Cybersecurity Policy Research in the Social Sciences: A Systematic Literature Review and Bibliometric Analysis

Authors

  • Refa Andrean Tri P Universitas Sebelas Maret, Indonesia
  • Ismi Dwi Astuti Nurhaeni Universitas Sebelas Maret, Indonesia
  • Faizatul Ansoriyah Universitas Sebelas Maret, Indonesia

DOI:

https://doi.org/10.58524/smartsociety.v6i2.1275

Keywords:

Bibliometric Analysis, Conceptual Model, Cybersecurity Policy, Social Sciences, Systematic Literature Review

Abstract

The global digital transformation has positioned cybersecurity policy as a strategic issue within the social sciences rather than merely a technical concern. Although cybersecurity has been widely examined in technical, engineering, and information systems domains, studies that systematically map cybersecurity policy research from a social science perspective remain limited and fragmented across governance, regulatory, institutional, and socio-political dimensions. Therefore, a comprehensive synthesis is needed to better understand the development, intellectual structure, and future directions of cybersecurity policy scholarship within the social sciences. This study aims to map the development of cybersecurity policy research, identify publication patterns based on countries, institutions, sources, and publication types, and synthesize the key determinants and social dimensions associated with cybersecurity policy. The study employs a Systematic Literature Review and bibliometric analysis of 70 Scopus-indexed articles published up to March 17, 2026. The findings reveal a substantial increase in cybersecurity policy research over the past decade, particularly in studies related to governance, regulation, and geopolitical issues, reflecting a growing multidisciplinary orientation. The thematic synthesis and literature analysis identify five key determinants of cybersecurity policy and several social, political, and economic dimensions frequently associated with cybersecurity governance. These findings are integrated into a conceptual model developed from literature synthesis and bibliometric mapping to illustrate the relationships among the identified determinants and associated dimensions. This study contributes to enriching the cybersecurity policy literature from a social science perspective and provides directions for future research and policy development.

References

Afshari-Mofrad, M., Amrollahi, A., & Abedin, B. (2024). Adopt agile cybersecurity policymaking to counter emerging digital risks. MIS Quarterly Executive, 23(4), 371–386. https://doi.org/10.17705/2msqe.00102

Alhumud, T. A. A., Omar, A., & Altohami, W. M. A. (2023). An assessment of cybersecurity performance in the Saudi universities: A total quality management approach. Cogent Education, 10(2),1-16. https://doi.org/10.1080/2331186X.2023.2265227

Al Husaeni, D. F., & Nandiyanto, A. B. D. (2022). Bibliometric using VOSviewer with Publish or Perish (using Google Scholar data): From step-by-step processing for users to the practical examples in the analysis of digital learning articles in pre and post COVID-19 pandemic. ASEAN Journal of Science and Engineering, 2(1), 19–46. https://doi.org/10.17509/ajse.v2i1.37368

Andreasson, A., Artman, H., Brynielsson, J., & Franke, U. (2020). A census of Swedish government administrative authority employee communications on cybersecurity during the COVID-19 pandemic. Proceedings of the 2020 IEEE/ACM International Conference on Advances in Social Networks Analysis and Mining (ASONAM), 727–733. https://doi.org/10.1109/ASONAM49781.2020.9381324

Antonio, J. M. A. (2024). Disparities and backlogs in Mexico’s national and international cybersecurity policies vis-à-vis the United States and Canada: Challenges of cooperation for North America. Norteamérica, 19(1), 35-68. https://doi.org/10.22201/cisan.24487228e.2024.1.663

Baezner, M. (2020). Cybersecurity in Switzerland: Challenges and the way forward for the swiss armed forces. Connections, 19(1), 63–72. https://doi.org/10.11610/Connections.19.1.06

Barcellos-Paula, L., Gil-Lafuente, A. M., & Merigó, J. M. (2025). Research on cybersecurity and business: A bibliometric review (2004-2023). Management Notebooks, 25(1), 19–36. https://doi.org/10.5295/cdg.242288lb

Barrington, M. J., D’Souza, R. S., Mascha, E. J., Narouze, S., & Kelley, G. A. (2024). Systematic reviews and meta-analyses in regional anesthesia and pain medicine (Part I): Guidelines for preparing the review protocol. Regional Anesthesia and Pain Medicine, 49(6), 391–402. https://doi.org/10.1136/rapm-2023-104801

Ben Mamia, S., Schunck, C. H., Arunkumar, M., & Roßnagel, H. (2025). Security awareness versus secure behaviour: A bibliometric study of the state of research on human factors in IT Security. In H. Rossnagel, C. H. Schunck, & D. Pohn (Eds.), Lecture Notes in Informatics (LNI), Proceedings—Series of the Gesellschaft für Informatik (GI): P-364 (pp. 167–173). Gesellschaft für Informatik (GI). https://doi.org/10.18420/OID2025_13

