Open research questions in Cybersecurity and Cyber Warfare Studies
43 unresolved questions extracted from the limitations and future-work sections of 1,535 Cybersecurity and Cyber Warfare Studies papers in our library. Each links back to the study that raised it.
What the literature leaves open
The importance of ensuring access to specialized public services for sustainable development has been emphasized in numerous international documents and national policies. The United Nations 2030 Agenda regards “ensuring equitable access to essential public services” as a core objective, linked to Sustainable Development Goals (SDGs) 9 and 16, which focus on building resilient infrastructure, promoting transparent institutions, and ensuring access to justice. The World Bank (2022) also highlights that specialized public services such as property registration, intellectual property protection, and electronic notarization play a direct role in enhancing market efficiency, fostering trust, and reducing transaction costs, which are foundational elements of economic development. In Vietnam, the Socio-Economic Development Strategy 2021–2030 identifies “expanding and improving the quality of public services” as a key solution to ensure social equity and enhance governance effectiveness. For example, implementing electronic notarization services not only helps reduce time and costs for citizens and businesses but also supports the broader goal of digitalizing the economy. However, disparities in access across regions, population groups, and sectors remain, highlighting the urgent need to improve technical infrastructure, the legal framework, and organizational capacity to ensure that specialized public services can genuinely serve as a driving force for sustainable development. 4.1 Firstly, improving the legal framework Electronic notarization, as a specialized public service, requires a robust and flexible legal framework to ensure legality, transparency, and efficiency in handling electronic records. According to Governance for Sustainable Development (Meuleman, 2008), consistency and transparency in the legal system are essential foundations for building a sustainable administrative environment, directly contributing to the achievement of Sustainable Development Goals such as SDG 16 (Peace, Justice, and Strong Institutions). Developing coherent regulations including technical standards, authentication procedures, and information security measures while eliminating Veredas do Direito, v.23, e237723 – 2026 Veredas do Direito, v.23 n.2, e23xxx – 2026 16 APPROACHING ELECTRONIC NOTARIZATION IN VIETNAM: FROM PUBLIC SERVICE PRACTICE TO A SUSTAINABLE DEVELOPMENT PERSPECTIVE overlapping administrative requirements, such as the simultaneous submission of paper and electronic documents, will promote transparency and efficiency.
APPROACHING ELECTRONIC NOTARIZATION IN VIETNAM: FROM PUBLIC SERVICE PRACTICE TO A SUSTAINABLE DEVELOPMENT PERSPECTIVE · 2026 · DOIABORDANDO A NOTARIZAÇÃO ELETRÔNICA NO VIETNÃ: DA PRÁTICA DO SERVIÇO PÚBLICO À PERSPECTIVA DO DESENVOLVIMENTO SUSTENTÁVEL Nguyen Chi Khang* *University of Economics and Law, Vietnam National University Ho Chi Minh City, Ho Chi Minh…
APPROACHING ELECTRONIC NOTARIZATION IN VIETNAM: FROM PUBLIC SERVICE PRACTICE TO A SUSTAINABLE DEVELOPMENT PERSPECTIVE · 2026 · DOIcannot be adequately theorised through the lens of agency alone and if the intermestic character of AI governance means that international dependencies and domestic accountability deficits are structurally inseparable, then the conceptual vocabulary currently available to schol- ars and policymakers is insufficient for the task.
AI sovereignty without power? Reviewing strategic agency, infrastructural dependence and digital imperialism · 2026 · DOIThis white paper proposed the Global IIoT Governance Framework (GIIGF) as a focused contribution to global policy discussion on securing IIoT-enabled critical infrastructure. The framework responds to a practical challenge: IIoT cybersecurity risk is increasingly global, cross-sector and supply-chain dependent, while governance remains fragmented across jurisdictions and sectors. GIIGF provides six governance pillars: global policy alignment, risk-based governance, critical infrastructure protection, supply chain assurance, incident reporting and infor- mation sharing, and continuous monitoring and improvement. Together, these pillars support a governance approach that is practical, adaptable and policy-oriented. The paper does not claim that GIIGF is an official global standard or government-adopted policy. Rather, it provides a structured proposal that may support international dialogue, national policy development, sector guidance and organisational cyber resilience planning. Future work may develop sector-specific implementation profiles, maturity assessment tools, international benchmarking methods and templates for incident reporting or sup- plier assurance. These should be treated as extensions of GIIGF rather than separate frameworks. The immediate priority is to establish a clear and globally adaptable gover- nance foundation for IIoT-enabled critical infrastructure.
