, lowest-effort security setting.
- MSP — Managed Service Provider
- An outside company you hire to run your IT — email, computers, networks, helpdesk — so you don't need in-house staff for it.
- MSSP — Managed Security Service Provider
- Like an MSP, but focused on security specifically — monitoring for threats, responding to incidents, managing your security tools.
- DPA — Data Processing Agreement
- The part of a contract that says how a vendor is allowed to handle your data — what they can do with it, how they protect it, how long they keep it. Where "is our data used to train AI?" should be answered in writing.
- SaaS — Software as a Service
- Software you use over the internet by subscription instead of installing it — your email, CRM, accounting tool, etc. Many SaaS tools have quietly added AI features.
- DNS — Domain Name System
- The internet's address book, turning names (like a website) into the numbers computers use. DNS filtering blocks known-bad addresses before you reach them — a cheap, high-value protection you can often turn on for free.
- SPF / DKIM / DMARC — email authentication
- Three settings that prove your email really comes from you, so scammers can't easily impersonate your domain. DMARC is the policy that ties the other two together.
- CIS — Center for Internet Security
- A non-profit that publishes free, widely-respected security best-practice standards.
- IG1 — CIS Controls, Implementation Group 1
- The "essential cyber hygiene" tier of the CIS Controls — the minimum, foundational set of safeguards designed specifically for small, under-resourced organizations.
- TIPPSS — Trust, Identity, Privacy, Protection, Safety, Security
- A six-dimension framework (an IEEE standard, originally for connected medical devices) for thinking about whether a connected system is trustworthy. VCRI uses these six dimensions in its assessments.
- VCAR — VCRI's consequence / dollar-at-risk measure
- VCRI's way of expressing not just "how weak is this" but "how much does it cost or hurt if it fails" — so you can fix what matters most first.
- VCRI — Value Chain Risk Institute
- The non-profit (501(c)(3)) that publishes these free guides and the BeaconScore self-assessment.
- BeaconScore — VCRI's free security self-assessment
- A free tool that turns your security posture into a clear grade and shows what to fix first — like a beacon, it shows you the way. Nothing you enter leaves your browser. Open it →
- PII — Personally Identifiable Information
- Information that identifies a specific person — name, SSN, address, account numbers. The kind of data you should never paste into a free/consumer AI.
- HIPAA — Health Insurance Portability and Accountability Act
- The U.S. law governing how health information must be protected. If you handle patient data, it shapes what you're allowed to do with AI and vendors.
- PCI — Payment Card Industry (Data Security Standard)
- The security rules for handling credit-card data. If you take card payments, these apply to you.
- CC BY — Creative Commons Attribution license
- A license that lets anyone freely use, share, and adapt this material — even commercially — as long as they credit the source. It's why these guides are free to spread.
Missing a term? Tell us — info@valuechainrisk.org. Part of the Small Business Security Starter Kit.