How to read this glossary
Each entry gives the term as a security practitioner uses it, then the nearest honest equivalent in credit language. The translations are analogies, not identities — a backup is not literally collateral — but they are the analogies that let a relationship manager, broker or credit committee reason about cyber posture with the instincts they already have.
The glossary
Attack surface
In security terms: Everything an attacker could reach and attempt to exploit: internet-facing services, user accounts, devices, third-party integrations.
In credit terms: Exposure. The larger and less inventoried the attack surface, the wider the range of loss events a lender is implicitly financing.
Multi-factor authentication (MFA)
In security terms: A second proof of identity beyond a password, blocking most credential-theft attacks outright.
In credit terms: A primary control covenant. Its absence is the cyber equivalent of unsecured exposure — many insurers will not quote without it, which itself is a credit signal.
Patching cadence
In security terms: How quickly known software vulnerabilities are fixed once vendors release updates.
In credit terms: Management quality. Slow patching is operational-discipline information, the way persistent late filings colour a credit file.
End-of-life (EOL) systems
In security terms: Software or hardware no longer receiving security fixes from its vendor.
In credit terms: Deferred maintenance liability — a known, growing exposure with no mitigation path except replacement. Directly analogous to an asset run past its depreciation schedule.
Ransomware resilience
In security terms: The combination of controls (backups, segmentation, EDR) determining whether a ransomware event is a bad week or an existential loss.
In credit terms: Business-interruption severity. For an SME, ransomware is the single most plausible cyber path to a missed debt-service payment.
Backup separation (offline / immutable backups)
In security terms: Copies of data that an attacker with production access cannot encrypt or delete.
In credit terms: Loss-given-event mitigant. Backups convert a potential write-off scenario into a recoverable interruption — the collateral of operational data.
Incident response plan
In security terms: The rehearsed procedure for detecting, containing and recovering from a security event.
In credit terms: Contingency planning, as a lender means it: evidence that a shock produces a managed drawdown on resources rather than an uncontrolled default cascade.
Security posture
In security terms: The aggregate current state of an organisation's security controls and exposures.
In credit terms: The balance-sheet snapshot of operational cyber health — the thing a rating summarises, the way a credit score summarises repayment behaviour.
Posture drift
In security terms: The gradual decay of controls between assessments: an exception here, a disabled setting there.
In credit terms: Covenant erosion. The reason point-in-time certificates under-inform: the state at assessment and the state at loss event can differ materially.
Continuous monitoring
In security terms: Measuring controls from live telemetry rather than annual audit.
In credit terms: Ongoing covenant testing instead of annual accounts — the difference between hearing about deterioration now and eleven months from now.
Agentless assessment
In security terms: Reading security state through a provider's own APIs with read-only credentials — no software installed on the customer's systems.
In credit terms: Low-friction due diligence: verification that does not disturb the business being verified, like open-banking data against posted statements.
Cyber-financial resilience rating
In security terms: A 0–100 score aggregating weighted security factors into a single, comparable measure of resilience.
In credit terms: A leading indicator of operational default risk — designed to be read alongside financial metrics, not instead of them.
Why the translation matters
SME lending decisions increasingly price operational risk they cannot see. A borrower’s financials say nothing about whether one phishing email could interrupt trading for a month — yet that scenario now sits among the most plausible causes of a small firm’s sudden distress. The vocabulary gap is part of why the risk stays unpriced: security reports arrive in a language credit teams were never given a dictionary for.
TrustQuant’s resilience rating is built as that dictionary’s output: security telemetry in, a 0–100 score and factor-level reasoning out, designed to be read by lenders and insurers without a security background. See what one looks like in a sample report.