<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.3 20210610//EN" "JATS-journalpublishing1-3-mathml3.dtd">
<article xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:ali="http://www.niso.org/schemas/ali/1.0/" article-type="research-article" dtd-version="1.3" xml:lang="EN">
<front>
<journal-meta>
<journal-id journal-id-type="publisher-id">Front. Polit. Sci.</journal-id>
<journal-title-group>
<journal-title>Frontiers in Political Science</journal-title>
<abbrev-journal-title abbrev-type="pubmed">Front. Polit. Sci.</abbrev-journal-title>
</journal-title-group>
<issn pub-type="epub">2673-3145</issn>
<publisher>
<publisher-name>Frontiers Media S.A.</publisher-name>
</publisher>
</journal-meta>
<article-meta>
<article-id pub-id-type="doi">10.3389/fpos.2025.1749390</article-id>
<article-version article-version-type="Version of Record" vocab="NISO-RP-8-2008"/>
<article-categories>
<subj-group subj-group-type="heading">
<subject>Original Research</subject>
</subj-group>
</article-categories>
<title-group>
<article-title>The service doctrine: How intelligence mandates shape national cybersecurity ecosystems?</article-title>
</title-group>
<contrib-group>
<contrib contrib-type="author" corresp="yes">
<name>
<surname>Kelemen</surname>
<given-names>Roland</given-names>
</name>
<xref ref-type="aff" rid="aff1"><sup>1</sup></xref>
<xref ref-type="corresp" rid="c001"><sup>&#x002A;</sup></xref>
<uri xlink:href="https://loop.frontiersin.org/people/3153304"/>
<role vocab="credit" vocab-identifier="https://credit.niso.org/" vocab-term="conceptualization" vocab-term-identifier="https://credit.niso.org/contributor-roles/conceptualization/">Conceptualization</role>
<role vocab="credit" vocab-identifier="https://credit.niso.org/" vocab-term="investigation" vocab-term-identifier="https://credit.niso.org/contributor-roles/investigation/">Investigation</role>
<role vocab="credit" vocab-identifier="https://credit.niso.org/" vocab-term="methodology" vocab-term-identifier="https://credit.niso.org/contributor-roles/methodology/">Methodology</role>
<role vocab="credit" vocab-identifier="https://credit.niso.org/" vocab-term="Project administration" vocab-term-identifier="https://credit.niso.org/contributor-roles/project-administration/">Project administration</role>
<role vocab="credit" vocab-identifier="https://credit.niso.org/" vocab-term="supervision" vocab-term-identifier="https://credit.niso.org/contributor-roles/supervision/">Supervision</role>
<role vocab="credit" vocab-identifier="https://credit.niso.org/" vocab-term="Writing &#x2013; original draft" vocab-term-identifier="https://credit.niso.org/contributor-roles/writing-original-draft/">Writing &#x2013; original draft</role>
<role vocab="credit" vocab-identifier="https://credit.niso.org/" vocab-term="Writing &#x2013; review &#x0026; editing" vocab-term-identifier="https://credit.niso.org/contributor-roles/writing-review-editing/">Writing &#x2013; review &#x0026; editing</role>
</contrib>
<contrib contrib-type="author">
<name>
<surname>Bucko</surname>
<given-names>Boris</given-names>
</name>
<xref ref-type="aff" rid="aff2"><sup>2</sup></xref>
<role vocab="credit" vocab-identifier="https://credit.niso.org/" vocab-term="conceptualization" vocab-term-identifier="https://credit.niso.org/contributor-roles/conceptualization/">Conceptualization</role>
<role vocab="credit" vocab-identifier="https://credit.niso.org/" vocab-term="investigation" vocab-term-identifier="https://credit.niso.org/contributor-roles/investigation/">Investigation</role>
<role vocab="credit" vocab-identifier="https://credit.niso.org/" vocab-term="methodology" vocab-term-identifier="https://credit.niso.org/contributor-roles/methodology/">Methodology</role>
<role vocab="credit" vocab-identifier="https://credit.niso.org/" vocab-term="Writing &#x2013; review &#x0026; editing" vocab-term-identifier="https://credit.niso.org/contributor-roles/writing-review-editing/">Writing &#x2013; review &#x0026; editing</role>
</contrib>
<contrib contrib-type="author">
<name>
<surname>Mazuch</surname>
<given-names>Martin</given-names>
</name>
<xref ref-type="aff" rid="aff3"><sup>3</sup></xref>
<uri xlink:href="https://loop.frontiersin.org/people/3285716"/>
<role vocab="credit" vocab-identifier="https://credit.niso.org/" vocab-term="conceptualization" vocab-term-identifier="https://credit.niso.org/contributor-roles/conceptualization/">Conceptualization</role>
<role vocab="credit" vocab-identifier="https://credit.niso.org/" vocab-term="investigation" vocab-term-identifier="https://credit.niso.org/contributor-roles/investigation/">Investigation</role>
<role vocab="credit" vocab-identifier="https://credit.niso.org/" vocab-term="methodology" vocab-term-identifier="https://credit.niso.org/contributor-roles/methodology/">Methodology</role>
<role vocab="credit" vocab-identifier="https://credit.niso.org/" vocab-term="Writing &#x2013; review &#x0026; editing" vocab-term-identifier="https://credit.niso.org/contributor-roles/writing-review-editing/">Writing &#x2013; review &#x0026; editing</role>
</contrib>
<contrib contrib-type="author">
<name>
<surname>Squillace</surname>
<given-names>Joseph</given-names>
</name>
<xref ref-type="aff" rid="aff4"><sup>4</sup></xref>
<role vocab="credit" vocab-identifier="https://credit.niso.org/" vocab-term="conceptualization" vocab-term-identifier="https://credit.niso.org/contributor-roles/conceptualization/">Conceptualization</role>
<role vocab="credit" vocab-identifier="https://credit.niso.org/" vocab-term="investigation" vocab-term-identifier="https://credit.niso.org/contributor-roles/investigation/">Investigation</role>
<role vocab="credit" vocab-identifier="https://credit.niso.org/" vocab-term="methodology" vocab-term-identifier="https://credit.niso.org/contributor-roles/methodology/">Methodology</role>
<role vocab="credit" vocab-identifier="https://credit.niso.org/" vocab-term="Writing &#x2013; review &#x0026; editing" vocab-term-identifier="https://credit.niso.org/contributor-roles/writing-review-editing/">Writing &#x2013; review &#x0026; editing</role>
</contrib>
<contrib contrib-type="author">
<name>
<surname>Cappella</surname>
<given-names>Justice</given-names>
</name>
<xref ref-type="aff" rid="aff5"><sup>5</sup></xref>
<role vocab="credit" vocab-identifier="https://credit.niso.org/" vocab-term="conceptualization" vocab-term-identifier="https://credit.niso.org/contributor-roles/conceptualization/">Conceptualization</role>
<role vocab="credit" vocab-identifier="https://credit.niso.org/" vocab-term="investigation" vocab-term-identifier="https://credit.niso.org/contributor-roles/investigation/">Investigation</role>
<role vocab="credit" vocab-identifier="https://credit.niso.org/" vocab-term="methodology" vocab-term-identifier="https://credit.niso.org/contributor-roles/methodology/">Methodology</role>
<role vocab="credit" vocab-identifier="https://credit.niso.org/" vocab-term="Writing &#x2013; review &#x0026; editing" vocab-term-identifier="https://credit.niso.org/contributor-roles/writing-review-editing/">Writing &#x2013; review &#x0026; editing</role>
</contrib>
<contrib contrib-type="author">
<name>
<surname>Szab&#x00F3;</surname>
<given-names>Hedvig</given-names>
</name>
<xref ref-type="aff" rid="aff1"><sup>1</sup></xref>
<role vocab="credit" vocab-identifier="https://credit.niso.org/" vocab-term="conceptualization" vocab-term-identifier="https://credit.niso.org/contributor-roles/conceptualization/">Conceptualization</role>
<role vocab="credit" vocab-identifier="https://credit.niso.org/" vocab-term="investigation" vocab-term-identifier="https://credit.niso.org/contributor-roles/investigation/">Investigation</role>
<role vocab="credit" vocab-identifier="https://credit.niso.org/" vocab-term="methodology" vocab-term-identifier="https://credit.niso.org/contributor-roles/methodology/">Methodology</role>
<role vocab="credit" vocab-identifier="https://credit.niso.org/" vocab-term="Writing &#x2013; review &#x0026; editing" vocab-term-identifier="https://credit.niso.org/contributor-roles/writing-review-editing/">Writing &#x2013; review &#x0026; editing</role>
</contrib>
</contrib-group>
<aff id="aff1"><label>1</label><institution>Modern Technologies and Cybersecurity Law Department, Deak Ferenc Faculty of Law, Sz&#x00E9;chenyi Istv&#x00E1;n University</institution>, <city>Gy&#x0151;r</city>, <country country="hu">Hungary</country></aff>
<aff id="aff2"><label>2</label><institution>The Ministry of Education, Research, Development and Youth of the Slovak Republic</institution>, <city>Bratislava</city>, <country country="sk">Slovakia</country></aff>
<aff id="aff3"><label>3</label><institution>Faculty of Management Science and Informatics, University of &#x017D;ilina</institution>, <city>&#x017D;ilina</city>, <country country="sk">Slovakia</country></aff>
<aff id="aff4"><label>4</label><institution>Cybersecurity Analytics and Operations, Penn State University</institution>, <city>University Park</city>, <state>PA</state>, <country country="us">United States</country></aff>
<aff id="aff5"><label>5</label><institution>Business Management and Marketing, Penn State University</institution>, <city>University Park</city>, <state>PA</state>, <country country="us">United States</country></aff>
<author-notes>
<corresp id="c001"><label>&#x002A;</label>Correspondence: Roland Kelemen, <email xlink:href="mailto:kelemen.roland@ga.sze.hu">kelemen.roland@ga.sze.hu</email></corresp>
</author-notes>
<pub-date publication-format="electronic" date-type="pub" iso-8601-date="2026-01-12">
<day>12</day>
<month>01</month>
<year>2026</year>
</pub-date>
<pub-date publication-format="electronic" date-type="collection">
<year>2025</year>
</pub-date>
<volume>7</volume>
<elocation-id>1749390</elocation-id>
<history>
<date date-type="received">
<day>18</day>
<month>11</month>
<year>2025</year>
</date>
<date date-type="rev-recd">
<day>07</day>
<month>12</month>
<year>2025</year>
</date>
<date date-type="accepted">
<day>08</day>
<month>12</month>
<year>2025</year>
</date>
</history>
<permissions>
<copyright-statement>Copyright &#x00A9; 2026 Kelemen, Bucko, Mazuch, Squillace, Cappella and Szab&#x00F3;.</copyright-statement>
<copyright-year>2026</copyright-year>
<copyright-holder>Kelemen, Bucko, Mazuch, Squillace, Cappella and Szab&#x00F3;</copyright-holder>
<license>
<ali:license_ref start_date="2026-01-12">https://creativecommons.org/licenses/by/4.0/</ali:license_ref>
<license-p>This is an open-access article distributed under the terms of the <ext-link ext-link-type="uri" xlink:href="https://creativecommons.org/licenses/by/4.0/">Creative Commons Attribution License (CC BY)</ext-link>. The use, distribution or reproduction in other forums is permitted, provided the original author(s) and the copyright owner(s) are credited and that the original publication in this journal is cited, in accordance with accepted academic practice. No use, distribution or reproduction is permitted which does not comply with these terms.</license-p>
</license>
</permissions>
<abstract>
<p>This study provides a structured comparative analysis of how democratic and authoritarian regimes integrate cybersecurity into their national security architectures, with particular attention to the severely under-researched Central-Eastern European EU member states (Hungary and Slovakia). Using a most-different-systems design, the article contrasts the multi-stakeholder, cooperative model of a major rule-of-law democracy (United States) with the centralized, digital-sovereignty-driven approaches of three major authoritarian powers (China, Russia, Iran) and two smaller EU members. In addition to institutional structures and oversight mechanisms, the analysis explicitly incorporates public trust dynamics as a critical variable of cybersecurity resilience. Findings show that democratic systems generate higher legitimacy but slower operational tempo, whereas authoritarian models achieve rapid capability integration at the expense of societal trust and private-sector autonomy. In the Central-Eastern European cases, the interplay of NIS2 obligations and pronounced centralizing tendencies produces distinctive governance patterns that deviate from both the classic &#x201C;cooperating cyberfare state&#x201D; and the &#x201C;smart total-control&#x201D; archetypes. The study demonstrates that sustained public trust&#x2014;fostered through transparent communication, accountable institutions and meaningful societal inclusion&#x2014;acts as a force multiplier for cybersecurity resilience across all regime types. By filling three identified gaps (small EU member states, cross-regime empirical depth, and public-trust integration), the article advances both the comparative politics of cybersecurity governance and practical policy recommendations for strengthening transatlantic and intra-EU cyber resilience.</p>
</abstract>
<kwd-group>
<kwd>central-eastern Europe</kwd>
<kwd>cooperative vs. monocratic cybersecurity</kwd>
<kwd>cybersecurity governance</kwd>
<kwd>digital sovereignty</kwd>
<kwd>most-different-systems design</kwd>
<kwd>national security</kwd>
<kwd>public trust</kwd>
</kwd-group>
<funding-group>
<funding-statement>The author(s) declared that financial support was received for this work and/or its publication. The Article Processing Charge (APC) for this publication was funded by Sz&#x00E9;chenyi Istv&#x00E1;n University.</funding-statement>
</funding-group>
<counts>
<fig-count count="0"/>
<table-count count="1"/>
<equation-count count="0"/>
<ref-count count="119"/>
<page-count count="14"/>
<word-count count="12543"/>
</counts>
<custom-meta-group>
<custom-meta>
<meta-name>section-at-acceptance</meta-name>
<meta-value>Politics of Technology</meta-value>
</custom-meta>
</custom-meta-group>
</article-meta>
</front>
<body>
<sec sec-type="intro" id="sec1">
<label>1</label>
<title>Introduction</title>
<p>In the 21st-century security environment, public trust in national security institutions has emerged as a cornerstone of sustainable security. This trust is a multifaceted concept, encompassing both diffuse institutional trust in the legitimacy of state actors and specific, sector-level confidence in their competence and integrity. The absence of either dimension directly undermines the credibility of state security policy, the societal acceptance of defence operations, and the effectiveness of strategic communication, a relationship explored in detail in <xref ref-type="bibr" rid="ref56">Kelemen et al. (2024a)</xref>. Recent analyses of contemporary crises, including pandemics, democratic backsliding, and domestic extremism, consistently highlight that national security actors&#x2014;from intelligence services to armed forces&#x2014;are increasingly dependent on active societal cooperation to achieve desired outcomes (<xref ref-type="bibr" rid="ref53">Jones, 2025</xref>). This interdependence is particularly pronounced within the social pillar of the United Nations Sustainable Development Goals (SDGs), especially SDG 16 (Peace, Justice and Strong Institutions), where rule-of-law-based, transparent, and accountable institutions generate high levels of public trust, which in turn enable the long-term implementation of complex security strategies, including those addressing climate change, energy security, and hybrid threats (<xref ref-type="bibr" rid="ref97">United Nations, 2021</xref>).</p>
<p>Public trust is not merely a normative ideal but an operational necessity. Without it, populations resist restrictive measures, withhold cooperation with authorities, and become more vulnerable to disinformation campaigns. NATO member states have increasingly recognized this linkage, integrating sustainability considerations into their national security strategies on the understanding that social stability, economic well-being, and security resilience are inseparable (<xref ref-type="bibr" rid="ref74">NATO, 2022</xref>). The NATO Climate Change and Security Action Plan, for instance, explicitly frames climate change as a &#x201C;defining challenge&#x201D; that requires enhanced societal trust and cross-sectoral collaboration to achieve effective mitigation and adaptation (<xref ref-type="bibr" rid="ref73">NATO, 2021</xref>). Sustaining public trust therefore demands continuous, two-way, transparent communication, institutional accountability, and the meaningful involvement of societal stakeholders.</p>
<p>The significance of public trust is amplified in the cybersecurity&#x2013;national security nexus, where threats are largely invisible, protective measures are frequently classified, and the role of the private sector is indispensable. These characteristics render societal trust particularly fragile (<xref ref-type="bibr" rid="ref8">Barrinha and Renard, 2020</xref>). Democratic regimes, with their emphasis on transparency and multi-stakeholder cooperation, tend to foster greater public legitimacy yet often experience slower decision-making and coordination challenges due to voluntary private-sector participation and stringent oversight requirements (<xref ref-type="bibr" rid="ref65">Manjikian, 2023</xref>). In contrast, authoritarian systems, guided by the ideology of digital sovereignty, establish highly centralized, monocratic structures in which private actors are subordinated to or co-opted by the state, enabling rapid integration of offensive and defensive cyber capabilities into the national security apparatus (<xref ref-type="bibr" rid="ref18">Conduit, 2023</xref>; <xref ref-type="bibr" rid="ref86">Santaniello and Barbieri, 2024</xref>). Empirical studies confirm that authoritarian regimes achieve greater operational agility across the full spectrum of cyber warfare, whereas democratic systems, bound by rule-of-law constraints and private-sector autonomy, frequently face delayed responses and fragmented implementation (<xref ref-type="bibr" rid="ref107">Whyte, 2020</xref>; <xref ref-type="bibr" rid="ref9005">Egloff and Smeets, 2023</xref>; <xref ref-type="bibr" rid="ref85">Saeed et al., 2023</xref>).</p>
<p>Within the European context, the implementation of the NIS2 Directive reveals stark divergences in governance models among member states, producing fragmentation rather than convergence (<xref ref-type="bibr" rid="ref100">Veigurs et al., 2024</xref>; <xref ref-type="bibr" rid="ref86">Santaniello and Barbieri, 2024</xref>). Public&#x2013;private cooperation ranges from the predominantly voluntary US model, through mandatory reporting regimes in several EU states, to the subordinate &#x201C;patriotic hacker&#x201D; arrangements observed in authoritarian systems (<xref ref-type="bibr" rid="ref49">Huang et al., 2021</xref>; <xref ref-type="bibr" rid="ref18">Conduit, 2023</xref>). The dual-use nature of cyber capabilities creates novel dilemmas in both regime types: democratic societies expose private actors to geopolitical pressure, while authoritarian regimes, by incorporating proxy actors, simultaneously enhance resilience and risk erosion of centralized control (<xref ref-type="bibr" rid="ref87">Shah et al., 2023</xref>; <xref ref-type="bibr" rid="ref66">McIntosh et al., 2023</xref>).</p>
