Cybersecurity Policy Research in the Social Sciences: A Systematic Literature Review and Bibliometric Analysis
DOI:
https://doi.org/10.58524/smartsociety.v6i2.1275Keywords:
Bibliometric Analysis, Conceptual Model, Cybersecurity Policy, Social Sciences, Systematic Literature ReviewAbstract
The global digital transformation has positioned cybersecurity policy as a strategic issue within the social sciences rather than merely a technical concern. Although cybersecurity has been widely examined in technical, engineering, and information systems domains, studies that systematically map cybersecurity policy research from a social science perspective remain limited and fragmented across governance, regulatory, institutional, and socio-political dimensions. Therefore, a comprehensive synthesis is needed to better understand the development, intellectual structure, and future directions of cybersecurity policy scholarship within the social sciences. This study aims to map the development of cybersecurity policy research, identify publication patterns based on countries, institutions, sources, and publication types, and synthesize the key determinants and social dimensions associated with cybersecurity policy. The study employs a Systematic Literature Review and bibliometric analysis of 70 Scopus-indexed articles published up to March 17, 2026. The findings reveal a substantial increase in cybersecurity policy research over the past decade, particularly in studies related to governance, regulation, and geopolitical issues, reflecting a growing multidisciplinary orientation. The thematic synthesis and literature analysis identify five key determinants of cybersecurity policy and several social, political, and economic dimensions frequently associated with cybersecurity governance. These findings are integrated into a conceptual model developed from literature synthesis and bibliometric mapping to illustrate the relationships among the identified determinants and associated dimensions. This study contributes to enriching the cybersecurity policy literature from a social science perspective and provides directions for future research and policy development.
References
Afshari-Mofrad, M., Amrollahi, A., & Abedin, B. (2024). Adopt agile cybersecurity policymaking to counter emerging digital risks. MIS Quarterly Executive, 23(4), 371–386. https://doi.org/10.17705/2msqe.00102
Alhumud, T. A. A., Omar, A., & Altohami, W. M. A. (2023). An assessment of cybersecurity performance in the Saudi universities: A total quality management approach. Cogent Education, 10(2),1-16. https://doi.org/10.1080/2331186X.2023.2265227
Al Husaeni, D. F., & Nandiyanto, A. B. D. (2022). Bibliometric using VOSviewer with Publish or Perish (using Google Scholar data): From step-by-step processing for users to the practical examples in the analysis of digital learning articles in pre and post COVID-19 pandemic. ASEAN Journal of Science and Engineering, 2(1), 19–46. https://doi.org/10.17509/ajse.v2i1.37368
Andreasson, A., Artman, H., Brynielsson, J., & Franke, U. (2020). A census of Swedish government administrative authority employee communications on cybersecurity during the COVID-19 pandemic. Proceedings of the 2020 IEEE/ACM International Conference on Advances in Social Networks Analysis and Mining (ASONAM), 727–733. https://doi.org/10.1109/ASONAM49781.2020.9381324
Antonio, J. M. A. (2024). Disparities and backlogs in Mexico’s national and international cybersecurity policies vis-à-vis the United States and Canada: Challenges of cooperation for North America. Norteamérica, 19(1), 35-68. https://doi.org/10.22201/cisan.24487228e.2024.1.663
Baezner, M. (2020). Cybersecurity in Switzerland: Challenges and the way forward for the swiss armed forces. Connections, 19(1), 63–72. https://doi.org/10.11610/Connections.19.1.06
Barcellos-Paula, L., Gil-Lafuente, A. M., & Merigó, J. M. (2025). Research on cybersecurity and business: A bibliometric review (2004-2023). Management Notebooks, 25(1), 19–36. https://doi.org/10.5295/cdg.242288lb
Barrington, M. J., D’Souza, R. S., Mascha, E. J., Narouze, S., & Kelley, G. A. (2024). Systematic reviews and meta-analyses in regional anesthesia and pain medicine (Part I): Guidelines for preparing the review protocol. Regional Anesthesia and Pain Medicine, 49(6), 391–402. https://doi.org/10.1136/rapm-2023-104801
