Institutional Conversion And The Politics Of Digital Insecurity

Abstract: Digital insecurity becomes leverage only when authorities recognised by relevant governance bodies convert cyber risk into binding rules, restrictions, or supervisory duties that alter the terms of participation. This process is called institutional conversion. Three pathways matter most: reliability shock, supplier risk governance, and exposure cascade. Comparing the European Union with Nigeria shows that the same mechanism operates across different governance settings but produces different outcomes. In the EU, costs are projected outward through sanctions, supplier restrictions, and resilience rules. In Nigeria, they are absorbed more domestically through infrastructure protection, prudential supervision, and compliance burdens.

Problem statement: Why do comparable cyber incidents generate sharply different political and economic consequences across governance settings?

So what?: Analysts and policymakers should look beyond the immediate operational effects of cyber incidents to the institutional processes that convert cyber risk into enduring consequences. That shift helps identify where digital insecurity will reshape market access, supplier choice, and regulatory authority, and where it will remain a bounded technical event.

Source: shutterstock.com/Funtap

Introduction

Cyber insecurity now shapes sanctions, supplier exclusion, market access, investment screening, prudential supervision, and digital regulation. Yet similar forms of digital insecurity do not produce similar political consequences. Some hacks remain bounded security events, managed through incident response, attribution disputes, or limited defensive adaptation. Others are translated into durable restrictions, compliance burdens, supervisory duties, or altered conditions of market participation. Explaining that variation matters. Contemporary global security is increasingly organised through digital infrastructures, and their vulnerability affects not only technical resilience but also the terms of political authority and economic order. Existing scholarship explains much about cyber operations, economic coercion, and network asymmetry, but it is less precise about the institutional stage through which digital insecurity becomes binding governance.[1]

This article argues that cyber insecurity becomes leverage only when recognised authorities translate digital risk into binding consequences that materially alter participation. I call this process institutional conversion. Leverage, as used here, is not synonymous with cybersecurity regulation in general. It refers more narrowly to the capacity to impose or structure binding economic or organisational consequences based on digitally framed insecurity. It is present when cyber risk is translated into restrictions, supervisory burdens, exclusions, or altered access conditions that alter the expected costs of participation. This distinguishes leverage from ordinary governance hardening, which may improve resilience without significantly redistributing access, costs, or strategic advantage.

Cyber conflict scholarship has shown why digital operations often fail to compel directly. Geoeconomic scholarship has clarified how states exploit sanctions, regulation, and asymmetric dependencies. Research on infrastructure and standards has shown how technical systems govern access, hierarchy, and dependence. What remains under-specified is the conversion stage between digital insecurity and binding consequence. The central claim here is that cyber insecurity becomes strategically consequential when institutions with recognised jurisdiction classify digital risk as a governable threat, attach binding instruments to that classification, and thereby shift the costs of participation.[2]

The argument is developed through a comparative case design. The European Union is the anchor case because it offers a highly legalised setting in which cyber insecurity has been translated into sanctions, supplier governance, and resilience regulation with outward-facing effects. Nigeria serves as a bounded contrast. It reveals a more domestically absorbed pattern in which cyber insecurity is translated into tighter internal supervision, heightened protection of critical infrastructure, and denser compliance duties. The point is not that the two cases possess equivalent power. It is that the same mechanism can operate across very different governance settings while producing different types of binding consequences.

Cyber Insecurity and the Missing Conversion Stage

Cyber conflict scholarship has produced valuable insights into the strategic limits of digital operations. Attribution is often contested, signalling can be ambiguous, operational effects may be reversible, and thresholds for compellence remain uncertain. Many cyber operations, therefore, disrupt without producing stable behavioural change. This literature is persuasive on why cyber activity often fails to compel directly. Still, it leaves a related question less fully developed: when and through what process does cyber insecurity become the basis for binding governance with economic and strategic effects?[3]

That question matters because many of the most significant consequences of cyber insecurity emerge after the incident itself. A breach may not compel a target directly, yet it can trigger stronger reporting duties, supplier restrictions, supervisory expectations, or resilience mandates. The political force of cyber insecurity often lies not only in intrusion or disruption, but in the institutional response that follows. If analysis stops at the operational moment, it misses where many of the durable consequences are actually produced.