<p>A conspicuous gap in the literature is the near-total under-representation of smaller and medium-sized Central-Eastern European EU member states (e.g., Hungary and Slovakia) in comparative cybersecurity governance research. Most studies focus either on major democracies (United States, Germany, France) or on major authoritarian powers (China, Russia, Iran), rarely employing a &#x201C;most different systems&#x201D; design that would place these two extremes and Central-Eastern European cases within a single analytical framework (<xref ref-type="bibr" rid="ref100">Veigurs et al., 2024</xref>; <xref ref-type="bibr" rid="ref86">Santaniello and Barbieri, 2024</xref>; <xref ref-type="bibr" rid="ref87">Shah et al., 2023</xref>). Empirical analysis is also lacking on how the &#x201C;national security exception&#x201D; in democratic systems erodes rule-of-law oversight mechanisms (prior judicial authorisation, proportionality), and on the extent to which the authoritarian &#x201C;smart total-control&#x201D; logic is exportable or adaptable to EU member states in the region. Finally, there is a striking scarcity of in-depth, cross-regime comparative studies examining the actual effectiveness&#x2014;rather than merely the formal regulation&#x2014;of public&#x2013;private cooperation, particularly along the voluntary versus mandatory reporting dimension (<xref ref-type="bibr" rid="ref85">Saeed et al., 2023</xref>; <xref ref-type="bibr" rid="ref6">Arroyabe et al., 2024</xref>).</p>
<p>The present study addresses these three critical gaps by (1) incorporating Central-Eastern European EU member states (Hungary and Slovakia), (2) simultaneously analyzing a major democracy (United States) and major authoritarian powers (China, Russia, Iran) within a &#x201C;most different systems&#x201D; framework, and (3) conducting an in-depth examination of the practical functioning of oversight mechanisms, public&#x2013;private relationships, and public trust dynamics, moving beyond formal legal texts.</p>
<p>To address these gaps systematically, this study is guided by three central research questions:</p>
<list list-type="order">
<list-item><p>How do the underlying logics of cybersecurity governance models in rule-of-law democracies and authoritarian regimes differ, particularly concerning the integration of national security frameworks and cybersecurity institutions?</p></list-item>
<list-item><p>In what ways does public trust function as a critical variable for national cybersecurity resilience, and how does its role vary across these different political systems?</p></list-item>
<list-item><p>What specific governance patterns emerge in Central-Eastern European EU member states at the intersection of supranational legal requirements, such as the NIS2 Directive, and national centralizing tendencies?</p></list-item>
</list>
<p>This article argues that while democratic and authoritarian states converge in establishing dual legal-institutional structures, these frameworks diverge fundamentally in their function and purpose. We posit that democratic models are defined by an inherent structural tension between security imperatives and fundamental rights, which creates persistent legitimacy challenges (<xref ref-type="bibr" rid="ref86">Santaniello and Barbieri, 2024</xref>), whereas authoritarian models achieve a seamless synergy for state control at the expense of societal trust and long-term innovative capacity (<xref ref-type="bibr" rid="ref18">Conduit, 2023</xref>). The analysis demonstrates that public trust acts as a critical force multiplier for cybersecurity resilience across all regime types, and its erosion&#x2014;whether through over-surveillance in democracies or coercion in autocracies&#x2014;directly undermines a nation&#x2019;s defensive capabilities (<xref ref-type="bibr" rid="ref80">Park and Kwon, 2024</xref>). Finally, the Central-Eastern European cases reveal the formation of a distinctive subtype within the broader cooperative model, featuring governance patterns that deviate from the classic archetypes and offering crucial insights for strengthening intra-EU and transatlantic cyber resilience.</p>
</sec>
<sec id="sec2">
<label>2</label>
<title>Methodology and analytical framework</title>
<p>This study employs a qualitative, comparative analytical methodology designed to capture the structural logics through which different political regimes integrate cybersecurity into their national security architectures. The aim is not merely to describe institutional arrangements, but to identify the underlying governance principles, patterns of authority concentration, and mechanisms of democratic or non-democratic control that shape the cybersecurity&#x2013;national security nexus.</p>
<sec id="sec3">
<label>2.1</label>
<title>The structure of the inquiry</title>
<p>The research follows a structured, focused comparison across six country cases&#x2014;Hungary, Slovakia, the United States, China, Russia, and Iran&#x2014;selected on the basis of two criteria. First, each represents a mature or consolidating cybersecurity governance system with established national security linkages. Second, they collectively capture the principal regime types relevant to contemporary cyber governance: rule-of-law democracies and authoritarian cyber-sovereignty models. This design enables the identification of convergent institutional structures as well as divergent political logics.</p>
</sec>
<sec id="sec4">
<label>2.2</label>
<title>Sources and data</title>
<p>The analysis is based on a triangulation of (1) national cybersecurity and national security legislation; (2) institutional documents, strategies, and publicly available oversight records; (3) relevant case law, particularly from the European Court of Human Rights; and (4) peer-reviewed academic literature on cybersecurity governance, surveillance oversight, and state&#x2013;society relations. This multilayered source base allows the comparison to move beyond formal legal texts and incorporate the practical functioning of institutions.</p>
</sec>
<sec id="sec5">
<label>2.3</label>
<title>Analytical perspectives on the cyber&#x2013;national security nexus</title>
<p>To ensure comparability across diverse political systems, the study applies three analytical dimensions derived inductively from the literature and the preliminary case mapping:</p>
<list list-type="order">
<list-item><p>The logic of dual governance structures&#x2014;examining how cybersecurity legislation and national security frameworks interact, whether in tension or synergy, and how this relationship shapes the distribution of authority.</p></list-item>
<list-item><p>The effectiveness of independent oversight&#x2014;assessing parliamentary, judicial, and administrative checks on national security powers related to cybersecurity, with particular attention to prior authorization, transparency, and proportionality standards.</p></list-item>
<list-item><p>Civil&#x2013;state relations in the cybersecurity ecosystem&#x2014;evaluating whether cooperation with private actors and civil society reflects voluntariness, regulated partnership, or legally enforced subordination.</p></list-item>
</list>
<p>These dimensions provide a consistent lens for identifying regime-specific patterns and cross-cutting differences.</p>
<p>To ensure analytical rigor and facilitate the replicability of our findings, the qualitative assessments presented&#x2014;particularly in the comparative synthesis table (<xref ref-type="table" rid="tab1">Table 1</xref>)&#x2014;were operationalized according to a consistent set of criteria. For instance, the &#x2018;Strength of Independent Oversight&#x2019; was coded based on a composite evaluation of three factors: (1) the legal requirement for prior, independent (preferably judicial) authorization for intrusive surveillance measures; (2) the documented practical effectiveness of parliamentary committees, assessed through public records and academic literature; and (3) the availability of effective legal remedies for citizens against state overreach, as interpreted in relevant case law. Similarly, the &#x2018;Nature of Civil&#x2013;State Relations&#x2019; was categorized along a spectrum from &#x2018;Voluntary partnership&#x2019; to &#x2018;Full subordination&#x2019; based on whether legal frameworks emphasize incentives and self-regulation, mandate compliance through reporting and auditing requirements, or legally compel private actors to serve as direct instruments of state security.</p>
<table-wrap position="float" id="tab1">
<label>Table 1</label>
<caption>
<p>Comparative analysis of cybersecurity governance models, oversight mechanisms, and public trust dynamics in the six case countries (United States, Hungary, Slovakia, China, Russia, Iran).</p>
</caption>
<table frame="hsides" rules="groups">
<thead>
<tr>
<th align="left" valign="top">Country</th>
<th align="left" valign="top">Relationship between cybersecurity and national security (tension vs. synergy)</th>
<th align="left" valign="top">Strength of independent oversight in national security-related cyber measures</th>
<th align="left" valign="top">Nature of civil&#x2013;state relations in the cybersecurity&#x2013;national security nexus</th>
</tr>
</thead>
<tbody>
<tr>
<td align="left" valign="middle">Hungary</td>
<td align="left" valign="middle">Tension (hybrid model with concentration of powers)</td>
<td align="left" valign="middle">Exists but limited (parliamentary oversight formal; lack of prior judicial control)</td>
<td align="left" valign="middle">Regulated partnership (mandatory but consultative)</td>
</tr>
<tr>
<td align="left" valign="middle">Slovakia</td>
<td align="left" valign="middle">Tension (centralised NIS2 framework alongside national security dimension)</td>
<td align="left" valign="middle">Exists but developing (limited parliamentary access; structural judicial independence issues)</td>
<td align="left" valign="middle">Regulated partnership (compliance-driven, lacking strategic depth)</td>
</tr>
<tr>
<td align="left" valign="middle">United States</td>
<td align="left" valign="middle">Strong tension (public voluntary PPP vs. covert bulk collection &#x2013; Section 702)</td>
<td align="left" valign="middle">Limited and fragmented (FISC secret; partial congressional oversight; civil litigation cumbersome)</td>
<td align="left" valign="middle">Voluntary partnership (persistent trust deficit)</td>
</tr>
<tr>
<td align="left" valign="middle">China</td>
<td align="left" valign="middle">Full synergy (cybersecurity&#x2009;=&#x2009;regime security)</td>
<td align="left" valign="middle">Absent (party-state control)</td>
<td align="left" valign="middle">Full subordination (NIL Article 7)</td>
</tr>
<tr>
<td align="left" valign="middle">Russia</td>
<td align="left" valign="middle">Full synergy (sovereign internet&#x2009;=&#x2009;political control)</td>
<td align="left" valign="middle">Absent (direct FSB access)</td>
<td align="left" valign="middle">Full subordination (Yarovaya package)</td>
</tr>
<tr>
<td align="left" valign="middle">Iran</td>
<td align="left" valign="middle">Full synergy (NIN&#x2009;=&#x2009;theocratic digital sovereignty)</td>
<td align="left" valign="middle">Absent (IRGC/MOIS dominance)</td>
<td align="left" valign="middle">Full subordination (Protection Bill)</td>
</tr>
</tbody>
</table>
</table-wrap>
</sec>
<sec id="sec6">
<label>2.4</label>
<title>Comparative structure of the inquiry</title>
<p>The study employs a &#x201C;most different systems&#x201D; logic within each regime cluster. Hungary, Slovakia, and the United States differ institutionally yet share rule-of-law constraints; China, Russia, and Iran diverge culturally and institutionally but converge in authoritarian cyber-sovereignty practices. This approach allows the analysis to isolate the role of political regime type as the main explanatory factor across cases.</p>
</sec>
<sec id="sec7">
<label>2.5</label>
<title>Limitations of the approach</title>
<p>The comparison focuses on national-level legislation and institutional mechanisms rather than operational cyber capabilities or intelligence practices unavailable through open sources. While this constitutes an inherent limitation, the selected analytical dimensions are sufficient to reveal the constitutional and governance structures that define each country&#x2019;s approach to cybersecurity and national security integration.</p>
<p>Furthermore, the selection of country cases, while purposefully designed to contrast major democratic and authoritarian archetypes alongside under-researched Central-Eastern European states, introduces a potential selection bias. The findings may not be generalizable to other types of political systems, such as those with different historical trajectories or distinct rule-of-law traditions. Future research could build upon this study&#x2019;s framework by expanding the comparative analysis to include a wider range of country cases.</p>
</sec>
</sec>
<sec id="sec8">
<label>3</label>
<title>Results: comparative analysis of national cybersecurity governance frameworks</title>
<p>This chapter presents the empirical findings of the study by analyzing the legal and institutional frameworks governing the intersection of cybersecurity and national security in two distinct clusters of states. The first section examines models operating within a rule-of-law framework&#x2014;Hungary, Slovakia, and the United States&#x2014;highlighting their shared challenges in balancing security with democratic oversight and fundamental rights, alongside their divergent institutional solutions. The second section analyses authoritarian models&#x2014;China, Russia, and Iran&#x2014;where cybersecurity governance is primarily instrumentalized as a tool for state control, surveillance, and regime stability.</p>
<sec id="sec9">
<label>3.1</label>
<title>Rule-of-law models: balancing security imperatives and fundamental rights</title>
<p>Governance models in democratic states are characterized by a persistent tension between the need for effective security measures and the obligation to uphold the rule of law. These frameworks typically feature constitutionally limited powers, mechanisms for parliamentary and judicial oversight, and a complex ecosystem of public-private cooperation. However, as the cases of Hungary, Slovakia, and the United States demonstrate, significant variations exist in how this balance is struck. These differences are shaped by distinct legal traditions, national security priorities, and, in the European context, the influence of supranational legal frameworks like those of the European Union.</p>
<sec id="sec10">
<label>3.1.1</label>
<title>The Hungarian hybrid model: state-centric control with EU overlays</title>
<p>According to the European Union Agency for Cybersecurity, the goal of cyber governance is to increase societal participation and cooperation in cyber-related measures, considering international agreements, strategies, and standards based on &#x201C;good practices&#x201D; [<xref ref-type="bibr" rid="ref33">European Union Agency for Cybersecurity (ENISA), 2023</xref>]. Experience from recent decades confirms that a comprehensive governmental approach integrating all critical sectors is necessary in the field of cybersecurity (<xref ref-type="bibr" rid="ref13">Cavelty and Egloff, 2019</xref>). Hungary, like other European states, treats cyberspace protection as a national security issue due to the all-of-society risk (<xref ref-type="bibr" rid="ref45">Government resolution 1089/2025 (III. 31.) on Hungary&#x2019;s cybersecurity strategy 2025</xref>), resulting in regulations and an institutional structure that has led to the convergence of cybersecurity and national security tasks. Hungary&#x2019;s cybersecurity governmental approach operates through a dual regulatory structure that combines the traditional legal environment for national security with cybersecurity legislation. Hungarian cybersecurity regulations align with European Union directives and NATO cybersecurity principles (<xref ref-type="bibr" rid="ref82">Pijpers et al., 2021</xref>). <xref ref-type="bibr" rid="ref2">Act LXIX of 2024 on Hungary&#x2019;s cybersecurity (n.d.)</xref> defines the state framework for cybersecurity, regulating the protection of electronic information systems, as well as the tasks, competencies, procedures, and incident management rules for essential and important organizations. The legal status and powers of national security services, however, are established by the <xref ref-type="bibr" rid="ref1">Act CXXV of 1995 on the National Security Services, 1995</xref>, which includes provisions for intervention in information systems to counter threats from cyberspace. These two pieces of legislation complement each other in delineating cyber defence authority-coordination functions from more traditional national security tasks.</p>
<p>The Hungarian cybersecurity model is hybrid and collaborative, with implementation built on three pillars (<xref ref-type="bibr" rid="ref61">Liebetrau, 2022</xref>). In the civilian national security sector, the National Cyber Security Center (NCSC), operating within the National Security Special Service, performs general cyber authority and national incident response functions. In the defence sector, the defence cybersecurity authority is vested in the minister responsible for defence, while the defence cyber incident response center is operated by the Military National Security Service, which is also responsible for supporting military cyber operations. In civilian public administration, the Supervisory Authority for Regulatory Affairs oversees the cybersecurity certification of digital products and services. While this structure serves functional specialization, it simultaneously concentrates information gathering and intervention powers, which presents risks that need to be managed from the perspective of democratic control and the rule of law. Democratic oversight forms the basis for the legitimate operation of the national security system. In Hungary, the services&#x2019; activities are subject to parliamentary committee control; however, this mechanism is often formal in practice and provides limited substantive oversight of sensitive areas of cybersecurity activities, such as monitoring electronic communications network traffic and taking measures necessary to interrupt cyberattacks. From a rule of law perspective, the greatest challenge is ensuring the proportionality and necessity of covert measures and state interventions in cyberspace (<xref ref-type="bibr" rid="ref90">Soesanto and Smeets, 2021</xref>).</p>