Ben Mamia, S., Schunck, C. H., Arunkumar, M., & Roßnagel, H. (2025). Security awareness versus secure behaviour: A bibliometric study of the state of research on human factors in IT Security. In H. Rossnagel, C. H. Schunck, & D. Pohn (Eds.), Lecture Notes in Informatics (LNI), Proceedings—Series of the Gesellschaft für Informatik (GI): P-364 (pp. 167–173). Gesellschaft für Informatik (GI). https://doi.org/10.18420/OID2025_13
Carrapico, H., & Farrand, B. (2020). Discursive continuity and change in the time of COVID-19: The case of EU cybersecurity policy. Journal of European Integration, 42(8), 1111–1126. https://doi.org/10.1080/07036337.2020.1853122
Charlet, K., & King, H. (2020). The future of cybersecurity policy. IEEE Security & Privacy, 18(1), 8–10. https://doi.org/10.1109/MSEC.2019.2953368
Farooqui, M. O., Sarhan, A., & Mustafa, F. (2025). Aviation cyber security in India: Legal gaps, international frameworks, and policy reforms. Yustisia Jurnal Hukum, 14(2), 186–224. https://doi.org/10.20961/yustisia.v14i2.101653
Farrand, B., Carrapico, H., & Turobov, A. (2024). The new geopolitics of EU cybersecurity: Security, economy and sovereignty. International Affairs, 100(6), 2379–2397. https://doi.org/10.1093/ia/iiae231
Fuster, G. G., & Jasmontaite, L. (2020). Cybersecurity regulation in the European Union: The digital, the critical and fundamental rights. In M. Christen, B. Gordijn, & M. Loi (Eds.), The ethics of cybersecurity (Vol, 21, pp. 97–115). Springer. https://doi.org/10.1007/978-3-030-29053-5_5
Gan, Y.-N., Li, D.-D., Robinson, N., & Liu, J.-P. (2022). Practical guidance on bibliometric analysis and mapping knowledge domains methodology – A summary. European Journal of Integrative Medicine, 56, 102203. https://doi.org/10.1016/j.eujim.2022.102203
Gao, X. (2024). Challenges and opportunities: Estonia's role in shaping EU cybersecurity policy. In A.-L. Högenauer & M. Mišík (Eds.), Small states in EU policy-making: Strategies, challenges, opportunities (pp. 159–173). Routledge. https://doi.org/10.4324/9781003380641-12
Górka, M. (2022). Catalysts of cyber threats on the example of Visegrad Group countries. Politics in Central Europe, 18(3), 317–342. https://doi.org/10.2478/pce-2022-0014
He, Y. (2024). China’s digital shadows: Unveiling the economic toll of cybercrime. Humanities and Social Sciences Communications, 11(1), 1416. https://doi.org/10.1057/s41599-024-03952-z
Holt, T. J., Griffith, M., Turner, N., Greene-Colozzi, E., Chermak, S., & Freilich, J. D. (2023). Assessing nation-state-sponsored cyberattacks using aspects of situational crime prevention. Criminology & Public Policy, 22(4), 825–848. https://doi.org/10.1111/1745-9133.12646
Imran, M. F., Gunawan, H., & Asmoro, D. (2024). Addressing the hurdles: Enhancing better policies in Indonesia cyber security management amidst uncertainty. Journal of Public Service Management, 8(2), 275–290. https://doi.org/10.24198/jmpp.v8i2.52212
Kaponig, M. G. H. (2020). Austria’s national cyber security and defense policy: Challenges and the way forward. Connections: The Quarterly Journal, 19(1), 21–37. https://doi.org/10.11610/Connections.19.1.03
Kelemen, R. (2023). The impact of the Russian-Ukrainian hybrid war on the European Union’s cybersecurity policies and regulations. Connections: The Quarterly Journal, 22(2), 75–90. https://doi.org/10.11610/Connections.22.2.55
Kianpour, M., & Frantz, C. (2024). Analysis of institutional design of European Union cyber incident and crisis management as a complex public good. Regulation & Governance, 19(4), 1037-1062. https://doi.org/10.1111/rego.12640
Kosasih, A., Aditya, T., & Ramadhan, S. A. (2025). Evaluation of infrastructure and cybersecurity in supporting the digital transformation of public services in Tangerang City. Jurnal Manajemen Pelayanan Publik, 9(3), 802–826. https://doi.org/10.24198/jmpp.v9i3.65900
Lang, M. (2025). The fragmented research space of cybersecurity: A map of the territory. In I. Praça, S. Bernardi, & P. R. M. Inácio (Eds.), Communications in Computer and Information Science (Vol. 2500, pp. 116–132). Springer. https://doi.org/10.1007/978-3-031-94855-8_8
Malatji, M., Marnewick, A. L., & von Solms, S. (2021). Cybersecurity policy and the legislative context of the water and wastewater sector in South Africa. Sustainability, 13(1), 1–33. https://doi.org/10.3390/su13010291
Malmqvist, J., Machado, T., Meikleham, A., & Hugo, R. (2019). Bibliographic data analysis of CDIO conference papers from 2005–2018. In J. Bennedsen, A. B. Lauritsen, K. Edström, N. Kuptasthien, J. Roslöf, & R. Songer (Eds.), Proceedings of the 15th International CDIO Conference (pp. 816–833). Aarhus University.
