Tired of hearing IT jargon you don’t understand? You’re not alone. At Initial IT, we believe in simplifying IT, and that includes decoding the endless sea of three-letter acronyms (TLAs) that dominate the tech world.
In short: IT is full of three-letter acronyms, and knowing a handful of them makes every supplier conversation easier. Here is a plain-English glossary of the ones that actually come up.
Key takeaways
- IT is full of three-letter acronyms (TLAs) that suppliers use without explaining them.
- This is a plain-English A to Z of the ones you will actually hear in business IT.
- Knowing a handful makes budgeting, security and supplier conversations much easier.
- Use the quick navigation to jump straight to the term you need.
- If a provider cannot explain an acronym simply, that tells you something in itself.

So here’s a clear, concise cheat sheet of the top 100 TLAs in the industry, what they mean, and why they matter to your business.
Quick navigation
Jump straight to the bit you need:
The complete A-Z list
Sorted alphabetically so you can find what you need without scrolling forever.
| TLA | Stands for | What it means |
|---|---|---|
| ACL | Access Control List | Determines who can access or modify resources in a network. |
| AD | Active Directory | Manages team member access to systems and data in Windows environments. |
| API | Application Programming Interface | Allows software programs to talk to each other. |
| APT | Advanced Persistent Threat | A prolonged, targeted cyberattack. |
| AV | Anti-Virus | Software that detects and removes malicious software. |
| BEC | Business Email Compromise | A type of phishing attack that targets companies via email fraud. |
| BGP | Border Gateway Protocol | Controls how data is routed between large networks. |
| CAD | Computer-Aided Design | Software used for designing products or buildings. |
| CPU | Central Processing Unit | The brain of a computer. |
| CRM | Customer Relationship Management | Software to manage interactions with customers. |
| CSV | Comma-Separated Values | A simple file format used to store tabular data. |
| CTO | Chief Technology Officer | Senior executive responsible for technology strategy. |
| DAC | Discretionary Access Control | A system where the data owner decides who has access. |
| DBA | Database Administrator | Manages and maintains databases. |
| DDR | Double Data Rate | A type of fast computer memory. |
| DFS | Distributed File System | Allows access to files across multiple locations. |
| DHCP | Dynamic Host Configuration Protocol | Automatically assigns IP addresses to devices. |
| DLP | Data Loss Prevention | Tools that stop sensitive data from leaving the company network. |
| DMZ | Demilitarised Zone | A security buffer zone between a private network and the internet. |
| DNS | Domain Name System | Translates website names (like google.com) into IP addresses. |
| DNSSEC | DNS Security Extensions | Protects DNS from tampering. |
| DRP | Disaster Recovery Plan | A strategy for restoring operations after a cyberattack or failure. |
| EDR | Endpoint Detection and Response | Advanced threat detection and response on individual devices. |
| ERP | Enterprise Resource Planning | Software to manage day-to-day business activities. |
| FAT | File Allocation Table | A file system for organising data on disks. |
| FDE | Full Disk Encryption | Encrypts everything on a hard drive. |
| FTP | File Transfer Protocol | Used to transfer files over the internet. |
| GPO | Group Policy Object | Centralised way to control team member settings in Windows. |
| GUI | Graphical Team member Interface | Visual way to interact with computers (menus, icons). |
| HTML | HyperText Markup Language | The standard language for web pages. |
| HTTP | HyperText Transfer Protocol | Transfers web content between servers and browsers. |
| HTTPS | Secure HyperText Transfer Protocol | Encrypted version of HTTP that protects your data online. |
| IAM | Identity and Access Management | Ensures only the right staff can access the right resources. |
| IDS | Intrusion Detection System | Monitors networks for suspicious activity. |
| IoT | Internet of Things | Devices connected to the internet, like smart thermostats. |
| IP | Internet Protocol | The rules that govern internet addressing and routing. |
| IPS | Intrusion Prevention System | Detects and blocks cyber threats. |
| IPT | IP Telephony | Voice communication using internet protocol networks. |
| ISP | Internet Service Provider | The company that gives you internet access. |
| IT | Information Technology | The use of computers to store, retrieve, transmit, and manipulate data. |
| ITSM | IT Service Management | How IT services are delivered to team members. |
| LAN | Local Area Network | A network within a small geographic area, like an office. |
| LDAP | Lightweight Directory Access Protocol | Used to access and maintain directory information. |
| MDM | Mobile Device Management | Secures and manages smartphones and tablets in a business. |
| MFA | Multi-Factor Authentication | Adds extra layers of login security beyond just a password. |
| NAS | Network Attached Storage | A device that provides file storage over a network. |
| NAT | Network Address Translation | Allows multiple devices to share one IP address. |
| NDR | Network Detection & Response | Monitors and responds to threats at the network level. |
| OEM | Original Equipment Manufacturer | A company that makes parts for another company’s product. |
| OS | Operating System | Software that manages computer hardware. |
