Research archive REVIEW DRAFT

Inside the research · The method

Compare consistently.
Understand in context.

Structured-focused comparative case study analysis

This method gives the study a clear way to compare: ask the same questions in each case, read the evidence closely, and look for patterns while keeping the context that gives them meaning.

The logic of the comparison
A focused research question
Define what the comparison needs to explain
The same questionsApplied to the evidence in every caseCode relevant passages · Connect themes
Compare patterns in context
Develop lessons with stated limits
In this dissertation: 18 questions, six policy themes, and four country cases. The method supplies the common structure; each case supplies evidence and context.
Scott W. Waddell, D.S.I.Based on the 2025 dissertationResearch design: Chapter 3, pp. 32–49

Why this method fit the question

Depth, with a common basis for comparison.

The study sought to understand how policies were being adapted, what challenges emerged, and what lessons the United States could consider. This design supported a close reading of policy evidence and a consistent comparison across different settings.

Structured

Ask the same questions.

Each case is read through the same 18 questions. This gives the study a shared basis: an approach in one case can be compared with the same aspect of another.

Focused

Stay close to the problem.

The study focuses on policy issues tied to AI, Web 3.0, and the protection of critical infrastructure. It examines the parts of each case that help answer the research question.

Comparative

Learn from differences.

The comparison shows what cases share and where they differ. A close look at each setting helps readers judge which lessons may carry over, and what would need to change.

Traceable interpretation

Show how the reasoning develops.

Key passages receive codes. Related codes connect to themes, and themes connect to the shared questions. Checking sources and keeping notes helps make that path visible.

Practical policy learning

Find lessons that can be adapted.

The comparison shows what was tried, what was hard, and what was reported to work. Context helps readers judge whether a lesson fits their own setting.

The fit was between the question and the method. The study needed a shared way to compare, a close reading of policy, and lessons that took each setting into account. Structured-focused analysis brought those needs together.

Plain-language explanation of the design and its strengths, based on pp. 32–35, 40–43, and 46–49. The study's limits remain part of that explanation.

The study at a glance

  1. 01Set the question
    and the lens
  2. 02Select cases
    that serve the question
  3. 03Gather the
    written evidence
  4. 04Code passages
    and develop themes
  5. 05Compare patterns
    and check interpretations
  6. 06Draw lessons
    with limits

A simplified route through Chapter 3 and its research-design diagram (Figure 1, p. 33). Coding and theme development involved repeated review, not a single pass.

The question and the lens

Start with a policy problem.

The central question was how the United States could adapt its cyberspace policies to safeguard national security as AI and Web 3.0 develop. Standards, government–business cooperation, and the cybersecurity workforce were particular concerns.

Systems Theory

What depends on what?

Critical infrastructure systems are connected. A disruption in one can affect others. This lens asks how policies address those shared risks and support resilience.

Capacity Building Theory

What makes a policy workable?

Policies need strong institutions, skilled people, and partners who can work together. This lens looks at how countries build the skills and support to keep their systems secure.

The two theories operate within the study's critical infrastructure protection framework. Research question: p. 5; framework and alignment: pp. 34–35.

One question set, used for every country.

The study used three questions in each of six themes: what the country did, what challenges it faced, and what successes or new ideas were reported. Explore the question groups below.

Policy adaptation and technology

  1. How did the country adapt its cybersecurity policies in response to AI and Web 3.0?
  2. What challenges did it face in adapting those policies?
  3. What successes and innovations emerged?

Plain-language paraphrases of Table 1, questions 1a–1c, p. 41.

Compliance and regulation

  1. How did the country design its compliance and regulatory frameworks for AI and Web 3.0?
  2. What were its main compliance challenges?
  3. What successes and innovations emerged?

Plain-language paraphrases of Table 1, questions 2a–2c, p. 41.

Public-private collaboration

  1. How did the country encourage partnerships between government and business in cybersecurity?
  2. What challenges did it face in developing those partnerships?
  3. What successes emerged from its collaboration models?

Plain-language paraphrases of Table 1, questions 3a–3c, pp. 41–42.