<p>Hungarian regulation recognizes an active (and in some cases repressive) toolkit that goes beyond prevention. The Act on National Security Services expressly authorizes national security services to &#x201C;intervene in information systems for the purpose of countering threats from cyberspace,&#x201D; within a covert information gathering framework subject to external authorization. In parallel, the Act on Cybersecurity makes it the task of the National Cyber Security Center to, among other things, analyze electronic communications network traffic without content for threat and attack detection, and further stipulates that the NCSC &#x201C;executes or initiates&#x201D; the measures necessary to interrupt an attack. Only a person designated by the Government may decide on the execution of the interruption. The measures must be necessary and proportionate, and must be consistent with national security, defence, law enforcement, and foreign policy interests as a tool of cyber deterrence (<xref ref-type="bibr" rid="ref90">Soesanto and Smeets, 2021</xref>). From the perspective of the democratic legitimacy of measures, the supervisory and authorization procedures applied in these measures are crucial. In the case of <xref ref-type="bibr" rid="ref92">Szab&#x00F3; and Vissy (2016)</xref>, the European Court of Human Rights (ECtHR) found that the Hungarian framework for national security secret surveillance provides too broad authorization and lacks adequate guarantees of prior independent authorization and effective remedies, which is particularly relevant for the democratic control of network-level detection and system-level intervention. This standard was further refined in Big Brother Watch and Others v. the United Kingdom (<xref ref-type="bibr" rid="ref46">Grand Chamber, 2021</xref>) and Centrum f&#x00F6;r r&#x00E4;ttvisa v. Sweden (<xref ref-type="bibr" rid="ref14">Centrum f&#x00F6;r r&#x00E4;ttvisa v. Sweden, grand chamber, app. No. 35252/08 (European court of human rights, 25 June 2021), n.d.</xref>): bulk techniques and covert surveillance systems are only compatible with Article 8 of the Convention with &#x201C;end-to-end&#x201D; safeguards (preferably judicial, prior authorization; narrow, foreseeable purpose and category system; strict selection and access rules; continuous independent supervision; detailed logging; substantive ex post control; and&#x2014;where possible&#x2014;delayed notification; <xref ref-type="bibr" rid="ref108">Zalnieriute, 2022</xref>). These standards were confirmed in <xref ref-type="bibr" rid="ref28">Ekimdzhiev and others v. Bulgaria, app. Nos. 70078/12 and 5 others (European court of human rights, 11 January 2022) (2022)</xref>. These standards, applied to the Hungarian hybrid, collaborative model, require that alongside the concentration of service and defence cyber operational powers and network monitoring, truly independent ex ante authorization, external and ex post control ensure the enforcement of fundamental rights. These requirements are not merely legal-technical guarantees but minimum conditions for the democratic legitimacy of state cybersecurity intervention in a multi-actor ecosystem, as they delineate the &#x201C;constitutional interface&#x201D; through which the state&#x2019;s monopoly on coercion can be reconciled with the involvement of market, academic, and civil capacities. The acceptability of intervention stems not only from the severity of the threat but from accountability, which creates the basis of trust for cooperation.</p>
<p>The integration of cybersecurity into the Hungarian legal system stems partly from the state&#x2019;s defence function in the Hobbesian sense, thus guaranteeing security remains the exclusive task of the state. However, in the digital sphere, this responsibility is shared: alongside the state, economic actors, universities, and civil society are also participants in the cyber defence ecosystem (<xref ref-type="bibr" rid="ref58">Kianpour et al., 2025</xref>). The Hungarian cybersecurity ecosystem includes the civil, economic, and scientific spheres, as university and industry actors also participate in strategic planning through the National Cybersecurity Forum. However, cooperation is typically consultative, not decision-making, so the role of civil control is limited. This operational model aligns with broader trends in the country&#x2019;s governance, where indicators measuring the accountability of executive and legislative branches have shown a significant decline over the past two decades (<xref ref-type="bibr" rid="ref40">Freedom House, 2024</xref>). In such an environment, fostering trust-based, strategic partnerships in sensitive security areas becomes inherently challenging. Civil-state partnership is not merely a technical but a constitutional issue; the rule of law can only be enforced in cyberspace if society is part of shaping security decisions. International experience (<xref ref-type="bibr" rid="ref52">Jardine et al., 2024</xref>) shows that civil involvement does not reduce the state&#x2019;s capacity for action but increases public trust and resilience. Actualizing social control would require regular public reports of decision-making processes and the expansion of citizen remedy channels, the latter is currently absent in practice. During the management of cybersecurity crisis situations, the Operational Task Force and the National Cybersecurity Working Group receive a directing role, but their decision-making is not public, and there are no mandatory transparency requirements for civil feedback. The level of democratic oversight in Hungary is limited: although parliamentary control formally exists, due to the overlap of cybersecurity and national security functions, decision-making remains within the closed circles of the executive branch, without parliamentary control.</p>
</sec>
<sec id="sec11">
<label>3.1.2</label>
<title>The Slovak centralized model: aligning with the EU&#x2019;S NIS directive</title>
<p>The legal and institutional framework forms the backbone of Slovakia&#x2019;s approach to cybersecurity as a dimension of national security. It determines the distribution of competences, the scope of obligations imposed on public and private actors, and the mechanisms of coordination among state institutions. Understanding this framework is therefore essential to evaluate how Slovakia integrates cybersecurity into its broader national security strategy and how effectively democratic oversight and rule-of-law safeguards are embedded within it.</p>
<p>The cornerstone of Slovak cybersecurity legislation is Act No. 69/2018 Coll. on Cybersecurity, which established obligations for operators of essential and digital services, defined risk management principles, and required incident reporting to the NB&#x00DA; SR (<xref ref-type="bibr" rid="ref4">Act no. 69/2018 Coll. On cybersecurity, 2018</xref>). This Act transposed Directive (EU) 2016/1148 [<xref ref-type="bibr" rid="ref24">Directive (EU) 2016/1148, 2016</xref>], integrating cybersecurity into national security and critical infrastructure protection. In December 2024, Act No. 366/2024 Coll. was adopted, amending the Cybersecurity Act to transpose Directive (EU) 2022/2555 (NIS2) into Slovak law (<xref ref-type="bibr" rid="ref3">Act no. 366/2024 Coll. Amending act no. 69/2018 Coll, 2024</xref>). The reform transformed the Slovak system into a risk-based model emphasizing accountability, executive liability, and modernized sanction mechanisms [<xref ref-type="bibr" rid="ref76">NB&#x00DA; SR (National Security Authority), 2024</xref>]. According to the Ministry of Investment, Regional Development and Informatization (MIRRI SR), this amendment represents a &#x2018;full functional transposition of NIS2&#x2019; [<xref ref-type="bibr" rid="ref68">MIRRI SR (Ministry of Investment, Regional Development and Informatization), 2024</xref>]. However, transitional provisions delay certain obligations, such as the establishment of sectoral CSIRTs and staff certification, until 2026 (<xref ref-type="bibr" rid="ref44">Government Office SR, 2024</xref>). The NB&#x00DA; SR&#x2019;s 2023 report indicated that around 50% of obligated entities had not met audit and reporting requirements, revealing capacity gaps rather than legislative deficiencies [<xref ref-type="bibr" rid="ref75">NB&#x00DA; SR (National Security Authority), 2023</xref>]. Despite these implementation challenges, Slovakia&#x2019;s legislative framework demonstrates a high degree of alignment with EU standards and establishes a solid legal foundation for the institutional system that underpins national cybersecurity governance. The gradual shift from formal compliance to proactive risk management reflects the country&#x2019;s effort to balance technical regulation with strategic resilience objectives.</p>
<p>Slovakia&#x2019;s cybersecurity governance combines functional centralization with sectoral specialization. The National Security Authority (NB&#x00DA; SR) acts as the national competent authority, overseeing compliance and certification, and operates the National Cybersecurity Center SK-CERT, which handles incidents of national and strategic relevance. Concurrently, the Ministry of Investment, Regional Development and Informatization (MIRRI SR) manages the governmental CSIRT. SK team, responsible for cybersecurity incidents within public administration and e-government systems (<xref ref-type="bibr" rid="ref89">Smernica, 2024</xref>). Other ministries contribute complementary roles: the Ministry of Defence directs military cyber operations (<xref ref-type="bibr" rid="ref67">Ministry of Defence SR, 2024</xref>), the Ministry of Interior investigates cybercrime, and the Ministry of Foreign and European Affairs coordinates cyber diplomacy (<xref ref-type="bibr" rid="ref43">Government of the Slovak Republic, 2021</xref>).</p>
<p>Democratic oversight of cybersecurity governance in Slovakia continues to develop within the existing legal framework. The National Council&#x2019;s Committee on Defence and Security holds the mandate to review the activities of the National Security Authority (N&#x00E1;rodn&#x00FD; bezpe&#x010D;nostn&#x00FD; &#x00FA;rad&#x2014;NB&#x00DA; SR), although access to classified operational information is naturally restricted due to confidentiality requirements (<xref ref-type="bibr" rid="ref71">National Council of the Slovak Republic, 2023</xref>). Consequently, parliamentary scrutiny primarily focuses on legislative and strategic aspects rather than detailed operational oversight. However, this oversight is hampered by significant structural weaknesses. The Act on Cybersecurity grants the NB&#x00DA; SR broad powers to block harmful content in cyberspace without prior judicial authorization (<xref ref-type="bibr" rid="ref91">Sokol and R&#x00F3;zenfeldov&#x00E1;, 2025</xref>). Furthermore, the legal framework lacks a mandate for systematic ex-post parliamentary oversight of such interventions, creating a significant democratic accountability gap (<xref ref-type="bibr" rid="ref106">West, 2023</xref>; <xref ref-type="bibr" rid="ref60">Kovani&#x010D; and Coufalova, 2020</xref>; <xref ref-type="bibr" rid="ref16">Chovancov&#x00E1;, 2016</xref>).</p>
<p>This institutional configuration reflects a broader European effort to balance national security imperatives with rule-of-law safeguards. In Slovakia, independent judicial authorization for cybersecurity measures is still being refined within the national legal system, while constitutional guarantees under Articles 19 and 22&#x2014;protecting privacy and the secrecy of correspondence&#x2014;continue to serve as a guiding principle. Relevant case law of the European Court of Human Rights, particularly Szab&#x00F3; and Vissy v. Hungary (2016) and Big Brother Watch v. United Kingdom (2021), highlights the importance of prior independent oversight of digital surveillance (<xref ref-type="bibr" rid="ref31">European Court of Human Rights, 2016</xref>, <xref ref-type="bibr" rid="ref32">2021</xref>). However, the effectiveness of prior judicial approval for the most intrusive measures is undermined by systemic challenges to judicial independence and impartiality, an issue previously highlighted in ECtHR critiques of the Slovak legal system (<xref ref-type="bibr" rid="ref48">Hron and Ill&#x00FD;ov&#x00E1;, 2025</xref>; <xref ref-type="bibr" rid="ref99">Va&#x0161;ko, 2022</xref>; <xref ref-type="bibr" rid="ref59">Knutelsk&#x00E1;, 2011</xref>; <xref ref-type="bibr" rid="ref63">Luk&#x00E1;&#x010D; et al., 2025</xref>). The European Union Agency for Fundamental Rights (FRA) has noted that several EU Member States, including Slovakia, continue to develop more comprehensive oversight mechanisms [<xref ref-type="bibr" rid="ref39">FRA (European Union Agency for Fundamental Rights), 2022</xref>]. Overall, Slovakia&#x2019;s approach demonstrates substantial alignment with European legal standards, while offering scope for the gradual enhancement of parliamentary and judicial oversight to further strengthen democratic accountability in cybersecurity governance.</p>
<p>Cooperation between the state and private operators forms a key component of Slovakia&#x2019;s cybersecurity system. Private providers of essential and digital services are required to report incidents and conduct regular cybersecurity audits under the supervision of the National Security Authority (N&#x00E1;rodn&#x00FD; bezpe&#x010D;nostn&#x00FD; &#x00FA;rad&#x2014;NB&#x00DA; SR; <xref ref-type="bibr" rid="ref4">Act no. 69/2018 Coll. On cybersecurity, 2018</xref>). However, the relationship remains largely confined to compliance-driven mechanisms rather than strategic, trust-based collaboration. This deficit is rooted in significant legal, cultural, and economic barriers. Culturally, a pervasive &#x2018;compliance-driven&#x2019; mindset, often stemming from a post-communist legacy of state-centric control, and a mutual &#x2018;blaming culture&#x2019; discourage the open information sharing essential for effective partnership (<xref ref-type="bibr" rid="ref11">Calcara et al., 2022</xref>; <xref ref-type="bibr" rid="ref83">Pollini et al., 2022</xref>). This underlying trust deficit is empirically evidenced by the National Security Authority&#x2019;s (NB&#x00DA; SR) 2023 report, which found that approximately 50% of obligated entities failed to meet their mandatory audit requirements&#x2014;a figure that points not only to capacity gaps but also to a fundamental lack of proactive engagement from the private sector [<xref ref-type="bibr" rid="ref75">NB&#x00DA; SR (National Security Authority), 2023</xref>]. Economically, significant resource constraints also hamper the capacity of both state and private actors to engage in more robust joint activities (<xref ref-type="bibr" rid="ref69">Mishra et al., 2022</xref>). The structured involvement of private entities in strategic cybersecurity policy-making is gradually developing, offering opportunities to deepen public&#x2013;private collaboration. Data exchange between state authorities and private operators is primarily based on bilateral arrangements, while aggregated statistical insights are shared selectively. Continued improvements in transparency and communication can further reinforce societal trust and participatory governance.</p>
<p>In comparison, several EU Member States&#x2014;such as Estonia and the Netherlands&#x2014;have adopted more inclusive models by institutionalizing dialog through Information Sharing and Analysis Centers (ISACs) and National Cybersecurity Forums (<xref ref-type="bibr" rid="ref52">Jardine et al., 2024</xref>). In Slovakia, cooperation is formalized in the National Cybersecurity Strategy 2021&#x2013;2025, which provides for a Steering Committee to coordinate implementation of the Action Plan, involving all stakeholders and conducting annual reviews; Act No. 69/2018 Coll. likewise obliges the Authority to cooperate with other state bodies, CSIRT units and operators of essential services (<xref ref-type="bibr" rid="ref4">Act no. 69/2018 Coll. On cybersecurity, 2018</xref>; <xref ref-type="bibr" rid="ref43">Government of the Slovak Republic, 2021</xref>).</p>
</sec>
<sec id="sec12">
<label>3.1.3</label>
<title>The US decentralized model: public-private partnership and advisory governance</title>
<p>The United States operates the world&#x2019;s most sophisticated yet deeply paradoxical cybersecurity governance system. It simultaneously projects two contradictory faces to domestic and international audiences: a highly visible, liberal-market-oriented public-private partnership model that celebrates voluntary cooperation and industry self-regulation, and a largely invisible, constitutionally contested national-security surveillance apparatus that relies on compulsory bulk collection and secret legal authorities (<xref ref-type="bibr" rid="ref7">Atkins and Lawson, 2021</xref>; <xref ref-type="bibr" rid="ref105">Weiss and Krieger, 2025</xref>). This duality is not accidental but structurally embedded, reflecting both ideological commitment to limited government intervention in the economy and an uncompromising post-9/11 interpretation of national security imperatives.</p>
<p>The &#x201C;public face&#x201D; is built on advisory coordination and voluntary frameworks rather than binding regulation. The Cybersecurity and Infrastructure Security Agency (CISA), established in 2018 under the Department of Homeland Security, is the principal civilian coordinator for critical infrastructure protection. Despite its ambitious mandate, CISA&#x2019;s authority remains largely advisory: it issues alerts, deploys detection tools, coordinates incident response, and can issue Binding Operational Directives&#x2014;yet these are mandatory only for federal civilian agencies, not private operators of critical infrastructure (<xref ref-type="bibr" rid="ref17">CISA, 2015</xref>). Similarly, the widely respected NIST Cybersecurity Framework (CSF 2.0 as of 2024) and Special Publication 800&#x2013;53 remain strictly voluntary standards that private entities adopt only when market forces, insurance requirements, or contractual obligations demand it (<xref ref-type="bibr" rid="ref77">NIST, 2020</xref>; <xref ref-type="bibr" rid="ref78">NIST, 2024</xref>).</p>
<p>The flagship legislative attempt to institutionalize cooperation&#x2014;the Cybersecurity Information Sharing Act of 2015 (<xref ref-type="bibr" rid="ref17">CISA, 2015</xref>)&#x2014;aimed to remove legal and liability barriers to voluntary threat-indicator sharing between government and industry. Despite initial optimism, participation has been persistently underwhelming. Empirical studies of the financial services sector, long considered the most advanced example of US public-private partnership through the FS-ISAC, reveal enduring trust deficits, asymmetric information flows, and competitive disincentives that severely limit timely bidirectional sharing (<xref ref-type="bibr" rid="ref7">Atkins and Lawson, 2021</xref>; <xref ref-type="bibr" rid="ref96">Ullah et al., 2024</xref>). Firms fear reputational damage, regulatory second-order effects, and potential misuse of shared data by government agencies, while the absence of mandatory reporting requirements creates classic collective-action problems in a highly competitive environment. As a result, even after major incidents such as SolarWinds (2020) and Colonial Pipeline (2021), significant &#x201C;regulatory gaps&#x201D; persist (<xref ref-type="bibr" rid="ref7">Atkins and Lawson, 2021</xref>; <xref ref-type="bibr" rid="ref94">The White House, 2023</xref>).</p>
<p>The &#x201C;hidden face&#x201D; of the model is the vast national-security surveillance architecture anchored in Section 702 of the Foreign Intelligence Surveillance Act (<xref ref-type="bibr" rid="ref38">Foreign Intelligence Surveillance Act of 1978, 1978</xref>; FISA &#x00A7;702, as reauthorised in 2018 and again in 2024) and residual authorities from the USA PATRIOT Act of 2001 (<xref ref-type="bibr" rid="ref98">USA PATRIOT act of 2001, 2001</xref>). These statutes authorize the National Security Agency (NSA) to conduct warrantless collection of both content and metadata of communications whenever at least one communicant is reasonably believed to be a non-US person located abroad&#x2014;a category that inevitably sweeps in massive volumes of purely domestic US person communications (&#x201C;incidental collection&#x201D;). The NSA&#x2019;s unique &#x201C;dual-hat&#x201D; leadership of both foreign signals intelligence (SIGINT) and the Cybersecurity Directorate creates a profound conflict of interest: the same organization tasked with defending private networks against foreign adversaries is simultaneously the world&#x2019;s most prolific collector of private communications, including those of the very firms it claims to protect (<xref ref-type="bibr" rid="ref105">Weiss and Krieger, 2025</xref>).</p>
<p>This arrangement generates acute rule-of-law tensions. The Fourth Amendment&#x2019;s guarantee against unreasonable searches and seizures is significantly weakened in the digital domain, particularly for data stored or transiting overseas. Oversight is delegated to the secretive Foreign Intelligence Surveillance Court (FISC), which operates ex parte, publishes almost no opinions, and historically approved 99&#x2013;100% of government applications even after the 2013 Snowden disclosures revealed systematic overreach (<xref ref-type="bibr" rid="ref26">Donohue, 2016</xref>; <xref ref-type="bibr" rid="ref27">Edgar, 2024</xref>). Civil liberties scholars argue that the combination of bulk collection programs (historically PRISM and Upstream) and minimization procedures that permit querying US person identifiers without judicial warrant constitutes a de facto general warrant regime prohibited by the Founders (<xref ref-type="bibr" rid="ref26">Donohue, 2016</xref>; <xref ref-type="bibr" rid="ref42">Goitein, 2023</xref>).</p>
