Security and regulation: Cybersecurity, privacy, and trust

Citation: Katina Michael, Rebecca Herold, George Roussos, “Security and regulation: Cybersecurity, privacy, and trust- protecting information and ensuring responsible technology use”, Computers & Security, Volume 162, 2026, 104804, https://doi.org/10.1016/j.cose.2025.104804.

Security and regulation: Cybersecurity, privacy, and trust- protecting information and ensuring responsible technology use

1. Introduction

Cybersecurity, privacy and trust constitute the three pillars of the digital economy. As organizations increasingly rely on digital infrastructure for their operations, the integration of these pillars as functional requirements is essential. The expectation from customers and stakeholders is clear: personal data and organizational information must remain secure as businesses navigate increasingly complex socio-technical systems subject to vulnerabilities across interconnected supply chains, value chains, and care chains. The urgency of addressing cybersecurity challenges cannot be overstated. According to the World Economic Forum, estimates suggest that cybercrime is costing the global economy at least $10.5 trillion USD annually. Responding to these challenges requires more than technical solutions alone. A holistic, socio-technical approach is paramount; one that recognizes the interplay between social actors (humans and organizations) and technical components (software, hardware, firmware, data and infrastructure) as they interact to achieve security and privacy objectives within a given environmental setting (laws, regulations, policies, industries). This Special Issue brings together cutting-edge research that addresses cybersecurity and regulation from multiple perspectives, examining the complex assemblages of stakeholders, technologies, and governance frameworks that constitute our contemporary cybersecurity ecosystem.

2. In this special issue

This Special Issue presents a diverse collection of research contributions that address the global cybersecurity and regulation challenge through various approaches and methodologies. We received 60 papers and have accepted 9. The papers are clustered into thematic areas that reflect the interdisciplinary nature of contemporary cybersecurity and privacy challenges and implicitly engage with dual-use risks across multiple domains.

2.1. Regulatory frameworks and compliance

Beltrán's work on "AI Algorithms Under Scrutiny: GDPR, DSA, AI Act and CRA as Pillars for Algorithmic Security and Privacy in the European Union" provides a comprehensive analysis of how multiple regulatory frameworks intersect to govern algorithmic security and privacy. This contribution is particularly timely given the increasing deployment of AI systems in security-critical applications and the need to ensure these systems comply with evolving legal standards. Cojocaru's research on "Aligning Regulation and Governance for Cyber Resilience: A Theoretical Framework for the UK Financial Sector" addresses the critical challenge of aligning regulatory requirements with organizational governance structures. The financial sector represents a particularly important domain given its systemic importance and the sensitive nature of the data it processes.

The transition from incident management to crisis management is explored by Ruohonen et al. in "From Cyber Security Incident Management to Cyber Security Crisis Management in the European Union." This work recognizes that modern cybersecurity challenges can escalate beyond routine incidents to become full-scale crises requiring coordinated responses at organizational, national, and supranational levels. Ruohonen et al. recognize that security is indeed a communal good requiring participation across multiple sectors and structures. Mirtsch et al.'s examination of "Certification as a Compensation Mechanism for Weak Regulation? Exploring the Diffusion of the International Standard ISO/IEC 27001 for Information Security Management" raises important questions about the relationship between voluntary certification schemes and regulatory frameworks. This research contributes to our understanding of how organizations navigate complex compliance landscapes and whether certification can effectively supplement regulatory oversight.

2.2. Emerging technologies and threat landscapes

Oranekwu et al.'s work on "Scalable Automation for IoT Cybersecurity Compliance: Ontology-Driven Reasoning for Real-Time Assessment" tackles the critical challenge of securing Internet of Things deployments. Given that IoT devices represent significant attack vectors due to their often-limited security features and widespread deployment, automated compliance assessment mechanisms are essential for maintaining security at scale. Abduaziz et al.’s contribution on "Semi-Supervised Traceability Analysis of Investigative Scanners of Darknet Traffic" addresses the need to understand and trace cybercriminal activities in hidden online spaces. This research exemplifies the importance of developing sophisticated analytical tools to combat evolving cyber threats and understand the motivations and operational parameters of threat actors.

