Author
Listed:
- Benedetta Cotta
- Maria Stella Righettini
Abstract
The accelerated digitalisation of society has amplified cybersecurity threats and revealed their cross‐sectoral nature. Yet, the policy instruments used to address these challenges remain insufficiently examined. This study conducts a scoping review of 980 academic articles (2007–2024) and applies Hood's NATO framework (Nodality, Authority, Treasure, Organisation) to map how cybersecurity policy instruments are deployed and combined. The analysis identifies emerging thematic domains and shows that governance approaches are multi‐instrumental, sector‐specific, and evolving. It highlights differences in reliance on informational, regulatory, financial, and operational tools, as well as patterns in their combination. These findings underscore the need for coordinated policy mixes that respond to both digital risks and institutional contexts. Advancing a Whole‐of‐Government (WoG) perspective, the study shows that a holistic, cross‐sectoral integration of tools can tackle the cybersecurity's technical complexity while accounting for human and organisational factors. By offering a novel framework for analysing instrument configurations, the article contributes to more adaptive and integrated cybersecurity governance strategies. La acelerada digitalización de la sociedad ha intensificado las amenazas a la ciberseguridad y revelado su carácter intersectorial. Sin embargo, los instrumentos políticos utilizados para abordar estos desafíos siguen sin estar suficientemente analizados. Este estudio realiza una revisión exploratoria de 980 artículos académicos (2007–2024) y aplica el marco NATO de Hood (Nodalidad, Autoridad, Recursos, Organización) para analizar cómo se implementan y combinan los instrumentos políticos de ciberseguridad. El análisis identifica dominios temáticos emergentes y muestra que los enfoques de gobernanza son multiinstrumentales, sectoriales y en constante evolución. Destaca las diferencias en la dependencia de herramientas informativas, regulatorias, financieras y operativas, así como los patrones en su combinación. Estos hallazgos subrayan la necesidad de combinaciones de políticas coordinadas que respondan tanto a los riesgos digitales como a los contextos institucionales. Al promover una perspectiva integral del gobierno, el estudio demuestra que una integración holística e intersectorial de herramientas puede abordar la complejidad técnica de la ciberseguridad, teniendo en cuenta los factores humanos y organizativos. Al ofrecer un marco novedoso para el análisis de configuraciones de instrumentos, este artículo contribuye a estrategias de gobernanza de la ciberseguridad más adaptativas e integradas. 社会数字化进程的加速加剧了网络安全威胁,并凸显了其跨部门的性质。然而,用于应对这些挑战的政策工具仍未得到充分研究。本研究对980篇学术文章(2007‐2024年)进行了范围界定性回顾,并运用胡德的北约框架(节点性、权威性、资源、组织)来分析网络安全政策工具的部署和组合方式。分析结果识别出新兴的主题领域,并表明治理方法是多工具的、特定于行业的,且不断演变。研究重点关注了对信息、监管、金融和运营工具的依赖程度差异,以及这些工具组合的模式。这些发现强调了制定协调一致的政策组合的必要性,以应对数字风险和制度环境。本研究提出全政府(WoG)视角,表明工具的整体性、跨部门整合能够在应对网络安全技术复杂性的同时,兼顾人为因素和组织因素。本文提出了一种分析工具配置的新框架,有助于构建更具适应性和一体化的网络安全治理战略。
Suggested Citation
Benedetta Cotta & Maria Stella Righettini, 2026.
"Governing Cybersecurity in the Digital Age: Mapping Comprehensive Policy Mixes With the Nodality‐Authority‐Treasure‐Organization Lens,"
Review of Policy Research, Policy Studies Organization, vol. 43(4), July.
Handle:
RePEc:bla:revpol:v:43:y:2026:i:4:n:e70113
DOI: 10.1111/ropr.70113
Download full text from publisher
Corrections
All material on this site has been provided by the respective publishers and authors. You can help correct errors and omissions. When requesting a correction, please mention this item's handle: RePEc:bla:revpol:v:43:y:2026:i:4:n:e70113. See general information about how to correct material in RePEc.
If you have authored this item and are not yet registered with RePEc, we encourage you to do it here. This allows to link your profile to this item. It also allows you to accept potential citations to this item that we are uncertain about.
We have no bibliographic references for this item. You can help adding them by using this form .
If you know of missing items citing this one, you can help us creating those links by adding the relevant references in the same way as above, for each refering item. If you are a registered author of this item, you may also want to check the "citations" tab in your RePEc Author Service profile, as there may be some citations waiting for confirmation.
For technical questions regarding this item, or to correct its authors, title, abstract, bibliographic or download information, contact: Wiley Content Delivery (email available below). General contact details of provider: https://edirc.repec.org/data/ipsonea.html .
Please note that corrections may take a couple of weeks to filter through
the various RePEc services.