<p>The 2023 National Cybersecurity Strategy explicitly acknowledges the failures of the purely voluntary model and attempts a partial rebalancing by shifting greater responsibility onto technology manufacturers and critical infrastructure operators (<xref ref-type="bibr" rid="ref94">The White House, 2023</xref>). Yet it deliberately avoids imposing EU-style comprehensive regulation, maintaining the fundamental liberal-market philosophy. Meanwhile, Section 702 was reauthorized in April 2024 with only modest reforms, preserving the core surveillance authorities despite documented abuses (<xref ref-type="bibr" rid="ref27">Edgar, 2024</xref>).</p>
<p>Thus, the American model remains caught in a structural contradiction: under-regulated in its civilian partnership face and overreaching in its surveillance face. This duality produces persistent legitimacy deficits both domestically and internationally. Domestically, the erosion of public trust in government handling of private data has been consistently documented in public opinion surveys since the 2013 Snowden disclosures, creating a lasting barrier to deeper public-private cooperation (<xref ref-type="bibr" rid="ref42">Goitein, 2023</xref>). Internationally, the model faces accusations of digital hegemony and extraterritorial overreach. While the system has proven remarkably resilient and adaptive, its internal tensions continue to generate political controversy and constitutional litigation, making the United States a uniquely ambivalent global standard-setter in cybersecurity governance.</p>
</sec>
</sec>
<sec id="sec13">
<label>3.2</label>
<title>Authoritarian models: cybersecurity as a tool for state control</title>
<p>Authoritarian states approach the nexus of cybersecurity and national security not as a balancing act with fundamental rights, but as an opportunity to reinforce regime stability and extend state power over the digital sphere. These models are characterized by the principle of &#x201C;digital sovereignty,&#x201D; the subordination of the private sector to state security organs, and the use of cybersecurity infrastructure for mass surveillance and the suppression of dissent. The legal frameworks in China, Russia, and Iran, while distinct in their specifics, share a common logic: the law serves as an instrument of control, rather than a constraint on power.</p>
<sec id="sec14">
<label>3.2.1</label>
<title>The Chinese authoritarian cybersecurity model: sovereignty, control, and selective flexibility</title>
<p>China&#x2019;s cybersecurity governance is anchored in a dual legal framework that intertwines universal intelligence obligations with targeted sectoral regulations. The 2017 National Intelligence Law (NIL) mandates that all organizations and citizens assist state intelligence efforts (Article 7), effectively conscripting private entities into the security apparatus (<xref ref-type="bibr" rid="ref19">Creemers, 2022</xref>). Complementing this are the 2017 Cybersecurity Law (CSL), the 2021 Data Security Law (DSL), and the 2021 Personal Information Protection Law (PIPL) (<xref ref-type="bibr" rid="ref22">Cybersecurity Law of the People&#x2019;s Republic of China, 2017</xref>; <xref ref-type="bibr" rid="ref23">Data Security Law of the People&#x2019;s Republic of China, 2021</xref>; <xref ref-type="bibr" rid="ref81">Personal Information Protection Law of the People&#x2019;s Republic of China, 2021</xref>), which establish a hierarchical data classification system&#x2014;encompassing &#x201C;core,&#x201D; &#x201C;important,&#x201D; and &#x201C;national core&#x201D; data&#x2014;and impose stringent obligations on operators of critical information infrastructure (CIIOs) to localize data and undergo security assessments for cross-border transfers (<xref ref-type="bibr" rid="ref47">Guo and Li, 2024</xref>; <xref ref-type="bibr" rid="ref15">Cheng, 2022</xref>). Central to enforcement is the Cyberspace Administration of China (CAC), a multifunctional body that regulates, audits, catalogs prohibited foreign technologies, and exercises content oversight, often with opaque criteria that prioritize national security (<xref ref-type="bibr" rid="ref20">Creemers, 2023</xref>; <xref ref-type="bibr" rid="ref104">Wei, 2022</xref>).</p>
<p>Ideologically, the model is underpinned by &#x201C;cyberspace sovereignty&#x201D; (wangluo zhuquan), which posits the state&#x2019;s exclusive authority over digital infrastructure, data flows, and content within its borders, rejecting Western notions of a borderless internet in favor of territorial control (<xref ref-type="bibr" rid="ref19">Creemers, 2022</xref>; <xref ref-type="bibr" rid="ref84">Ramich and Piskunov, 2022</xref>). This principle is operationalized through technical mechanisms like mandatory data localization&#x2014;requiring personal and &#x201C;important&#x201D; data to remain on domestic servers&#x2014;and CAC-mandated security reviews for outbound transfers, whose vague definitions of &#x201C;critical data&#x201D; enable discretionary state intervention to avert perceived threats (<xref ref-type="bibr" rid="ref47">Guo and Li, 2024</xref>; <xref ref-type="bibr" rid="ref20">Creemers, 2023</xref>). Recent amendments, including the 2024 Network Data Security Management Regulations, signal selective relaxation for non-sensitive digital trade to bolster economic integration, yet reinforce core controls (<xref ref-type="bibr" rid="ref9">Bird and Bird, 2025</xref>).</p>
<p>In implementation, private tech firms are legally bound to furnish data and technical aid to security organs (NIL Article 14; CSL Article 28), rendering conglomerates like Alibaba and Tencent de facto extensions of state surveillance while granting them leeway when commercial goals align with regime stability (<xref ref-type="bibr" rid="ref5">Aho and Duffield, 2020</xref>; <xref ref-type="bibr" rid="ref103">Wang et al., 2024</xref>). This symbiosis extends to societal control: the Great Firewall enforces layered censorship&#x2014;delegated to firms via self-policing&#x2014;while mass surveillance systems like Skynet and the Social Credit System enable real-time monitoring and pre-emptive repression under the guise of &#x201C;social stability&#x201D; (<xref ref-type="bibr" rid="ref5">Aho and Duffield, 2020</xref>; <xref ref-type="bibr" rid="ref95">Trevaskes, 2024</xref>). The CAC&#x2019;s 2023 vulnerability disclosure rules further integrate private reporting into a unified &#x201C;chess game&#x201D; of threat sharing, blending economic incentives with political coercion (<xref ref-type="bibr" rid="ref12">Cary, 2024</xref>).</p>
<p>Critically, this framework embodies &#x201C;rule by law,&#x201D; where statutes serve Party objectives rather than constrain power. Broad, ambiguous terms like &#x201C;national security&#x201D; and &#x201C;critical infrastructure&#x201D; facilitate overreach, sidelining privacy under PIPL exceptions and curtailing judicial review, as courts rarely challenge CAC decisions (<xref ref-type="bibr" rid="ref104">Wei, 2022</xref>; <xref ref-type="bibr" rid="ref20">Creemers, 2023</xref>). While fostering innovation&#x2014;evidenced by reduced cost stickiness post-CSL (<xref ref-type="bibr" rid="ref103">Wang et al., 2024</xref>)&#x2014;the model entrenches authoritarianism, diverging sharply from liberal multi-stakeholder paradigms (<xref ref-type="bibr" rid="ref84">Ramich and Piskunov, 2022</xref>).</p>
</sec>
<sec id="sec15">
<label>3.2.2</label>
<title>The nexus of cybersecurity and national security in Russia: a model of digital sovereignty and state control</title>
<p>Russia&#x2019;s authoritarian cyber-security model rests on a dual legal-institutional framework that grants the state comprehensive operational, technical, and content control over the national internet segment (RuNet) while instrumentalising private-sector infrastructure. Three interlocking legislative pillars form its core: the Sovereign Internet Law (<xref ref-type="bibr" rid="ref37">Federal Law No. 90-FZ of 1, 2019</xref>), the Data Localization Law (<xref ref-type="bibr" rid="ref34">Federal Law No. 242-FZ of 21, 2015</xref>), and the Yarovaya package (<xref ref-type="bibr" rid="ref36">Federal law no. 374-FZ, 2016</xref>). These laws are enforced primarily by two agencies: the Federal Service for Supervision of Communications, Information Technology and Mass Media (Roskomnadzor), responsible for content blocking, registration, and fining, and the Federal Security Service (FSB), which conducts operative-technical surveillance and operates the System for Operative Investigative Activities (SORM; <xref ref-type="bibr" rid="ref29">Epifanova, 2020</xref>; <xref ref-type="bibr" rid="ref62">Litvinenko, 2021</xref>; <xref ref-type="bibr" rid="ref70">Moyakine and Tabachnik, 2021</xref>).</p>
<p>The ideological foundation of the model is &#x201C;digital sovereignty,&#x201D; which justifies the transformation of the Russian internet into a controllable, potentially isolatable space. The 2019 Sovereign Internet Law mandated the installation of Deep Packet Inspection (DPI) equipment in ISP networks under Roskomnadzor supervision, enabling real-time identification and blocking of prohibited content, as well as centralized traffic routing through state nodes. It also required the creation of an independent national Domain Name System and routing infrastructure capable of sustaining RuNet autonomy in the event of external disconnection (<xref ref-type="bibr" rid="ref30">Ermoshina et al., 2021</xref>; <xref ref-type="bibr" rid="ref41">Glasze et al., 2023</xref>). Regional disconnection exercises conducted between 2019 and 2021 demonstrated the system&#x2019;s technical feasibility (<xref ref-type="bibr" rid="ref30">Ermoshina et al., 2021</xref>).</p>
<p>Private-sector subordination is achieved primarily through the Yarovaya package and the long-standing SORM framework. Telecommunication providers and &#x201C;organizers of information dissemination&#x201D;&#x2014;a category that can include foreign internet companies&#x2014;must store metadata for 3&#x2009;years and communication content (voice, text, images, video) for 6&#x2009;months, and hand over encryption keys or decryption capabilities to the FSB upon request without judicial warrant. The Data Localization Law complements this by mandating storage of Russian citizens&#x2019; personal data on domestic servers, thereby guaranteeing FSB access (<xref ref-type="bibr" rid="ref93">Taylor, 2020</xref>; <xref ref-type="bibr" rid="ref70">Moyakine and Tabachnik, 2021</xref>; <xref ref-type="bibr" rid="ref88">Sivetc, 2021</xref>).</p>
<p>In practice, these instruments have been weaponized for political repression, most dramatically since the 2022 invasion of Ukraine. The &#x201C;fake news&#x201D; amendments (<xref ref-type="bibr" rid="ref35">Federal law no. 32-FZ, 2022</xref>) introduced penalties of up to 15&#x2009;years&#x2019; imprisonment for disseminating information contradicting the official narrative, enabling the rapid blocking of independent media outlets (Meduza, Dozhd, Echo Moskvy) and Western platforms (Facebook, Instagram, Twitter/X). The combination of DPI systems and centralized blacklists allowed thousands of websites to be rendered inaccessible within hours, while VPN and proxy circumvention tools have been systematically degraded (<xref ref-type="bibr" rid="ref55">Kaye, 2022</xref>; <xref ref-type="bibr" rid="ref30">Ermoshina et al., 2021</xref>).</p>
<p>From a rule-of-law perspective, the Russian model exhibits profound deficiencies. Independent judicial oversight is effectively absent: FSB demands for decryption occur without court approval, statutory definitions such as &#x201C;extremist activity&#x201D; or &#x201C;incitement to mass riots&#x201D; remain deliberately vague, and proportionality or necessity tests are never applied. Privacy and freedom of expression are consistently subordinated to nebulous state-security imperatives, transforming ostensibly cyber-security measures into instruments of comprehensive political control (<xref ref-type="bibr" rid="ref70">Moyakine and Tabachnik, 2021</xref>; <xref ref-type="bibr" rid="ref88">Sivetc, 2021</xref>).</p>
</sec>
<sec id="sec16">
<label>3.2.3</label>
<title>Iran: a theocratic model of digital sovereignty and repression</title>
<p>Iran has developed one of the world&#x2019;s most sophisticated authoritarian cybersecurity architectures, centered on the National Information Network (NIN, locally known as SHOMA). Officially framed as a strategic project to secure &#x201C;digital sovereignty&#x201D; and protect Islamic-Iranian cultural identity, the NIN aims to create a fast, inexpensive national intranet while progressively isolating citizens from the global internet (<xref ref-type="bibr" rid="ref9012">Supreme Council of Cyberspace, 2012</xref>; <xref ref-type="bibr" rid="ref9013">Supreme Council of Cyberspace, 2017</xref>). Strategic oversight is exercised by the Supreme Council of Cyberspace (SCC), established in 2012 by order of the Supreme Leader and chaired by the President, which subordinates all cyber-policy decisions to theocratic-political priorities enshrined in Articles 44 and 175 of the Constitution of the Islamic Republic of Iran (Supreme Council of Cyberspace Founding Decree, 2012; <xref ref-type="bibr" rid="ref9002">Constitution of the Islamic Republic of Iran, 1979</xref>). At the operational level, the Islamic Revolutionary Guard Corps (IRGC) cyber units and the Ministry of Intelligence and Security (MOIS) dominate both offensive/defensive capabilities and domestic surveillance, despite persistent institutional rivalry (<xref ref-type="bibr" rid="ref9011">Serscikov, 2025</xref>; <xref ref-type="bibr" rid="ref9007">Keremo&#x011F;lu and Weidmann, 2020</xref>).</p>
<p>Technically, the NIN rests on massive domestic data-center construction and the mandatory routing of local traffic through state-controlled infrastructure. Internet service providers (ISPs) are legally obliged to filter content, throttle international bandwidth, and hand over user data on demand (<xref ref-type="bibr" rid="ref9003">Dal and Nisbet, 2022</xref>). The controversial &#x201C;Regulatory System for the Protection of Users in Cyberspace&#x201D; bill (commonly known as the Protection Bill, debated 2022&#x2013;2024) sought to institutionalize this control further by mandating data localization, forcing foreign platforms to appoint local representatives, criminalizing unapproved VPNs, and granting authorities direct bandwidth-allocation powers (<xref ref-type="bibr" rid="ref9009">Protection Bill, 2022</xref>; <xref ref-type="bibr" rid="ref40">Freedom House, 2024</xref>). Domestic platforms such as Soroush and Facenema consequently enjoy preferential speed and pricing, creating a de-facto walled garden (<xref ref-type="bibr" rid="ref9014">Yalcintas and Alizadeh, 2020</xref>).</p>
<p>The repressive potential of this architecture was dramatically demonstrated during the 2022&#x2013;2023 Woman, Life, Freedom protests following Mahsa Amini&#x2019;s death. Authorities imposed the longest and most comprehensive internet shutdowns ever recorded, combined near-total international traffic blocks with permanent bans on Instagram and WhatsApp, and deployed deep-packet inspection and mandatory national-ID-linked SIM registration to identify and arrest thousands of protesters (<xref ref-type="bibr" rid="ref9004">Earl et al., 2022</xref>; <xref ref-type="bibr" rid="ref9006">Feldstein, 2021</xref>).</p>
<p>Despite its sophistication, the model remains constrained. Legally, it operates with virtually no independent judicial oversight, violating constitutional guarantees of privacy and freedom of expression (<xref ref-type="bibr" rid="ref9002">Constitution of the Islamic Republic of Iran, 1979</xref>, Arts 23&#x2013;25). Institutionally, rivalry between the IRGC and MOIS fragments coordination (<xref ref-type="bibr" rid="ref9011">Serscikov, 2025</xref>). Socially, widespread VPN use, mesh networks, and creative encryption continue to undermine state control, proving that even advanced digital repression is neither technically nor socially impermeable (<xref ref-type="bibr" rid="ref9003">Dal and Nisbet, 2022</xref>; <xref ref-type="bibr" rid="ref9006">Feldstein, 2021</xref>).</p>
</sec>
</sec>
</sec>
<sec id="sec17">
<label>4</label>
<title>Divergent trajectories in the governance of the cybersecurity-national security nexus</title>
<p>The findings presented in the previous chapter reveal a stark divergence in how states govern the nexus of cybersecurity and national security. While all examined countries have developed complex legal frameworks to address digital threats, the underlying logic of how national security imperatives are integrated with cybersecurity measures differs profoundly. Rule-of-law models emphasize transparency, accountability, and multi-stakeholder participation to build public trust and balance security with human rights, whereas authoritarian approaches prioritize centralized control, state sovereignty, and rapid mobilization, often at the expense of civil liberties (<xref ref-type="bibr" rid="ref51">Jaber, 2025</xref>; <xref ref-type="bibr" rid="ref64">Malvenishvili, 2023</xref>). Indeed, in authoritarian systems, the absence of public trust is not a system failure but a design feature; governance is predicated on coercion and top-down mobilization rather than voluntary cooperation, rendering empirical measures of trust both unobtainable and conceptually secondary to the model&#x2019;s functioning (<xref ref-type="bibr" rid="ref102">Wang and Han, 2025</xref>). This chapter moves beyond the descriptive analysis of individual models to a comparative synthesis, interpreting the results to answer how different political regimes structure this critical relationship. To do so, this discussion will compare the rule-of-law and authoritarian models across three dimensions that emerged from the case studies: first, the nature and internal logic of the dual legal-institutional structures that link national security agencies with cybersecurity authorities; second, the practical effectiveness of oversight mechanisms intended to ensure the accountability of these fused powers (<xref ref-type="bibr" rid="ref86">Santaniello and Barbieri, 2024</xref>); and third, the prevailing models of civil-state cooperation in this hybrid security domain (<xref ref-type="bibr" rid="ref80">Park and Kwon, 2024</xref>). Through this analysis, we can identify the fundamental fault lines that separate democratic and authoritarian approaches to governing the cybersecurity-national security nexus and explore the distinct trade-offs each model presents in terms of crisis adaptability, innovation, and long-term legitimacy (<xref ref-type="bibr" rid="ref10">Boeke, 2018</xref>; <xref ref-type="bibr" rid="ref102">Wang and Han, 2025</xref>).</p>
<sec id="sec18">
<label>4.1</label>
<title>The logic of dual structures: convergence in form, divergence in function</title>