Education and workforce development

  1. How did the country develop its cybersecurity education programs?
  2. What key challenges did it face in cybersecurity education?
  3. What successes emerged from its education initiatives?

Plain-language paraphrases of Table 1, questions 4a–4c, p. 42.

National security and resilience

  1. How did the country adapt its cybersecurity policies to protect national security in the AI and Web 3.0 era?
  2. What key challenges did it face in maintaining national security in cyberspace?
  3. What successes emerged from its cybersecurity initiatives?

Plain-language paraphrases of Table 1, questions 5a–5c, p. 42.

International cooperation

  1. How did the country take part in international cybersecurity cooperation?
  2. What challenges did it face in that cooperation?
  3. What successes emerged from its international collaborations?

Plain-language paraphrases of Table 1, questions 6a–6c, p. 42.

These questions were applied to documentary evidence for each case. They were not interview questions put to participants.

Purposeful case selection

Choose cases that serve the question.

The study chose cases with useful policy experience, shared features that made comparison possible, and enough written evidence to study closely. Differences in size, resources, and forms of government gave the comparison depth.

How it was applied here: Estonia, Sweden, the United Kingdom, and the United States offered different cybersecurity approaches within democratic systems. Their policy records supported the inquiry. They were selected for their relevance, rather than drawn as a random sample of countries.

More about the selection

The dissertation also cites the countries' Global Cybersecurity Index standing and relevance to the Information Technology sector. It considered other democracies, but limited the study to these four cases. Scott's fluency in Swedish supported access to Sweden's native-language documents.

Case selection and rationale: pp. 35–38. These are the study's selection reasons, not a current ranking of national cybersecurity performance.

Gathering the evidence

Read the policies, then read around them.

The study read existing records: what governments had set out in policy and law, alongside research that helped place those records in context.

Official records

What countries put on paper

National cybersecurity strategies, policy documents, legislative acts, and government reports.

Research and commentary

How those policies were examined

Academic literature, industry white papers, think tank reports, and publications from international organizations.

University library and research databasesOfficial government repositoriesLibrarian support for searches

There were no interviews or focus groups. The records could show how policies were described and discussed. They offered less insight into the decisions and day-to-day work behind them.

Where the documents came from

The methods chapter describes archival research through the APUS Library and sources including JSTOR, Scopus, IEEE Xplore, Google Scholar, Semantic Scholar, and ProQuest. Government repositories included the U.S. Federal Register and the government portals of the United Kingdom, Sweden, and Estonia.

Chapter 3 calls original policy and legal records primary sources, and research about them secondary sources. Its limitations section also describes the study as relying on secondary data. In either usage, this was a study of existing documents, without firsthand interviews.

Collection: pp. 38–39. Documentary evidence and absence of interviews or focus groups: pp. 44–45.

From documents to patterns

Make the evidence comparable.

Coding means labeling a relevant passage to identify what it is about. A codebook is the guide to those labels. A theme connects related ideas into a broader pattern.

First-cycle coding

Label the material.

  • Descriptive codes summarize a topic.
  • In Vivo codes preserve wording from the document.
  • Process codes identify an action.

Second-cycle coding

Connect the labels.

Related codes are linked into broader groups through axial coding. In this study, those second-cycle groups and themes refer to the same level of analysis.

What does that look like?

Illustrative example · not study data

This made-up teaching example uses a topic about cybersecurity training. It shows how a passage can become part of a comparison. It contains no quotes, case findings, or counts from the study.

Start with a relevant passage.

Imagine a document about a cybersecurity training program. The researcher marks a passage that fits the study's questions about education.

Describe the topic and the action.

Illustrative labels might be training program for the topic and developing skills for the action. An In Vivo code would use the document's actual words; none is invented in this example.

Connect it with related material.

Related labels can be grouped under a broader theme such as education and workforce development. The researcher reviews the material and judges how it fits the theme.

Ask the same questions across cases.

How did each country develop its programs? What challenges did it face? What successes were reported? The comparison examines the evidence for each question while retaining the country's context.

