IDEAS home Printed from https://ideas.repec.org/a/bla/revpol/v43y2026i4ne70102.html

Muddle and Match: Narrative Coherence in United States Cybersecurity Policy

Author

Listed:
  • Jonathan Lewallen

Abstract

The Narrative Policy Framework (NPF) provides a systematic means of using narrative elements to describe how policymakers define issues, including characters, plot, and setting. In this article I introduce the concept of narrative coherence: the extent to which different narrative elements “fit” together in a logical way. Narrative coherence operates at three levels: facial validity across narrative elements, agreement across policy narrators, and consistency across issue domains. I then use narratives in U.S. congressional oversight reports on cybersecurity to generate hypotheses about the presence (or absence) and effects of narrative coherence and incoherence. Cybersecurity is a challenging policy problem for policymakers to define. The term generally refers to protection against vulnerabilities in computer systems and Internet activity, but cybersecurity has acquired multiple dimensions and causes with multiple component issues as more systems became connected to the Internet and computing changes in ways that create new vulnerabilities. I find that congressional oversight reports tell relatively coherent stories for individual component issues associated with cybersecurity, but across these component issues the overall narrative is less coherent. These findings indicate that policymakers define cybersecurity problems in different ways depending on what kind of vulnerability or problem they talk about, and calls into question the usefulness of cybersecurity as an umbrella term for some vulnerabilities. The article offers several hypotheses for further research into narrative coherence as both a dependent and independent variable. 叙事政策框架(NPF)提供了一种系统的方法,利用叙事要素来描述政策制定者如何定义议题,包括人物、情节和背景。本文引入了叙事连贯性的概念:不同叙事要素在逻辑上相互契合的程度。叙事连贯性体现在三个层面:叙事要素之间的表面效度、政策叙述者之间的一致性以及议题领域的一致性。随后,我利用美国国会关于网络安全的监督报告中的叙事,提出关于叙事连贯性和不连贯性的存在(或缺失)及其影响的假设。网络安全是一个令政策制定者难以界定的政策问题。该术语通常指的是保护计算机系统和互联网活动免受漏洞侵害,但随着越来越多的系统接入互联网以及计算方式的变革产生新的漏洞,网络安全已呈现出多维度、多成因的复杂局面。我发现,国会监督报告在描述与网络安全相关的各个组成部分时,叙述相对连贯,但就这些组成部分而言,整体叙事的连贯性较差。这些发现表明,政策制定者对网络安全问题的定义因所讨论的漏洞或问题类型而异,这使得“网络安全”作为涵盖某些漏洞的统称的有效性受到质疑。本文提出了若干假设,供进一步研究将叙事连贯性作为因变量和自变量的作用。 El Marco de Política Narrativa (NPF, por sus siglas en inglés) proporciona un método sistemático para utilizar elementos narrativos que describan cómo los responsables políticos definen los problemas, incluyendo personajes, trama y contexto. En este artículo, presento el concepto de coherencia narrativa: el grado en que los diferentes elementos narrativos se “encajan” de forma lógica. La coherencia narrativa opera en tres niveles: validez aparente entre los elementos narrativos, acuerdo entre los narradores de políticas y consistencia entre los dominios de los problemas. A continuación, utilizo narrativas de informes de supervisión del Congreso de EE. UU. sobre ciberseguridad para generar hipótesis sobre la presencia (o ausencia) y los efectos de la coherencia e incoherencia narrativas. La ciberseguridad es un problema político complejo de definir para los responsables políticos. El término generalmente se refiere a la protección contra vulnerabilidades en sistemas informáticos y la actividad en Internet, pero la ciberseguridad ha adquirido múltiples dimensiones y causas con múltiples problemas componentes a medida que más sistemas se conectan a Internet y la informática cambia de maneras que crean nuevas vulnerabilidades. Observo que los informes de supervisión del Congreso presentan historias relativamente coherentes para los problemas componentes individuales asociados con la ciberseguridad, pero en el conjunto de estos problemas componentes, la narrativa general es menos coherente. Estos hallazgos indican que los responsables políticos definen los problemas de ciberseguridad de distintas maneras, según el tipo de vulnerabilidad o problema al que se refieran, y ponen en tela de juicio la utilidad de la ciberseguridad como término genérico para ciertas vulnerabilidades. El artículo propone varias hipótesis para futuras investigaciones sobre la coherencia narrativa como variable dependiente e independiente.

Suggested Citation

  • Jonathan Lewallen, 2026. "Muddle and Match: Narrative Coherence in United States Cybersecurity Policy," Review of Policy Research, Policy Studies Organization, vol. 43(4), July.
  • Handle: RePEc:bla:revpol:v:43:y:2026:i:4:n:e70102
    DOI: 10.1111/ropr.70102
    as

    Download full text from publisher

    File URL: https://doi.org/10.1111/ropr.70102
    Download Restriction: no

    File URL: https://libkey.io/10.1111/ropr.70102?utm_source=ideas
    LibKey link: if access is restricted and if your library uses this service, LibKey will redirect you to where you can use your library subscription to access this item
    ---><---

    More about this item

    Statistics

    Access and download statistics

    Corrections

    All material on this site has been provided by the respective publishers and authors. You can help correct errors and omissions. When requesting a correction, please mention this item's handle: RePEc:bla:revpol:v:43:y:2026:i:4:n:e70102. See general information about how to correct material in RePEc.

    If you have authored this item and are not yet registered with RePEc, we encourage you to do it here. This allows to link your profile to this item. It also allows you to accept potential citations to this item that we are uncertain about.

    We have no bibliographic references for this item. You can help adding them by using this form .

    If you know of missing items citing this one, you can help us creating those links by adding the relevant references in the same way as above, for each refering item. If you are a registered author of this item, you may also want to check the "citations" tab in your RePEc Author Service profile, as there may be some citations waiting for confirmation.

    For technical questions regarding this item, or to correct its authors, title, abstract, bibliographic or download information, contact: Wiley Content Delivery (email available below). General contact details of provider: https://edirc.repec.org/data/ipsonea.html .

    Please note that corrections may take a couple of weeks to filter through the various RePEc services.

    IDEAS is a RePEc service. RePEc uses bibliographic data supplied by the respective publishers.