Skip to main content
01543 524594  ·  hello@initialit.co.uk
CYBER ESSENTIALS · MICROSOFT PARTNER · UK HELPDESK · 5.0 ★ GOOGLE
HomeBlog › Cyber Security

The Top 100 Three-Letter Acronyms (TLAs) Every Business Should Know in IT

Andy Price · Founder23 July 2025 · 5 min read

Tired of hearing IT jargon you don’t understand? You’re not alone. At Initial IT, we believe in simplifying IT, and that includes decoding the endless sea of three-letter acronyms (TLAs) that dominate the tech world.

In short: IT is full of three-letter acronyms, and knowing a handful of them makes every supplier conversation easier. Here is a plain-English glossary of the ones that actually come up.

Key takeaways

  • IT is full of three-letter acronyms (TLAs) that suppliers use without explaining them.
  • This is a plain-English A to Z of the ones you will actually hear in business IT.
  • Knowing a handful makes budgeting, security and supplier conversations much easier.
  • Use the quick navigation to jump straight to the term you need.
  • If a provider cannot explain an acronym simply, that tells you something in itself.
Key points on the top 100 IT three-letter acronyms every business should know

So here’s a clear, concise cheat sheet of the top 100 TLAs in the industry, what they mean, and why they matter to your business.

Quick navigation

Jump straight to the bit you need:

The complete A-Z list

Sorted alphabetically so you can find what you need without scrolling forever.