Geoeconomic scholarship addresses a different dimension of the puzzle. Work on sanctions, economic statecraft, and weaponised interdependence shows how states exploit market size, jurisdiction, network centrality, and infrastructural dependence to impose costs and shape strategic behaviour. This literature demonstrates that power increasingly operates through legally administered and institutionally mediated forms of coercion rather than through force alone.[4]

Yet it too leaves a specific issue under-theorised. Structural advantage may create permissive conditions for coercion. Still, it does not by itself explain why one cyber incident remains a bounded security problem while another is recoded into sanctions, supplier exclusion, or denser supervisory governance.

Research on infrastructure and standards reinforces this argument. Technical systems govern because they structure interoperability, access, reliability, and dependence. Resilience, trusted supply, and cybersecurity are therefore never merely technical matters. They shape who bears risk, who may define acceptable exposure, and who can impose conditions on continued participation. However, this literature still lacks sufficient attention to the institutional process through which cyber insecurity is translated into exclusion, audit, liability, or market restructuring.[5]

The missing analytical stage is institutional conversion. Institutional conversion is the process by which recognised authorities translate digital insecurity into binding governance that alters the terms of participation. The concept is narrower than any state response to cyber risk, but broader than direct cyber compellence. It captures the institutional work through which technical insecurity becomes politically legible, legally actionable, and administratively enforceable. The relevant question is therefore not only who has cyber capability or structural power, but who can define insecurity as governable, attach binding consequences to that definition, and sustain those consequences over time.

Institutional Conversion under Uneven Cyber Capacity

Institutional conversion unfolds through three linked moves. The first is authoritative recoding: classifying a cyber incident, supplier dependency, or pattern of exposure not simply as a technical problem but as a governable threat with implications for security, resilience, trusted supply, or systemic stability. The second is instrument selection and proceduralisation. Once recoded, insecurity is attached to binding instruments such as sanctions, procurement restrictions, licensing decisions, mandatory reporting, audit obligations, resilience requirements, or supervisory rules. The third is binding cost shifting. These measures alter the expected costs of participation by raising compliance burdens, restricting access, increasing oversight, forcing vendor substitution, or changing market conditions.

This mechanism differs from direct cyber coercion. The target is not shaped solely by the operational effect of the original incident. Rather, the incident, dependency, or exposure becomes the basis for a secondary layer of governance that reorganises economic participation. This is why cyber episodes that appear strategically inconclusive at the point of intrusion can still generate durable political and economic effects.

There are three pathways through which conversion tends to occur. The first is reliability shock. Visible disruption to critical services or infrastructures generates pressure for resilience-framed intervention. The second is supplier risk governance. Dependence on particular vendors or external providers is recoded as a security problem, enabling exclusion, de-risking, or the use of trusted supplier frameworks. The third is the exposure cascade. Repeated breaches, control failures, or weak governance trigger more stringent obligations regarding reporting, audit, oversight, and liability. These pathways synthesise insights from cyber coercion, geoeconomic, infrastructure-governance, and resilience scholarship discussed in notes 3–5. They are analytically distinct but can reinforce one another.

Whether conversion occurs and what form it takes depends on uneven cyber capacity. Cyber capacity means more than technical skill. It combines diagnostic, regulatory, and enforcement capacities. Diagnostic capacity makes cyber risk intelligible for administration; regulatory capacity translates that diagnosis into binding rules or restrictions; and enforcement capacity monitors compliance and sustains consequences over time. High-capacity actors are more likely to convert cyber insecurity into outward-facing restrictions, supplier governance, or broad compliance architectures. Lower capacity actors may still perform conversion, but more often through inward-facing supervisory tightening, prudential adaptation, and domestically absorbed compliance burdens.

The framework yields three observable implications. First, cyber insecurity should be followed by explicit authoritative framing that links digital risk to governable consequences. Second, one should observe the selection of binding instruments that alter participation. Third, one should observe concrete downstream effects, such as exclusion, vendor substitution, stronger reporting and audit duties, increased supervisory pressure, or changed access conditions. The theory is weakened if major consequences appear without identifiable recoding and proceduralisation, or if outcomes are explained entirely by unrelated market shifts.