| OTP | One-Time Password | A temporary password valid for one login. |
| PAM | Privileged Access Management | Controls and monitors access to critical systems. |
| Portable Document Format | A universal file format for documents. | |
| PST | Personal Storage Table | File type used by Microsoft Outlook. |
| QoS | Quality of Service | Prioritises internet traffic for better performance. |
| RAID | Redundant Array of Independent Disks | Improves data storage performance or redundancy. |
| RDP | Remote Desktop Protocol | Allows control of a computer remotely. |
| RMM | Remote Monitoring & Management | Used by IT providers to maintain systems offsite. |
| ROM | Read-Only Memory | Permanent computer memory. |
| RSA | Rivest, Shamir, Adleman | A popular encryption algorithm. |
| SaaS | Software as a Service | Software accessed via the internet, like Microsoft 365. |
| SAN | Storage Area Network | High-speed network of storage devices. |
| SDK | Software Development Kit | Tools for developers to build applications. |
| SDN | Software-Defined Networking | Simplifies how networks are managed and configured. |
| SIEM | Security Information & Event Management | Collects and analyses security data in real time. |
| SIM | Subscriber Identity Module | Used in mobile phones to access networks. |
| SMTP | Simple Mail Transfer Protocol | Sends email messages. |
| SNMP | Simple Network Management Protocol | Manages networked devices like routers. |
| SoC | System on Chip | All-in-one microchip for computing tasks. |
| SOC | Security Operations Centre | A team that monitors and responds to cyber threats 24/7. |
| SQL | Structured Query Language | Manages and manipulates data in databases. |
| SSD | Solid State Drive | Fast data storage device. |
| SSH | Secure Shell | Secure way to access remote systems. |
| SSL | Secure Sockets Layer | Encrypts data between browser and server. |
| SSO | Single Sign-On | One login grants access to multiple systems. |
| TCP | Transmission Control Protocol | Ensures reliable delivery of data over the internet. |
| TFA | Two-Factor Authentication | Another name for MFA, double security. |
| TLS | Transport Layer Security | More secure successor to SSL. |
| TPM | Trusted Platform Module | Hardware chip for secure cryptographic operations. |
| UAT | Team member Acceptance Testing | Final phase of software testing by real staff. |
| UDP | Team member Datagram Protocol | Faster, less reliable data transmission than TCP. |
| UI | Team member Interface | What staff see and interact with on a computer. |
| URL | Uniform Resource Locator | The address of a web page. |
| USB | Universal Serial Bus | Common connector for data and power. |
| UTM | Unified Threat Management | Combines multiple security tools in one solution. |
| VoIP | Voice over IP | Makes phone calls over the internet. |
| VPN | Virtual Private Network | Creates a secure, encrypted connection over the internet. |
| WAF | Web Application Firewall | Protects web apps by filtering and monitoring HTTP traffic. |
| WAN | Wide Area Network | A network over a large geographic area. |
| Wi-Fi | Wireless Fidelity | A wireless method for connecting to the internet. |
| XML | eXtensible Markup Language | A standard way to structure data for sharing. |
| BYOD | Bring Your Own Device | Policy allowing staff to use personal devices for work. |
| CASB | Cloud Access Security Broker | Security layer between staff and cloud services. |
| DDoS | Distributed Denial of Service | An attack that floods a service with traffic to take it offline. |
| FaaS | Function as a Service | Cloud platform for running code without managing servers. |
| IaaS | Infrastructure as a Service | Cloud-hosted servers, storage and networking. |
| MSP | Managed Service Provider | An IT company that runs your IT department for a monthly fee. |
| NIST | National Institute of Standards and Technology | US body whose cyber framework is used worldwide. |
| PaaS | Platform as a Service | Cloud platform for building and running applications. |
| PII | Personally Identifiable Information | Data that can identify a specific person. |
| RBAC | Role-Based Access Control | Access decisions based on a team’s job role. |
| ZTNA | Zero Trust Network Access | A model where every connection is verified, no implicit trust. |
Frequently asked questions
What is the most important acronym in cyber security?
MFA (Multi-Factor Authentication) is the most important. It’s one of the simplest and most powerful tools to protect your accounts and data. If you do nothing else this year, switch on MFA for every account that supports it.
Are all these acronyms relevant to small businesses?
Not all, but many are. In particular, the cyber-security ones matter most (MFA, EDR, SOC, BEC, DLP). The Microsoft 365, RMM and backups ones (DRP, RAID, NAS) come next. The rest are useful background, so you understand what your IT provider is talking about.
How can I tell which ones matter to my business?
A good IT provider, like us, can help you assess which tools matter for your size and sector. Book a 30-min IT review. We’ll give you a no-jargon summary of what’s worth investing in next.
Do you cover all the cyber security acronyms with your services?
Yes. Our managed IT packages include EDR, MFA, SIEM-grade monitoring, DLP, conditional access (the modern equivalent of ACL/RBAC for cloud), DRP and Cyber Essentials alignment as standard. See pricing for what’s in each tier.
Bookmark this page, you’ll never be stumped by another acronym again. Spotted one we’ve missed? Email us and we’ll add it to the list.