TLAStands forWhat it means
ACLAccess Control ListDetermines who can access or modify resources in a network.
ADActive DirectoryManages team member access to systems and data in Windows environments.
APIApplication Programming InterfaceAllows software programs to talk to each other.
APTAdvanced Persistent ThreatA prolonged, targeted cyberattack.
AVAnti-VirusSoftware that detects and removes malicious software.
BECBusiness Email CompromiseA type of phishing attack that targets companies via email fraud.
BGPBorder Gateway ProtocolControls how data is routed between large networks.
CADComputer-Aided DesignSoftware used for designing products or buildings.
CPUCentral Processing UnitThe brain of a computer.
CRMCustomer Relationship ManagementSoftware to manage interactions with customers.
CSVComma-Separated ValuesA simple file format used to store tabular data.
CTOChief Technology OfficerSenior executive responsible for technology strategy.
DACDiscretionary Access ControlA system where the data owner decides who has access.
DBADatabase AdministratorManages and maintains databases.
DDRDouble Data RateA type of fast computer memory.
DFSDistributed File SystemAllows access to files across multiple locations.
DHCPDynamic Host Configuration ProtocolAutomatically assigns IP addresses to devices.
DLPData Loss PreventionTools that stop sensitive data from leaving the company network.
DMZDemilitarised ZoneA security buffer zone between a private network and the internet.
DNSDomain Name SystemTranslates website names (like google.com) into IP addresses.
DNSSECDNS Security ExtensionsProtects DNS from tampering.
DRPDisaster Recovery PlanA strategy for restoring operations after a cyberattack or failure.
EDREndpoint Detection and ResponseAdvanced threat detection and response on individual devices.
ERPEnterprise Resource PlanningSoftware to manage day-to-day business activities.
FATFile Allocation TableA file system for organising data on disks.
FDEFull Disk EncryptionEncrypts everything on a hard drive.
FTPFile Transfer ProtocolUsed to transfer files over the internet.
GPOGroup Policy ObjectCentralised way to control team member settings in Windows.
GUIGraphical Team member InterfaceVisual way to interact with computers (menus, icons).
HTMLHyperText Markup LanguageThe standard language for web pages.
HTTPHyperText Transfer ProtocolTransfers web content between servers and browsers.
HTTPSSecure HyperText Transfer ProtocolEncrypted version of HTTP that protects your data online.
IAMIdentity and Access ManagementEnsures only the right staff can access the right resources.
IDSIntrusion Detection SystemMonitors networks for suspicious activity.
IoTInternet of ThingsDevices connected to the internet, like smart thermostats.
IPInternet ProtocolThe rules that govern internet addressing and routing.
IPSIntrusion Prevention SystemDetects and blocks cyber threats.
IPTIP TelephonyVoice communication using internet protocol networks.
ISPInternet Service ProviderThe company that gives you internet access.
ITInformation TechnologyThe use of computers to store, retrieve, transmit, and manipulate data.
ITSMIT Service ManagementHow IT services are delivered to team members.
LANLocal Area NetworkA network within a small geographic area, like an office.
LDAPLightweight Directory Access ProtocolUsed to access and maintain directory information.
MDMMobile Device ManagementSecures and manages smartphones and tablets in a business.
MFAMulti-Factor AuthenticationAdds extra layers of login security beyond just a password.
NASNetwork Attached StorageA device that provides file storage over a network.
NATNetwork Address TranslationAllows multiple devices to share one IP address.
NDRNetwork Detection & ResponseMonitors and responds to threats at the network level.
OEMOriginal Equipment ManufacturerA company that makes parts for another company’s product.
OSOperating SystemSoftware that manages computer hardware.
OTPOne-Time PasswordA temporary password valid for one login.
PAMPrivileged Access ManagementControls and monitors access to critical systems.
PDFPortable Document FormatA universal file format for documents.
PSTPersonal Storage TableFile type used by Microsoft Outlook.
QoSQuality of ServicePrioritises internet traffic for better performance.
RAIDRedundant Array of Independent DisksImproves data storage performance or redundancy.
RDPRemote Desktop ProtocolAllows control of a computer remotely.
RMMRemote Monitoring & ManagementUsed by IT providers to maintain systems offsite.
ROMRead-Only MemoryPermanent computer memory.
RSARivest, Shamir, AdlemanA popular encryption algorithm.
SaaSSoftware as a ServiceSoftware accessed via the internet, like Microsoft 365.
SANStorage Area NetworkHigh-speed network of storage devices.
SDKSoftware Development KitTools for developers to build applications.
SDNSoftware-Defined NetworkingSimplifies how networks are managed and configured.
SIEMSecurity Information & Event ManagementCollects and analyses security data in real time.
SIMSubscriber Identity ModuleUsed in mobile phones to access networks.
SMTPSimple Mail Transfer ProtocolSends email messages.
SNMPSimple Network Management ProtocolManages networked devices like routers.
SoCSystem on ChipAll-in-one microchip for computing tasks.
SOCSecurity Operations CentreA team that monitors and responds to cyber threats 24/7.
SQLStructured Query LanguageManages and manipulates data in databases.
SSDSolid State DriveFast data storage device.
SSHSecure ShellSecure way to access remote systems.
SSLSecure Sockets LayerEncrypts data between browser and server.
SSOSingle Sign-OnOne login grants access to multiple systems.
TCPTransmission Control ProtocolEnsures reliable delivery of data over the internet.
TFATwo-Factor AuthenticationAnother name for MFA, double security.
TLSTransport Layer SecurityMore secure successor to SSL.
TPMTrusted Platform ModuleHardware chip for secure cryptographic operations.
UATTeam member Acceptance TestingFinal phase of software testing by real staff.
UDPTeam member Datagram ProtocolFaster, less reliable data transmission than TCP.
UITeam member InterfaceWhat staff see and interact with on a computer.
URLUniform Resource LocatorThe address of a web page.
USBUniversal Serial BusCommon connector for data and power.
UTMUnified Threat ManagementCombines multiple security tools in one solution.
VoIPVoice over IPMakes phone calls over the internet.
VPNVirtual Private NetworkCreates a secure, encrypted connection over the internet.
WAFWeb Application FirewallProtects web apps by filtering and monitoring HTTP traffic.
WANWide Area NetworkA network over a large geographic area.
Wi-FiWireless FidelityA wireless method for connecting to the internet.
XMLeXtensible Markup LanguageA standard way to structure data for sharing.
BYODBring Your Own DevicePolicy allowing staff to use personal devices for work.
CASBCloud Access Security BrokerSecurity layer between staff and cloud services.
DDoSDistributed Denial of ServiceAn attack that floods a service with traffic to take it offline.
FaaSFunction as a ServiceCloud platform for running code without managing servers.
IaaSInfrastructure as a ServiceCloud-hosted servers, storage and networking.
MSPManaged Service ProviderAn IT company that runs your IT department for a monthly fee.
NISTNational Institute of Standards and TechnologyUS body whose cyber framework is used worldwide.
PaaSPlatform as a ServiceCloud platform for building and running applications.
PIIPersonally Identifiable InformationData that can identify a specific person.
RBACRole-Based Access ControlAccess decisions based on a team’s job role.
ZTNAZero Trust Network AccessA model where every connection is verified, no implicit trust.

Frequently asked questions

What is the most important acronym in cyber security?

MFA (Multi-Factor Authentication) is the most important. It’s one of the simplest and most powerful tools to protect your accounts and data. If you do nothing else this year, switch on MFA for every account that supports it.

Are all these acronyms relevant to small businesses?

Not all, but many are. In particular, the cyber-security ones matter most (MFA, EDR, SOC, BEC, DLP). The Microsoft 365, RMM and backups ones (DRP, RAID, NAS) come next. The rest are useful background, so you understand what your IT provider is talking about.

How can I tell which ones matter to my business?

A good IT provider, like us, can help you assess which tools matter for your size and sector. Book a 30-min IT review. We’ll give you a no-jargon summary of what’s worth investing in next.

Do you cover all the cyber security acronyms with your services?

Yes. Our managed IT packages include EDR, MFA, SIEM-grade monitoring, DLP, conditional access (the modern equivalent of ACL/RBAC for cloud), DRP and Cyber Essentials alignment as standard. See pricing for what’s in each tier.

Bookmark this page, you’ll never be stumped by another acronym again. Spotted one we’ve missed? Email us and we’ll add it to the list.