Research Design and Case Selection

The article uses a comparative qualitative case design to trace the mechanism across two different governance settings. The European Union is selected as the anchor case because it provides a highly legalised and document-rich environment in which cyber insecurity has been translated into sanctions, supplier restrictions, and resilience regulation with significant market effects. Nigeria serves as a bounded contrast because it allows the mechanism to be observed where external coercive reach is narrower and cyber governance operates more through domestic supervisory, legal, and infrastructural instruments.

The comparison is functional rather than symmetrical. The article does not treat the EU and Nigeria as equivalent units of aggregate geopolitical power. The purpose is to observe whether the same institutional sequence appears across different contexts of authority, legalisation, market projection, and regulatory capacity. The structured comparison asks the same questions of each case: how was cyber insecurity framed, what instruments were selected, and what downstream consequences followed? The empirical focus draws on official legal texts, regulatory instruments, policy statements, and supervisory materials because the argument centres on authoritative recoding and procedural specification.[6]

External-Facing Conversion

The European Union provides the clearest example of external-facing institutional conversion. Its significance lies not simply in market size but in the repeated translation of cyber insecurity into binding legal and administrative measures that alter supplier access, compliance expectations, and the room for manoeuvre available to targeted actors. In the EU context, cyber upplieinsecurity is not treated merely as a technical issue for operators. It is classified as a threat to Union security, the resilience of critical infrastructure, the integrity of the internal market, and trusted supply.[7]

The first move is authoritative recoding. Council Decision (CFSP) 2019/797 established the legal basis for restrictive measures against cyberattacks that threaten the Union or its Member States. This is analytically important because a cyber attack is no longer limited to a bounded digital event. It is reclassified as conduct capable of triggering restrictive economic measures under Union authority. A similar recoding occurs in the EU’s 5G governance. The coordinated 5G risk assessment and the subsequent 5G Toolbox did not frame supplier dependence as a narrow procurement issue. They treated it as a security problem rooted in systemic dependence and exposure associated with high-risk suppliers. The Commission’s 2023 communication on implementation of the 5G Cybersecurity Toolbox reinforced this framing by supporting member state restrictions on suppliers considered to pose serious risks.[8]

The same logic appears in resilience regulation. NIS2 broadens the set of entities subject to cybersecurity risk management, governance duties, and incident reporting. DORA performs a parallel move in the financial sector by treating ICT and cyber risk as a matter of operational resilience requiring harmonised management, testing, incident reporting, and oversight of critical third-party providers. In each instance, digital insecurity is formally moved from technical administration into binding market governance.

The second move is instrument selection and proceduralisation. In the sanctions domain, the Union can impose travel bans and asset freezes on persons and entities responsible for significant cyber attacks. On July 30, 2020, the Council used that framework for the first time against six individuals and three entities linked to WannaCry, NotPetya, Operation Cloud Hopper, and the attempted cyber attack against the OPCW. This first use matters because it demonstrates movement from legal possibility to operationalised economic consequence.[9]

In the 5G domain, the principal tools are procurement restriction, trusted supplier policy, and structured de-risking. The 5G Toolbox called for strategic and technical measures that would strengthen security requirements, restrict high-risk suppliers, and diversify the supply chain. The Commission’s 2023 implementation communication lent political weight to this process by explicitly supporting restrictions on suppliers deemed to pose serious risks. These are not classic sanctions, but they are binding market-shaping instruments. They alter who may credibly participate in critical network environments and on what terms.

NIS2 and DORA extend conversion through resilience governance. They proceduralise cyber insecurity into a standing architecture of incident reporting, governance responsibility, testing, auditability, and oversight. Their force lies less in dramatic exclusion than in the creation of durable compliance systems that reshape the expected conditions of participation across digitally mediated sectors.

The final move is binding cost shifting. In the sanctions context, the cost shift is direct. Asset freezes and associated restrictions impose legal and financial penalties on listed actors while signalling that malicious cyber activity can trigger broader economic repercussions. In the 5G setting, the cost shift appears through altered vendor choice and substitution pressure. High-risk supplier restrictions force network operators to reduce dependence, reconsider procurement strategies, and absorb transition costs. The downstream effects are concrete: restricted suppliers lose market access, operators face reconfiguration costs, and member states are pressed to de-risk and diversify.

