Glossary
This page is the quick acronym reference. For plain-language explainers of the underlying concepts and technologies (Zero Trust, SASE, EDR/XDR, CNAPP, ransomware, machine identity, and more), see Cybersecurity Concepts & Terminology.
M&A / finance
- ARR — Annual Recurring Revenue. The core revenue metric for SaaS valuation.
- NRR / NDR — Net Revenue (Dollar) Retention. Revenue from existing customers incl. expansion/churn; >120% is considered strong.
- Rule of 40 — Growth rate % + profit (FCF) margin % ≥ 40; balances growth and profitability.
- EV — Enterprise Value (equity + net debt). Numerator in valuation multiples.
- EV/Revenue, EV/ARR, EV/EBITDA — Valuation multiples; cyber defaults to EV/ARR for vendors, EV/EBITDA for services.
- CIM — Confidential Information Memorandum. The detailed sell-side document.
- Teaser — Anonymized one/two-page sell-side summary sent to prospective buyers.
- IOI / LOI — Indication of Interest / Letter of Intent. Non-binding then near-binding offer stages.
- Buy-and-build — PE strategy: a platform acquisition + serial bolt-on (tuck-in) acquisitions.
- Tuck-in / bolt-on — Small acquisition integrated into an existing platform.
- Take-private — Acquiring a public company and delisting it (common in cyber PE).
- Secondary buyout — Sponsor-to-sponsor sale.
- Unitranche — Single blended senior+sub debt facility at one rate; dominant in mid-market software buyouts.
- Dry powder — Committed but uninvested fund capital.
- CVC — Corporate Venture Capital.
- Control / scarcity / strategic premium — Uplifts to valuation for control, category leadership, and synergy.
Cybersecurity categories
- EPP / EDR / XDR — Endpoint Protection / Detection & Response / Extended (cross-domain) D&R.
- SASE / SSE / ZTNA — Secure Access Service Edge / Security Service Edge / Zero Trust Network Access.
- IAM / PAM / IGA / CIEM / ITDR — Identity & Access Mgmt / Privileged Access Mgmt / Identity Governance & Administration / Cloud Infrastructure Entitlement Mgmt / Identity Threat Detection & Response.
- CNAPP / CSPM / CWPP / DSPM — Cloud-Native App Protection Platform / Cloud Security Posture Mgmt / Cloud Workload Protection Platform / Data Security Posture Mgmt.
- SIEM / SOAR / TIP — Security Information & Event Mgmt / Security Orchestration, Automation & Response / Threat Intelligence Platform.
- MDR / MSSP / MSP — Managed Detection & Response / Managed Security Service Provider / Managed Service Provider.
- ASM / BAS / PTaaS — Attack Surface Mgmt / Breach & Attack Simulation / Penetration Testing as a Service.
- GRC / TPRM — Governance, Risk & Compliance / Third-Party Risk Mgmt.
- DLP — Data Loss Prevention.
- SAST / DAST / SCA / ASPM — Static/Dynamic App Security Testing / Software Composition Analysis / Application Security Posture Mgmt.
- OT / ICS — Operational Technology / Industrial Control Systems.
- AI-SPM — AI Security Posture Management.
Threat economy
- RaaS — Ransomware-as-a-Service.
- IAB — Initial Access Broker.
- BEC — Business Email Compromise.
- Double extortion — Encrypt + exfiltrate-and-threaten-to-leak.
Regulation
- NIS2 — EU Network & Information Security Directive 2.
- DORA — Digital Operational Resilience Act (EU financial sector).
- CMMC — Cybersecurity Maturity Model Certification (US defense).
- FedRAMP / IL4 / IL5 — Federal cloud authorization / DoD Impact Levels.
- CIRCIA — Cyber Incident Reporting for Critical Infrastructure Act (US).
- GDPR / CCPA / CPRA — EU / California privacy regimes.
Updated 2026-08-16 18:13 UTC · © El Dorado Capital · el-doradocapital.com · Market intelligence for informational purposes only; not investment advice.