2.3. Privacy and trust in digital systems

Abellán et al.'s research on "Privacy Evaluation of the European Digital Identity Wallet's Architecture and Reference Framework" provides essential analysis of privacy implications in emerging digital identity systems. As governments and organizations move toward digital identity solutions, ensuring these systems protect privacy while enabling necessary functionality represents a fundamental challenge. The intersection of business adoption and security considerations is explored by Vasudevan et al. in "Mapping the Metaverse Minefield: A TIPS Framework for Security-Conscious Business Adoption." This work recognizes that emerging virtual environments pose novel security and privacy challenges, and that organizations need structured frameworks to navigate these challenges while capitalizing on new opportunities.

2.4. Risk disclosure and organizational responses

Moore and Adams contribute important empirical research with "How Informative are Cybersecurity Risk Disclosures?” when firms are targeted by ransomware. This work addresses the critical question of how organizations communicate cybersecurity incidents to stakeholders and whether current disclosure practices provide adequate information for decision-making. Understanding responsibilization beyond regulatory compliance and toward multi-stakeholder accountability solutions remains essential for improving organizational cybersecurity and privacy practices.

3. Examples of contemporary cybersecurity dual-use challenges

Contemporary cybersecurity discourse concerns the dual-use nature of cybersecurity technologies and techniques. Dual-use technologies are those that can serve both beneficial defensive purposes and potentially harmful offensive applications. This characteristic creates tensions in cybersecurity research, development and governance that demand careful ethical and policy considerations. The offensive-defensive dynamics in cybersecurity create what might be termed a technological arms race, where innovations intended for protection inevitably inform new attack vectors. Encryption technologies protect privacy and secure communications, yet these same technologies can shield transnational crime activities from law enforcement oversight. Artificial intelligence is acutely demonstrative of the dual-use challenge. While AI can enhance defensive cybersecurity capabilities through anomaly detection, pattern recognition, and automated threat response, the same technologies can be weaponized for sophisticated attacks. Machine learning algorithms that identify vulnerabilities to patch them before they become a nuisance, can equally be employed to discover and exploit those same weaknesses. Similarly, automated scanning tools designed to help organizations identify security weaknesses in their own systems can be repurposed for reconnaissance in malicious campaigns. Deepfake technologies, initially developed for entertainment and creative applications, have become tools for social engineering attacks and disinformation campaigns.

The dual-use challenge permeates through every modern technology, dependent on how it is applied; and can even encompass entire systems and infrastructures. For example:

  • IoT devices can enhance quality of life through smart home automation and industrial efficiency, yet simultaneously create vast attack surfaces when inadequately secured;

  • Blockchain technologies promise decentralized trust and transparency but have also enabled ransomware and social engineering operations through cryptocurrencies that obscure financial trails;

  • Cloud computing infrastructures provide scalability and efficiency while concentrating vast amounts of sensitive data in massive repositories that magnify the impact of successful breaches.

The governance of dual-use technologies in cybersecurity requires navigating complex ethical terrains. Overly restrictive approaches to security research and tool development may impede legitimate defensive capabilities and academic inquiry, yet overly permissive approaches risk enabling malicious actors and privacy breaches. International differences in legal frameworks further complicate this landscape: technologies and practices legal in one jurisdiction may be prohibited in others, creating challenges for multinational companies and research laboratories that are collaborating across the world.

Several principles can guide responsible approaches to dual-use technologies in cybersecurity. First, transparency about capabilities and the identification of the limitations helps build appropriate trust. Second, ethical frameworks for security and privacy research should emphasize responsible minimum-necessary disclosure, stakeholder engagement, and assessment of potential harms alongside benefits. Third, education and capacity building should emphasize not merely technical capabilities but also ethical reasoning and the social implications, particularly anticipated negative externalities. Fourth, regulatory approaches should be risk-based and proportionate, focusing on high risk applications while preserving space for beneficial innovation and legitimate security research.

