Cybersecurity is experiencing mission creep. Policymakers are casting more and more problems as issues of cybersecurity. So reframed, wildly different policy issues, from misinformation, to child social media safety laws, to antitrust regulations, to alleged journalist misconduct, to anti-sex trafficking statutes become what this Article calls “cybersecuritized.” Before this reframing, these issues present as important but not existential. But once cybersecuritization positions the issues as threats intensified by their technological nature, they gain access to the politics and law of urgency and exceptionalism and invite troubling governance responses.
Positioned as security threats, cybersecuritized issues become endowed with the apparent normative power to override countervailing considerations, oversimplifying the problem. Cybersecuritization’s oversimplification similarly risks unidimensional solutions and invites use of argumentative trump cards, like First Amendment challenges. Cybersecuritization also invites deference to purported specialists and their proposed solutions. Together, the reductive tendencies of cybersecuritization and the deference it prompts to specialists renders ultimate governance choices more opaque. And this opacity can erode public trust and political legitimacy.
This Article surfaces the phenomenon of cybersecuritization and offers a novel framework for analyzing and critiquing it. Mining cases from across criminal and civil domains, the account also demonstrates the insidiousness of cybersecuritization and the likelihood that it will continue to expand. Confronting cybersecuritization is crucial. If we continue to ignore it, we risk abdicating further responsibility for difficult choices to the trump card of cybersecurity. This Article’s analysis and critique aim to help reclaim the hard work of governance for our hands.
* Visiting Assistant Professor, Harvard Law School (2025-2026); Assistant Professor, University of New Hampshire Franklin Pierce School of Law; Affiliated Fellow, Yale Law School Information Society Project (ISP); Faculty Affiliate, Berkman Klein Center for Internet & Society at Harvard University. J.D., Yale Law School; M.Phil, International Relations, Oxford University (Marshall Scholar); B.A., Stanford University. Thank you to Kendra Albert, Chinmayi Arun, Jack Balkin, Elettra Bietti, Aliza Hochman Bloom, Doni Bloomfield, Anupam Chander, Kevin Dorst, Steven Arrigg Koh, Paul Heaton, Ela Leshem, Asaf Lubin, Jonathan Masur, Alan Rozenshtein, David Simon, Quinn White, Josephine Wolff, and Lua Yuille for substantial comments. Thank you also to colleagues at the 2025 Indiana University Center for Applied Cybersecurity Research Speaker Series, the 2025 Law & STEM Junior Faculty Forum, the 2024 Northeastern University School of Law Faculty Colloquium, the 2024 Suffolk University Law School Faculty Colloquium, the Yale ISP Fall 2024 Ideas Series, Crimfest 2024, the 2023 Cybersecurity Law & Policy Scholars Conference, and my research assistant Connor Brady.
The full text of this Article is available to download as a PDF.