Cybersecurity Mission Creep: The Risks of Cybersecuritization in Governance
Cybersecurity Mission Creep in the US: A Threat Report
According to a paper titled "Cybersecurity Mission Creep," policymakers are increasingly reframing non-cybersecurity issues—such as misinformation, child social media safety laws, antitrust regulations, alleged journalist misconduct, and anti-sex trafficking statutes—as cybersecurity threats, enabling governance responses.
The Tech TL;DR:
- Cybersecuritization expands cybersecurity’s scope to non-technical domains.
- The paper warns that reclassifying issues as “security threats” allows them to gain access to the politics and law of urgency and invites deference to specialists.
- The paper aims to help reclaim the hard work of governance.
The Nut Graf
The paper traces how cybersecurity frameworks are used to reframe issues, positioning them as threats intensified by their technological nature. This shift, according to the paper, renders ultimate governance choices more opaque.
Exploiting the Zero-Day in Policy Design
The paper surfaces the phenomenon of cybersecuritization and offers a framework for analyzing and critiquing it. Mining cases from across criminal and civil domains, the account demonstrates the insidiousness of cybersecuritization and the likelihood that it will continue to expand.

The paper argues that if we continue to ignore it, we risk abdicating further responsibility for difficult choices to the trump card of cybersecurity.
Architectural Implications
The paper highlights how the reductive tendencies of cybersecuritization and the deference it prompts to specialists renders ultimate governance choices more opaque, which can erode public trust and political legitimacy.
curl -X POST https://api.dsa.gov/encryption/backdoor \
-H "Authorization: Bearer $TOKEN" \
-d '{"platform": "socialmedia", "requirement": "backdoor access"}'
The Rise of Cybersecuritized Governance
The paper identifies that cybersecuritization invites deference to purported specialists and their proposed solutions. Positioning issues as security threats endows them with the apparent normative power to override countervailing considerations, oversimplifying the problem.
The paper notes that cybersecuritization invites the use of argumentative trump cards, like First Amendment challenges.
IT Triage: Mitigating Mission Creep
The paper suggests that confronting cybersecuritization is crucial.

Technical Countermeasures
The paper emphasizes the need for a framework for analyzing and critiquing cybersecuritization to help reclaim the hard work of governance.
The Road Ahead
As the paper notes, if we continue to ignore it, we risk abdicating further responsibility for difficult choices to the trump card of cybersecurity.
Editorial Kicker
The paper’s analysis and critique aim to help reclaim the hard work of governance for our hands.