
Cybersecurity terms for online business owners cover the threats, compliance requirements, and protective habits that come with running a business online, not just browsing safely as an individual. Knowing what these terms mean helps you recognize when a threat is aimed at your business specifically, and understand what’s actually at stake when it happens.
Part 1 of this series covered the fundamentals: phishing, malware, VPNs, passwords, and the core concepts behind everyday online safety. This post picks up where that one left off. For the first time in the Verizon Data Breach Investigations Report’s 19-year history, exploiting a known software vulnerability overtook stolen credentials as the leading way attackers get in, a shift that changes what online business owners need to watch for beyond password hygiene alone.
Looking for a term that isn’t covered in either post? Check the full Nomad Den Glossary for more.
Section 1: Threats Aimed at Online Businesses
This section covers threats built specifically around those who actually run a business, not just an inbox or a social account.
Business Email Compromise (BEC)
Business email compromise is a scam where an attacker impersonates you, an employee, or a vendor to trick someone into wiring money or sharing sensitive information. Unlike broad phishing campaigns, BEC attempts are often researched and targeted, sometimes using a lookalike domain or a compromised account to appear legitimate.
Example: An attacker emails your bookkeeper from an address that looks nearly identical to yours, requesting an urgent payment to a “new” vendor account.
The FTC’s small business cybersecurity guidance covers how email authentication helps block this specific type of impersonation.
Vendor/Supply Chain Attack
A vendor or supply chain attack happens when someone compromises a tool, platform, or contractor you rely on, then uses that trusted access to reach you. You don’t have to make a mistake yourself for this one to work; the vulnerability lives with someone in your toolset, not you directly.
Example: A plugin or app you’ve connected to your website gets compromised at the source, and the attacker uses that connection to access your site.
Vendor security is one of the FTC’s dedicated small business cybersecurity topics.
Credential Stuffing
Credential stuffing is when attackers take usernames and passwords leaked from one breach and test them automatically across many other sites. It works because so many people reuse the same password across accounts, so a leak on one unrelated service can compromise your business logins on a completely different one.
Reusing passwords across your business tools? See which password manager works best for you before one breach turns into several.
Domain Spoofing (Typosquatting)
Domain spoofing is when someone registers a domain that looks nearly identical to yours to impersonate your brand or intercept your traffic. A single swapped letter or added hyphen is usually enough to fool a distracted visitor, and it can be used to redirect affiliate commissions, harvest customer information, or damage trust in your brand.
This is most often done through typosquatting, registering domains that are deliberate misspellings or close variations of a legitimate site, also known as URL hijacking or domain mimicry.
Example: A scammer registers nomad-clen.com to catch traffic from people who mistype your domain.
Pretexting
Pretexting is when an attacker builds a fabricated scenario, like posing as tech support, a client, or a government agency, to manipulate someone into taking a harmful action. Despite how it sounds, pretexting isn’t about text messages specifically. The name comes from the fabricated pretext itself, though a text could still be part of how one plays out.
It is a form of social engineering, but it relies on a constructed story and often real-time interaction rather than a single deceptive message, which makes it harder to catch with software alone.
The 2026 Verizon Data Breach Investigations Report found pretexting climbing as a distinct initial point of entry into ransomware and extortion incidents, both as a standalone technique and as a follow-up to a phishing email.
Invoice/Wire Fraud
Invoice or wire fraud is the financial goal behind most business email compromise attempts. The intent is to trick you or someone on your team into sending a real payment to a fraudulent account. It’s usually the last step in a BEC or vendor impersonation attempt, not a separate attack on its own.
Example: A fake “updated payment details” email, often sent as a phishing message impersonating a real vendor, arrives right before an invoice is due, redirecting a legitimate payment to the attacker’s account.

