Collection / Research

Technology · Security

Cyberspace policy,
cooperation &
resilience.

What can four countries teach the United States about cyber resilience?

Research by Scott W. Waddell, D.S.I.ORCID iD

2025 dissertation · Four-country comparison

01 The overview

Start with
the question.

How can the United States adapt cyberspace policies to protect national security as artificial intelligence and Web 3.0 develop?

Research question, paraphrased from the published explainer

A comparison of Estonia, Sweden, the United Kingdom, and the United States based on documents collected for a study completed in early 2025; policy lessons depend on national and institutional context.

In brief

The study compares Estonia, Sweden, the United Kingdom, and the United States. Its documentary analysis points to policy coordination, public-private cooperation, and workforce development as priorities for U.S. cyber resilience.

Keep in mind This is a 2025 documentary comparison, not a test of policy effectiveness or a current policy inventory. Practices depend on national context; document-reference counts do not rank cybersecurity performance.

02 The findings

What the documents reveal.

Coordination gaps and a thin Web 3.0 evidence base, read within the scope of the 2025 study.

01Study findings

Reported U.S. coordination and information-sharing gaps

The study describes fragmented federal, state, and private-sector rules alongside strong U.S. technical and military cyber capabilities. It also identifies privacy, liability, and competitive concerns that discourage companies from sharing information with government.

Limits of this finding

These are findings from the study’s documentary comparison, not measurements of the effect of any particular rule or a description verified against today’s policies. The article’s three-state hospital example is explicitly illustrative.

02Study findings

Limited Web 3.0 coverage in the policy-adaptation theme

The explainer reports that five of the 184 tagged references in the policy-adaptation theme concerned the impact of Web 3.0. It describes Web 3.0 as thinly represented in this part of the evidence despite its prominence in the study’s title.

Limits of this finding

These counts concern one coding theme, not all 989 tagged references or a count of documents. They do not establish that Web 3.0 is ineffective or show how widely it is deployed today.

03 The methods

Four countries.
A shared set of questions.

A documentary comparison completed in 2025. Read it as a study of its time.

Cases and evidence

The study compares Estonia, Sweden, the United Kingdom, and the United States using eighteen structured questions across six themes. Its evidence consists of national strategies, laws, government reports, academic papers, and industry white papers. It used documentary analysis; no one was interviewed.

Evidence limit The documents show what institutions reported, which may differ from implementation. The comparison is a snapshot of the evidence collected for the 2025 study; exact collection dates are not reported in the published explainer.

The comparison

4Country casesEstonia · Sweden · United Kingdom · United States

18Shared questionsApplied across six themes

Documents → codes → themes → cross-country comparison

The same question set structures each case. Coded references describe attention in the material, not cybersecurity performance.
Study design
Structured-focused qualitative comparison of four countries using documentary evidence and six coding themes.
Analytical framework
Systems Theory connects infrastructure interdependence with systemic risk. The explainer also describes the importance of institutions, trained people, and public-private cooperation.
Time scope
A documentary snapshot for the 2025 dissertation. Exact data collection dates are not reported in the published explainer; this is not a current policy inventory.
Follow the methods and source notes
The question and the lensStart with a policy problem.

The central question was how the United States could adapt its cyberspace policies to safeguard national security as AI and Web 3.0 develop. Standards, government–business cooperation, and the cybersecurity workforce were particular concerns.

What depends on what?

Critical infrastructure systems are connected. A disruption in one can affect others. This lens asks how policies address those shared risks and support resilience.

What makes a policy workable?

Policies need strong institutions, skilled people, and partners who can work together. This lens looks at how countries build the skills and support to keep their systems secure.

One question set, used for every country.

The study used three questions in each of six themes: what the country did, what challenges it faced, and what successes or new ideas were reported. Explore the question groups below.

Policy adaptation and technology

  1. How did the country adapt its cybersecurity policies in response to AI and Web 3.0?
  2. What challenges did it face in adapting those policies?
  3. What successes and innovations emerged?

Plain-language paraphrases of Table 1, questions 1a–1c, p. 41.

Compliance and regulation

  1. How did the country design its compliance and regulatory frameworks for AI and Web 3.0?
  2. What were its main compliance challenges?
  3. What successes and innovations emerged?

Plain-language paraphrases of Table 1, questions 2a–2c, p. 41.

Public-private collaboration

  1. How did the country encourage partnerships between government and business in cybersecurity?
  2. What challenges did it face in developing those partnerships?
  3. What successes emerged from its collaboration models?

Plain-language paraphrases of Table 1, questions 3a–3c, pp. 41–42.

