1 / 24
A story from a 2025 doctoral study

The Battleground You Live In

How cyberspace became critical infrastructure, then a domain of power, and what four countries do about it.

Adapted from the dissertation of Scott W. Waddell, D.S.I., American Public University System, 2025.

Findings are as of the study's completion in early 2025. The podcast linked from this site uses a synthetic voice. The presentation is grounded in the study; added sector details cite CISA and other official sources, and the methods page identifies the author's account of AI assistance. Use the arrow keys to move; press P for a plain-English line on any slide.

Act 1 · The network you live in

Start with the water.

16 sectors. Shared dependencies.

Select any sector to follow its dependencies.

Follow a dependency

Clean water supports patient care

Water plants use treatment chemicals from outside suppliers. Health providers need water to clean, sterilize tools, and give care such as dialysis. Treatment supplies can matter far beyond the water plant.

Arrows follow a service from its provider to its user.

Sources for this example
Read all 16 examples

A disruption in one sector can affect others.

About the examples and sector names

These are selected service dependencies from official sources, not a complete network or new findings from the study. The dissertation explains interconnection on pp. 10–11 and names the sector count on p. 19. Sector labels follow CISA’s list; older documents use “Government Facilities” for Government Services and Facilities.

Act 1 · The network you live in

The network has a digital layer.

Information technology supports operations across the other 15 sectors.

Information
Technology
Software · Computing
Data services
A shared digital layer
Explore the connections

What does IT make possible?

Select a sector to see an example of the software, computing, or data services it uses.

These links show reliance on IT services. Sectors also connect directly and through communications, energy, water, and transportation.

Sources and what this diagram shows

CISA: Information Technology Sector and the 2016 IT Sector-Specific Plan, pp. 2, 4. This is a schematic of shared reliance, not a map of traffic routes. IT and Communications are distinct sectors that work together to provide Internet services. Other dependencies exist alongside this digital layer.

Act 1 · The network you live in

Everything is plugged into everything.

The study leans on an idea called Systems Theory: a country's infrastructure is one interlocking system, and its security has to be judged as a whole, not piece by piece.

A breach in financial networks

can disrupt global supply chains.

An attack on the energy sector

has the potential to cripple communication systems.

Wiring critical infrastructure into one network changed the nature of the risk: from isolated incidents to systemic risks that cross sectors.

Act 1 · The network you live in

Five domains, one battleground.

The United States Department of Defense counts cyberspace as an operational domain alongside air, land, maritime, and space. Four familiar domains, plus one. That makes five.

Cyberspace “serves both as a battleground and as a vital enabler of economic and societal functions.”the study, p. 18

Three pillars

U.S. policy rests on deterrence, defense, and resilience.

Offense and defense

The country has built offensive capabilities alongside defensive ones.

No borders

Cyberspace lacks clear territorial boundaries, and states compete to shape its rules.

The study's own phrase: cyberspace evolves “as both a domain of power and a critical infrastructure layer.” Not the power at the wall. The kind states hold.

Act 2 · The day it stopped being theory

Estonia, 2007.

Not with tanks. With traffic.

Estonia's banks and government institutions came under attack: distributed denial-of-service attacks, which flood a site with so many fake requests that real people cannot get through.

Estonians dealt with the state online, through a national digital identity system. That made the country modern. It also made it exposed.

The response was government and business side by side, including the bank Swedbank, pooling what they had.

The study calls 2007 the moment Estonia stopped treating cybersecurity as a technical issue and started treating it as a core national defense priority.

The study gives no date within the year, no named attacker, and no scene. Neither does this slide.

Act 2 · The day it stopped being theory

What Estonia built.

A data embassy

A backup of critical state data kept beyond its borders, so that data stays secure and reachable during an attack.

NATO's cyber defence centre

Based in Tallinn and established in response to the 2007 attacks. Its annual exercise simulates a large-scale cyberattack with private technology companies and national security forces.

A Cyber Defence League

Volunteer private-sector specialists who provide support during cyber incidents, under a unified military command.

A “no-legacy principle”

Replace outdated systems quickly, so new technologies can be integrated without the drag of old ones.

Its limits are just as concrete: budget constraints, a shortage of skilled people, and proximity to Russia with the persistent threat of state-sponsored attacks.

Act 2 · The day it stopped being theory

Sweden: the whole society.

The 2007 attacks next door were a wake-up call for Sweden, which strengthened its energy, finance, and telecommunications sectors as critical national infrastructure.

One coordinator

The Swedish Civil Contingencies Agency, MSB, coordinates what Sweden calls a whole-of-society approach: government, civil society, and business together.

A Cyber Defense Act

Sets standards in sectors like finance and healthcare and requires public and private players to cooperate.

