Use this glossary to understand the common IT terminology we use every day. Click any term to read a plain-language explanation and how it relates to your business.
DNS Filtering
IT Solutions uses DNS filtering to help protect their customers from malicious websites. Sometimes safe sites like for local TV stations link to malicious website through advertising on the sites. Other sites are just known bad sites. Blocking access to these sites helps protect our customers.
Occasionally a site is blocked that should not be blocked. This is rare, but it can happen. More often a safe site is blocked due to advertising on the site that links to a known bad site. In these cases, reloading the web page can have bring up different advertising and allow access.
If a site you think is safe is blocked several times, please put a ticket in for us to investigate. The URL that is being blocked is at the top in your browser tab. Please copy it and send it to us. If the URL is something different than the site you went to, it is usually an advertisement on the site that is causing this and there is nothing we can do about it. We are blocking the page for your safety.
Below is an example of a URL for an advertisement on a local new site that triggered the filter. Notice how the site is not a local news site.
EDR (Endpoint Detection and Response)
EDR, or Endpoint Detection and Response, is security software installed on the devices themselves, such as laptops, desktops, and servers. It watches continuously for behavior that suggests an attack, rather than waiting for a known virus signature to match.
When EDR finds something suspicious, it can act. It can block the activity, isolate the machine from the rest of the network, and give an IT team the details they need to respond. This is a large step beyond traditional antivirus, which mostly checks for known bad files and does not see new or sneaky attacks.
Firewall
A firewall is a barrier that filters the traffic coming into and going out of your network. It follows a set of rules to decide which traffic is allowed through and which is blocked, and it controls who can reach what on your systems.
Think of a firewall as the gatekeeper for your network. It is essential, but it is not enough on its own. Modern threats arrive through email, malicious links, and other channels that a firewall does not catch, so security needs to be layered. A firewall is one important layer, not the whole answer.
GRC (Governance, Risk, and Compliance)
GRC, or Governance, Risk, and Compliance, is a framework that ties together how an organization governs itself, manages its risks, and meets its requirements. It makes sure your policies align with your business goals, that risks are identified and handled, and that you stay in line with the rules that apply to you.
Unlike a specific security tool, GRC is a practice. It brings the business and technology sides together to make decisions with awareness of the risks involved. For many industries, it is the structure that keeps audits, insurance, and customer expectations in order.
IAM (Identity and Access Management)
IAM, or Identity and Access Management, is the set of policies and tools that control who can access your systems and data. It makes sure each person can reach only what they need, and only for as long as they need it.
IAM covers things like single sign-on, multi-factor authentication, and role-based access. It prevents both outsiders from getting in and insiders from having more access than their job requires. When someone leaves or changes roles, a good IAM system removes or adjusts their access right away.
MDR (Managed Detection and Response)
MDR, or Managed Detection and Response, is a service where a provider monitors your systems, spots threats, and takes action on your behalf. It pairs security technology with human analysts who investigate alerts around the clock, decide which are real, and contain what they find.
Most small and mid-sized businesses do not have the budget to staff a 24/7 security team of their own. MDR gives them that coverage without having to hire it. A good MDR provider watches your network constantly and responds before a small incident turns into a costly breach.
MFA (Multi-Factor Authentication)
MFA, or Multi-Factor Authentication, requires you to prove your identity in more than one way before you get in. A password is the first factor. The second factor is usually a code sent to your phone, an authenticator app, or a physical hardware key. It can also be a fingerprint or face scan.
A password alone can be stolen, guessed, or reused after a breach on another site. With MFA turned on, a stolen password is not enough for an attacker to get in. They would also need your phone or your key. For Microsoft 365, MFA costs nothing extra, and it is one of the largest security improvements a small business can make.
PAM (Privileged Access Management)
PAM, or Privileged Access Management, is a focused part of identity security that deals with high-privilege accounts. These are the administrator accounts, IT staff, and other users who hold broad access to your systems.
Instead of a whole team sharing one admin login, PAM gives each person their own privileges, stores passwords in a secure vault, and logs what each one does. This matters because a compromised admin account is the worst kind of breach. If an attacker gets that, they can do nearly anything. PAM makes those accounts far harder to misuse.
Preventative Maintenance
Preventative maintenance is cleaning and testing hardware on a regular basis to detect and repair or replace items before they fail. This extends the life of the hardware, reduces down time and saves you money.