4. Cybersecurity and regulation thematic challenges for the future

Significant cybersecurity and regulation research questions for the next five years will be driven by the rapid evolution of technology, the escalating sophistication of cyber threats, and new legal requirements. Example areas include the regulation of AI, the need for global standards, the governance of quantum technologies, and balancing regulatory burdens with effective security measures and privacy protections. Table 1 presents five major cybersecurity and regulation thematic challenges with 13 specific areas of consideration in the form of research questions that need to be addressed by future work.

Table 1. The five major cybersecurity and regulation thematic challenges for the future.

Thematic Area

1. Artificial intelligence and automation

A. How should AI-driven cybersecurity, cyber warfare, and privacy protections be regulated?

The dual-use nature of AI for both offense and defense poses a significant regulatory challenge. Technology diplomacy and increased public awareness is needed to define acceptable and responsible use while preventing the weaponization of AI by state and non-state actors.

B. What are the ethical and regulatory considerations of AI-driven decision-making in security and privacy protection?

The use of AI in threat detection and incident response raises concerns about bias, accountability, transparency, privacy, and human oversight. Professional practice, codes of conduct, and future research must determine how to ensure AI systems are fair, auditable, privacy protecting, and ultimately accountable to human operators.

C. How can regulations address the use of deepfakes and synthetic media in cyberattacks?

The use of AI to generate sophisticated and deceptive content is an increasing threat. Research is needed to explore how regulations can combat disinformation, social engineering, personal safety threats, and fraud enabled by synthetic media.

2. International cooperation and governance

A. How can a globally harmonized regulatory framework for cybersecurity and privacy be achieved?

The borderless nature of the internet makes it difficult to enforce disparate national regulations. Research is needed to identify viable pathways for international cooperation that balance national interests with the need for shared collective cybersecurity and privacy protection

B. How can regulations incentivize a global standard of cybersecurity and privacy?

With threats crossing national borders, a race-to-the-bottom in cybersecurity and privacy standards can create systemic risks. Research should focus on regulatory models that encourage all nations, regardless of their economic development, to improve their cybersecurity profile and agree upon common privacy problems that need urgent attention.

3. Data privacy and liability

A. How can privacy regulations adapt to the new realities of data collection and AI?

The increasing collection of personal data by AI systems creates new challenges for privacy protection. Research must explore how privacy frameworks like the OECD Privacy Principles and NIST Privacy Framework can be updated to support regulations covering the opaque data processing practices of modern AI.

B. How can individuals be recompensed for the data they generate and maintain control of secondary use?

The requirement for large language models (LLMs) to rely on data that is generated by individuals requires fair recompense. When individuals consent to share their data with third parties, they should be entitled to some form of remuneration, whether monetary or otherwise.

C. How should liability for cybersecurity and privacy breaches be allocated?

The complex supply and value chains of modern software and hardware make it difficult to determine responsibility after a cyberattack or privacy breach. Research is needed to develop liability frameworks, for example after a data breach in the cloud, that are fair and promote better security and privacy practices through mechanisms such as service level agreements (SLAs).

D. How can regulations balance security and privacy requirements with the potential for innovation?

Overly prescriptive regulations could hinder the development of new technologies, while a lack of regulation could lead to security and privacy vulnerabilities. Research is needed to find how regulations can encourage secure design without slowing down the pace of technological progress.

4. Emerging technologies

A. What are the regulatory requirements for securing quantum technologies?

The open source nature of modern technology (software, firmware hardware, infrastructure) development creates vulnerabilities that are difficult to track. Research is needed to identify security and privacy regulatory models that can mitigate to the least vulnerabilities possible the integrity of the technology supply chain without overburdening developers.