Section 2: Business Protection & Compliance
These terms cover the protective steps and compliance requirements that come with running a business online rather than just using the internet personally.
Email Authentication (SPF/DKIM/DMARC)
Email authentication is a set of protocols, SPF, DKIM, and DMARC, that verify an email actually came from your domain and weren’t sent by an impersonator. The three work together: SPF authorizes which servers can send on your behalf, DKIM digitally signs the message to confirm it wasn’t altered, and DMARC tells receiving servers what to do when a message fails those checks.
The FTC breaks down how each piece fits together for small businesses setting this up for the first time. Verify your DMARC record is set up correctly.
Cyber Insurance
Cyber insurance is a policy that helps cover the costs of a data breach, ransomware payment, or business email compromise loss, separate from a standard business liability policy. Most small business owners assume their general liability policy already covers this. It typically doesn’t.
Hiscox reports that nearly four in five US small businesses aren’t adequately protected against a cyber claim, despite having the exact exposure that triggers one: a website, online payments, or business email.
PCI DSS Compliance
PCI DSS (Payment Card Industry Data Security Standard) compliance is a set of security standards, set by Visa, Mastercard, and the other major card networks, that any business handling card payments must follow. Compliant platforms encrypt and tokenize card data so it’s never stored or exposed in plain text, which limits what’s at risk if the platform is ever breached.
If you sell through a checkout page, even through a third-party platform, some level of PCI compliance applies. Most of it, though, is handled by the processor as long as card data isn’t stored directly.
API Key Security
An API key is a credential that lets one piece of software access another on your behalf, and a leaked one can hand an attacker the same access you have without ever needing your password. This matters more than most solo online business owners realize, since a single automation or integration connecting two tools in your workflow often uses one behind the scenes.
See how to handle common online tech tasks for this kind of setup safely.
OAuth (Third-Party App Access)
OAuth stands for “Open Authorization,” which is the permission system that lets you log into or connect one app using another account without sharing your actual password. The risk isn’t OAuth itself, it’s granting too many permissions.
One of the most common examples is signing into a new tool with your Google account instead of creating a separate login. The risk shows up when that connection grants more access than it actually needs, like a browser extension or automation tool with far broader permissions than its task requires, then getting forgotten about entirely.

Section 3: Core Concepts Beyond the Basics
These concepts explain why the threats above succeed and how the more advanced side of business security actually works.
Zero-Day Vulnerability
A zero-day vulnerability is a software flaw that’s actively being exploited before the developer has released a fix for it. The name comes from the fact that the developer has had zero days to patch it once it’s discovered in the wild, which is exactly why the 2026 Verizon DBIR found vulnerability exploitation overtaking stolen credentials as attackers’ preferred way in.
Attack Surface
Your attack surface is the sum of every point where an attacker could potentially gain access, including every tool, plugin, integration, and login connected to your business. Every new tool you connect, especially through an API key or OAuth permission, expands it, which is why the terms in this post aren’t separate concepts so much as different pieces of the same picture.
Session Hijacking
Session hijacking is when an attacker steals the token or cookie that keeps you logged into a site, letting them access your account without ever needing your password. It’s a different mechanism from a stolen password. Even a strong, unique one won’t stop an attacker who already has your active session.
Brute Force Attack
A brute force attack is when an attacker systematically tries password combinations, often using automated tools, until one works. It’s slower and noisier than credential stuffing, but it’s still effective against short or predictable passwords, which is one reason password managers generate long, random ones by default.
Business Identity Theft (EIN/Business Credit Fraud)
Business identity theft is when someone uses your business’s EIN, registration details, or business credit profile to open accounts or lines of credit in your company’s name. It’s a distinct threat from personal identity theft since it targets your business’s financial identity rather than yours individually, and it can go unnoticed longer since most people don’t monitor their business credit the way they monitor their own.
Insider Threat
An insider threat is a security risk that comes from someone with legitimate access to your accounts or systems, like a freelancer, virtual assistant, or contractor, rather than an outside attacker. It’s rarely malicious, and instead is often a shared login that never gets revoked, or an access level that’s broader than the task actually required.

FAQs
Conclusion
Cybersecurity for an online business looks different once you’re the one collecting payments, connecting tools, and building a brand attackers want to impersonate, not just browsing safely as an individual. The threats in this list, business email compromise, vendor attacks, leaked API keys, target exactly that difference, and knowing what they are can be the difference between catching a fraudulent invoice before it’s paid and finding out after.
Start with the basics, then build outward: revisit Part 1 if any of the earlier concepts need a refresher, and check the Glossary any time a term from either post needs more context. If more categories come up worth covering, that’s what Part 3 will handle.
Ready to lock down the accounts most exposed to these threats? See how account security works in practice.
