Cyber security. Cyber-security. Cybersecurity.
I've spent years writing the word.
And I still occasionally stop and wonder which version I'm supposed to use.
Cyber security
Cyber-security
Cybersecurity
For a while, all three seemed to exist at the same time.
Standards used one.
Government guidance used another.
Vendors often made up their own.
Some organizations even managed to use two different spellings in the same document.
Gradually, though, cybersecurity won.
At least it seems to have. Except it hasn’t. I say Cyber security
Because the words look better written like that.
Most major frameworks, vendors, publications, and certification bodies have gradually converged on the single-word version.
Nobody announced the change.
There wasn't a committee meeting where someone declared,
"Right then ... from Monday we're all using one word."
The profession simply drifted that way. Again. I didn’t.
Oddly enough, I don't think the spelling is the interesting part.
The interesting part is that mature professions eventually stop arguing about vocabulary.
The language settles.
The ideas become more important than the words used to describe them.
I suspect cybersecurity is quietly reaching that point.
Although ...
You'll still find me writing Cyber security.
Probably with a fountain pen.
On a sheet of paper.
Before typing cybersecurity into the final document.
(Only to appease the red squiggly line of the spell checker)
Some habits, it seems, have their own governance framework.
Language quietly standardizes like that.
(Seriously. I’m writing utter bollocks now)
Nobody announces it.
It just happens.
Oddly enough, I don't think the spelling is the interesting part.
The interesting part is what it says about the profession.
When a field is young, even the vocabulary is still evolving.
As a profession matures, the language gradually settles.
Maybe that's a small sign that cybersecurity is still growing up.
Or perhaps, in another ten years, we'll all be arguing over whether AI governance should be one word too.