<p>A central finding of this comparative analysis is that both rule-of-law and authoritarian states have converged on a functionally similar dual legal-institutional structure to govern the cybersecurity-national security nexus. In each case, a broad, pre-existing national security framework coexists with a newer, more specific body of cybersecurity legislation. This formal convergence is striking: in Hungary, the Act on National Security Services operates alongside the Act on Cybersecurity; in the United States, the Foreign Intelligence Surveillance Act (FISA) provides the national security mandate while the Cybersecurity Information Sharing Act (CISA) governs partnership; in China, the National Intelligence Law (NIL) underpins the Cybersecurity Law (CSL); and in Russia, the operational powers of the FSB complement the technical controls of the &#x201C;Sovereign Internet Law.&#x201D;</p>
<p>However, this convergence in form masks a profound divergence in function and purpose. In rule-of-law models, these two pillars exist in a state of structural tension. The relationship is ideally one of checks and balances, where cybersecurity partnerships are meant to be transparent and rights-respecting, while the more opaque national security surveillance powers are&#x2014;in theory&#x2014;constrained by legal and procedural safeguards (<xref ref-type="bibr" rid="ref54">Karim et al., 2019</xref>). The American model exemplifies this tension in its most extreme form, creating a paradoxical system where the &#x201C;public face&#x201D; of voluntary partnership coexists uneasily with the &#x201C;hidden face&#x201D; of mass surveillance under FISA, generating persistent legal and political conflict. The Central European models, influenced by EU law, attempt to formally integrate these pillars, but still grapple with the inherent friction between state security prerogatives and the procedural rights demanded by supranational legal norms (<xref ref-type="bibr" rid="ref57">Kelemen et al., 2024b</xref>).</p>
<p>In stark contrast, authoritarian models are designed not for tension but for synergy. The dual structures do not check but rather amplify state power. The national security legislation (e.g., China&#x2019;s NIL, Russia&#x2019;s laws on extremism) provides the overarching ideological justification and coercive authority&#x2014;the &#x201C;why&#x201D;&#x2014;while the cybersecurity laws (e.g., China&#x2019;s CSL, Russia&#x2019;s Yarovaya package) deliver the specific technical and legal instruments for implementation&#x2014;the &#x201C;how.&#x201D; This fusion creates a powerful apparatus for social control, where cybersecurity measures become indistinguishable from tools of state surveillance and repression (<xref ref-type="bibr" rid="ref18">Conduit, 2023</xref>). The principle of &#x201C;cyber sovereignty,&#x201D; central to these regimes, explicitly legitimizes this fusion, framing the extension of state control into the digital realm as a necessary act of national self-defence (<xref ref-type="bibr" rid="ref101">Wang, 2016</xref>; <xref ref-type="bibr" rid="ref50">Hung, 2025</xref>). Thus, while the architectural blueprint appears superficially similar across regimes, its application reveals a fundamental divide: one system is designed to manage and constrain power, the other to maximize and project it.</p>
</sec>
<sec id="sec19">
<label>4.2</label>
<title>The reality of oversight: from flawed guarantees to formalized absence</title>
<p>The most significant divergence between rule-of-law and authoritarian governance models lies in the role and effectiveness of independent oversight mechanisms. While authoritarian systems are defined by the formalized absence of meaningful accountability, the case studies reveal that even in democratic states, the oversight of powers at the cybersecurity-national security nexus is often procedurally flawed and practically ineffective.</p>
<p>Authoritarian models systematically dismantle or co-opt any form of independent oversight. In China, Russia, and Iran, parliamentary bodies and courts function as instruments of the executive, not as checks upon it. Legal frameworks are intentionally crafted with ambiguous terms like &#x201C;national security&#x201D; or &#x201C;extremist activity,&#x201D; which grants security agencies (the CAC, FSB, and IRGC) virtually unlimited discretion (<xref ref-type="bibr" rid="ref104">Wei, 2022</xref>; <xref ref-type="bibr" rid="ref88">Sivetc, 2021</xref>). The legal process is inverted: rather than constraining power, the law is used to legitimize its arbitrary exercise, a clear manifestation of &#x201C;rule by law&#x201D; (<xref ref-type="bibr" rid="ref9010">Schumann, 2025</xref>). In these systems, judicial or parliamentary review of surveillance or content-blocking decisions is either non-existent or a mere formality, leaving no effective remedy for citizens against state overreach (Donais, 2017).</p>
<p>In contrast, rule-of-law models formally embed both parliamentary and judicial oversight, yet these guarantees are consistently weakened when confronted with national security imperatives. In Hungary and Slovakia, parliamentary committee oversight is often described as a mere formality, hampered by the dominance of the governing majority and a lack of technical expertise to scrutinize complex cyber operations (<xref ref-type="bibr" rid="ref106">West, 2023</xref>; <xref ref-type="bibr" rid="ref60">Kovani&#x010D; and Coufalova, 2020</xref>). More critically, the case law of the European Court of Human Rights (Szab&#x00F3; and Vissy v. Hungary; Big Brother Watch v. UK) reveals systemic deficiencies in prior judicial authorization for secret surveillance across Europe, a critique that applies directly to the weak judicial safeguards in both the Hungarian and Slovak systems (<xref ref-type="bibr" rid="ref108">Zalnieriute, 2022</xref>; <xref ref-type="bibr" rid="ref48">Hron and Ill&#x00FD;ov&#x00E1;, 2025</xref>).</p>
<p>The United States presents a unique paradox. It possesses a highly institutionalized oversight body in the Foreign Intelligence Surveillance Court (FISC), yet its effectiveness is deeply contested. Operating in secret, with an ex parte process where only the government&#x2019;s case is heard, the FISC has historically approved over 99% of surveillance applications (<xref ref-type="bibr" rid="ref26">Donohue, 2016</xref>). This has led critics to argue that the court functions more as a legitimizing rubber stamp than as a robust check on the executive, particularly concerning the NSA&#x2019;s bulk collection programs under FISA Section 702 (<xref ref-type="bibr" rid="ref42">Goitein, 2023</xref>).</p>
<p>Thus, while a clear line separates the formalized absence of oversight in authoritarian states from the flawed guarantees in democracies, the latter are far from a complete solution. The &#x201C;national security&#x201D; justification tends to create a zone of exception where executive power expands, and judicial and legislative scrutiny recedes, even within otherwise robust constitutional systems (<xref ref-type="bibr" rid="ref9008">Perriello, 2024</xref>). The critical difference, however, remains: in democracies, these deficiencies are subject to public debate, legal challenge, and potential reform, whereas in authoritarian systems, they are a deliberate feature of the design.</p>
</sec>
<sec id="sec20">
<label>4.3</label>
<title>The civil&#x2013;state relationship: from partnership to subordination</title>
<p>The models examined in the previous chapter delineate three distinct types of civil&#x2013;state relations, ranging from voluntary, incentive-based partnership (United States), through regulated partnership with mandatory elements (EU Member States: Hungary and Slovakia), to legally enforced, complete subordination (authoritarian models). The more the state&#x2019;s control over cyberspace becomes totalised, the more the private sector is transformed into an extended executive arm of the state; conversely, in democratic models, it is precisely the lack of trust and voluntariness that constitutes the greatest practical limitation.</p>
<p>In states implementing authoritarian/totalitarian models, compulsory subordination is observed, as exemplified by China (<xref ref-type="bibr" rid="ref72">National Intelligence Law of the People&#x2019;s Republic of China, 2017</xref>, Article 7), Russia (Yarovaya Package 2016, Sovereign Internet Law 2019) and Iran (National Information Network and Protection Bill 2022&#x2013;2024). In these countries, legal provisions explicitly oblige the private sector to provide immediate and unrestricted data, surrender decryption keys, and actively participate in censorship and surveillance. Companies do not function as partners but as operative executors of state control. The principle of &#x201C;no right of refusal&#x201D; (China), the mandatory deployment of DPI-based filtering systems (Russia), and the state-supported domestic platforms favored by pricing policy (Iran) structurally embed the private sector into the surveillance&#x2013;repressive apparatus serving regime stability.</p>
<p>The democratic model based on voluntary, incentive-driven partnership is most characteristically represented by the United States. The voluntary public-private partnership model emphasized by the Cybersecurity Information Sharing Act (<xref ref-type="bibr" rid="ref17">CISA, 2015</xref>) and the 2023 National Cybersecurity Strategy is, in principle, built on mutual benefits and trust. In practice, however, the lack of trust (lingering effects of the Snowden revelations and data privacy scandals), the unidirectional nature of liability protection, and market logic (cost of security investment versus profit) leave a significant portion of critical infrastructure under-protected. For this reason, the 2023 Strategy explicitly formulates the objectives of &#x201C;rebalancing the responsibility to defend cyberspace&#x201D; and &#x201C;realigning incentives,&#x201D; thereby acknowledging that voluntariness alone is insufficient.</p>
<p>The European Union follows a distinct regulatory model. The regulated partnership interwoven with mandatory elements is characteristic of the EU as a whole and thus of the two countries examined. This is illustrated by the compulsory incident reporting, audits and risk management required by the NIS/NIS2 Directives, meaning that partnership is not entirely voluntary. At the same time, neither Hungary nor Slovakia possesses the coercive toolkit found in authoritarian models (no mandatory backdoors, no obligation to surrender keys, no DPI requirement for ISPs). Here, the principal problem is not the degree of legal compulsion but the absence of deeper, strategic cooperation: the private sector continues to operate primarily in a compliance-driven mindset; due to a &#x201C;blame culture&#x201D; and mutual distrust, genuine, proactive information-sharing does not emerge (see the 2023 NB&#x00DA; report for Slovakia: approximately 50% of obliged entities failed to meet even the audit requirements). The National Cybersecurity Forum (Hungary) and the Steering Committee of the National Cybersecurity Strategy (Slovakia) perform a consultative rather than decision-making role. While both countries exhibit this pattern of state-centric, consultative partnership, a notable difference lies in their institutional architecture: Slovakia maintains a more centralized model with the National Security Authority (NB&#x00DA; SR) as the single national competent authority, whereas Hungary&#x2019;s &#x2018;hybrid model&#x2019; distributes key functions across civilian, military, and regulatory bodies, potentially creating greater coordination challenges.</p>
</sec>
<sec id="sec21">
<label>4.4</label>
<title>Comparative synthesis and policy recommendations for rule-of-law models</title>
<p>In the three democratic models examined, the relationship between cybersecurity and national security exhibits persistent tension. This tension&#x2014;compounded by the limited scope of independent oversight and the only partial strategic depth of civil&#x2013;state relations&#x2014;produces moderate operational effectiveness and a legitimacy deficit (<xref ref-type="table" rid="tab1">Table 1</xref>).</p>
<p>Drawing on the findings of the preceding chapters, the future development of democratic cyber governance should be guided by a triple balancing principle&#x2014;transparency, innovation, and the protection of fundamental rights. This principle is formulated here as a set of recommendations adaptable to all rule-of-law states:</p>
<list list-type="order">
<list-item><p>While preserving the existing dual regulatory structure (cybersecurity law alongside national security law), guarantees of transparency, verifiability, and proportionality must be codified and institutionalized in full conformity with the &#x201C;end-to-end safeguards&#x201D; developed in ECtHR case law, particularly with respect to network-level monitoring and system-level interventions.</p></list-item>
<list-item><p>The current consultative forums for civil&#x2013;state cooperation (e.g., the Hungarian National Cybersecurity Forum, the Slovak Steering Committee, and the sector-specific ISACs in the United States) should be transformed into a Cyber Governance Council endowed with genuine decision-preparation and, where appropriate, co-decision powers, in which critical infrastructure operators, academia, and civil society are represented on a paritary basis.</p></list-item>
<list-item><p>To stimulate innovation and proactive engagement, positive incentives should be introduced (tax relief, reduced cyber-insurance premiums, state-backed guarantee funds) that reward exceeding the minimum requirements laid down in cybersecurity regulation and encourage strategic-level information-sharing.</p></list-item>
<list-item><p>In order to sustain democratic legitimacy, a regular, anonymized yet substantive public reporting obligation must be imposed concerning major incidents and measures of national security relevance.</p></list-item>
</list>
<p>Implementation of these recommendations would enable rule-of-law models to integrate cybersecurity into the national security framework not as an instrument of exclusive state control, but as a transparent, innovation-driven, and fundamental-rights-compliant governance system. This would ensure continued alignment with Euro-Atlantic constitutional standards while simultaneously enhancing societal resilience.</p>
</sec>
</sec>
<sec sec-type="conclusions" id="sec22">
<label>5</label>
<title>Conclusion</title>
<p>The elevation of cybersecurity to a core domain of state security has inevitably extended national-security practices into the digital realm, creating one of the twenty-first century&#x2019;s most profound constitutional dividing lines. The comparison of six states clearly demonstrates that there is no continuum, only a rupture, between rule-of-law and authoritarian governance logics. Where democratic states attempt to bridge the trust deficit by extending the national-security exception into cyberspace, they undermine their own legitimacy. Where authoritarian states instrumentalize cybersecurity for regime stability, they purchase short-term effectiveness at the price of long-term societal and technological fragility.</p>
<p>Democratic societies therefore have no other realistic path: they must take their own constitutional principles and traditions deadly seriously in the digital domain as well. This requires treating cybersecurity as a collectively produced public good whose precondition in a rule-of-law state is an accountable and fundamental-rights-compliant institutional system. The erosion of this system means that democracies will gradually but surely lose the very legitimacy advantage that has hitherto distinguished them from authoritarian models.</p>
<p>In cyberspace there is no neutral governance. Whoever compromises their own principles here will, in the long run, dismantle their own resilience.</p>
</sec>
</body>
<back>
<sec sec-type="data-availability" id="sec23">
<title>Data availability statement</title>
<p>The original contributions presented in the study are included in the article/supplementary material, further inquiries can be directed to the corresponding author.</p>
</sec>
<sec sec-type="author-contributions" id="sec24">
<title>Author contributions</title>
<p>RK: Conceptualization, Investigation, Methodology, Project administration, Supervision, Writing &#x2013; original draft, Writing &#x2013; review &#x0026; editing. BB: Conceptualization, Investigation, Methodology, Writing &#x2013; review &#x0026; editing. MM: Conceptualization, Investigation, Methodology, Writing &#x2013; review &#x0026; editing. JS: Conceptualization, Investigation, Methodology, Writing &#x2013; review &#x0026; editing. JC: Conceptualization, Investigation, Methodology, Writing &#x2013; review &#x0026; editing. HS: Conceptualization, Investigation, Methodology, Writing &#x2013; review &#x0026; editing.</p>
</sec>
<sec sec-type="COI-statement" id="sec25">
<title>Conflict of interest</title>
<p>The author(s) declared that this work was conducted in the absence of any commercial or financial relationships that could be construed as a potential conflict of interest.</p>
</sec>
<sec sec-type="ai-statement" id="sec26">
<title>Generative AI statement</title>
<p>The author(s) declared that Generative AI was not used in the creation of this manuscript.</p>
<p>Any alternative text (alt text) provided alongside figures in this article has been generated by Frontiers with the support of artificial intelligence and reasonable efforts have been made to ensure accuracy, including review by the authors wherever possible. If you identify any issues, please contact us.</p>
</sec>
<sec sec-type="disclaimer" id="sec27">
<title>Publisher&#x2019;s note</title>
<p>All claims expressed in this article are solely those of the authors and do not necessarily represent those of their affiliated organizations, or those of the publisher, the editors and the reviewers. Any product that may be evaluated in this article, or claim that may be made by its manufacturer, is not guaranteed or endorsed by the publisher.</p>
</sec>
<ref-list>
<title>References</title>
<ref id="ref1"><mixed-citation publication-type="book"><person-group person-group-type="author"><collab>Act CXXV of 1995 on the National Security Services</collab></person-group>. (<year>1995</year>). <publisher-loc>Hungary</publisher-loc>.</mixed-citation></ref>
<ref id="ref2"><mixed-citation publication-type="book"><source>Act LXIX of 2024 on Hungary&#x2019;s cybersecurity</source>. <publisher-loc>Hungary</publisher-loc>.</mixed-citation></ref>
<ref id="ref3"><mixed-citation publication-type="book"><source>Act no. 366/2024 Coll. Amending act no. 69/2018 Coll</source>. (<year>2024</year>). <publisher-loc>Slovak Republic</publisher-loc>.</mixed-citation></ref>
<ref id="ref4"><mixed-citation publication-type="book"><source>Act no. 69/2018 Coll. On cybersecurity</source>. (<year>2018</year>). <publisher-loc>Slovak Republic</publisher-loc>.</mixed-citation></ref>
<ref id="ref5"><mixed-citation publication-type="journal"><person-group person-group-type="author"><name><surname>Aho</surname><given-names>B.</given-names></name> <name><surname>Duffield</surname><given-names>R.</given-names></name></person-group> (<year>2020</year>). <article-title>Beyond surveillance capitalism: privacy, regulation and big data in Europe and China</article-title>. <source>Econ. Soc.</source> <volume>49</volume>, <fpage>187</fpage>&#x2013;<lpage>212</lpage>. doi: <pub-id pub-id-type="doi">10.1080/03085147.2019.1690275</pub-id></mixed-citation></ref>