In the resilience domain, the costs are more administrative but still consequential. NIS2 expands cybersecurity governance and reporting burdens across essential entities. DORA requires financial actors to invest in ICT risk management, resilience testing, incident reporting, and scrutiny of critical third-party providers. Firms, therefore, bear higher compliance costs and stronger supervisory expectations. The cumulative effect is not just better defence. It is a reorganisation of participation through denser obligations and altered market access conditions.

The dominant EU pathways are supplier risk governance and exposure cascade, with sanctions providing a more visible form of external projection. Cyber insecurity becomes leverage here not because disruption compels directly, but because recognised authorities convert cyber risk into sanctions, supplier exclusion, and resilience obligations that materially reshape participation. The EU case thus demonstrates the mechanism in a setting where costs can be projected outward across markets and infrastructures.

Domestically Absorbed Conversion

Nigeria provides the bounded contrast. It shows the same basic mechanism, but with a narrower external reach and more uneven regulatory capacity. Nigeria lacks the EU’s market power and legal harmonisation, so its conversion operates primarily within its own borders. The Nigerian case should not be read as equivalent to the EU’s outward-facing leverage. Its significance lies in demonstrating a domestically absorbed form of institutional conversion in which cyber insecurity is translated into tighter internal supervision, enhanced protection of critical infrastructure, and denser compliance obligations across nationally significant sectors.[10]

The first move is authoritative recoding. Nigeria’s cyber governance framework treats digital insecurity as a matter of national security, critical infrastructure continuity, financial stability, and data governance. The Cybercrimes framework links cyber governance to the protection of critical national information infrastructure. Although the framework criminalises certain acts, its governance effect comes from the designation and protection of infrastructure rather than from prosecution alone. The Designation and Protection of Critical National Information Infrastructure Order, 2024, goes further by identifying ICT systems and networks as critical infrastructure and extending cybersecurity governance across sectors central to economic development, public safety, government operations, defence, finance, health, transport, food, and industry. Cyber insecurity is therefore not framed as an isolated technical problem. It is classified as a governable threat to nationally significant systems.[11]

A parallel recoding is visible in data governance. The Nigeria Data Protection Act 2023 and the Nigeria Data Protection Commission’s compliance guidance move data exposure and weak digital governance into a framework of lawful obligation. Controllers and processors are placed within a regime of compliance, filing, verification, and possible investigation. Likewise, the Central Bank of Nigeria’s 2024 Risk-Based Cybersecurity Framework for deposit money banks and payment service banks treats cyber risk as a prudential and supervisory issue rather than a matter left entirely to private discretion.[12]

The second move is instrument selection and proceduralisation. The CNII Order provides for protection plans, minimum standards, trusted information-sharing arrangements, and periodic audits and inspections of designated infrastructure. These are concrete instruments through which cyber vulnerability is translated into an administratively structured regime of obligation. In finance, the Central Bank’s framework imposes minimum cybersecurity requirements on regulated institutions. In data governance, the NDPA and NDPC compliance arrangements attach filing duties, verification requirements, and potential investigative exposure to the handling of data.

These instruments differ from EU sanctions or broad supplier exclusions, and that difference is analytically important. Nigeria’s conversion operates less through externally projected market discipline and more through internal supervisory, legal, and infrastructural governance. Yet the mechanism remains the same. Recognised authorities classify cyber insecurity as governable and attach binding instruments to that classification.

The final move is binding cost shifting. Under the CNII Order, owners and operators of designated infrastructure face the costs of meeting standards, participating in information-sharing arrangements, and operating under the possibility of audits and inspections. In the financial sector, banks and payment service providers must absorb the governance, reporting, and organisational costs associated with compliance with the Central Bank’s cybersecurity framework. In data governance, controllers and processors bear the burdens of filing, verification, internal governance adjustment, and potential investigation.

These are concrete downstream effects. Critical infrastructure operators face audit exposure and compliance costs. Financial institutions face stronger supervisory pressure and must devote resources to governance and controls. Data controllers and processors encounter new organisational obligations and legal risk. Cyber insecurity thus becomes consequential in Nigeria by altering the domestic terms of lawful participation rather than by generating broad external leverage.