Most people regularly change the oil in their car even though they are not having any problems with it. Most people have their teeth cleaned to help prevent problems with them. People do the same with their computer hardware for the same reasons.
We’ve also come to find that "an ounce of prevention" saves us time and money too, as we’re not allocating resources reacting to emergencies which could have been prevented with maintenance. This helps keep our rates to you lower.
RD Gateway (Remote Desktop Gateway)
RD Gateway, or Remote Desktop Gateway, is a Microsoft role that lets authorized users connect to remote desktops and applications from outside the network over an encrypted HTTPS connection. Instead of pointing RDP at the internet, traffic goes to the gateway, which forwards it to the right machine.
RD Gateway is a smarter way to provide remote access. It wraps RDP in a secure encrypted tunnel, lets you enforce authentication and access rules, and requires only a single port (443) to be open rather than exposing the whole RDP service to the internet. That cuts the attack surface attackers constantly scan for.
RDP (Remote Desktop Protocol)
RDP, or Remote Desktop Protocol, is a Microsoft technology that lets you connect to and control another computer over a network as if you were sitting right in front of it. It is a common and useful tool for IT teams doing remote support and for administrators managing machines.
RDP is also one of the most abused doorways on the internet. Attackers constantly scan for servers with RDP exposed, then try to guess passwords or use ones stolen elsewhere. We strongly advise never exposing RDP directly to the internet, and instead putting it behind a VPN with MFA and strong access controls.
SASE (Secure Access Service Edge)
SASE, or Secure Access Service Edge, is an approach that combines networking and security into one service delivered from the cloud. It bundles wide-area networking with tools like firewall, secure web gateway, and VPN into a single platform.
The idea is that people and applications no longer sit inside one building, so the security that used to live at the edge of the office should follow them wherever they go. Because everything is routed through the cloud, users get secure access whether they are at the office, at home, or on the road, and the business stops managing a stack of separate appliances.
SIEM (Security Information and Event Management)
SIEM, or Security Information and Event Management, is a platform that collects log data from all the systems and tools in your environment and pulls it into one place. It then looks for patterns that might point to an attack, giving security teams a single view across the whole network.
A SIEM also helps with compliance because it keeps a record of what happened and when. The catch is that a SIEM can generate a huge amount of noise. Without a team to sort real alerts from false ones, it is easy to get overwhelmed, which is why many businesses use an MDR service to run it for them.
SLA
A Service Level Agreement (SLA) is a promise from your IT company on how fast they will start working on a problem. This is typically four hours, or two hours if you pay more money.
Hold on a second...These terms specify a company could wait up to four hours before work is started, with no guarantee when it will end?!?
Not acceptable. IT Solutions has never drafted an SLA with any client. We don’t need one. Because our work is 70% proactive and almost entirely behind the scenes, so a tech can easily pause a proactive project to react when a customer needs them.
If you present us with a problem impacting your ability to get work done, we are working on it within a matter of minutes--not two to four hours. Non-critical requests receive the appropriate response based on a determination between our customer and us. Mission critical? IT Solutions techs are working on it immediately, and we will dispatch a technician for onsite if need in just a few minutes.
SOC (Security Operations Center)
A SOC, or Security Operations Center, is the team and the function that monitors and defends an organization's systems around the clock. Security analysts watch dashboards and alerts, investigate anything suspicious, and respond to incidents as they happen.
The SOC is the heart of a strong security posture, but staffing one 24/7 is costly. Because of this, many managed service providers operate a SOC and sell it as a service, which is where Managed Detection and Response comes in. It gives you a security team watching your network without the cost of hiring one.
SSO (Single Sign-On)
SSO, or Single Sign-On, lets a user log in once with one set of credentials and get access to many applications. Instead of remembering a different password for every system, an employee signs in one time and reaches everything they are authorized to use.
Fewer passwords means less password fatigue, and it reduces the temptation to reuse the same password across many accounts, which is a major security risk. When SSO is combined with MFA, you get both convenience and a much stronger barrier against a compromised login.
Understanding Managed Services
"Managed Services" is the top buzz phrase in our industry. When this term comes up, pay attention for subjects like "billing the customer". If it’s referenced in their presentation of their Managed Services, they likely don’t understand Managed Services.