<ref id="ref6"><mixed-citation publication-type="journal"><person-group person-group-type="author"><name><surname>Arroyabe</surname><given-names>M. F. A.</given-names></name> <name><surname>Arranz</surname><given-names>C. F. A.</given-names></name> <name><surname>de Fernanz Arroyabe</surname><given-names>I.</given-names></name> <name><surname>de Fernanz Arroyabe</surname><given-names>J. C.</given-names></name></person-group> (<year>2024</year>). <article-title>Navigating cybersecurity: environment&#x2019;s impact on standards adoption and board involvement</article-title>. <source>J. Comput. Inf. Syst.</source> doi: <pub-id pub-id-type="doi">10.1080/08874417.2024.2394440</pub-id></mixed-citation></ref>
<ref id="ref7"><mixed-citation publication-type="journal"><person-group person-group-type="author"><name><surname>Atkins</surname><given-names>S.</given-names></name> <name><surname>Lawson</surname><given-names>C.</given-names></name></person-group> (<year>2021</year>). <article-title>Cooperation amidst competition: cybersecurity partnership in the US financial services sector</article-title>. <source>J. Cybersecur.</source> <volume>7</volume>:<fpage>tyab024</fpage>. doi: <pub-id pub-id-type="doi">10.1093/cybsec/tyab024</pub-id></mixed-citation></ref>
<ref id="ref8"><mixed-citation publication-type="journal"><person-group person-group-type="author"><name><surname>Barrinha</surname><given-names>A.</given-names></name> <name><surname>Renard</surname><given-names>T.</given-names></name></person-group> (<year>2020</year>). <article-title>Power and diplomacy in the post-liberal cyberspace</article-title>. <source>Int. Aff.</source> <volume>96</volume>, <fpage>749</fpage>&#x2013;<lpage>766</lpage>. doi: <pub-id pub-id-type="doi">10.1093/ia/iiz274</pub-id></mixed-citation></ref>
<ref id="ref9"><mixed-citation publication-type="other"><person-group person-group-type="author"><collab id="coll1">Bird and Bird</collab></person-group> (<year>2025</year>) China data protection and cybersecurity: Annual review of 2024 and outlook for 2025 (II). Available online at: <ext-link xlink:href="https://www.twobirds.com/en/insights/2025/china/china-data-protection-and-cybersecurity-annual-review-of-2024-and-outlook-for-2025-%28ii%29" ext-link-type="uri">https://www.twobirds.com/en/insights/2025/china/china-data-protection-and-cybersecurity-annual-review-of-2024-and-outlook-for-2025-%28ii%29</ext-link> (Accessed: 18 November 2025).</mixed-citation></ref>
<ref id="ref10"><mixed-citation publication-type="journal"><person-group person-group-type="author"><name><surname>Boeke</surname><given-names>S.</given-names></name></person-group> (<year>2018</year>). <article-title>National cyber crisis management: different European approaches</article-title>. <source>Governance</source> <volume>31</volume>, <fpage>87</fpage>&#x2013;<lpage>102</lpage>. doi: <pub-id pub-id-type="doi">10.1111/gove.12309</pub-id></mixed-citation></ref>
<ref id="ref11"><mixed-citation publication-type="journal"><person-group person-group-type="author"><name><surname>Calcara</surname><given-names>A.</given-names></name> <name><surname>Csernatoni</surname><given-names>R.</given-names></name> <name><surname>Lavall&#x00E9;e</surname><given-names>C.</given-names></name> <name><surname>Siddi</surname><given-names>M.</given-names></name></person-group> (<year>2022</year>). <article-title>State-industry relations and cybersecurity governance in Europe</article-title>. <source>Rev. Int. Polit. Econ.</source> <volume>29</volume>, <fpage>1237</fpage>&#x2013;<lpage>1262</lpage>. doi: <pub-id pub-id-type="doi">10.1080/09692290.2021.1913438</pub-id></mixed-citation></ref>
<ref id="ref12"><mixed-citation publication-type="book"><person-group person-group-type="author"><name><surname>Cary</surname><given-names>D.</given-names></name></person-group> (<year>2024</year>). <source>Governing cybersecurity</source>. <publisher-loc>China</publisher-loc>: <publisher-name>Interpret</publisher-name>.</mixed-citation></ref>
<ref id="ref13"><mixed-citation publication-type="journal"><person-group person-group-type="author"><name><surname>Cavelty</surname><given-names>M. D.</given-names></name> <name><surname>Egloff</surname><given-names>F. J.</given-names></name></person-group> (<year>2019</year>). <article-title>The politics of cybersecurity: balancing different roles of the state</article-title>. <source>St. Antony's Int. Rev.</source> <volume>15</volume>, <fpage>9</fpage>&#x2013;<lpage>32</lpage>.</mixed-citation></ref>
<ref id="ref14"><mixed-citation publication-type="other"><source>Centrum f&#x00F6;r r&#x00E4;ttvisa v. Sweden, grand chamber, app. No. 35252/08 (European court of human rights, 25 June 2021)</source>.</mixed-citation></ref>
<ref id="ref15"><mixed-citation publication-type="journal"><person-group person-group-type="author"><name><surname>Cheng</surname><given-names>P.</given-names></name></person-group> (<year>2022</year>). <article-title>Decoding the rise of central Bank digital currency in China: designs, problems, and prospects</article-title>. <source>J. Bank. Regul.</source> <volume>24</volume>, <fpage>156</fpage>&#x2013;<lpage>170</lpage>. doi: <pub-id pub-id-type="doi">10.1057/s41261-022-00193-5</pub-id></mixed-citation></ref>
<ref id="ref16"><mixed-citation publication-type="journal"><person-group person-group-type="author"><name><surname>Chovancov&#x00E1;</surname><given-names>K.</given-names></name></person-group> (<year>2016</year>). <article-title>Institutional opportunities of the parliamentary opposition in Slovakia: useless tools or powerful weapons?</article-title> <source>Politolog. Cas. / Czech J. Polit. Sci.</source> <volume>23</volume>, <fpage>211</fpage>&#x2013;<lpage>234</lpage>. doi: <pub-id pub-id-type="doi">10.5817/PC2016-3-211</pub-id></mixed-citation></ref>
<ref id="ref17"><mixed-citation publication-type="other"><person-group person-group-type="author"><collab>CISA</collab></person-group> (<year>2015</year>). <article-title>Binding Operational Directive 15-01: Critical Vulnerability Mitigation Requirement for Federal Civilian Executive Branch Departments and Agencies</article-title>. Available online at: <ext-link xlink:href="https://www.cisa.gov/news-events/directives/binding-operational-directive-15-01" ext-link-type="uri">https://www.cisa.gov/news-events/directives/binding-operational-directive-15-01</ext-link> (Accessed November 13, 2025).</mixed-citation></ref>
<ref id="ref18"><mixed-citation publication-type="journal"><person-group person-group-type="author"><name><surname>Conduit</surname><given-names>D.</given-names></name></person-group> (<year>2023</year>). <article-title>Digital authoritarianism and the devolution of authoritarian rule: examining Syria&#x2019;s patriotic hackers</article-title>. <source>Inf. Commun. Technol. Law</source> <volume>32</volume>, <fpage>979</fpage>&#x2013;<lpage>997</lpage>. doi: <pub-id pub-id-type="doi">10.1080/13510347.2023.2187781</pub-id></mixed-citation></ref>
<ref id="ref9002"><mixed-citation publication-type="other"><person-group person-group-type="author"><collab>Constitution of the Islamic Republic of Iran</collab></person-group>. (<year>1979</year>). Available online at: <ext-link xlink:href="https://www.constituteproject.org/constitution/Iran_1989" ext-link-type="uri">https://www.constituteproject.org/constitution/Iran_1989</ext-link> (Accessed November 13, 2025).</mixed-citation></ref>
<ref id="ref19"><mixed-citation publication-type="journal"><person-group person-group-type="author"><name><surname>Creemers</surname><given-names>R.</given-names></name></person-group> (<year>2022</year>). <article-title>China&#x2019;s emerging data protection framework</article-title>. <source>SSRN Electron. J.</source> doi: <pub-id pub-id-type="doi">10.2139/ssrn.3964684</pub-id></mixed-citation></ref>
<ref id="ref20"><mixed-citation publication-type="journal"><person-group person-group-type="author"><name><surname>Creemers</surname><given-names>R.</given-names></name></person-group> (<year>2023</year>). <article-title>Cybersecurity law and regulation in China: securing the smart state</article-title>. <source>China Law Soc. Rev.</source> <volume>6</volume>, <fpage>111</fpage>&#x2013;<lpage>150</lpage>. doi: <pub-id pub-id-type="doi">10.1163/27669217-12340020</pub-id></mixed-citation></ref>
<ref id="ref21"><mixed-citation publication-type="other"><source>Cybersecurity information sharing act of 2015 (CISA 2015), pub. L. No. 114&#x2013;113, div. N, 129 stat. 2935</source>.</mixed-citation></ref>
<ref id="ref22"><mixed-citation publication-type="other"><person-group person-group-type="author"><collab id="coll3">Cybersecurity Law of the People&#x2019;s Republic of China</collab></person-group> (<year>2017</year>). <source>Standing Committee of the National People&#x2019;s congress of the people&#x2019;s republic of China</source>.</mixed-citation></ref>
<ref id="ref9003"><mixed-citation publication-type="journal"><person-group person-group-type="author"><name><surname>Dal</surname><given-names>A.</given-names></name> <name><surname>Nisbet</surname><given-names>E. C.</given-names></name></person-group> (<year>2022</year>). <article-title>Walking through firewalls: circumventing censorship of social media and online content in a networked authoritarian context</article-title>. <source>Soc. Media Soc.</source> <volume>8</volume>. doi: <pub-id pub-id-type="doi">10.1177/20563051221137738</pub-id></mixed-citation></ref>
<ref id="ref23"><mixed-citation publication-type="other"><person-group person-group-type="author"><collab id="coll4">Data Security Law of the People&#x2019;s Republic of China</collab></person-group> (<year>2021</year>). <source>Standing Committee of the National People&#x2019;s congress of the people&#x2019;s republic of China</source>.</mixed-citation></ref>
<ref id="ref24"><mixed-citation publication-type="journal"><person-group person-group-type="author"><collab id="coll5">Directive (EU) 2016/1148</collab></person-group>. (<year>2016</year>). <article-title>2022/2555 of the European Parliament and of the council of 14 December 2022 on measures for a high common level of cybersecurity across the union (NIS2 directive)</article-title>. <source>Off. J. Eur. Union L333</source>, <fpage>80</fpage>&#x2013;<lpage>152</lpage>.</mixed-citation></ref>
<ref id="ref26"><mixed-citation publication-type="book"><person-group person-group-type="author"><name><surname>Donohue</surname><given-names>L. K.</given-names></name></person-group> (<year>2016</year>). <source>The future of foreign intelligence: Privacy and surveillance in the digital age</source>. <publisher-loc>Oxford</publisher-loc>: <publisher-name>Oxford University Press</publisher-name>.</mixed-citation></ref>
<ref id="ref9004"><mixed-citation publication-type="journal"><person-group person-group-type="author"><name><surname>Earl</surname><given-names>J.</given-names></name> <name><surname>Maher</surname><given-names>T. V.</given-names></name> <name><surname>Pan</surname><given-names>J.</given-names></name></person-group> (<year>2022</year>). <article-title>The digital repression of social movements, protest, and activism: a synthetic review</article-title>. <source>Sci. Adv.</source> <volume>8</volume>:<fpage>eabl8198</fpage>. doi: <pub-id pub-id-type="doi">10.1126/sciadv.abl8198</pub-id></mixed-citation></ref>
<ref id="ref27"><mixed-citation publication-type="other"><person-group person-group-type="author"><name><surname>Edgar</surname><given-names>T.</given-names></name></person-group> (<year>2024</year>) Reauthorizing section 702: Congress missed its best chance for real reform. Lawfare, 22 April. Available online at: <ext-link xlink:href="https://www.lawfaremedia.org/article/reauthorizing-section-702-congress-missed-its-best-chance-real-reform" ext-link-type="uri">https://www.lawfaremedia.org/article/reauthorizing-section-702-congress-missed-its-best-chance-real-reform</ext-link> (Accessed: 18 November 2025).</mixed-citation></ref>
<ref id="ref9005"><mixed-citation publication-type="journal"><person-group person-group-type="author"><name><surname>Egloff</surname><given-names>F. J.</given-names></name> <name><surname>Smeets</surname><given-names>M.</given-names></name></person-group> (<year>2023</year>). <article-title>Publicly attributing cyber attacks: a framework</article-title>. <source>J. Strateg. Stud.</source> <volume>46</volume>, <fpage>502</fpage>&#x2013;<lpage>533</lpage>. doi: <pub-id pub-id-type="doi">10.1080/01402390.2021.1895117</pub-id></mixed-citation></ref>
<ref id="ref28"><mixed-citation publication-type="other"><source>Ekimdzhiev and others v. Bulgaria, app. Nos. 70078/12 and 5 others (European court of human rights, 11 January 2022)</source>.</mixed-citation></ref>
<ref id="ref29"><mixed-citation publication-type="book"><person-group person-group-type="author"><name><surname>Epifanova</surname><given-names>A.</given-names></name></person-group> (<year>2020</year>). <source>Deciphering Russia&#x2019;s &#x201C;sovereign internet law&#x201D;: Tightening control and accelerating the splinternet. DGAP analysis no. 2</source>. <publisher-loc>Berlin</publisher-loc>: <publisher-name>German Council on Foreign Relations</publisher-name>.</mixed-citation></ref>
<ref id="ref30"><mixed-citation publication-type="journal"><person-group person-group-type="author"><name><surname>Ermoshina</surname><given-names>K.</given-names></name> <name><surname>Loveluck</surname><given-names>B.</given-names></name> <name><surname>Musiani</surname><given-names>F.</given-names></name></person-group> (<year>2021</year>). <article-title>A market of black boxes: the political economy of internet surveillance and censorship in Russia</article-title>. <source>J. Inf. Technol. Polit.</source> <volume>19</volume>, <fpage>18</fpage>&#x2013;<lpage>33</lpage>. doi: <pub-id pub-id-type="doi">10.1080/19331681.2021.1905972</pub-id></mixed-citation></ref>
<ref id="ref31"><mixed-citation publication-type="other"><person-group person-group-type="author"><collab id="coll6">European Court of Human Rights</collab></person-group> (<year>2016</year>) <source>Case of Szab&#x00F3; and Vissy v. Hungary (application no. 37138/14)</source></mixed-citation></ref>
<ref id="ref32"><mixed-citation publication-type="other"><person-group person-group-type="author"><collab id="coll7">European Court of Human Rights</collab></person-group> <year>2021</year> <source>Case of big brother watch and others v. the United Kingdom (applications nos. 58170/13, 62322/14 and 24960/15)</source></mixed-citation></ref>
<ref id="ref33"><mixed-citation publication-type="book"><person-group person-group-type="author"><collab id="coll8">European Union Agency for Cybersecurity (ENISA)</collab></person-group> (<year>2023</year>). <source>Governance framework for National Cybersecurity Strategies</source>. <publisher-loc>Heraklion</publisher-loc>: <publisher-name>ENISA</publisher-name>.</mixed-citation></ref>
<ref id="ref34"><mixed-citation publication-type="other"><person-group person-group-type="author"><collab id="coll9">Federal Law No. 242-FZ of 21</collab></person-group>. (<year>2015</year>). <source>On amendments to certain legislative acts of the Russian Federation regarding clarification of personal data processing procedures in information and telecommunication networks (Data Localization Law)</source>.</mixed-citation></ref>
<ref id="ref35"><mixed-citation publication-type="other"><person-group person-group-type="author"><collab id="coll10">Federal law no. 32-FZ</collab></person-group> (<year>2022</year>). <source>On amendments to the criminal code of the Russian Federation</source>.</mixed-citation></ref>
<ref id="ref36"><mixed-citation publication-type="other"><person-group person-group-type="author"><collab id="coll11">Federal law no. 374-FZ</collab></person-group> (<year>2016</year>). On amendments to the Federal law on counteracting terrorism and certain legislative acts of the Russian Federation (Yarovaya law).</mixed-citation></ref>
<ref id="ref37"><mixed-citation publication-type="journal"><person-group person-group-type="author"><collab id="coll12">Federal Law No. 90-FZ of 1</collab></person-group> (<year>2019</year>). <article-title>On amendments to the Federal law &#x2018;on communications&#x2019; and the Federal law &#x2018;on information</article-title>. <source>Information Technologies and Protection of Information&#x2019; (Sovereign Internet Law).</source></mixed-citation></ref>
<ref id="ref9006"><mixed-citation publication-type="book"><person-group person-group-type="author"><name><surname>Feldstein</surname><given-names>S.</given-names></name></person-group> (<year>2021</year>). <source>The Rise of Digital Repression: How Technology is Reshaping Power, Politics, and Resistance</source>. <publisher-loc>Oxford</publisher-loc>: <publisher-name>Oxford University Press</publisher-name>.</mixed-citation></ref>
<ref id="ref38"><mixed-citation publication-type="other"><person-group person-group-type="author"><collab>Foreign Intelligence Surveillance Act of 1978</collab></person-group>. (<year>1978</year>). <source>pub. L. No. 95&#x2013;511, 92 stat. 1783 (codified as amended at 50 U.S.C. &#x00A7;&#x00A7; 1801&#x2013;1885c), especially section 702</source>.</mixed-citation></ref>
<ref id="ref39"><mixed-citation publication-type="other"><person-group person-group-type="author"><collab id="coll13">FRA (European Union Agency for Fundamental Rights)</collab></person-group> (<year>2022</year>). <source>Fundamental rights and digital security in the EU</source></mixed-citation></ref>
<ref id="ref40"><mixed-citation publication-type="book"><person-group person-group-type="author"><collab id="coll14">Freedom House</collab></person-group> (<year>2024</year>). <source>Nations in transit 2024: A region reordered by autocracy and democracy</source>. <publisher-loc>Washington, D.C.</publisher-loc>: <publisher-name>Freedom House</publisher-name>.</mixed-citation></ref>
<ref id="ref41"><mixed-citation publication-type="journal"><person-group person-group-type="author"><name><surname>Glasze</surname><given-names>G.</given-names></name> <name><surname>Cattaruzza</surname><given-names>A.</given-names></name> <name><surname>Douzet</surname><given-names>F.</given-names></name> <name><surname>Dammann</surname><given-names>F.</given-names></name> <name><surname>Bertran</surname><given-names>M.-G.</given-names></name> <name><surname>B&#x00F4;mont</surname><given-names>C.</given-names></name> <etal/></person-group>. (<year>2023</year>). <article-title>Contested spatialities of digital sovereignty</article-title>. <source>Geopolitics</source> <volume>28</volume>, <fpage>919</fpage>&#x2013;<lpage>958</lpage>. doi: <pub-id pub-id-type="doi">10.1080/14650045.2022.2050070</pub-id></mixed-citation></ref>
<ref id="ref42"><mixed-citation publication-type="book"><person-group person-group-type="author"><name><surname>Goitein</surname><given-names>E.</given-names></name></person-group> (<year>2023</year>). <source>The fourth amendment in the digital age</source>. <publisher-loc>New York</publisher-loc>: <publisher-name>Brennan Center for Justice</publisher-name>.</mixed-citation></ref>
<ref id="ref43"><mixed-citation publication-type="other"><person-group person-group-type="author"><collab id="coll15">Government of the Slovak Republic</collab></person-group> (<year>2021</year>) <source>National Cybersecurity Strategy of the Slovak Republic 2021&#x2013;2025</source></mixed-citation></ref>
<ref id="ref44"><mixed-citation publication-type="other"><person-group person-group-type="author"><collab id="coll16">Government Office SR</collab></person-group> (<year>2024</year>) <source>Prechodn&#x00E9; ustanovenia k z&#x00E1;konu 366/2024 Z. z</source></mixed-citation></ref>
<ref id="ref45"><mixed-citation publication-type="book"><source>Government resolution 1089/2025 (III. 31.) on Hungary&#x2019;s cybersecurity strategy</source>. <publisher-loc>Hungary</publisher-loc>.</mixed-citation></ref>