Telia and Ericsson

Partnerships with its telecom companies secure the country's communications.

“The challenge is not the technology itself, but how rapidly it changes, making it difficult for regulations to keep up.”a Swedish stakeholder, as quoted in the study, p. 61

Sweden's answer: task forces that put regulators and industry leaders in the same room, so that policy stays agile.

Act 3 · The next expansion

Artificial intelligence.

AI can watch a network and react to an attack in real time. The study calls it “no longer a discrete technological consideration but a foundational element of national security policy.”

It can be fooled

AI systems are vulnerable to adversarial attacks and to manipulated data.

Its failures spread

A failure in AI-driven security can cascade across energy, telecommunications, and finance.

It needs people and rules

Institutions, standards, and a skilled workforce able to manage and regulate AI-enhanced systems.

Act 3 · The next expansion

Web 3.0, and how thin the evidence is.

Web 3.0 is a loose name for systems built on blockchains and other decentralized tools, where no single company or agency holds the keys. Digital identities, smart contracts, and tokenized financial systems are being wired into economies.

No single point of failure

Decentralization makes it harder for attackers to target one point of failure.

No single point of control

It also brings substantial regulatory challenges, because traditional frameworks struggle with decentralized systems.

5 of 184
coded references in the policy-adaptation theme concern the impact of Web 3.0

A count of what the documents talked about, not a score. Even Estonia, the study's digital leader, has yet to fully integrate Web 3.0 into its cybersecurity strategy.

Act 3 · The next expansion

A front made of words.

The study notes that cyber-enabled disinformation can destabilize democratic institutions and influence public discourse.

The domain where you pay your bills is also the domain where you form your opinions. Both are now contested.

Act 4 · Four countries, one lens

One question, four countries, eighteen questions each.

“How can the United States develop and adapt its cyberspace policies to effectively safeguard national security interests amidst the emergence of Web 3.0 and AI technologies?”the main research question, p. 5

Four cases

Estonia, Sweden, the United Kingdom, and the United States, each asked the same standardized questions.

Six themes

Policy adaptation; compliance and regulation; public-private collaboration; education and workforce; national security and resilience; international cooperation. Three questions each.

Documents, not interviews

National strategies, laws, government reports, academic papers, and industry white papers, read and coded passage by passage with NVivo. No one was interviewed.

Two lenses

Systems Theory: everything is connected. Capacity Building Theory: rules need institutions, people, and partners.

Act 4 · Four countries, one lens

The numbers, honestly.

Passages from the four countries' documents were tagged into six themes. Across the six theme tables, that comes to 989 tagged references.

National security and resilience254
Public-private collaboration216
Policy adaptation and technology184
Compliance and regulation167
Education and workforce89
International cooperation79

These counts tell you how often a country's documents talked about something, not how well the country did it. The study itself avoids judging any country's effectiveness or global standing.

The United States had the most references in most tables. One plain reason could be that it produces a great many documents; that is this deck's reading, not the study's claim. In the national-security theme, the most-tagged idea across all four countries was protecting critical infrastructure; the second was cyber warfare and defense.

Act 4 · Four countries, one lens

The United Kingdom: the long game.

One centre

Britain runs its cyber policy through the National Cyber Security Centre, and plays for the long term.

Cyber Essentials

An affordable baseline of security for small and medium-sized businesses.

Sharing since 2013

A partnership called CiSP lets government and companies trade threat information in real time. Active Cyber Defence hands organizations tools that take down phishing sites.

CyberFirst

Reaches students from secondary school through professional training, with scholarships and internships. Apprenticeships run alongside it.

Its worries mirror its strengths: some regions have better access to cyber education than others; its own cyber agency says AI is advancing faster than the ability to regulate it; and leaving the European Union meant negotiating new agreements to keep sharing threat data.

Act 4 · Four countries, one lens

The United States: everything, and no centre.

It has more of everything. It leads the world in AI innovation. Its NIST cybersecurity framework, built with industry and academia, has been adopted and translated by countries around the world, and NIST followed it with a framework for AI risk. Information Sharing and Analysis Centers link critical industries. CyberCorps pays for students' cybersecurity education in exchange for government service. “Hunt forward” operations find threats with allies before they arrive.

So what is the problem?

The United States is not one system. Federal rules, state rules, and private-sector rules frequently diverge.

  • Healthcare. Federal privacy law, HIPAA, sits on top of state rules that vary, and the mismatch delayed comprehensive security protocols and left critical areas exposed.
  • States. Federal initiatives are frequently met with resistance from states that prefer local control. A company in several states faces several rulebooks.
  • Trust. Companies worry about privacy, liability, and competitors. Even after a 2015 law to encourage sharing, many still hold back.
  • Timing. The study finds the United States tends to address threats as they arise, where Britain plans ahead.
Act 5 · No country is an island

No country is an island.