The dominant Nigerian pathways are exposure cascade and reliability hardening. The exposure cascade manifests in the layering of legal, supervisory, and compliance obligations across cybercrime, data governance, and financial supervision. Reliability hardening is most evident in the CNII Order, where cybersecurity governance is tied to the continuity and integrity of systems deemed vital to the state and the economy. Supplier risk governance is less pronounced here than in the EU case. Nigeria does not have the market power to impose supplier restrictions on global vendors such as Huawei or foreign cloud providers, as the EU can. That asymmetry is precisely the point. Institutional conversion travels, but its repertoire depends on authority, legalisation, and the capacity to shift costs outward.

Comparative Implications

Taken together, the two cases distinguish the mechanism from variation in its expression. In both settings, cyber insecurity is authoritatively recoded, attached to institutional instruments, and converted into binding consequences. What varies is the direction and distribution of those consequences. The European Union projects costs outward across markets and infrastructures. Nigeria absorbs them more internally through domestic regulatory, supervisory, and infrastructural governance.[13]

This comparison clarifies three broader findings. First, institutional conversion is portable across contrasting governance environments. The mechanism is visible not only in a highly legalised actor such as the EU but also in a more capacity-constrained setting such as Nigeria. What travels is not a fixed policy template but a common sequence of recoding, proceduralisation, and cost shifting. Second, uneven cyber capacity shapes the repertoire of leverage. Stronger legalisation, market scale, and enforcement capacity permit outward projection through sanctions, supplier discipline, and resilience regulation. Narrower capacity produces inward-facing conversion through supervisory tightening, infrastructural hardening, and domestically borne compliance burdens. Third, the most durable effects of cyber insecurity are often institutionally produced rather than operationally immediate. The decisive movement is frequently not the intrusion itself, but the governance that follows it.

These findings matter for global security studies because they shift attention from cyber events as isolated acts to cyber insecurity as a mode of ordering. Digital insecurity becomes politically consequential when institutions transform it into rules, restrictions, obligations, and differentiated costs of participation. This helps explain why cyber politics belongs in closer conversation with work on governance, interdependence, and the administrative production of power. The strategic significance of cyber insecurity lies not only in what digital disruption does at the moment of attack, but in what recognised authorities can make of it afterwards.

Conclusion

This article has argued that cyber insecurity becomes leverage through institutional conversion. Digital disruption does not automatically generate strategic effect, and structural power alone does not explain why some incidents produce durable consequences while others remain bounded security events. What matters is whether recognised authorities can classify cyber risk as governable, attach binding instruments to that classification, and thereby alter the expected costs of participation.

The comparison between the European Union and Nigeria demonstrates the portability of this mechanism and the importance of uneven cyber capacity. In the EU, cyber insecurity is translated into external-facing sanctions, supplier restrictions, and resilience obligations that reshape participation across markets and infrastructures. In Nigeria, cyber insecurity is translated into domestic surveillance, critical infrastructure protection, and more stringent compliance duties across nationally significant sectors. The mechanism is common, but the repertoire of consequences differs.

The broader implication is that cyber insecurity should be analysed not only as a domain of attack and response, but also as a source of governance transformation. Its strategic significance lies in the institutional capacity to convert digital risk into durable obligations, exclusions, and cost burdens. Understanding that process is essential to explaining how contemporary global security is increasingly organised through infrastructures, standards, and governance alongside traditional military force.


[1] Martin C. Libicki, Cyberdeterrence and Cyberwar (Santa Monica, CA: RAND, 2009); Daniel W. Drezner, The Sanctions Paradox: Economic Statecraft and International Relations (Cambridge: Cambridge University Press, 1999); Henry Farrell and Abraham L. Newman, “Weaponized Interdependence: How Global Economic Networks Shape State Coercion,” International Security 44, no. 1 (2019): 42–79.

[2] David A. Baldwin, Economic Statecraft (Princeton, NJ: Princeton University Press, 1985); Robert D. Blackwill and Jennifer M. Harris, War by Other Means: Geoeconomics and Statecraft (Cambridge, MA: Harvard University Press, 2016); David Singh Grewal, Network Power: The Social Dynamics of Globalisation (New Haven, CT: Yale University Press, 2008).

