Date

8-20-2026

Department

Helms School of Government

Degree

Doctor of Philosophy in Public Administration (PhD)

Chair

Edwin P. Christmann

Keywords

cybersecurity, legislation, executive order, public policy, losses, damage, assessment

Disciplines

Public Affairs, Public Policy and Public Administration

Abstract

This quantitative longitudinal study examined the effectiveness of state cybersecurity legislation by analyzing the relationship between five state-level legislative features: mandatory frameworks, enforcement actions, information sharing, mandatory cybersecurity training, and government incentives, and two cybersecurity outcomes: the number of cyberattack victims and resulting economic losses. Using data from all 50 U.S. states from 2017 through 2024, the study evaluated whether these legislative features were associated with measurable reductions in cyberattack impacts. The findings indicate that none of the five legislative features significantly reduced the ratio of cyberattack victims to establishments. For economic losses, enforcement actions were modestly and negatively associated with losses, while information sharing was positively associated with reported losses. The results suggest that the presence of cybersecurity legislation alone is not sufficient to produce consistent preventive effects and that legislative features may function more effectively as accountability or resilience mechanisms than as direct prevention tools. Overall, the study points to a persistent gap between the theoretical promise of cybersecurity legislation and its observed effects in practice. These findings contribute to public administration scholarship by examining the extent to which state cybersecurity legislation aligns legislative formation, particularly with implementation, enforcement, and measurable outcomes.

Share

COinS