<ref id="ref46"><mixed-citation publication-type="other"><person-group person-group-type="author"><collab id="coll17">Grand Chamber</collab></person-group>. (<year>2021</year>). <source>Big brother watch and others v. the United Kingdom, grand chamber, app. Nos. 58170/13, 62322/14 and 24960/15 (European court of human rights, 25 may 2021)</source>.</mixed-citation></ref>
<ref id="ref47"><mixed-citation publication-type="journal"><person-group person-group-type="author"><name><surname>Guo</surname><given-names>S.</given-names></name> <name><surname>Li</surname><given-names>X.</given-names></name></person-group> (<year>2024</year>). <article-title>Cross-border data flow in China: shifting from restriction to relaxation?</article-title> <source>Comput. Law Secur. Rev.</source> <volume>56</volume>:<fpage>106079</fpage>. doi: <pub-id pub-id-type="doi">10.1016/j.clsr.2024.106079</pub-id></mixed-citation></ref>
<ref id="ref48"><mixed-citation publication-type="journal"><person-group person-group-type="author"><name><surname>Hron</surname><given-names>I.</given-names></name> <name><surname>Ill&#x00FD;ov&#x00E1;</surname><given-names>Z. M.</given-names></name></person-group> (<year>2025</year>). <article-title>ECtHR: KUL&#x00C1;K v. SLOVAKIA (application no. 57748/21, 3 April 2025): exposing structural flaws in the Slovak code of criminal procedure on legal professional privilege</article-title>. <source>Bratisl. Law Rev.</source> <volume>9</volume>, <fpage>255</fpage>&#x2013;<lpage>268</lpage>. doi: <pub-id pub-id-type="doi">10.46282/blr.2025.9.1.1020</pub-id></mixed-citation></ref>
<ref id="ref49"><mixed-citation publication-type="journal"><person-group person-group-type="author"><name><surname>Huang</surname><given-names>K.</given-names></name> <name><surname>Madnick</surname><given-names>S.</given-names></name> <name><surname>Zhang</surname><given-names>F.</given-names></name> <name><surname>Siegel</surname><given-names>M.</given-names></name></person-group> (<year>2021</year>). <article-title>Varieties of public&#x2013;private co-governance on cybersecurity within the digital trade: implications from Huawei&#x2019;s 5G</article-title>. <source>J. Chin. Gov.</source> <volume>7</volume>, <fpage>81</fpage>&#x2013;<lpage>110</lpage>. doi: <pub-id pub-id-type="doi">10.1080/23812346.2021.1923230</pub-id></mixed-citation></ref>
<ref id="ref50"><mixed-citation publication-type="journal"><person-group person-group-type="author"><name><surname>Hung</surname><given-names>H. T.</given-names></name></person-group> (<year>2025</year>). <article-title>Exploring China&#x2019;s cyber sovereignty concept and artificial intelligence governance model: a machine learning approach</article-title>. <source>J. Comput. Soc. Sci.</source> <volume>8</volume>:<fpage>24</fpage>. doi: <pub-id pub-id-type="doi">10.1007/s42001-024-00346-8</pub-id></mixed-citation></ref>
<ref id="ref51"><mixed-citation publication-type="journal"><person-group person-group-type="author"><name><surname>Jaber</surname><given-names>A.</given-names></name></person-group> (<year>2025</year>). <article-title>Cybersecurity governance and political structures: comparing centralized and decentralized approaches to cyber defense</article-title>. <source>Comp. Strateg.</source> <volume>44</volume>, <fpage>752</fpage>&#x2013;<lpage>771</lpage>. doi: <pub-id pub-id-type="doi">10.1080/01495933.2025.2507310</pub-id></mixed-citation></ref>
<ref id="ref52"><mixed-citation publication-type="journal"><person-group person-group-type="author"><name><surname>Jardine</surname><given-names>E.</given-names></name> <name><surname>Porter</surname><given-names>N.</given-names></name> <name><surname>Shandler</surname><given-names>R.</given-names></name></person-group> (<year>2024</year>). <article-title>Cyberattacks and public opinion: the effect of uncertainty in guiding preferences</article-title>. <source>J. Peace Res.</source> <volume>61</volume>:<fpage>178</fpage>. doi: <pub-id pub-id-type="doi">10.1177/00223433231218178</pub-id></mixed-citation></ref>
<ref id="ref53"><mixed-citation publication-type="book"><person-group person-group-type="author"><name><surname>Jones</surname><given-names>B.</given-names></name></person-group> (<year>2025</year>). <source>Trust in crisis: rebuilding public confidence in national security institutions</source>. <publisher-loc>Washington, DC</publisher-loc>: <publisher-name>Center for Strategic and International Studies</publisher-name>.</mixed-citation></ref>
<ref id="ref54"><mixed-citation publication-type="journal"><person-group person-group-type="author"><name><surname>Karim</surname><given-names>R.</given-names></name> <name><surname>Bonhi</surname><given-names>T. C.</given-names></name> <name><surname>Afroze</surname><given-names>R.</given-names></name></person-group> (<year>2019</year>). <article-title>Governance of cyberspace: personal liberty vs. national security</article-title>. <source>Int. J. Sci. Technol. Res.</source> <volume>8</volume>, <fpage>2636</fpage>&#x2013;<lpage>2641</lpage>.</mixed-citation></ref>
<ref id="ref55"><mixed-citation publication-type="journal"><person-group person-group-type="author"><name><surname>Kaye</surname><given-names>D.</given-names></name></person-group> (<year>2022</year>). <article-title>Online propaganda, censorship and human rights in Russia&#x2019;s war against reality</article-title>. <source>Am. J. Int. Law Unbound</source> <volume>116</volume>, <fpage>140</fpage>&#x2013;<lpage>144</lpage>. doi: <pub-id pub-id-type="doi">10.1017/aju.2022.22</pub-id></mixed-citation></ref>
<ref id="ref56"><mixed-citation publication-type="journal"><person-group person-group-type="author"><name><surname>Kelemen</surname><given-names>R.</given-names></name> <name><surname>Bucko</surname><given-names>B.</given-names></name> <name><surname>Mazuch</surname><given-names>M.</given-names></name></person-group> (<year>2024a</year>). <article-title>Modernizing Hungary&#x2019;s cybersecurity framework: addressing evolving threats and enhancing national resilience</article-title>. <source>Rechtskultur.</source></mixed-citation></ref>
<ref id="ref57"><mixed-citation publication-type="journal"><person-group person-group-type="author"><name><surname>Kelemen</surname><given-names>R.</given-names></name> <name><surname>Farkas</surname><given-names>&#x00C1;.</given-names></name> <name><surname>Bu&#x010D;ko</surname><given-names>B.</given-names></name> <name><surname>Jordan</surname><given-names>Z.</given-names></name></person-group> (<year>2024b</year>). <article-title>Public trust in national security institutions as a key to sustainable security</article-title>. <source>Connections Q. J.</source> <volume>23</volume>, <fpage>49</fpage>&#x2013;<lpage>62</lpage>. doi: <pub-id pub-id-type="doi">10.11610/Connections.23.4.03</pub-id></mixed-citation></ref>
<ref id="ref9007"><mixed-citation publication-type="journal"><person-group person-group-type="author"><name><surname>Keremo&#x011F;lu</surname><given-names>E.</given-names></name> <name><surname>Weidmann</surname><given-names>N. B.</given-names></name></person-group> (<year>2020</year>). <article-title>How dictators control the internet: a review essay</article-title>. <source>Comp. Polit. Stud.</source> <volume>53</volume>, <fpage>1690</fpage>&#x2013;<lpage>1703</lpage>. doi: <pub-id pub-id-type="doi">10.1177/0010414020912278</pub-id></mixed-citation></ref>
<ref id="ref58"><mixed-citation publication-type="journal"><person-group person-group-type="author"><name><surname>Kianpour</surname><given-names>M.</given-names></name> <name><surname>Davis</surname><given-names>P. A. E.</given-names></name> <name><surname>Windekilde</surname><given-names>I. M.</given-names></name></person-group> (<year>2025</year>). <article-title>Digital sovereignty in practice: analyzing the EU&#x2019;S NIS2 directive</article-title>. <source>Int. J. Inf. Secur.</source> <volume>24</volume>:<fpage>167</fpage>. doi: <pub-id pub-id-type="doi">10.1007/s10207-025-01090-4</pub-id></mixed-citation></ref>
<ref id="ref59"><mixed-citation publication-type="journal"><person-group person-group-type="author"><name><surname>Knutelsk&#x00E1;</surname><given-names>V.</given-names></name></person-group> (<year>2011</year>). <article-title>Working practices winning out over formal rules: parliamentary scrutiny of EU matters in the Czech Republic, Poland and Slovakia</article-title>. <source>Perspect. Eur. Polit. Soc.</source> <volume>12</volume>, <fpage>379</fpage>&#x2013;<lpage>397</lpage>. doi: <pub-id pub-id-type="doi">10.1080/15705854.2011.619527</pub-id></mixed-citation></ref>
<ref id="ref60"><mixed-citation publication-type="journal"><person-group person-group-type="author"><name><surname>Kovani&#x010D;</surname><given-names>M.</given-names></name> <name><surname>Coufalova</surname><given-names>A.</given-names></name></person-group> (<year>2020</year>). <article-title>The legitimacy of intelligence surveillance: the fight against terrorism in the Czech Republic and Slovakia</article-title>. <source>Intell. Natl. Secur.</source> <volume>35</volume>, <fpage>115</fpage>&#x2013;<lpage>130</lpage>. doi: <pub-id pub-id-type="doi">10.1080/02684527.2019.1634389</pub-id></mixed-citation></ref>
<ref id="ref61"><mixed-citation publication-type="journal"><person-group person-group-type="author"><name><surname>Liebetrau</surname><given-names>T.</given-names></name></person-group> (<year>2022</year>). <article-title>Organizing cyber capability across military and intelligence entities: collaboration, separation, or centralization</article-title>. <source>Policy Des. Pract.</source> <volume>6</volume>, <fpage>131</fpage>&#x2013;<lpage>145</lpage>. doi: <pub-id pub-id-type="doi">10.1080/25741292.2022.2127551</pub-id></mixed-citation></ref>
<ref id="ref62"><mixed-citation publication-type="journal"><person-group person-group-type="author"><name><surname>Litvinenko</surname><given-names>A.</given-names></name></person-group> (<year>2021</year>). <article-title>Re-defining borders online: Russia&#x2019;s strategic narrative on internet sovereignty</article-title>. <source>Media Commun.</source> <volume>9</volume>, <fpage>5</fpage>&#x2013;<lpage>15</lpage>. doi: <pub-id pub-id-type="doi">10.17645/mac.v9i4.4292</pub-id></mixed-citation></ref>
<ref id="ref63"><mixed-citation publication-type="journal"><person-group person-group-type="author"><name><surname>Luk&#x00E1;&#x010D;</surname><given-names>J.</given-names></name> <name><surname>Kudlov&#x00E1;</surname><given-names>Z.</given-names></name> <name><surname>Kop&#x010D;&#x00E1;kov&#x00E1;</surname><given-names>J.</given-names></name> <name><surname>Gallo</surname><given-names>P.</given-names></name></person-group> (<year>2025</year>). <article-title>Impact of socio-economic factors on digital literacy and security</article-title>. <source>TEM J.</source> <volume>14</volume>, <fpage>123</fpage>&#x2013;<lpage>134</lpage>. doi: <pub-id pub-id-type="doi">10.18421/TEM141-15</pub-id></mixed-citation></ref>
<ref id="ref64"><mixed-citation publication-type="book"><person-group person-group-type="author"><name><surname>Malvenishvili</surname><given-names>M.</given-names></name></person-group> (<year>2023</year>). &#x201C;<article-title>Analyzing cybersecurity strategies in democratic and authoritarian regimes: a comparative study of the United States and China</article-title>&#x201D; in <source>Cyber security policies and strategies of the world&#x2019;s leading states</source>. ed. <person-group person-group-type="editor"><name><surname>Khan</surname><given-names>A. A.</given-names></name></person-group> (<publisher-loc>Hershey, PA</publisher-loc>: <publisher-name>IGI Global</publisher-name>), <fpage>234</fpage>&#x2013;<lpage>255</lpage>.</mixed-citation></ref>
<ref id="ref65"><mixed-citation publication-type="book"><person-group person-group-type="author"><name><surname>Manjikian</surname><given-names>M.</given-names></name></person-group> (<year>2023</year>). <source>Cybersecurity ethics: A normative approach</source>. <publisher-loc>London</publisher-loc>: <publisher-name>Routledge</publisher-name>.</mixed-citation></ref>
<ref id="ref66"><mixed-citation publication-type="journal"><person-group person-group-type="author"><name><surname>McIntosh</surname><given-names>T.</given-names></name> <name><surname>Liu</surname><given-names>T.</given-names></name> <name><surname>Susnjak</surname><given-names>T.</given-names></name> <name><surname>Alavizadeh</surname><given-names>H.</given-names></name> <name><surname>Ng</surname><given-names>A.</given-names></name> <name><surname>Watters</surname><given-names>P.</given-names></name></person-group> (<year>2023</year>). <article-title>Harnessing GPT-4 for generation of cybersecurity GRC policies: a focus on ransomware attack mitigation</article-title>. <source>Comput. Secur.</source> <volume>134</volume>:<fpage>103424</fpage>. doi: <pub-id pub-id-type="doi">10.1016/j.cose.2023.103424</pub-id></mixed-citation></ref>
<ref id="ref67"><mixed-citation publication-type="other"><person-group person-group-type="author"><collab id="coll18">Ministry of Defence SR</collab></person-group> (<year>2024</year>). <source>Cyber Defence Framework</source></mixed-citation></ref>
<ref id="ref68"><mixed-citation publication-type="other"><person-group person-group-type="author"><collab id="coll19">MIRRI SR (Ministry of Investment, Regional Development and Informatization)</collab></person-group> (<year>2024</year>). <source>D&#x00F4;vodov&#x00E1; spr&#x00E1;va k NIS2 transpoz&#x00ED;cii</source></mixed-citation></ref>
<ref id="ref69"><mixed-citation publication-type="journal"><person-group person-group-type="author"><name><surname>Mishra</surname><given-names>A.</given-names></name> <name><surname>Alzoubi</surname><given-names>Y. I.</given-names></name> <name><surname>Anwar</surname><given-names>M. J.</given-names></name> <name><surname>Gill</surname><given-names>A. Q.</given-names></name></person-group> (<year>2022</year>). <article-title>Attributes impacting cybersecurity policy development: an evidence from seven nations</article-title>. <source>Comput. Secur.</source> <volume>120</volume>:<fpage>102820</fpage>. doi: <pub-id pub-id-type="doi">10.1016/j.cose.2022.102820</pub-id></mixed-citation></ref>
<ref id="ref70"><mixed-citation publication-type="journal"><person-group person-group-type="author"><name><surname>Moyakine</surname><given-names>E.</given-names></name> <name><surname>Tabachnik</surname><given-names>A.</given-names></name></person-group> (<year>2021</year>). <article-title>Struggling to strike the right balance between interests at stake: the &#x2018;Yarovaya&#x2019;, &#x2018;fake news&#x2019; and &#x2018;disrespect&#x2019; laws as examples of ill-conceived legislation in the age of modern technology</article-title>. <source>Comput. Law Secur. Rev.</source> <volume>40</volume>:<fpage>105512</fpage>. doi: <pub-id pub-id-type="doi">10.1016/j.clsr.2020.105512</pub-id></mixed-citation></ref>
<ref id="ref71"><mixed-citation publication-type="other"><person-group person-group-type="author"><collab id="coll20">National Council of the Slovak Republic</collab></person-group> (<year>2023</year>) <source>Mandate and activities of the defence and security committee</source></mixed-citation></ref>
<ref id="ref72"><mixed-citation publication-type="other"><person-group person-group-type="author"><collab id="coll21">National Intelligence Law of the People&#x2019;s Republic of China</collab></person-group> (<year>2017</year>) <source>Standing Committee of the National People&#x2019;s congress of the people&#x2019;s republic of China</source></mixed-citation></ref>
<ref id="ref73"><mixed-citation publication-type="book"><person-group person-group-type="author"><collab id="coll22">NATO</collab></person-group> (<year>2021</year>). <source>Climate change and security action plan</source>. <publisher-loc>Brussels</publisher-loc>: <publisher-name>NATO</publisher-name>.</mixed-citation></ref>
<ref id="ref74"><mixed-citation publication-type="book"><person-group person-group-type="author"><collab id="coll23">NATO</collab></person-group> (<year>2022</year>). <source>Strategic concept</source>. <publisher-loc>Brussels</publisher-loc>: <publisher-name>NATO</publisher-name>.</mixed-citation></ref>
<ref id="ref75"><mixed-citation publication-type="other"><person-group person-group-type="author"><collab id="coll24">NB&#x00DA; SR (National Security Authority)</collab></person-group> (<year>2023</year>) <source>Spr&#x00E1;va o stave kybernetickej bezpe&#x010D;nosti SR</source></mixed-citation></ref>
<ref id="ref76"><mixed-citation publication-type="other"><person-group person-group-type="author"><collab id="coll25">NB&#x00DA; SR (National Security Authority)</collab></person-group> (<year>2024</year>). <source>Preh&#x013E;ad zmien v z&#x00E1;kone o kybernetickej bezpe&#x010D;nosti</source></mixed-citation></ref>
<ref id="ref77"><mixed-citation publication-type="book"><person-group person-group-type="author"><collab id="coll26">NIST</collab></person-group> (<year>2020</year>). <source>Cybersecurity framework version 1.1</source>. <publisher-loc>Gaithersburg, MD</publisher-loc>: <publisher-name>National Institute of Standards and Technology</publisher-name>.</mixed-citation></ref>
<ref id="ref78"><mixed-citation publication-type="book"><person-group person-group-type="author"><collab id="coll27">NIST</collab></person-group> (<year>2024</year>). <source>Cybersecurity framework 2.0</source>. <publisher-loc>Gaithersburg, MD</publisher-loc>: <publisher-name>National Institute of Standards and Technology</publisher-name>.</mixed-citation></ref>
<ref id="ref80"><mixed-citation publication-type="other"><person-group person-group-type="author"><name><surname>Park</surname><given-names>S.</given-names></name> <name><surname>Kwon</surname><given-names>H.</given-names></name></person-group> (<year>2024</year>) &#x201C;Governance of cyber threat information sharing for public-private partnerships: comparative analysis of National Cases.&#x201D; In <italic>2024 IEEE/ACIS 24th international conference on computer and information science (ICIS 2024) &#x2013; Proceedings</italic>, pp. 41&#x2013;48.</mixed-citation></ref>
<ref id="ref9008"><mixed-citation publication-type="journal"><person-group person-group-type="author"><name><surname>Perriello</surname><given-names>L. E.</given-names></name></person-group> (<year>2024</year>). <article-title>Digital surveillance under European scrutiny. A dangerous alliance unveiled</article-title>. <source>Ital. Law J.</source> <volume>10</volume>, <fpage>237</fpage>&#x2013;<lpage>259</lpage>. doi: <pub-id pub-id-type="doi">10.23815/2421-2156.ITALJ</pub-id></mixed-citation></ref>
<ref id="ref81"><mixed-citation publication-type="other"><person-group person-group-type="author"><collab id="coll29">Personal Information Protection Law of the People&#x2019;s Republic of China</collab></person-group> (<year>2021</year>). <source>Standing Committee of the National People&#x2019;s congress of the people&#x2019;s republic of China</source>.</mixed-citation></ref>
<ref id="ref82"><mixed-citation publication-type="other"><person-group person-group-type="author"><name><surname>Pijpers</surname><given-names>P.B.M.J.</given-names></name> <name><surname>Boddens Hosang</surname><given-names>J.F.R.</given-names></name> <name><surname>Ducheine</surname><given-names>P.A.L.</given-names></name></person-group> (<year>2021</year>) Collective cyber defence &#x2013; The EU and NATO perspective on cyber attacks. Amsterdam law school research paper no. 2021&#x2013;37, Amsterdam Center for International law no. 2021&#x2013;13. Available online at: <ext-link xlink:href="https://ssrn.com/abstract=3962163" ext-link-type="uri">https://ssrn.com/abstract=3962163</ext-link> (Accessed: 18 November 2025).</mixed-citation></ref>