With IT Solutions, Managed Services is about setting up the correct processes and procedures to fix problems on a customer’s network before the customer knows they have a problem. Managed Services has absolutely nothing to do with how one bills for the work.
Think about it. They tell you they monitor your network 24/7, then they have a "Help Desk" for you to call them when you have a problem? If they were really monitoring and fixing your problems proactively, why would they need a Help Desk (or a ‘Hold Desk’ as is often the case)?
IT Solutions does not have a Hold Desk because we don't need one. When a customer calls they get a real technician every time, never a Help Desk. Our monitoring is so advanced that our techs spend less than 10% of their time answering calls from customers.
VPN (Virtual Private Network)
A VPN, or Virtual Private Network, creates an encrypted tunnel between your device and a network over the internet. This lets a remote employee reach the office network securely, and it keeps the data traveling between them scrambled so anyone snooping on the connection cannot read it.
VPNs are especially important for people working from home, traveling, or using public Wi-Fi. Without one, an attacker on the same coffee shop network could capture sensitive traffic. We use VPNs for secure remote access and to connect offices, and we always pair them with MFA so a stolen login is still not enough to reach your network.
What is Break Fix?
Typically a "Break-Fix" plan includes basics like anti-virus, backups, firewalls and so forth. There’s no extra work performed or offered until a call (the Break) comes in and an IT team is asked to do something (the Fix).
While waiting for the Fix, the customer also must deal with upset clients, frustrated staff and lost productivity. Add up these costs and Break Fix is very expensive.
How do we know this? We know this because we tried it many years ago and stopped offering it. Break fix is a bad deal for us, and more importantly, a bad deal for our customers. Contact us today to learn more.
White List IP
IP whitelisting is a security control that permits access to a system or network only from a specific list of approved IP addresses. Any request that comes from an address not on that list is blocked.
IP whitelisting is a common way to lock down admin panels, VPN endpoints, and payment systems to the addresses your own team uses. It is a strong first gate, but it has to be updated as your addresses change, and it should be paired with MFA and other layered controls rather than trusted on its own.
Who Likes A Help Desk?
A Help Desk is typically staffed by entry-level or newer techs who fix the simple things. More complicated calls are forwarded to a more senior technician.
The most frustrating thing about a Help Desk is being put on hold frequently because the person answering the phone can help you. First frustration is waiting on hold for someone to help. Then after you connect to someone, you are frequently put on hold again because the person answering doesn’t know how to fix the problem.
IT Solutions doesn’t have a Help Desk. Never have and never will. We’ve eliminated the need through extensive monitoring and proactive remediation of fixes for our clients.
When you do call IT Solutions, you get a qualified network technician every time. We’re a business, just like you are, and we understand that time is a precious resource. Quick answers and timely help mean money saved all around.
XDR (Extended Detection and Response)
XDR, or Extended Detection and Response, is a security platform that gathers and correlates threat data from across your whole environment. Instead of each tool working in its own silo, XDR looks at endpoints, servers, network traffic, email, and cloud applications together.
The value is in the correlation. A single alert from one tool might look harmless, but when XDR sees the same unusual behavior on several systems at once, it recognizes the pattern as an attack. This lets a security team catch threats that would slip past any single product. XDR grew out of EDR and pushes the same detection idea beyond just the endpoints.
Zero Trust
Zero Trust is a security model built on a simple idea: never trust, always verify. The old model assumed that once someone was inside the network, they were safe. Zero Trust assumes the opposite. Every access request is authenticated, authorized, and encrypted, no matter whether it comes from inside the building or somewhere on the internet.
This matters more today because the perimeter of the network has disappeared. Workers are remote, and applications live in the cloud, so the walls around the office no longer protect much. Zero Trust shrinks the blast radius of a breach, because a single stolen login only opens the doors it was granted, not the whole network.
ZTNA (Zero Trust Network Access)
ZTNA, or Zero Trust Network Access, applies the Zero Trust principle to how people reach your applications. Unlike a traditional VPN, which lets a user into the whole network, ZTNA grants access only to the specific application they are authorized to use.
Because such access is granted one application at a time after verifying the person and their device, a stolen or misused login cannot roam the entire network. This limits the damage an attacker can do even if they get in, and it fits well with remote workers and cloud applications.