The full analysis cycle

The study combined Saldaña's coding approach with Braun and Clarke's thematic analysis framework. Its six phases were: become familiar with the documents; generate initial codes; identify broader themes; review those themes; define and name them; and bring the findings together in the dissertation. Repeated review linked the evidence, themes, and research questions.

Two coding cycles and thematic analysis: pp. 39–41. Standard questions: Table 1, pp. 41–42. The example above is a teaching aid created for this page, not a reconstruction of the study's codebook.

Comparing and checking

Keep the reasoning connected to the evidence.

The shared questions gave the comparison its structure. Source checks, case details, and notes helped show how the researcher reached a view.

  • Compare different kinds of sources.

    The study checked interpretations across policy documents, legislation, national strategies, academic literature, and industry papers. This is called triangulation.

  • Preserve each country's context.

    A close account of the policies and setting of each case helps readers judge whether a lesson could apply elsewhere.

  • Record decisions about the analysis.

    Analytic memos are notes on coding and themes. They recorded key decisions. The researcher returned to the material as the coding process developed.

  • Use software to organize the comparison.

    NVivo supported the management of coded text, comparisons across countries through matrix coding queries, and visual exploration of themes.

What the numbers mean: the theme tables count coded references in the material. They describe the evidence discussed; they should not be read as scores for how safe a country is or as proof that a policy caused an outcome.

NVivo: pp. 40–41. Trustworthiness and documented decisions: pp. 42–43. Researcher interpretation remains a limitation, pp. 45–46. The explanation of counts is a reading guide based on the coding method and theme tables (pp. 81–82, 121, 162, 195, 237, 273).

The researcher and the tools

Scott did the intellectual work. Tools assisted the process.

The original research and the later article, podcast, and website are distinct stages. The role of AI in each deserves its own explanation.

NVivo in the dissertation

The methods chapter describes NVivo as the main qualitative analysis tool for organizing coded material, comparing cases, and exploring themes. That documented role is separate from the author's later account of LLM assistance.

AI in the later public-facing materials

AI was also used to adapt the finished dissertation into this article, podcast, and website. The podcast uses a synthetic voice. Those production activities explain how the study is presented here; they are separate from how the original research was conducted.

NVivo: pp. 40–41. Original AI use: author's account, recorded as AUCP-DEC-2026-035 / SR-09. Later production: this project's article, podcast, and website records.

Lessons and limits

Learn from the cases. Keep the context.

The comparison informed policy recommendations the United States could adapt to its own circumstances. It did not establish one country as a universal model.

Documents offer a partial view.

Public records may not reveal how a policy works in practice. Without interviews, the study had less access to firsthand decisions and experiences. Classified and proprietary material also limited visibility.

Countries differ.

A smaller country's approach may need major changes to work in a larger federal system. Government structures, resources, and timing affect whether a lesson can carry over.

Interpretation remains human.

A consistent coding process and software support do not remove researcher judgment. Preconceptions can influence which patterns receive attention and how they are understood.

The evidence reflects its time.

The findings describe the policies and material examined for the 2025 dissertation. AI, Web 3.0, and cybersecurity policy continue to change; this page explains the completed study.

Evidence access and interviews: pp. 44–45. Interpretation: pp. 45–46. Comparability: pp. 46–47. Time and resources: pp. 47–48. Context and responsible reporting: pp. 48–49.

Open access · Full dissertation, including the methods chapter.

Source and reading notes

Source study: Scott Wayne Waddell. 2025. Advancing U.S. Cyberspace Policies in the Age of AI and Web 3.0: A Comparative Case Study on Securing United States National Security Interests. Doctor of Strategic Intelligence dissertation, American Public University System. Published through ProQuest Dissertations & Theses. ISBN 979-8-3101-4740-9.

This page follows Chapter 3, “Methodology and Research Design,” pp. 32–49. The opening research question is on p. 5. Page references use the dissertation's printed page numbers.

  • The workflow simplifies Figure 1 (p. 33); the question explorer paraphrases all 18 questions in Table 1 (pp. 41–42).
  • The coding example is explicitly illustrative. It supplies no source quotation, measured result, or reconstructed research record.
  • AI-use information about 2023–2025 comes from the author's later account, as labeled above.