Mering, M. (2017). Bibliometrics: Understanding author-, article-, and journal-level metrics. Serials Review, 43(1), 41–45. https://doi.org/10.1080/00987913.2017.1282288
Mishra, A., Alzoubi, Y. I., Anwar, M. J., & Gill, A. Q. (2022). Attributes impacting cybersecurity policy development: An evidence from seven nations. Computers and Security, 120, 102820. https://doi.org/10.1016/j.cose.2022.102820
Napetvaridze, V., & Chochia, A. (2019). Cybersecurity in the making-policy and law: A case study of Georgia. International and Comparative Law Review, 19(2), 155–180. https://doi.org/10.2478/iclr-2019-0019
Norris, D. F., Mateczun, L., Joshi, A., & Finin, T. (2018). Cybersecurity at the grassroots: American local governments and the challenges of internet security. Journal of Homeland Security and Emergency Management, 15(3), 20170048. https://doi.org/10.1515/jhsem-2017-0048
Okigui, H. H., Cronjé, J. C., & Francke, E. R. (2024). An analysis of cybersecurity policy compliance in organizations. Applied Cybersecurity and Internet Governance, 3(2), 303–321. https://doi.org/10.60097/ACIG/191942
Oliveira, E., & Baldi, V. (2022). Systematic review on cybersecurity risks and behaviours: Methodological approaches. In Proceedings of the 7th International Conference on Complexity, Future Information Systems and Risk (COMPLEXIS 2022) (Vol. 1, pp. 49–56). SciTePress. https://doi.org/10.5220/0010762600003197
Ribeiro, D., Fonte, V., Ramos, L. F., & Silva, J. M. (2025). Assessing the information security posture of online public services worldwide: Technical insights, trends, and policy implications. Government Information Quarterly, 42(2), 102031. https://doi.org/10.1016/j.giq.2025.102031
Ruvin, O., Isaieva, N., Sukhomlyn, L., Kalachenkova, K., & Bilianska, N. (2020). Cybersecurity as an element of financial security in the conditions of globalization. Journal of Security and Sustainability Issues, 10(1), 175–188. https://doi.org/10.9770/jssi.2020.10.1(13)
Saeed, S. (2023). Digital workplaces and information security behavior of business employees: An empirical study of Saudi Arabia. Sustainability, 15(7), 6019. https://doi.org/10.3390/su15076019
Shkolnyk, I., Tiutiunyk, I., Semenog, A., Kovalenko, Y., & Pavlenko, L. (2025). Institutional, technological, and financial drivers of national cyber resilience under armed conflict and post-conflict recovery. Problems and Perspectives in Management, 23(4), 665–683. https://doi.org/10.21511/ppm.23(4).2025.45
Snider, K. L. G., Shandler, R., Zandani, S., & Canetti, D. (2021). Cyberattacks, cyber threats, and attitudes toward cybersecurity policies. Journal of Cybersecurity, 7(1), 1-11. https://doi.org/10.1093/cybsec/tyab019
Soni, K. D. (2025). Critical appraisal of systematic reviews and meta-analyses. Indian Journal of Anaesthesia, 69(1), 161–164. https://doi.org/10.4103/ija.ija_1223_24
Sterlini, P., Massacci, F., Kadenko, N., Fiebig, T., & Van Eeten, M. (2020). Governance challenges for European cybersecurity policies: Stakeholder views. IEEE Security & Privacy, 18(1), 46–54. https://doi.org/10.1109/MSEC.2019.2945309
Veale, M., & Brown, I. (2020). Cybersecurity. Internet Policy Review, 9(4), 1–22. https://doi.org/10.14763/2020.4.1533
Verhelst, A., & Wouters, J. (2020). Filling global governance gaps in cybersecurity: International and European legal perspectives. International Organisations Research Journal, 15(2), 105–124. https://doi.org/10.17323/1996-7845-2020-02-07
Wadesango, N., & Maveneka, E. (2025). Cyberthreats and their impact on financial integrity: Evaluating the effectiveness of local authorities’ cybersecurity policies in preventing and detecting fraud. Corporate Law and Governance Review, 7(2), 32–40. https://doi.org/10.22495/clgrv7i2p3
Wang, Q. H., Miller, S. M., & Deng, R. H. (2020). Driving cybersecurity policy insights from information on the internet. IEEE Security & Privacy, 18(6), 42–50. https://doi.org/10.1109/MSEC.2020.3000765
Downloads
Published
Issue
Section
License
Copyright (c) 2026 Refa Andrean Tri P, Ismi Dwi Astuti Nurhaeni, Faizatul Ansoriyah

This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License.
Authors who publish with the Smart Society: Community Service and Empowerment Journal retain all of the copyrights in their work. Smart Society: Community Service and Empowerment Journal, collaborates with with researchers from many countries as the Editors and the Advisory International Editorial Board make every effort to ensure that no wrong or misleading data, opinions, or statements are published in the journal. In any way, the contents of the articles and advertisements published in the are the sole and exclusive responsibility of their respective authors and advertisers.
Smart Society: Community Service and Empowerment Journal ( e-ISSN: 2807-5757 ) is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License
Authors who publish with Smart Society: Community Service and Empowerment Journal agree to the following terms:
1. The journal allows the author to hold the copyright of the article without restrictions.
2. The journal allows the author(s) to retain publishing rights without restrictions
3. The legal formal aspect of journal publication accessibility refers to Creative Commons Attribution ShareAlike 4.0 International License (CC BY-SA).

Smart Society: Community Service and Empowerment Journal is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License.