Education and workforce development

  1. How did the country develop its cybersecurity education programs?
  2. What key challenges did it face in cybersecurity education?
  3. What successes emerged from its education initiatives?

Plain-language paraphrases of Table 1, questions 4a–4c, p. 42.

National security and resilience

  1. How did the country adapt its cybersecurity policies to protect national security in the AI and Web 3.0 era?
  2. What key challenges did it face in maintaining national security in cyberspace?
  3. What successes emerged from its cybersecurity initiatives?

Plain-language paraphrases of Table 1, questions 5a–5c, p. 42.

International cooperation

  1. How did the country take part in international cybersecurity cooperation?
  2. What challenges did it face in that cooperation?
  3. What successes emerged from its international collaborations?

Plain-language paraphrases of Table 1, questions 6a–6c, p. 42.

Purposeful case selectionChoose cases that serve the question.

The study chose cases with useful policy experience, shared features that made comparison possible, and enough written evidence to study closely. Differences in size, resources, and forms of government gave the comparison depth.

How it was applied here: Estonia, Sweden, the United Kingdom, and the United States offered different cybersecurity approaches within democratic systems. Their policy records supported the inquiry. They were selected for their relevance, rather than drawn as a random sample of countries.

The dissertation also cites the countries' Global Cybersecurity Index standing and relevance to the Information Technology sector. It considered other democracies, but limited the study to these four cases. Scott's fluency in Swedish supported access to Sweden's native-language documents.

Gathering the evidenceRead the policies, then read around them.

The study read existing records: what governments had set out in policy and law, alongside research that helped place those records in context.

What countries put on paper

National cybersecurity strategies, policy documents, legislative acts, and government reports.

How those policies were examined

Academic literature, industry white papers, think tank reports, and publications from international organizations.

There were no interviews or focus groups. The records could show how policies were described and discussed. They offered less insight into the decisions and day-to-day work behind them.

The methods chapter describes archival research through the APUS Library and sources including JSTOR, Scopus, IEEE Xplore, Google Scholar, Semantic Scholar, and ProQuest. Government repositories included the U.S. Federal Register and the government portals of the United Kingdom, Sweden, and Estonia.

Chapter 3 calls original policy and legal records primary sources, and research about them secondary sources. Its limitations section also describes the study as relying on secondary data. In either usage, this was a study of existing documents, without firsthand interviews.

From documents to patternsMake the evidence comparable.

Coding means labeling a relevant passage to identify what it is about. A codebook is the guide to those labels. A theme connects related ideas into a broader pattern.

Label the material.

  • Descriptive codes summarize a topic.
  • In Vivo codes preserve wording from the document.
  • Process codes identify an action.

Connect the labels.

Related codes are linked into broader groups through axial coding. In this study, those second-cycle groups and themes refer to the same level of analysis.

The study combined Saldaña's coding approach with Braun and Clarke's thematic analysis framework. Its six phases were: become familiar with the documents; generate initial codes; identify broader themes; review those themes; define and name them; and bring the findings together in the dissertation. Repeated review linked the evidence, themes, and research questions.

Comparing and checkingKeep the reasoning connected to the evidence.

The shared questions gave the comparison its structure. Source checks, case details, and notes helped show how the researcher reached a view.

  • 1

    Compare different kinds of sources.

    The study checked interpretations across policy documents, legislation, national strategies, academic literature, and industry papers. This is called triangulation.

  • 2

    Preserve each country's context.

    A close account of the policies and setting of each case helps readers judge whether a lesson could apply elsewhere.

  • 3

    Record decisions about the analysis.

    Analytic memos are notes on coding and themes. They recorded key decisions. The researcher returned to the material as the coding process developed.

  • 4

    Use software to organize the comparison.

    NVivo supported the management of coded text, comparisons across countries through matrix coding queries, and visual exploration of themes.

What the numbers mean: the theme tables count coded references in the material. They describe the evidence discussed; they should not be read as scores for how safe a country is or as proof that a policy caused an outcome.

The researcher and the toolsScott did the intellectual work. Tools assisted the process.

The original research and the later article, podcast, and website are distinct stages. The role of AI in each deserves its own explanation.

AI assistance went beyond proofreading.

According to Scott's account, he used tools from OpenAI and Anthropic to help correct spelling and grammar and keep the paper's flow consistent. AI also assisted with creating the codebook, developing themes, and parsing sources for codes and themes. Scott carried out the intellectual work of the study.

Author's account supplied September 13, 2026. This disclosure supplements the published methods chapter; it is not presented as a statement found in that chapter.

NVivo in the dissertation

The methods chapter describes NVivo as the main qualitative analysis tool for organizing coded material, comparing cases, and exploring themes. That documented role is separate from the author's later account of LLM assistance.

AI in the later public-facing materials

AI was also used to adapt the finished dissertation into this article, podcast, and website. The podcast uses a synthetic voice. Those production activities explain how the study is presented here; they are separate from how the original research was conducted.

  • Published method guide Dissertation pp. 40–41; author's 2026-09-13 account, AUCP-DEC-2026-035 / SR-09; project production records
Lessons and limitsLearn from the cases. Keep the context.

The comparison informed policy recommendations the United States could adapt to its own circumstances. It did not establish one country as a universal model.

Documents offer a partial view.

Public records may not reveal how a policy works in practice. Without interviews, the study had less access to firsthand decisions and experiences. Classified and proprietary material also limited visibility.

Countries differ.

A smaller country's approach may need major changes to work in a larger federal system. Government structures, resources, and timing affect whether a lesson can carry over.

Interpretation remains human.

A consistent coding process and software support do not remove researcher judgment. Preconceptions can influence which patterns receive attention and how they are understood.

The evidence reflects its time.

The findings describe the policies and material examined for the 2025 dissertation. AI, Web 3.0, and cybersecurity policy continue to change; this page explains the completed study.

04 The limitations

What the evidence
leaves open.

Explainer author’s interpretation

Do more coded references mean better cybersecurity?

No. The explainer totals 989 tagged references across the six theme tables. These are coded references, not a count of documents or a performance score. Its suggestion that the United States may have higher counts because it produces more documents is the explainer author’s interpretation, not a finding attributed to the dissertation.

The counts describe attention within the analyzed material. They do not establish policy effectiveness, implementation quality, or a ranking of national cybersecurity performance.

This profile summarizes the published explainer, including its account of the study’s theoretical framework. It is not an independent review of the dissertation or an update of national policies. Bibliographic metadata comes separately from the maintained Zotero record.

What the dissertation recommends

Study recommendations

As summarized in the explainer, the study recommends a more unified national framework, formal and incentivized public-private cooperation, and sustained cybersecurity education and workforce development. It calls for adapting practices to the United States rather than adopting a universal blueprint.

These are policy proposals, not interventions whose effects were tested by this study. Lessons from smaller or more centralized countries may not transfer directly to the U.S. federal system.

05 Keep exploring

One study.
Several ways in.

Read the narrative explainer, revisit the earlier presentation, or return to the original research.

02 / Earlier presentation

The slide-by-slide version.

Revisit the interactive presentation and its detailed guide to the research method.

Interactive presentation · Method guide Open the earlier presentation
04 / Listen

The audio adaptation.

Jordan narrates using a synthetic voice.

14 minutes · Audio and transcript Read the transcript

Script-derived transcript; audio comparison completed with one noted uncertainty.

06 Cite the research

Keep the source
with the finding.

This section identifies the original dissertation by Scott Wayne Waddell. The explainer is a separate work by Scott W. Waddell, D.S.I..

Full citation record

Choose a bibliography format. Chicago notes and bibliography is shown as a bibliography entry; add the relevant page number when citing a specific passage in a note.

APA 7
Waddell, S. W. (2025). Advancing U.S. cyberspace policies in the age of AI and Web 3.0: A comparative case study on securing United States national security interests [Doctoral dissertation (Doctor of Strategic Intelligence), American Public University System]. ProQuest Dissertations & Theses. https://www.proquest.com/docview/3180520287
MLA 9
Waddell, Scott Wayne. Advancing U.S. Cyberspace Policies in the Age of AI and Web 3.0: A Comparative Case Study on Securing United States National Security Interests. 2025, ProQuest Dissertations & Theses. American Public University System, Doctoral dissertation (Doctor of Strategic Intelligence). ProQuest, https://www.proquest.com/docview/3180520287.
Chicago 18 · bibliography
Waddell, Scott Wayne. “Advancing U.S. Cyberspace Policies in the Age of AI and Web 3.0: A Comparative Case Study on Securing United States National Security Interests.” Doctoral dissertation (Doctor of Strategic Intelligence), American Public University System, 2025. ProQuest Dissertations & Theses. https://www.proquest.com/docview/3180520287.
Chicago 18 · author-date
Waddell, Scott Wayne. 2025. “Advancing U.S. Cyberspace Policies in the Age of AI and Web 3.0: A Comparative Case Study on Securing United States National Security Interests.” Doctoral dissertation (Doctor of Strategic Intelligence), American Public University System. ProQuest Dissertations & Theses. https://www.proquest.com/docview/3180520287.

Import the RIS file into Zotero to use another citation style. Bibliographic metadata and formatted references come from the maintained Zotero record.