<ref id="ref83"><mixed-citation publication-type="journal"><person-group person-group-type="author"><name><surname>Pollini</surname><given-names>A.</given-names></name> <name><surname>Callari</surname><given-names>T. C.</given-names></name> <name><surname>Tedeschi</surname><given-names>A.</given-names></name> <name><surname>Ruscio</surname><given-names>D.</given-names></name> <name><surname>Save</surname><given-names>L.</given-names></name> <name><surname>Chiarugi</surname><given-names>F.</given-names></name> <etal/></person-group>. (<year>2022</year>). <article-title>Leveraging human factors in cybersecurity: an integrated methodological approach</article-title>. <source>Cogn. Tech. Work</source> <volume>24</volume>, <fpage>371</fpage>&#x2013;<lpage>390</lpage>. doi: <pub-id pub-id-type="doi">10.1007/s10111-021-00683-y</pub-id>, <pub-id pub-id-type="pmid">34149309</pub-id></mixed-citation></ref>
<ref id="ref9009"><mixed-citation publication-type="book"><person-group person-group-type="author"><collab>Protection Bill</collab></person-group>. (<year>2022</year>). <article-title>Regulatory System for Cyberspace Services Bill (Protection Bill).</article-title> <publisher-loc>Tehran</publisher-loc>: <publisher-name>Islamic Consultative Assembly</publisher-name>. Available online at: <ext-link xlink:href="https://rc.majlis.ir/fa/legal_draft/show/1600586" ext-link-type="uri">https://rc.majlis.ir/fa/legal_draft/show/1600586</ext-link> (Accessed November 13, 2025).</mixed-citation></ref>
<ref id="ref84"><mixed-citation publication-type="journal"><person-group person-group-type="author"><name><surname>Ramich</surname><given-names>M. S.</given-names></name> <name><surname>Piskunov</surname><given-names>D. A.</given-names></name></person-group> (<year>2022</year>). <article-title>The securitization of cyberspace: from rulemaking to establishing legal regimes</article-title>. <source>Vestn. RUDN. Mezhdunar. Otnosheniya</source> <volume>22</volume>, <fpage>238</fpage>&#x2013;<lpage>255</lpage>. doi: <pub-id pub-id-type="doi">10.22363/2313-0660-2022-22-2-238-255</pub-id></mixed-citation></ref>
<ref id="ref85"><mixed-citation publication-type="journal"><person-group person-group-type="author"><name><surname>Saeed</surname><given-names>S.</given-names></name> <name><surname>Suayyid</surname><given-names>S. A.</given-names></name> <name><surname>Al-Ghamdi</surname><given-names>M. S.</given-names></name> <name><surname>Al-Muhaisen</surname><given-names>H.</given-names></name> <name><surname>Almuhaideb</surname><given-names>A. M.</given-names></name></person-group> (<year>2023</year>). <article-title>A systematic literature review on cyber threat intelligence for organizational cybersecurity resilience</article-title>. <source>Sensors</source> <volume>23</volume>:<fpage>7273</fpage>. doi: <pub-id pub-id-type="doi">10.3390/s23167273</pub-id>, <pub-id pub-id-type="pmid">37631808</pub-id></mixed-citation></ref>
<ref id="ref86"><mixed-citation publication-type="journal"><person-group person-group-type="author"><name><surname>Santaniello</surname><given-names>M.</given-names></name> <name><surname>Barbieri</surname><given-names>M.</given-names></name></person-group> (<year>2024</year>). <article-title>Monocratic cybersecurity in the EU member states: insights from Italy, France, Germany and Spain</article-title>. <source>Eur. Politics Soc.</source> <volume>26</volume>, <fpage>1</fpage>&#x2013;<lpage>25</lpage>. doi: <pub-id pub-id-type="doi">10.1080/23745118.2024.2349893</pub-id>, <pub-id pub-id-type="pmid">41307611</pub-id></mixed-citation></ref>
<ref id="ref9010"><mixed-citation publication-type="journal"><person-group person-group-type="author"><name><surname>Schumann</surname><given-names>M. P.</given-names></name></person-group> (<year>2025</year>). <article-title>Legalizing control: the rise of restrictive internet regulation in sub-Saharan Africa</article-title>. <source>Democratization</source>, <volume>1&#x2013;26</volume>. doi: <pub-id pub-id-type="doi">10.1080/13510347.2025.2503370</pub-id></mixed-citation></ref>
<ref id="ref9011"><mixed-citation publication-type="journal"><person-group person-group-type="author"><name><surname>Serscikov</surname><given-names>G.</given-names></name></person-group> (<year>2025</year>). <article-title>NOCs and illegals in the current surveillance landscape: can mimicry help overcome evolving challenges?</article-title> <source>Intell. Natl. Secur.</source> <volume>40</volume>, <fpage>507</fpage>&#x2013;<lpage>532</lpage>. doi: <pub-id pub-id-type="doi">10.1080/02684527.2025.2485806</pub-id></mixed-citation></ref>
<ref id="ref87"><mixed-citation publication-type="journal"><person-group person-group-type="author"><name><surname>Shah</surname><given-names>M. U.</given-names></name> <name><surname>Iqbal</surname><given-names>F.</given-names></name> <name><surname>Rehman</surname><given-names>U.</given-names></name> <name><surname>Hung</surname><given-names>P. C. K.</given-names></name></person-group> (<year>2023</year>). <article-title>A comparative assessment of human factors in cybersecurity: implications for cyber governance</article-title>. <source>IEEE Access</source> <volume>11</volume>, <fpage>87970</fpage>&#x2013;<lpage>87987</lpage>. doi: <pub-id pub-id-type="doi">10.1109/ACCESS.2023.3296580</pub-id></mixed-citation></ref>
<ref id="ref88"><mixed-citation publication-type="journal"><person-group person-group-type="author"><name><surname>Sivetc</surname><given-names>L.</given-names></name></person-group> (<year>2021</year>). <article-title>Controlling free expression &#x201C;by infrastructure&#x201D; in the Russian internet: the consequences of RuNet sovereignization</article-title>. <source>First Monday</source> <volume>26</volume>:<fpage>698</fpage>. doi: <pub-id pub-id-type="doi">10.5210/fm.v26i5.11698</pub-id></mixed-citation></ref>
<ref id="ref89"><label>NIS2</label><mixed-citation publication-type="other"><person-group person-group-type="author"><collab id="coll30">Smernica</collab></person-group> (<year>2024</year>) <source>&#x010C;o je SK-CERT, CSIRT &#x010D;i ENISA a pre&#x010D;o s&#x00FA; d&#x00F4;le&#x017E;it&#x00E9; pre na&#x0161;u kyberbezpe&#x010D;nos&#x0165;?</source></mixed-citation></ref>
<ref id="ref90"><mixed-citation publication-type="book"><person-group person-group-type="author"><name><surname>Soesanto</surname><given-names>S.</given-names></name> <name><surname>Smeets</surname><given-names>M.</given-names></name></person-group> (<year>2021</year>). &#x201C;<article-title>Cyber deterrence: the past, present, and future</article-title>&#x201D; in <source>NL ARMS Netherlands annual review of military studies 2020: Deterrence in the 21st century&#x2014;Insights from theory and practice</source>. eds. <person-group person-group-type="editor"><name><surname>Osinga</surname><given-names>F.</given-names></name> <name><surname>Sweijs</surname><given-names>T.</given-names></name></person-group> (<publisher-loc>The Hague</publisher-loc>: <publisher-name>T.M.C. Asser Press</publisher-name>), <fpage>409</fpage>&#x2013;<lpage>429</lpage>.</mixed-citation></ref>
<ref id="ref91"><mixed-citation publication-type="journal"><person-group person-group-type="author"><name><surname>Sokol</surname><given-names>P.</given-names></name> <name><surname>R&#x00F3;zenfeldov&#x00E1;</surname><given-names>L. B.</given-names></name></person-group> (<year>2025</year>). <article-title>Content blocking mechanism in cybersecurity: Slovakia case study</article-title>. <source>EURASIP J. Inf. Secur.</source> <volume>2025</volume>:<fpage>4</fpage>. doi: <pub-id pub-id-type="doi">10.1186/s13635-025-00190-x</pub-id></mixed-citation></ref>
<ref id="ref9012"><mixed-citation publication-type="book"><person-group person-group-type="author"><collab>Supreme Council of Cyberspace</collab></person-group> (<year>2012</year>). <article-title>Founding Decree of the Supreme Council of Cyberspace</article-title>. <publisher-loc>Tehran</publisher-loc>: <publisher-name>Office of the Supreme Leader</publisher-name>. Available online at: <ext-link xlink:href="https://www.leader.ir/fa/content/9213/" ext-link-type="uri">https://www.leader.ir/fa/content/9213/</ext-link> (Accessed November 13, 2025).</mixed-citation></ref>
<ref id="ref9013"><mixed-citation publication-type="book"><person-group person-group-type="author"><collab>Supreme Council of Cyberspace</collab></person-group> (<year>2017</year>). <article-title>Tabyin-e al-Z&#x0101;m&#x0101;t-e Shabake-ye Mell&#x012B;-ye E&#x1E6D;&#x1E6D;el&#x0101;&#x2019;&#x0101;t (Clarification of the Requirements of the National Information Network)</article-title>. <publisher-loc>Tehran</publisher-loc>: <publisher-name>Supreme Council of Cyberspace</publisher-name>. Available online at: <ext-link xlink:href="https://www.ekhtebar.ir/&#x0645;&#x0635;&#x0648;&#x0628;&#x0647;-&#x0634;&#x0648;&#x0631;&#x0627;&#x06CC;-&#x0639;&#x0627;&#x0644;&#x06CC;-&#x0641;&#x0636;&#x0627;&#x06CC;-&#x0645;&#x062C;&#x0627;&#x0632;&#x06CC;-&#x0628;&#x0627;-&#x0639;&#x0646;&#x0648;&#x0627;&#x0646;-&#x0633;/" ext-link-type="uri">https://www.ekhtebar.ir/&#x0645;&#x0635;&#x0648;&#x0628;&#x0647;-&#x0634;&#x0648;&#x0631;&#x0627;&#x06CC;-&#x0639;&#x0627;&#x0644;&#x06CC;-&#x0641;&#x0636;&#x0627;&#x06CC;-&#x0645;&#x062C;&#x0627;&#x0632;&#x06CC;-&#x0628;&#x0627;-&#x0639;&#x0646;&#x0648;&#x0627;&#x0646;-&#x0633;/</ext-link> (Accessed November 13, 2025).</mixed-citation></ref>
<ref id="ref92"><mixed-citation publication-type="book"><person-group person-group-type="author"><name><surname>Szab&#x00F3;</surname><given-names>V.</given-names></name> <name><surname>Vissy</surname><given-names>V.</given-names></name></person-group> (<year>2016</year>). <source>App. No. 37138/14 (European court of human rights, 12 January 2016)</source>. <publisher-loc>Hungary</publisher-loc>.</mixed-citation></ref>
<ref id="ref93"><mixed-citation publication-type="journal"><person-group person-group-type="author"><name><surname>Taylor</surname><given-names>R. D.</given-names></name></person-group> (<year>2020</year>). <article-title>Data localization: the internet in the balance</article-title>. <source>Telecommun. Policy</source> <volume>44</volume>:<fpage>102003</fpage>. doi: <pub-id pub-id-type="doi">10.1016/j.telpol.2020.102003</pub-id></mixed-citation></ref>
<ref id="ref94"><mixed-citation publication-type="book"><person-group person-group-type="author"><collab id="coll31">The White House</collab></person-group> (<year>2023</year>). <source>National Cybersecurity Strategy</source>. <publisher-loc>Washington, DC</publisher-loc>.</mixed-citation></ref>
<ref id="ref95"><mixed-citation publication-type="journal"><person-group person-group-type="author"><name><surname>Trevaskes</surname><given-names>S.</given-names></name></person-group> (<year>2024</year>). <article-title>Integrating stability maintenance into comprehensive governance: the burgeoning &#x201C;safe China&#x201D; behemoth</article-title>. <source>Modern China</source> <volume>50</volume>, <fpage>3</fpage>&#x2013;<lpage>34</lpage>. doi: <pub-id pub-id-type="doi">10.1177/00977004231205889</pub-id></mixed-citation></ref>
<ref id="ref96"><mixed-citation publication-type="journal"><person-group person-group-type="author"><name><surname>Ullah</surname><given-names>M. W.</given-names></name> <name><surname>Alam</surname><given-names>M. T.</given-names></name> <name><surname>Sultana</surname><given-names>T.</given-names></name> <name><surname>Rahman</surname><given-names>M. M.</given-names></name> <name><surname>Faraji</surname><given-names>M. R.</given-names></name> <name><surname>Ahmed</surname><given-names>M. F.</given-names></name></person-group> (<year>2024</year>). <article-title>A systematic review on information security policies in the USA banking system and global banking: risks, rewards, and future trends</article-title>. <source>Edelweiss Applied Sci. Technol.</source> <volume>8</volume>, <fpage>8437</fpage>&#x2013;<lpage>8453</lpage>. doi: <pub-id pub-id-type="doi">10.55214/25768484.v8i6.3816</pub-id></mixed-citation></ref>
<ref id="ref97"><mixed-citation publication-type="book"><person-group person-group-type="author"><collab id="coll32">United Nations</collab></person-group> (<year>2021</year>). <source>Our common agenda &#x2013; policy brief 2: strengthening the international response to complex global shocks</source>. <publisher-loc>New York</publisher-loc>: <publisher-name>United Nations</publisher-name>.</mixed-citation></ref>
<ref id="ref98"><mixed-citation publication-type="other"><person-group person-group-type="author"><collab>USA PATRIOT act of 2001</collab></person-group>. (<year>2001</year>). <source>pub. L. No. 107&#x2013;56, 115 stat. 272 (uniting and strengthening America by providing appropriate tools required to intercept and obstruct terrorism act of 2001)</source>.</mixed-citation></ref>
<ref id="ref99"><mixed-citation publication-type="journal"><person-group person-group-type="author"><name><surname>Va&#x0161;ko</surname><given-names>A.</given-names></name></person-group> (<year>2022</year>). <article-title>The legal regulation of special means by the intelligence Agency of the Slovak Republic within the case law of the European court of human rights</article-title>. <source>Access to Justice in Eastern Europe</source> <volume>5</volume>, <fpage>123</fpage>&#x2013;<lpage>140</lpage>. doi: <pub-id pub-id-type="doi">10.33327/AJEE-2022.5.3.123</pub-id></mixed-citation></ref>
<ref id="ref100"><mixed-citation publication-type="other"><person-group person-group-type="author"><name><surname>Veigurs</surname><given-names>M.</given-names></name> <name><surname>Lasmanis</surname><given-names>T.</given-names></name> <name><surname>Romanovs</surname><given-names>A.</given-names></name></person-group> (<year>2024</year>). &#x201C;IT governance in critical sectors: towards the NIS2 implementation.&#x201D; In <italic>2024 IEEE 65th international scientific conference on information technology and management science of Riga Technical University (ITMS)</italic>, pp. 1&#x2013;6.</mixed-citation></ref>
<ref id="ref101"><mixed-citation publication-type="journal"><person-group person-group-type="author"><name><surname>Wang</surname><given-names>C.</given-names></name></person-group> (<year>2016</year>). <article-title>Four principles on internet governance reflecting a global norm based on international law</article-title>. <source>J. Nanjing University of Posts and Telecommunications (Social Science Edition)</source> <volume>16</volume>, <fpage>1</fpage>&#x2013;<lpage>6</lpage>. doi: <pub-id pub-id-type="doi">10.14132/j.cnki.1673-5439.2016.01.002</pub-id></mixed-citation></ref>
<ref id="ref102"><mixed-citation publication-type="journal"><person-group person-group-type="author"><name><surname>Wang</surname><given-names>Y.</given-names></name> <name><surname>Han</surname><given-names>R.</given-names></name></person-group> (<year>2025</year>). <article-title>Authoritarian elasticity: how autocracies may effectively mobilize for crisis management</article-title>. <source>Governance</source> <volume>38</volume>, <fpage>1</fpage>&#x2013;<lpage>20</lpage>. doi: <pub-id pub-id-type="doi">10.1111/gove.70074</pub-id></mixed-citation></ref>
<ref id="ref103"><mixed-citation publication-type="journal"><person-group person-group-type="author"><name><surname>Wang</surname><given-names>F.</given-names></name> <name><surname>Wang</surname><given-names>H.</given-names></name> <name><surname>Li</surname><given-names>J.</given-names></name></person-group> (<year>2024</year>). <article-title>The effect of cybersecurity legislation on firm cost behavior: evidence from China</article-title>. <source>Pac. Basin Financ. J.</source> <volume>86</volume>:<fpage>102460</fpage>. doi: <pub-id pub-id-type="doi">10.1016/j.pacfin.2024.102460</pub-id></mixed-citation></ref>
<ref id="ref104"><mixed-citation publication-type="journal"><person-group person-group-type="author"><name><surname>Wei</surname><given-names>X.</given-names></name></person-group> (<year>2022</year>). <article-title>A critical evaluation of China&#x2019;s legal responses to cyberterrorism</article-title>. <source>Comput. Law Secur. Rev.</source> <volume>47</volume>:<fpage>105768</fpage>. doi: <pub-id pub-id-type="doi">10.1016/j.clsr.2022.105768</pub-id></mixed-citation></ref>
<ref id="ref105"><mixed-citation publication-type="journal"><person-group person-group-type="author"><name><surname>Weiss</surname><given-names>M.</given-names></name> <name><surname>Krieger</surname><given-names>N.</given-names></name></person-group> (<year>2025</year>). <article-title>The political economy of cybersecurity: governments, firms and opportunity structures for business power</article-title>. <source>Contemp. Secur. Policy</source> <volume>46</volume>, <fpage>403</fpage>&#x2013;<lpage>428</lpage>. doi: <pub-id pub-id-type="doi">10.1080/13523260.2025.2474867</pub-id></mixed-citation></ref>
<ref id="ref106"><mixed-citation publication-type="journal"><person-group person-group-type="author"><name><surname>West</surname><given-names>H.</given-names></name></person-group> (<year>2023</year>). <article-title>Parliamentary committees and ex-post oversight: institutional options and design</article-title>. <source>Parliam. Aff.</source> <volume>76</volume>, <fpage>345</fpage>&#x2013;<lpage>362</lpage>. doi: <pub-id pub-id-type="doi">10.1093/pa/gsac012</pub-id></mixed-citation></ref>
<ref id="ref107"><mixed-citation publication-type="journal"><person-group person-group-type="author"><name><surname>Whyte</surname><given-names>C.</given-names></name></person-group> (<year>2020</year>). <article-title>Cyber conflict or democracy &#x201C;hacked&#x201D;? How cyber operations enhance information warfare</article-title>. <source>J. Cybersecur.</source> <volume>6</volume>:<fpage>tyaa013</fpage>. doi: <pub-id pub-id-type="doi">10.1093/cybsec/tyaa013</pub-id></mixed-citation></ref>
<ref id="ref9014"><mixed-citation publication-type="journal"><person-group person-group-type="author"><name><surname>Yalcintas</surname><given-names>A.</given-names></name> <name><surname>Alizadeh</surname><given-names>N.</given-names></name></person-group> (<year>2020</year>). <article-title>Digital protectionism and national planning in the age of the internet: the case of Iran</article-title>. <source>J. Inst. Econ.</source> <volume>16</volume>, <fpage>519</fpage>&#x2013;<lpage>536</lpage>. doi: <pub-id pub-id-type="doi">10.1017/S1744137420000077</pub-id></mixed-citation></ref>
<ref id="ref108"><mixed-citation publication-type="journal"><person-group person-group-type="author"><name><surname>Zalnieriute</surname><given-names>M.</given-names></name></person-group> (<year>2022</year>). <article-title>Big brother watch and others v. the United Kingdom</article-title>. <source>Am. J. Int. Law</source> <volume>116</volume>, <fpage>585</fpage>&#x2013;<lpage>592</lpage>. doi: <pub-id pub-id-type="doi">10.1017/ajil.2022.35</pub-id></mixed-citation></ref>
</ref-list>
<fn-group>
<fn fn-type="custom" custom-type="edited-by" id="fn0001">
<p>Edited by: <ext-link ext-link-type="uri" xlink:href="https://loop.frontiersin.org/people/3052690/overview">Luiz Rog&#x00E9;rio Franco Goldoni</ext-link>, Brazilian Army Command and General Staff College, Brazil</p></fn>
<fn fn-type="custom" custom-type="reviewed-by" id="fn0002">
<p>Reviewed by: <ext-link ext-link-type="uri" xlink:href="https://loop.frontiersin.org/people/3254616/overview">Zhamilia Klycheva</ext-link>, TransResearch Consortium, United States</p>
<p><ext-link ext-link-type="uri" xlink:href="https://loop.frontiersin.org/people/3295647/overview">Ma&#x0142;gorzata Krystyna Kamola-Cie&#x015B;lik</ext-link>, University of Szczecin, Poland</p></fn>
</fn-group>
</back>
</article>