When everything becomes a cybersecurity problem, nothing is

There’s a new academic paper out that raises a uncomfortable question: are we slapping the “cybersecurity” label on too many things?

Titled “Cybersecurity Mission Creep,” the paper argues that policymakers are reframing all kinds of issues — misinformation, child social media safety, antitrust, journalist misconduct, anti-sex trafficking laws — as cybersecurity problems. The author calls this “cybersecuritization.”

The problem? Once an issue gets framed as a security threat, it gains access to the politics of urgency and exceptionalism. Normal governance guardrails stop applying. Oversimplification sets in. Solutions become one-dimensional. And challenging those solutions gets harder, because who wants to be seen as soft on cybersecurity?

The paper also warns about deference to specialists. When something is branded a cybersecurity issue, the so-called experts get more say than they probably should. That makes governance choices less transparent and erodes public trust.

It’s a fair point. Not every tech policy debate needs to be a national security argument. Some issues are important without being existential.

Worth a read if you’re in the policy space. Link to the full paper is in the references below.

References