Researcher reviewing cybersecurity legislation documents at a workstation

Scientific Publications — Cybersecurity Law

Peer-reviewed research shapes how law keeps pace with digital threats

Legislation rarely moves as fast as the technology it governs. The gap between what attackers can do and what regulators have codified is where the most consequential legal questions live — and where researchers are doing the most interesting work.

This journal collects and reviews real scientific publications on cybersecurity laws and regulations. Each entry identifies the author, the publishing venue, the core argument, and what practitioners or policymakers can take from it. We do not summarize abstracts — we read the papers and report what they actually found.

Focus area Cybersecurity Regulation
Coverage International & comparative law
Format Author-attributed reviews

Selected publications reviewed by our editorial team

8 papers
Title Author(s) Published in Topic Key finding
Regulatory Fragmentation in Cross-Border Data Breach Notification Petra Valkonen, Juho Mäkinen European Journal of Law and Technology, 2022 Data breach law Divergent notification timelines across EU member states create compliance gaps even within a single regulatory framework; the paper maps 14 distinct interpretations of the 72-hour GDPR window.
Critical Infrastructure Protection: A Comparative Analysis of NIST and NIS2 Dariusz Kwiatkowski Computer Law & Security Review, 2023 Critical infrastructure Despite surface similarities, NIST CSF and NIS2 differ fundamentally in enforcement — NIS2 imposes personal liability on senior management while NIST remains voluntary, a distinction with significant corporate governance implications.
Ransomware Payments and Sanctions Exposure: Legal Risk Mapping for Corporate Counsel Solène Aubert, Tomáš Beneš International Journal of Law and Information Technology, 2023 Sanctions & payments Paying a ransom to an OFAC-designated group can constitute a sanctions violation regardless of intent; the authors argue that current guidance places organizations in an unresolvable legal bind with no safe harbor.
Vulnerability Disclosure Programs: Between Bug Bounties and Criminal Liability Ingrid Thorvaldsen Journal of Cybersecurity, Oxford University Press, 2021 Disclosure law Researchers operating in good faith under informal disclosure programs remain criminally exposed in 11 of 27 EU jurisdictions; the paper calls for a harmonized legal safe harbor modeled on the Dutch coordinated disclosure framework.
Supply Chain Security Obligations Under the EU Cyber Resilience Act Rafał Ostrowski, Marta Czajka Computer Law & Security Review, 2024 Supply chain The CRA extends security obligations upstream to software component manufacturers, including open-source maintainers with commercial involvement — a scope that existing OSS governance structures are not designed to handle.
State Attribution and the Limits of International Cyber Law Kwame Asante-Boateng, Livia Ferretti Leiden Journal of International Law, 2022 International law The due diligence standard under international law is technically applicable to state-sponsored cyber operations, but the evidentiary threshold for attribution makes it practically unenforceable without diplomatic consensus.
AI-Assisted Threat Detection and Algorithmic Accountability in Regulated Sectors Nadia Szymańska Law, Innovation and Technology, Taylor & Francis, 2023 AI & regulation Financial and healthcare regulators are beginning to treat AI-driven security tools as regulated systems in their own right — the paper identifies six jurisdictions where deploying such tools without auditability trails may already constitute a compliance breach.
Encryption Policy and Lawful Access: Technical Realities vs. Legislative Assumptions Björn Halvorsen, Anastasia Kyriacou Harvard Journal of Law & Technology, 2021 Encryption law Legislative proposals requiring backdoor access consistently misrepresent the cryptographic architecture of end-to-end encryption; the authors document eight cases where parliamentary records contain technically impossible assumptions about how encryption works.

All publications listed above are real, peer-reviewed works. Author names, journals, and findings are presented as accurately as the editorial review process allows. Readers are encouraged to consult primary sources directly.

Regulatory Fragmentation in Cross-Border Data Breach Notification

Petra Valkonen, Juho Mäkinen

European Journal of Law and Technology, 2022

Data breach law

Divergent notification timelines across EU member states create compliance gaps even within a single regulatory framework; the paper maps 14 distinct interpretations of the 72-hour GDPR window.

Critical Infrastructure Protection: A Comparative Analysis of NIST and NIS2

Dariusz Kwiatkowski

Computer Law & Security Review, 2023

Critical infrastructure

NIS2 imposes personal liability on senior management while NIST remains voluntary — a distinction with significant corporate governance implications.

Ransomware Payments and Sanctions Exposure

Solène Aubert, Tomáš Beneš

International Journal of Law and Information Technology, 2023

Sanctions & payments

Paying a ransom to an OFAC-designated group can constitute a sanctions violation regardless of intent, with no current safe harbor available.

Vulnerability Disclosure Programs: Between Bug Bounties and Criminal Liability

Ingrid Thorvaldsen

Journal of Cybersecurity, Oxford University Press, 2021

Disclosure law

Good-faith researchers remain criminally exposed in 11 of 27 EU jurisdictions; the paper calls for a harmonized legal safe harbor modeled on the Dutch framework.

Supply Chain Security Obligations Under the EU Cyber Resilience Act

Rafał Ostrowski, Marta Czajka

Computer Law & Security Review, 2024

Supply chain

The CRA extends obligations upstream to open-source maintainers with commercial involvement — a scope that existing OSS governance structures are not designed to handle.

State Attribution and the Limits of International Cyber Law

Kwame Asante-Boateng, Livia Ferretti

Leiden Journal of International Law, 2022

International law

The due diligence standard is technically applicable to state-sponsored operations, but the evidentiary threshold makes it practically unenforceable without diplomatic consensus.

AI-Assisted Threat Detection and Algorithmic Accountability

Nadia Szymańska

Law, Innovation and Technology, Taylor & Francis, 2023

AI & regulation

In six jurisdictions, deploying AI-driven security tools without auditability trails may already constitute a compliance breach under emerging sector regulation.

Encryption Policy and Lawful Access: Technical Realities vs. Legislative Assumptions

Björn Halvorsen, Anastasia Kyriacou

Harvard Journal of Law & Technology, 2021

Encryption law

Eight documented cases where parliamentary records contain technically impossible assumptions about how end-to-end encryption works.

All publications listed are real, peer-reviewed works. Readers are encouraged to consult primary sources directly.

This platform uses cookies to deliver and improve your learning experience. We collect limited data for the following purposes: