How cyberspace became critical infrastructure, then a domain of power, and what four countries do about it.
Adapted from the dissertation of Scott W. Waddell, D.S.I., American Public University System, 2025.
Findings are as of the study's completion in early 2025. The podcast linked from this site uses a synthetic voice. The presentation is grounded in the study; added sector details cite CISA and other official sources, and the methods page identifies the author's account of AI assistance. Use the arrow keys to move; press P for a plain-English line on any slide.
16 sectors. Shared dependencies.
Select any sector to follow its dependencies.
Water plants use treatment chemicals from outside suppliers. Health providers need water to clean, sterilize tools, and give care such as dialysis. Treatment supplies can matter far beyond the water plant.
Arrows follow a service from its provider to its user.
A disruption in one sector can affect others.
These are selected service dependencies from official sources, not a complete network or new findings from the study. The dissertation explains interconnection on pp. 10–11 and names the sector count on p. 19. Sector labels follow CISA’s list; older documents use “Government Facilities” for Government Services and Facilities.
Information technology supports operations across the other 15 sectors.
These links show reliance on IT services. Sectors also connect directly and through communications, energy, water, and transportation.
CISA: Information Technology Sector and the 2016 IT Sector-Specific Plan, pp. 2, 4. This is a schematic of shared reliance, not a map of traffic routes. IT and Communications are distinct sectors that work together to provide Internet services. Other dependencies exist alongside this digital layer.
The study leans on an idea called Systems Theory: a country's infrastructure is one interlocking system, and its security has to be judged as a whole, not piece by piece.
can disrupt global supply chains.
has the potential to cripple communication systems.
Wiring critical infrastructure into one network changed the nature of the risk: from isolated incidents to systemic risks that cross sectors.
The United States Department of Defense counts cyberspace as an operational domain alongside air, land, maritime, and space. Four familiar domains, plus one. That makes five.
U.S. policy rests on deterrence, defense, and resilience.
The country has built offensive capabilities alongside defensive ones.
Cyberspace lacks clear territorial boundaries, and states compete to shape its rules.
The study's own phrase: cyberspace evolves “as both a domain of power and a critical infrastructure layer.” Not the power at the wall. The kind states hold.
Not with tanks. With traffic.
Estonia's banks and government institutions came under attack: distributed denial-of-service attacks, which flood a site with so many fake requests that real people cannot get through.
Estonians dealt with the state online, through a national digital identity system. That made the country modern. It also made it exposed.
The response was government and business side by side, including the bank Swedbank, pooling what they had.
The study calls 2007 the moment Estonia stopped treating cybersecurity as a technical issue and started treating it as a core national defense priority.
The study gives no date within the year, no named attacker, and no scene. Neither does this slide.
A backup of critical state data kept beyond its borders, so that data stays secure and reachable during an attack.
Based in Tallinn and established in response to the 2007 attacks. Its annual exercise simulates a large-scale cyberattack with private technology companies and national security forces.
Volunteer private-sector specialists who provide support during cyber incidents, under a unified military command.
Replace outdated systems quickly, so new technologies can be integrated without the drag of old ones.
Its limits are just as concrete: budget constraints, a shortage of skilled people, and proximity to Russia with the persistent threat of state-sponsored attacks.
The 2007 attacks next door were a wake-up call for Sweden, which strengthened its energy, finance, and telecommunications sectors as critical national infrastructure.
The Swedish Civil Contingencies Agency, MSB, coordinates what Sweden calls a whole-of-society approach: government, civil society, and business together.
Sets standards in sectors like finance and healthcare and requires public and private players to cooperate.
Partnerships with its telecom companies secure the country's communications.
Sweden's answer: task forces that put regulators and industry leaders in the same room, so that policy stays agile.
AI can watch a network and react to an attack in real time. The study calls it “no longer a discrete technological consideration but a foundational element of national security policy.”
AI systems are vulnerable to adversarial attacks and to manipulated data.
A failure in AI-driven security can cascade across energy, telecommunications, and finance.
Institutions, standards, and a skilled workforce able to manage and regulate AI-enhanced systems.
Web 3.0 is a loose name for systems built on blockchains and other decentralized tools, where no single company or agency holds the keys. Digital identities, smart contracts, and tokenized financial systems are being wired into economies.
Decentralization makes it harder for attackers to target one point of failure.
It also brings substantial regulatory challenges, because traditional frameworks struggle with decentralized systems.
A count of what the documents talked about, not a score. Even Estonia, the study's digital leader, has yet to fully integrate Web 3.0 into its cybersecurity strategy.
The study notes that cyber-enabled disinformation can destabilize democratic institutions and influence public discourse.
The domain where you pay your bills is also the domain where you form your opinions. Both are now contested.
Estonia, Sweden, the United Kingdom, and the United States, each asked the same standardized questions.
Policy adaptation; compliance and regulation; public-private collaboration; education and workforce; national security and resilience; international cooperation. Three questions each.