[3] Thomas Rid, Cyber War Will Not Take Place (London: Hurst, 2013); Jon R. Lindsay, “Stuxnet and the Limits of Cyber Warfare,” Security Studies 22, no. 3 (2013): 365–404; Erica D. Borghard and Shawn W. Lonergan, “The Logic of Coercion in Cyberspace,” Security Studies 26, no. 3 (2017): 452–81; Brandon Valeriano and Ryan C. Maness, Cyber War versus Cyber Realities: Cyber Conflict in the International System (Oxford: Oxford University Press, 2015).

[4] Baldwin, Economic Statecraft; Drezner, The Sanctions Paradox; Blackwill and Harris, War by Other Means; Farrell and Newman, “Weaponized Interdependence.”

[5] Grewal, Network Power; Francesca Musiani et al., eds., The Turn to Infrastructure in Internet Governance (New York: Palgrave Macmillan, 2016); Jean-Christophe Plantin and Gabriele de Seta, “WeChat as Infrastructure: The Techno-Nationalist Shaping of Chinese Digital Platforms,” Chinese Journal of Communication 12, no. 3 (2019): 257–73.

[6] Council of the European Union, Council Decision (CFSP) 2019/797 of 17 May 2019 concerning restrictive measures against cyber-attacks threatening the Union or its Member States, Official Journal of the European Union L 129I (May 17, 2019): 13–19; European Commission, Communication from the Commission: Implementation of the 5G Cybersecurity Toolbox, C(2023) 4049 final (Brussels, June 15, 2023); Directive (EU) 2022/2555, Official Journal of the European Union L 333 (December 27, 2022): 80–152; Regulation (EU) 2022/2554, Official Journal of the European Union L 333 (December 27, 2022): 1–79; Federal Republic of Nigeria, Designation and Protection of Critical National Information Infrastructure Order, 2024; Federal Republic of Nigeria, Nigeria Data Protection Act, 2023.

[7] Council of the European Union, Council Decision (CFSP) 2019/797, 13–19.

[8] European Commission, Implementation of the 5G Cybersecurity Toolbox.

[9] Council of the European Union, “EU Imposes the First Ever Sanctions against Cyber-Attacks,” press release, July 30, 2020.

[10] Federal Republic of Nigeria, Cybercrimes (Prohibition, Prevention, Etc.) (Amendment) Act, 2024; Federal Republic of Nigeria, Designation and Protection of Critical National Information Infrastructure Order, 2024.

[11] Federal Republic of Nigeria, Designation and Protection of Critical National Information Infrastructure Order, 2024, S.I. No. 21 of 2024, Official Gazette 111, no. 107 (Lagos, June 25, 2024): B511–29.

[12] Federal Republic of Nigeria, Nigeria Data Protection Act, 2023; Nigeria Data Protection Commission, Guidance Notice on Registration of Data Controllers and Data Processors of Major Importance (February 14, 2024; updated July 23, 2025); Nigeria Data Protection Commission, General Application and Implementation Directive (March 20, 2025); Central Bank of Nigeria, Risk-Based Cybersecurity Framework and Guidelines for Deposit Money Banks and Payment Service Banks (Abuja: Central Bank of Nigeria, 2024).

[13] Council of the European Union, Council Decision (CFSP) 2019/797, 13–19; European Commission, Implementation of the 5G Cybersecurity Toolbox; Directive (EU) 2022/2555, 80–152; Regulation (EU) 2022/2554, 1–79; Federal Republic of Nigeria, Designation and Protection of Critical National Information Infrastructure Order, 2024; Federal Republic of Nigeria, Nigeria Data Protection Act, 2023; Central Bank of Nigeria, Risk-Based Cybersecurity Framework and Guidelines.

Categories

Institutions gain IP-authenticated and remote digital access to all issues of The Defence Horizon Journal’s Special Edition.

Digital access is: 

  • Fully-searchable;
  • With intuitive display options;
  • Accessible and VPAT-compliant (including read-aloud technology); 
  • Cross-platform compatible;
  • Includes usage reports and MARC records.

Institutions can access a free 1-month trial and/or request pricing.

Languages

Sign Up For Our Newsletter

Get the content you need, just when you need it.

DONATE

Support our mission by making a donation.

Visit our Partner