Global IIoT Governance Framework (GIIGF): International Policy and Cyber Resilience Guidelines for Critical Infrastructure · 2026 · DOIThe University sector is key to Australia, Lithuania and the Ukraine but each country has undertaken its own cyber security journey. A key next step is starting to collect case studies of cyber incidents at universities of the three countries to gain a greater insight and understanding. In conclusion Australian universities generally operate under a mature national cyber security framework, guided by the Australian Cyber Security Centre and national Cyber Security Strategy, with strong investment in dedicated security operations and compliance obligations. Australian Universities also have to deal with other security issues as foreign interference. Lithuanian universities benefit from the European Union's NIS2 Directive and ENISA guidance, placing them within a well regulated regional framework, though resources vary across institutions. Ukrainian universities face a uniquely challenging environment, contending with active state sponsored cyber threats intensified by ongoing conflict, which has simultaneously exposed vulnerabilities and accelerated practical cyber resilience. Across all three, a common challenge remains the gap between policy frameworks and consistent implementation at the institutional level and the protection on universities into the future.
Whether this framework will generate the de facto and de jure compliance pattern characteristic of the Brussels Effect is an open question the framework can evaluate but does not predict. If the framework is correct, governance harmonization in the global digital order is not a matter of finding the right institutional design or the right diplomatic instrument; it is structurally limited by the constitutive incompatibility of the three governance logics.
Incompatible Sovereignties: Chokepoint Conflict and the Structure of Digital Governance · 2026 · DOIThis paper proposes a conceptual framework and does not provide empirical performance results. Future research should evaluate the model through tabletop exercises, cyber ranges, controlled purple-team assessments, and post-incident case studies. Useful empirical questions include whether deception assets reduce dwell time, whether active defense thresholds reduce false positives, whether evidence packages improve provider or law enforcement outcomes, and whether organizations recover faster when identity-first recovery sequencing is preplanned. Legal and regulatory variation is another limitation. The model is intentionally conservative and designed for broad applicability, but specific deployments require jurisdiction- specific review. Privacy, labor, sectoral, contract, export-control, and evidence rules may alter 21 what is permissible. Future work should develop jurisdiction-specific overlays and sector- specific variants for healthcare, financial services, education, cloud services, and critical infrastructure. Finally, deception itself can fail. If decoys are unrealistic, stale, overused, or poorly isolated, sophisticated attackers may identify them and change tactics. If decoys are too realistic, legitimate users may interact with them or responders may confuse them with production assets. Research should therefore examine how to tune deception realism, measure false-positive immunity, and maintain ethical governance at scale.
Cyber Self‑Defense Under Active Intrusion: A Lawful, Ethical, and Operational Framework for Defensive Deception, Containment, Attribution, and Recovery · 2026 · DOIseveral studies, While the CISI and cyberfarming metrics advance comparative acknowledged. cyber First, data availability constrained parts of the analysis. Many sectors lack transparent reporting on vendors, technological origins, or procurement histories.
Digital soil sovereignty: a comparative analysis of state cyber postures using the CISI framework · 2026 · DOIThe research is limited to the comparison of macro rules, and does not involve issues such as corporate compliance, technical paths, and emerging scenarios, which can be further expanded in future research to promote the construction of a new global data governance order that takes into account sovereign security, personal rights, and digital development.
A Comparative Study on Rules for Protecting Personal Privacy in Cross-Border Data Flow-Taking China, the United States, and Europe as Examples · 2026 · DOIThe paper relies on empirical data from Cyber Risk Assessments conducted between 2023-2025 specifically in São Paulo State Government, limiting the generalizability of findings to other Brazilian states or government contexts.
From risk to resilience: addressing cybersecurity threats in Brazil’s government digital transformation · 2026 · DOIcontinue to rely on cyberspace for coercion, despite limited evidence of its effectiveness? What are the implications for the study and practice of cyber coercion? This article categorizes the evolution and consequences of this scholar-practitioner gap through a comparative review of the academic literature and policy debates within the United States.
Highlighting the lessons from India, this paper concludes the following: (i) digital sovereignty is a form of discourse which does not imply any specific policy, (ii) digital sovereignty relates to user control over their data, however, the role and limits of the State is not clearly defined and (iii) digital platforms are highly vulnerable to changing geopolitics in which their existence is not determined by user-platform interactions but by international relations.
Emily Goldman from the US Cyber Command and Department of Defense historian Michael Warner posit that while deterrence might have been effective in the Cold War to keep the Soviet Union at bay, it alone is insufficient to prevent present-day malicious cyber operations below the threshold of war.
Specifically, I outline two key, interrelated phenomena: (1) Facebook’s evolving strategy, including a greater engagement with civil society organizations and (2) the focus of digital rights activists in Africa on issues like Internet shutdowns, government surveillance, and the lack of data privacy frameworks.
Recent scholarship provides the opportunity for an assessment of the underexplored but promising marriage between science and technology studies (STS) and Internet governance (IG) research.
The article ends by exploring both local narratives and global-local policy dynamics, concluding that there is a need to conduct further research on the specific ways in which CCTV policy travels through borders and between the scales of government, and the processes by which it becomes embedded in diverse geographic, political and institutional settings.
Local surveillance in a global world: Zooming in on the proliferation of CCTV in Catalonia · 2011 · DOISurveillance technologies were deployed, including but not limited to airborne warning and control system planes (AWACS), a variety of security robots, video surveillance cameras and radio frequency identification chips (RFID).