National strategies, laws, government reports, academic papers, and industry white papers, read and coded passage by passage with NVivo. No one was interviewed.
Systems Theory: everything is connected. Capacity Building Theory: rules need institutions, people, and partners.
Passages from the four countries' documents were tagged into six themes. Across the six theme tables, that comes to 989 tagged references.
These counts tell you how often a country's documents talked about something, not how well the country did it. The study itself avoids judging any country's effectiveness or global standing.
The United States had the most references in most tables. One plain reason could be that it produces a great many documents; that is this deck's reading, not the study's claim. In the national-security theme, the most-tagged idea across all four countries was protecting critical infrastructure; the second was cyber warfare and defense.
Britain runs its cyber policy through the National Cyber Security Centre, and plays for the long term.
An affordable baseline of security for small and medium-sized businesses.
A partnership called CiSP lets government and companies trade threat information in real time. Active Cyber Defence hands organizations tools that take down phishing sites.
Reaches students from secondary school through professional training, with scholarships and internships. Apprenticeships run alongside it.
Its worries mirror its strengths: some regions have better access to cyber education than others; its own cyber agency says AI is advancing faster than the ability to regulate it; and leaving the European Union meant negotiating new agreements to keep sharing threat data.
It has more of everything. It leads the world in AI innovation. Its NIST cybersecurity framework, built with industry and academia, has been adopted and translated by countries around the world, and NIST followed it with a framework for AI risk. Information Sharing and Analysis Centers link critical industries. CyberCorps pays for students' cybersecurity education in exchange for government service. “Hunt forward” operations find threats with allies before they arrive.
The United States is not one system. Federal rules, state rules, and private-sector rules frequently diverge.
Cyberattacks cross borders. All four countries belong to alliances that try to share the load, and the study says no single country can address these threats alone.
Helps run research and training at NATO's cyber centre, and takes part in the EU's cyber rapid response teams.
Works through the European Union and its Nordic neighbours, and aligns with the EU's data protection law, GDPR.
Belongs to Five Eyes, the intelligence-sharing alliance with the United States, Canada, Australia, and New Zealand.
Takes part in the United Nations group that writes the norms for how states should behave in cyberspace.
Europe has one data protection law. The United States has sector-by-sector rules and voluntary sharing, and the study finds the mismatch complicates data sharing with allies. An executive order that limits foreign access to sensitive American data protects the country and, at the same time, makes cooperation harder.
The assumption has always been that the biggest economy, with the most technology and the deepest pockets, leads in cybersecurity. The study says its analysis challenges assumptions that larger economies inherently lead in cybersecurity innovation.
The study calls this its most significant theoretical contribution.
If a country has good cybersecurity rules, why would it still get hacked? Because rules do nothing on their own. The study's second lens, Capacity Building Theory, says they need institutions to apply them, trained people to run them, and partners in business who actually cooperate.
Human error, the study notes, remains one of the most common causes of security breaches.
A great fire plan is worthless if nobody in the building knows where the extinguishers are.
A unified national cybersecurity framework; a federal task force working with CISA and NIST to bring federal and state rules into line; a central coordinating body modelled on Britain's.
Standing platforms where government and industry talk; real-time sharing; tax credits, grants, and liability protection for companies that take part.
Cybersecurity in schools from the early grades, expanded vocational training, and scholarships that create a pipeline.
These are proposals informed by the comparison, with no promise that one package works everywhere.
In the air, at sea, on land, and in space, the military is the one that shows up. In cyberspace, the front line is a water plant owned by a utility, a hospital, a bank, and the phone in your pocket.
put the state itself at the centre and rebuilt around it.
put one agency at the centre and made partnership the law.
put one centre at the centre and played the long game.
by design, has no centre. That is the gap the study's recommendations try to close.
A country's cybersecurity is not a product it buys. It is a shape it agrees to take.
About 4,000 words, written for a general reader.
Narrated by a synthetic voice, and it says so.
Waddell, Scott Wayne. 2025. Advancing U.S. Cyberspace Policies in the Age of AI and Web 3.0: A Comparative Case Study on Securing United States National Security Interests. Doctor of Strategic Intelligence dissertation, American Public University System. ProQuest Dissertations & Theses. ISBN 979-8-3101-4740-9.
Read the open-access dissertation at its official ProQuest record.
Structured-focused comparative case study analysis.
The same 18 questions organize the evidence for all four countries.
Each comparison addresses the policy issues at the heart of the research question.
Patterns emerge without treating countries with different institutions and resources as interchangeable.
Coded passages, comparisons across sources, and research notes support the path to policy lessons.
Explore why these countries were chosen, how the documents were analyzed, and how the researcher and tools contributed.
A consistent comparison preserves the detail needed to judge which policy lessons might transfer. Source: dissertation, Chapter 3, pp. 32–49.
Enter the passphrase to continue.