Cyberattacks cross borders. All four countries belong to alliances that try to share the load, and the study says no single country can address these threats alone.

Estonia

Helps run research and training at NATO's cyber centre, and takes part in the EU's cyber rapid response teams.

Sweden

Works through the European Union and its Nordic neighbours, and aligns with the EU's data protection law, GDPR.

Britain

Belongs to Five Eyes, the intelligence-sharing alliance with the United States, Canada, Australia, and New Zealand.

United States

Takes part in the United Nations group that writes the norms for how states should behave in cyberspace.

Europe has one data protection law. The United States has sector-by-sector rules and voluntary sharing, and the study finds the mismatch complicates data sharing with allies. An executive order that limits foreign access to sensitive American data protects the country and, at the same time, makes cooperation harder.

Act 6 · The twist and the limits
Size is not what decides it.

The assumption has always been that the biggest economy, with the most technology and the deepest pockets, leads in cybersecurity. The study says its analysis challenges assumptions that larger economies inherently lead in cybersecurity innovation.

Estonia's ability to innovate despite limited resources “suggests that governance agility and focused resource allocation are equally critical.”the study, p. 322

The study calls this its most significant theoretical contribution.

Act 6 · The twist and the limits

The catch.

Act 6 · The twist and the limits

Rules do nothing on their own.

If a country has good cybersecurity rules, why would it still get hacked? Because rules do nothing on their own. The study's second lens, Capacity Building Theory, says they need institutions to apply them, trained people to run them, and partners in business who actually cooperate.

“Without sustained investment in workforce development, even the most well-designed cybersecurity policies and regulatory frameworks risk becoming ineffective.”the study, p. 13

Human error, the study notes, remains one of the most common causes of security breaches.

A great fire plan is worthless if nobody in the building knows where the extinguishers are.

Act 7 · Who holds the domain

Three things the study asks of the United States.

1 · Decide who is in charge

A unified national cybersecurity framework; a federal task force working with CISA and NIST to bring federal and state rules into line; a central coordinating body modelled on Britain's.

2 · Make partnership formal, and worth it

Standing platforms where government and industry talk; real-time sharing; tax credits, grants, and liability protection for companies that take part.

3 · Build the people

Cybersecurity in schools from the early grades, expanded vocational training, and scholarships that create a pipeline.

These are proposals informed by the comparison, with no promise that one package works everywhere.

“The time to act is now.”the author's closing words, p. 349
Act 7 · Who holds the domain

The state can name the domain. It cannot own it.

In the air, at sea, on land, and in space, the military is the one that shows up. In cyberspace, the front line is a water plant owned by a utility, a hospital, a bank, and the phone in your pocket.

Estonia

put the state itself at the centre and rebuilt around it.

Sweden

put one agency at the centre and made partnership the law.

Britain

put one centre at the centre and played the long game.

The United States

by design, has no centre. That is the gap the study's recommendations try to close.

A country's cybersecurity is not a product it buys. It is a shape it agrees to take.

Resources · Read it, hear it, check it

Read it. Hear it. Check it.

The explainer article

The Battleground You Live In

About 4,000 words, written for a general reader.

Download PDF
The podcast

A single-host episode, 14 minutes 40 seconds

Narrated by a synthetic voice, and it says so.

Download MP3
The study

Waddell, Scott Wayne. 2025. Advancing U.S. Cyberspace Policies in the Age of AI and Web 3.0: A Comparative Case Study on Securing United States National Security Interests. Doctor of Strategic Intelligence dissertation, American Public University System. ProQuest Dissertations & Theses. ISBN 979-8-3101-4740-9.

Read the open-access dissertation at its official ProQuest record.

The record · How this was made

The record.

Revision review note
Explore the research · The method behind the findings

Compare consistently.
Understand in context.

Structured-focused comparative case study analysis.

01

A common basis.

The same 18 questions organize the evidence for all four countries.

02

A clear focus.

Each comparison addresses the policy issues at the heart of the research question.

03

Context stays visible.

Patterns emerge without treating countries with different institutions and resources as interchangeable.

04

A traceable interpretation.

Coded passages, comparisons across sources, and research notes support the path to policy lessons.

How this study used it

Follow the evidence from question to policy lesson.

Explore why these countries were chosen, how the documents were analyzed, and how the researcher and tools contributed.

QuestionFour cases · same questionsDocuments · codes · themesComparison · policy lessons
Explore how the study was done

A consistent comparison preserves the detail needed to judge which policy lessons might transfer. Source: dissertation, Chapter 3, pp. 32–49.

Speaking plainly

The Battleground You Live In · podcast