Cybersecurity Mission Creep in the US
Interesting paper: “Cybersecurity Mission Creep.”
Abstract: Cybersecurity is experiencing mission creep. Policymakers are casting more and more problems as issues of cybersecurity. So reframed, wildly different policy issues, from misinformation, to child social media safety laws, to antitrust regulations, to alleged journalist misconduct, to anti-sex trafficking statutes become what this Article calls “cybersecuritized.” Before this reframing, these issues present as important but not existential. But once cybersecuritization positions the issues as threats intensified by their technological nature, they gain access to the politics and law of urgency and exceptionalism and invite troubling governance responses.
Positioned as security threats, cybersecuritized issues become endowed with the apparent normative power to override countervailing considerations, oversimplifying the problem. Cybersecuritization’s oversimplification similarly risks unidimensional solutions and invites use of argumentative trump cards, like First Amendment challenges. Cybersecuritization also invites deference to purported specialists and their proposed solutions. Together, the reductive tendencies of cybersecuritization and the deference it prompts to specialists renders ultimate governance choices more opaque. And this opacity can erode public trust and political legitimacy.
This Article surfaces the phenomenon of cybersecuritization and offers a novel framework for analyzing and critiquing it. Mining cases from across criminal and civil domains, the account also demonstrates the insidiousness of cybersecuritization and the likelihood that it will continue to expand. Confronting cybersecuritization is crucial. If we continue to ignore it, we risk abdicating further responsibility for difficult choices to the trump card of cybersecurity. This Article’s analysis and critique aim to help reclaim the hard work of governance for our hands.
Subscribe to comments on this entry
Clive Robinson • July 2, 2026 10:25 AM
@ Bruce, ALL,
From the article quote,
It’s a form of inverse “dog whistle”.
We all know and now despise politicians and others trotting out,
“Think of the Children”
Or similar which has given them the excuse to push “Online ID” through the back door of pretending it’s “Age Verification”.
Likewise “Client Side Scanning” again by the pretence of “Protecting Children”.
Then there is BLE Beaconing, brought in for “contact tracing” during C19, but I’ve never directly heard from anyone it did then any good.
But now it’s in Apple and Google’s OS and I’m told will be in Microsoft’s Win11.
All of it does not do what is written on the Political tin or legislation. But it sure does make mass surveillance now and long into the future easy and obligatory if you want to be a part of enforced modern society.
Back when UK Prime Minister Tony Blair was in power there was the,
“Number ten nudge unit”
https://www.lightnet.co.uk/the-nudge-unit-is-still-active-here-is-what-it-is-working-on-right-now/
It’s a form of policy enforcment not by reason and due consideration but by psychological warfare on citizens.
Thus making anything “cybersecurity” is a way to hang a label like “terrorism” on public disagreement with “policy”.
You will see it ramp up, until enough people can see they are being conned or manipulated, then some new label / method will be used in the,
“Do as we say, not do what is rational.”