Cyber Is Physick
One word, a dozen disciplines, and the budget line that keeps it alive
"Cyber" does the same work as "physick" did in 1720: it names an undifferentiated blob of ignorance administered by one guild. The difference is that physick was honest. Nobody knew enough to specialize, so the vocabulary didn't pretend otherwise. "Cyber" runs the process in reverse: one word imposed on top of fields that were already different, because a word that means nothing can fund everything.
In 1720 a physician practiced physick. Physick was bleeding you, purging you, compounding mercury pills, advising on your diet, quarantining your ship, and theorizing about the miasma that caused your fever. One word, because it was genuinely one field: a single undifferentiated body of ignorance, administered by one guild. The word was honest. Nobody knew enough to specialize, so the vocabulary didn't pretend otherwise.
Then the field speciated. Surgery split from the barbers. Pharmacology split from the apothecaries. John Snow took a pump handle off in Soho and epidemiology split from miasma theory. Pure Food and Drug Act, 1906. Food, Drug, and Cosmetic Act, 1938, passed over a hundred corpses from sulfanilamide dissolved in antifreeze. Kefauver-Harris, 1962, over thalidomide. Each split got its own methods, its own credentials, its own liability regime, and (this is the important part) its own word. Today, if you used "physick" to cover surgery, drug discovery, FDA regulation, food safety, grocery logistics, public health messaging, epidemiology, and bioweapons programs, people would correctly conclude you'd wandered in from a costume drama.
"Cyber" is physick. Except worse, because it runs the process in reverse.
Physick was one word for a field that hadn't differentiated yet. "Cyber" is one word imposed on top of fields that were already different. Cryptography is applied mathematics: proofs, peer review, IACR conferences, a discipline with a paper trail back to Shannon. Network engineering is infrastructure operations. Vulnerability research is adversarial program analysis, a cousin of reverse engineering. Incident response is firefighting with packet captures. Compliance is accounting: checklists, attestations, audit season. Signals intelligence is statecraft. Influence operations are propaganda, which is applied social psychology, which has nothing to do with any of the above. These fields have different methods, different talent pools, different failure modes, and different epistemics. A cryptographer and a SOC analyst have less professional overlap than a pharmacologist and a grocery store manager. The word "cyber" asserts they're the same thing.
Map the gradient, because the physick analogy runs disturbingly clean:
Exploit development is surgery. Invasive, precise, performed on a specific body, catastrophic when done badly, and practiced by a small guild that everyone else in the building finds slightly alarming.
Patch engineering is drug discovery. Slow, unglamorous, mostly failure, and the thing that actually moves the mortality statistics.
Compliance is FDA regulation. Or rather, compliance is what FDA regulation would be if the FDA never tested the drugs and instead certified that the pharmaceutical company possessed a policy about testing drugs. SOC 2 is a notarized letter saying the letter exists.
The SOC is epidemiological surveillance. Watching case counts, waiting for the anomaly, chronically understaffed, blamed for the outbreak.
Security awareness training is public health messaging. "Don't click the link" is "wash your hands," delivered with the same institutional sincerity and roughly the same compliance rate.
Nation-state offensive programs are bioweapons labs. Classified, deniable, officially defensive, and staffed by people who could be curing something instead.
Now ask the question the analogy demands: why did medicine's vocabulary speciate while security's vocabulary collapsed?
Not because of the technology. Because of the money.
Trace the word's actual pedigree. Norbert Wiener coined "cybernetics" in 1948 for feedback control theory: steersman, kubernetes, a real concept with real math. William Gibson clipped it to "cyberspace" in 1984 as an aesthetic; he has said, more or less, that it was evocative and meant nothing, which made it perfect. Then the Pentagon acquired it. Cyber Command stood up in 2010; by 2011 doctrine had declared "cyberspace" the fifth warfighting domain, alongside land, sea, air, and space. Read that list again. Four physical environments and one metaphor. That declaration wasn't ontology. It was a budget architecture: a domain gets a command, a command gets a budget, a budget gets contractors, and contractors get a word to put in front of everything they sell.
This is what "cyber" is for: it names a funding category, not a field. Congress can't appropriate money for "adversarial program analysis." No member knows what that is, and no lobbyist wants them to find out. Congress can appropriate money for Cyber. A word that means nothing can fund everything, and a word that funds everything will never be allowed to mean anything. The vagueness isn't a linguistic accident awaiting cleanup. The vagueness is the product.