Carrapico, H., & Farrand, B. (2020). Discursive continuity and change in the time of COVID-19: The case of EU cybersecurity policy. Journal of European Integration, 42(8), 1111–1126. https://doi.org/10.1080/07036337.2020.1853122

Charlet, K., & King, H. (2020). The future of cybersecurity policy. IEEE Security & Privacy, 18(1), 8–10. https://doi.org/10.1109/MSEC.2019.2953368

Farooqui, M. O., Sarhan, A., & Mustafa, F. (2025). Aviation cyber security in India: Legal gaps, international frameworks, and policy reforms. Yustisia Jurnal Hukum, 14(2), 186–224. https://doi.org/10.20961/yustisia.v14i2.101653

Farrand, B., Carrapico, H., & Turobov, A. (2024). The new geopolitics of EU cybersecurity: Security, economy and sovereignty. International Affairs, 100(6), 2379–2397. https://doi.org/10.1093/ia/iiae231

Fuster, G. G., & Jasmontaite, L. (2020). Cybersecurity regulation in the European Union: The digital, the critical and fundamental rights. In M. Christen, B. Gordijn, & M. Loi (Eds.), The ethics of cybersecurity (Vol, 21, pp. 97–115). Springer. https://doi.org/10.1007/978-3-030-29053-5_5

Gan, Y.-N., Li, D.-D., Robinson, N., & Liu, J.-P. (2022). Practical guidance on bibliometric analysis and mapping knowledge domains methodology – A summary. European Journal of Integrative Medicine, 56, 102203. https://doi.org/10.1016/j.eujim.2022.102203

Gao, X. (2024). Challenges and opportunities: Estonia's role in shaping EU cybersecurity policy. In A.-L. Högenauer & M. Mišík (Eds.), Small states in EU policy-making: Strategies, challenges, opportunities (pp. 159–173). Routledge. https://doi.org/10.4324/9781003380641-12

Górka, M. (2022). Catalysts of cyber threats on the example of Visegrad Group countries. Politics in Central Europe, 18(3), 317–342. https://doi.org/10.2478/pce-2022-0014

He, Y. (2024). China’s digital shadows: Unveiling the economic toll of cybercrime. Humanities and Social Sciences Communications, 11(1), 1416. https://doi.org/10.1057/s41599-024-03952-z

Holt, T. J., Griffith, M., Turner, N., Greene-Colozzi, E., Chermak, S., & Freilich, J. D. (2023). Assessing nation-state-sponsored cyberattacks using aspects of situational crime prevention. Criminology & Public Policy, 22(4), 825–848. https://doi.org/10.1111/1745-9133.12646

Imran, M. F., Gunawan, H., & Asmoro, D. (2024). Addressing the hurdles: Enhancing better policies in Indonesia cyber security management amidst uncertainty. Journal of Public Service Management, 8(2), 275–290. https://doi.org/10.24198/jmpp.v8i2.52212

Kaponig, M. G. H. (2020). Austria’s national cyber security and defense policy: Challenges and the way forward. Connections: The Quarterly Journal, 19(1), 21–37. https://doi.org/10.11610/Connections.19.1.03

Kelemen, R. (2023). The impact of the Russian-Ukrainian hybrid war on the European Union’s cybersecurity policies and regulations. Connections: The Quarterly Journal, 22(2), 75–90. https://doi.org/10.11610/Connections.22.2.55

Kianpour, M., & Frantz, C. (2024). Analysis of institutional design of European Union cyber incident and crisis management as a complex public good. Regulation & Governance, 19(4), 1037-1062. https://doi.org/10.1111/rego.12640

Kosasih, A., Aditya, T., & Ramadhan, S. A. (2025). Evaluation of infrastructure and cybersecurity in supporting the digital transformation of public services in Tangerang City. Jurnal Manajemen Pelayanan Publik, 9(3), 802–826. https://doi.org/10.24198/jmpp.v9i3.65900

Lang, M. (2025). The fragmented research space of cybersecurity: A map of the territory. In I. Praça, S. Bernardi, & P. R. M. Inácio (Eds.), Communications in Computer and Information Science (Vol. 2500, pp. 116–132). Springer. https://doi.org/10.1007/978-3-031-94855-8_8

Malatji, M., Marnewick, A. L., & von Solms, S. (2021). Cybersecurity policy and the legislative context of the water and wastewater sector in South Africa. Sustainability, 13(1), 1–33. https://doi.org/10.3390/su13010291

Malmqvist, J., Machado, T., Meikleham, A., & Hugo, R. (2019). Bibliographic data analysis of CDIO conference papers from 2005–2018. In J. Bennedsen, A. B. Lauritsen, K. Edström, N. Kuptasthien, J. Roslöf, & R. Songer (Eds.), Proceedings of the 15th International CDIO Conference (pp. 816–833). Aarhus University.

