Outside the Silicon Valley bubble, cybersecurity means Windows antivirus products, password policies, caution around unsolicited email, etc. Maybe the most sophisticated users of the term have a dim idea of what encryption means. When a government agency has "sophisticated cyber capabilities" I would generally take that to mean reams of paperwork asserting that Norton is properly installed on every desktop.
The whole dimension of vulnerabilities and exploits, protocol flaws, trust boundaries, techniques for selecting or creating less vulnerable software, getting crypto implementation details right, principle of least privilege... none of that stuff even registers. I briefly worked in an IT consulting company that sold security and PCI compliance services; nobody was talking about any of that stuff. It was all password policies, antivirus products, phishing awareness campaigns.
The government definitely has real computer security engineering work happening in the NSA, NIST (FIPS 140-2 in particular is no joke), and other very high end defense-related areas. But I would not generally expect people using the word "cyber" to have a fighting chance against a nation-state-level evil USB stick.