And once the word is doing that work, it starts doing incentive work everywhere it touches.
In procurement, it enables substitution fraud with a clean conscience. A vendor sells you compliance paperwork (accounting) priced and marketed as if it were exploit defense (surgery). Both are "cyber," so the invoice clears. Nobody sells you a grocery store and bills you for an oncology ward, because the vocabulary would expose the swap. In cyber, the vocabulary is the swap.
In hiring, it produces the job posting that demands a CISSP, kernel exploitation experience, fluency in NIST 800-53, and "strong communication skills," at a salary appropriate for exactly one of those. The req isn't written by someone confused. It's written by someone whose vocabulary has one word where the field has nine, and the word can't tell them their shopping list spans four professions.
In policy, it guarantees category error as a permanent operating condition. Export controls that treated cryptographic math like munitions. "Cyber 9/11" rhetoric that funds perimeter theater while patch latency (the actual mortality statistic) goes unmeasured. When one word covers both a phishing filter and an NSA implant, every policy conversation defaults to whichever meaning benefits the speaker, and the speaker with the biggest budget request gets to pick.
In the press, it flattens a teenager credential-stuffing a fast-food app and a foreign intelligence service living in the power grid into the same headline noun. Imagine medical reporting where "physick incident" covered both a paper cut and an anthrax release. You'd conclude the newspaper didn't want you to understand medicine. Correct conclusion, wrong century.
The standard objection: every field has umbrella terms; "medicine" still exists as a word. True, and instructive, because "medicine" sits on top of a differentiated vocabulary that everyone (courts, insurers, regulators, patients) is required to use when anything is actually at stake. Your malpractice suit doesn't allege bad medicine; it alleges a specific deviation from the standard of care of a specific specialty, established by expert testimony from that specialty. The umbrella term survives as informal shorthand precisely because the vocabulary underneath it got precise. "Cyber" has no precise vocabulary underneath. It's an umbrella over an umbrella over a budget line.
So how does it end? Because it will end. Physick died, and not because lexicographers voted.
Physick died when liability arrived. Licensure meant someone could lose a credential for doing surgery badly, which required "surgery" to be a defined thing done by defined people to a defined standard. Malpractice law forced courts to distinguish specialties, because you can't establish a standard of care for an undifferentiated blob. The 1938 Act meant a drug company could be destroyed for a specific failure in a specific process, which meant the process needed names. Precision entered the vocabulary at exactly the rate that imprecision started costing money. Not one day earlier.
The same actuaries are now circling "cyber," and they're the most honest people in the building, because they're the only ones whose incentive is to not be fooled by the word. Cyber insurers started out underwriting the blob and got annihilated by ransomware for it. Watch what they did next: exclusions for state-sponsored attacks, mandatory MFA attestations, specific controls named in specific policy language, war-exclusion litigation. Merck v. ACE ran for years over whether NotPetya was an "act of war," which is to say, over which word applies. Every exclusion clause is a speciation event. Every coverage dispute forces a court to decide that this incident was negligent patch management and that one was an act of a foreign power, and those are different things with different names and different prices.
That's the mechanism. Words don't sharpen because pedants complain. Words sharpen when a contract, a court, or a claims adjuster makes the blur expensive. Medicine got its vocabulary from its casualties. Security will get its vocabulary the same way, one litigated exclusion clause at a time, and some decades from now, "cyber" will sound exactly like "physick" sounds today: an antique bureaucratic grunt from the era before anyone was liable for anything.
In the meantime, the word sorts its speakers. Everyone who understands the field is either in on the grift (and it is a grift, in the strict sense: a substitution of the cheap thing for the expensive thing, enabled by a vocabulary that can't tell them apart) or has learned that anyone who says "cyber" unironically has just disclosed which side of the invoice they're on. Often both. Plenty of practitioners cash the cyber-labeled check with one hand and wince at the word with the other, which isn't hypocrisy; it's what it looks like to be an honest specialist inside a dishonest funding category.
The word isn't confused. The word is doing its job. The job is the problem.

AI does the same work as cyber. Every Department of War procurement has AI plastered all over it.
I use cyber security as my job description when talking to non IT people because trying to explain in more detail mostly adds confusion. But yes there are people who think that means someone who digs in to malware which is not what I do at all.