Mering, M. (2017). Bibliometrics: Understanding author-, article-, and journal-level metrics. Serials Review, 43(1), 41–45. https://doi.org/10.1080/00987913.2017.1282288

Mishra, A., Alzoubi, Y. I., Anwar, M. J., & Gill, A. Q. (2022). Attributes impacting cybersecurity policy development: An evidence from seven nations. Computers and Security, 120, 102820. https://doi.org/10.1016/j.cose.2022.102820

Napetvaridze, V., & Chochia, A. (2019). Cybersecurity in the making-policy and law: A case study of Georgia. International and Comparative Law Review, 19(2), 155–180. https://doi.org/10.2478/iclr-2019-0019

Norris, D. F., Mateczun, L., Joshi, A., & Finin, T. (2018). Cybersecurity at the grassroots: American local governments and the challenges of internet security. Journal of Homeland Security and Emergency Management, 15(3), 20170048. https://doi.org/10.1515/jhsem-2017-0048

Okigui, H. H., Cronjé, J. C., & Francke, E. R. (2024). An analysis of cybersecurity policy compliance in organizations. Applied Cybersecurity and Internet Governance, 3(2), 303–321. https://doi.org/10.60097/ACIG/191942

Oliveira, E., & Baldi, V. (2022). Systematic review on cybersecurity risks and behaviours: Methodological approaches. In Proceedings of the 7th International Conference on Complexity, Future Information Systems and Risk (COMPLEXIS 2022) (Vol. 1, pp. 49–56). SciTePress. https://doi.org/10.5220/0010762600003197

Ribeiro, D., Fonte, V., Ramos, L. F., & Silva, J. M. (2025). Assessing the information security posture of online public services worldwide: Technical insights, trends, and policy implications. Government Information Quarterly, 42(2), 102031. https://doi.org/10.1016/j.giq.2025.102031

Ruvin, O., Isaieva, N., Sukhomlyn, L., Kalachenkova, K., & Bilianska, N. (2020). Cybersecurity as an element of financial security in the conditions of globalization. Journal of Security and Sustainability Issues, 10(1), 175–188. https://doi.org/10.9770/jssi.2020.10.1(13)

Saeed, S. (2023). Digital workplaces and information security behavior of business employees: An empirical study of Saudi Arabia. Sustainability, 15(7), 6019. https://doi.org/10.3390/su15076019

Shkolnyk, I., Tiutiunyk, I., Semenog, A., Kovalenko, Y., & Pavlenko, L. (2025). Institutional, technological, and financial drivers of national cyber resilience under armed conflict and post-conflict recovery. Problems and Perspectives in Management, 23(4), 665–683. https://doi.org/10.21511/ppm.23(4).2025.45

Snider, K. L. G., Shandler, R., Zandani, S., & Canetti, D. (2021). Cyberattacks, cyber threats, and attitudes toward cybersecurity policies. Journal of Cybersecurity, 7(1), 1-11. https://doi.org/10.1093/cybsec/tyab019

Soni, K. D. (2025). Critical appraisal of systematic reviews and meta-analyses. Indian Journal of Anaesthesia, 69(1), 161–164. https://doi.org/10.4103/ija.ija_1223_24

Sterlini, P., Massacci, F., Kadenko, N., Fiebig, T., & Van Eeten, M. (2020). Governance challenges for European cybersecurity policies: Stakeholder views. IEEE Security & Privacy, 18(1), 46–54. https://doi.org/10.1109/MSEC.2019.2945309

Veale, M., & Brown, I. (2020). Cybersecurity. Internet Policy Review, 9(4), 1–22. https://doi.org/10.14763/2020.4.1533

Verhelst, A., & Wouters, J. (2020). Filling global governance gaps in cybersecurity: International and European legal perspectives. International Organisations Research Journal, 15(2), 105–124. https://doi.org/10.17323/1996-7845-2020-02-07

Wadesango, N., & Maveneka, E. (2025). Cyberthreats and their impact on financial integrity: Evaluating the effectiveness of local authorities’ cybersecurity policies in preventing and detecting fraud. Corporate Law and Governance Review, 7(2), 32–40. https://doi.org/10.22495/clgrv7i2p3

Wang, Q. H., Miller, S. M., & Deng, R. H. (2020). Driving cybersecurity policy insights from information on the internet. IEEE Security & Privacy, 18(6), 42–50. https://doi.org/10.1109/MSEC.2020.3000765

Downloads

Published

2026-06-29