5. Resilience and systemic risk

A. How can regulations promote cyber resilience and privacy protection across critical infrastructures?

Rather than merely focusing on prevention, regulations need to also encourage robust response and recovery capabilities. Research should investigate how to best incentivize resilience across vital sectors like energy, finance, healthcare, and other critical infrastructure and services.

B. How can regulations manage the systemic risk of interconnected digital systems?

A vulnerability in a single component can have cascading effects across multiple systems given the modern phenomenon of system entanglement. Research is needed to understand and regulate this systemic risk to prevent large-scale digital failures which may be catastrophic to the global economy and human securitization.

5. A call for a socio-technical cybersecurity covenant

The age of digital interdependence in the context of the cyber-physical-social-cognitive reality we live in demands a new covenant between technology, society and the given environment within which it exists. The challenge is not only technological; it is existential. We are designing systems that regulate human behavior, mediate relationships of power, and shape the conditions of trust in the information society. The question is therefore not just how to defend networks, but how to cultivate responsible cyber ecosystems capable of self-correction, accountability, and resilience. Cybersecurity must no longer be conceived as a defensive art of exclusion, but an inclusive practice of stewardship- one that harmonizes the technical with the human (social) and the environmental. This editorial, indeed this special, calls upon researchers, practitioners and policymakers to engage in the co-creation of this covenant, otherwise known as a “social contract”. Socio-technical systems theory provides a conceptual bridge for understanding this transformation. The convergence of AI, data, and governance offers unprecedented opportunities but only if guided by foresight, humility, and a shared sense of responsibility.

The challenge is achieving harmony between the social, technical and environmental subsystems, not merely balance. When these subsystems fall out of alignment—when the “human factors” of ergonomics, sociocultural practices, and community values are neglected, alongside the “environmental factors” of governance regimes, laws, regulations, policies and standards—complexity transforms into vulnerability. Within this broader ecological framing, cybersecurity and privacy are not endpoints but a dynamic process. It requires systems capable of learning and adaptation. The emphasis shifts from protection to resilience, from security perimeters to ecosystem and privacy awareness, and from technical optimization to joint optimization; the alignment of the social, technical and environmental dimensions for mutual security supporting privacy for all humans involved. Cybersecurity, privacy, and trust are not "nice-to-haves" but essential elements related to the long-term responsibility and sustainability of organizations and societies. As we navigate an increasingly digital world characterized by complex socio-technical systems, meshed supply chains, and evolving threat landscapes, the need for holistic, interdisciplinary approaches to security, privacy and regulation has never been greater.

The research presented in this Special Issue advances our understanding of these challenges and points toward productive directions for future work. By bringing together diverse perspectives on regulatory compliance, emerging technologies, privacy protection, risk communication, and organizational response, these contributions exemplify the kind of integrated scholarship necessary to address contemporary cybersecurity challenges effectively. We hope this collection stimulates further dialogue among researchers, practitioners, and policymakers working to build more secure, trustworthy, and privacy-respecting digital systems. The path forward requires sustained collaboration across disciplines, sectors, and stakeholder groups—a collective effort to ensure that technological innovation serves the public interest while protecting fundamental rights and promoting human flourishing.

Declaration of competing interest

Katina Michael has served as a board member of the Australian Privacy Foundation since 2008, and has served on the board of governors for the IEEE Society on the Social Implications of Technology since 2020 and the IEEE Society on Consumer Technology since 2025. She has also received funding from The Alan Turing Institute for a grant related to artificial intelligence in cybersecurity in 2022.

Citation: Katina Michael, Rebecca Herold, George Roussos, “Security and regulation: Cybersecurity, privacy, and trust- protecting information and ensuring responsible technology use”, Computers & Security, Volume 162, 2026, 104804, https://doi.org/10.1016/j.cose.2025.104804.



Previous
Previous

Shaping the Digital Future: Inside The University of Sydney’s New MBA

Next
Next

A Substance Use Disorder Virtual Treatment and Research Platform: A Proof of Concept