Whether ICANN, which will take over full responsibility for the Internet in October 2000, will be a purely technical organization or become an organization which deals also with the political, economic, cultural, social and legal aspects of the Internet - a `United Nations of the Information Age' - remains to be seen.
These extensions reposition private universities as socio-technical actors within a global digital security ecosystem, rather than purely educational institutions. 6.2.
TÁI ĐỊNH VỊ VAI TRÒ CỦA CÁC TRƯỜNG ĐẠI HỌC NGOÀI CÔNG LẬP TRONG CÔNG TÁC PHÒNG CHỐNG TỆ NẠN XÃ HỘI TRÊN KHÔNG GIAN MẠNG: ĐỘNG LỰC TỪ KHOA HỌC MỞ, TRÍ TUỆ NHÂN TẠO VÀ CHUYỂN ĐỔI SỐ TOÀN CẦU · 2026 · DOIWhile cascading risk and systemic vulnerability propagated through institutional disparities are identified as central structural challenges, the paper lacks concrete metrics and assessment frameworks for quantifying and monitoring these cascading effects in practice.
From risk to resilience: addressing cybersecurity threats in Brazil’s government digital transformation · 2026 · DOIThis research note explores the need for further research into increasing accounts of the unregulated acquisition, use, and control of personal data by foreign states in collaboration with certain African states.
Yet, there is limited research available on the respective national frameworks governing offensive cyber capabilities, and similarly little information on the applicable control mechanisms.
We argue that while some of the claims of this narrative are based at least in part on genuine security concerns and important unknowns, evidence for its extreme binary nature is lacking.
Based on our analysis, we demonstrate why cyber strategies anchored in persistent engagement and near-constant offensive maneuver are insufficient to address the range of threat actor behavior in cyberspace.
• The percentage of overstays varies widely by state: more than two-thirds of the undocumented who live in Hawaii, Massachusetts, Connecticut, and Pennsylvania are overstays.
The 2,000 Mile Wall in Search of a Purpose: Since 2007 Visa Overstays have Outnumbered Undocumented Border Crossers by a Half Million · 2017 · DOI
Most-cited papers in Cybersecurity and Cyber Warfare Studies
- After Snowden: Rethinking the Impact of Surveillance · International Political Sociology · 2014 · 217 citations
- From Nuclear War to Net War: Analogizing Cyber Attacks in International Law · Berkeley journal of international law · 2009 · 121 citations
- Infrastructural Geopolitics · International Studies Quarterly · 2022 · 103 citations
- Access granted: Facebook’s free basics in Africa · Media Culture & Society · 2020 · 90 citations
- The Rise of Data Politics: Digital China and the World · Studies in Comparative International Development · 2021 · 89 citations
- Risking Security: Policies and Paradoxes of Cyberspace Security · International Political Sociology · 2010 · 87 citations
- Public Actors Without Public Values: Legitimacy, Domination and the Regulation of the Technology Sector · Philosophy & Technology · 2021 · 74 citations
- Geographies of infrastructure II: Concrete, cloud and layered (in)visibilities · Progress in Human Geography · 2020 · 71 citations
- Cyber campaigns and strategic outcomes · Journal of Strategic Studies · 2020 · 69 citations
- Postscript: A Theory of Access Revisited · Society & Natural Resources · 2020 · 69 citations
Most recent work
- Digital platforms and the transformation of crime governance · The Journal of Chinese Sociology · 2026
- Multi-criteria analysis of cybersecurity maturity in the largest Latin American economies using CRITIC-WISP · Information & Computer Security · 2026
- Unpacking state-sponsored cyber conflict: Intelligence-driven strategic competition in cyberspace · Journal of Strategic Studies · 2026
- Advocacy coalitions in cyber warfare: From global negotiations to issue-specific initiatives · Politics · 2026
- NWICO 2.0: a decolonial framework for rethinking global digital communication · Annals of the International Communication Association · 2026
- From risk to resilience: addressing cybersecurity threats in Brazil’s government digital transformation · Frontiers in Computer Science · 2026
- COMPATIBILITY OF AI & CYBER WARFARE WITH INTERNATIONAL LAW · Zenodo (CERN European Organization for Nuclear Research) · 2026
- A Comparative Study on Rules for Protecting Personal Privacy in Cross-Border Data Flow-Taking China, the United States, and Europe as Examples · Lecture Notes in Education Psychology and Public Media · 2026
- JUDICIAL EFFICIENCY IN THE ERA OF DIGITAL ASSETS: PERSPECTIVES ON SMART TECHNOLOGIES · Access to Justice in Eastern Europe · 2026
- Cybersecurity laws and ethical implications: integrated cybersecurity governance model (CLEI-ICGM) · Journal of Cloud Computing · 2026
Find a gap in your own Cybersecurity and Cyber Warfare Studies sub-topic
This page shows what the Cybersecurity and Cyber Warfare Studies literature already flags as unresolved. To narrow it to your specific question, run the guided finder — it searches the gap library on demand and checks candidates against 250M+ OpenAlex works.
Open the Research Gap Finder →