Skip to content
NUPI skole
NTB

Research project

2021 - 2025 (Completed)

Cyber security, knowledge and practices (CYKNOW)

CYKNOW will promote better understanding of cyber security, as well as develop novel theoretical and methodological tools for cybersecurity research in particular.

Themes

  • Defence
  • Security policy
  • Cyber
  • Globalisation
  • Diplomacy
  • Foreign policy
  • Europe
  • Governance
  • International organizations
  • The EU

With almost daily news reports of attacks on digital networks and data infrastructures, it has become clear that the rapidly increasing digitalization of modern society goes hand in hand with security challenges. While criminals use cyberattacks to enrich themselves, major powers increasingly see cyberspace as an arena for conflict, where offensive cyber operations to steal secrets or sabotage vital infrastructure of their adversaries have become a daily activity.

On the other hand, there is little agreement on what cyber security is, how it is understood and practiced. While the cybersecurity industry frames the problem from a technical understanding that requires a technical solution in a kind of cat and mouse game between attacker and defender, politicians and strategists see this as a great power game where attack is often the best defense. These different interpretations of what cybersecurity is and how it can be achieved form the basis for CYKNOW.

CYKNOW starts from the premise that what cybersecurity is, is not a given, but is rather an effect of various processes that configure different actors, practices, technologies and discourses. Configurations that consequently produce different ways of understanding, experiencing and practicing what we generally refer to as cybersecurity. In other words, cybersecurity is best understood as an ongoing process shaped by different elements that mutually transform each other.

Through an interdisciplinary approach that fuses social sciences with science and technology studies and computational design and engineering, CYKNOW develops a new analytical framework for studying cybersecurity. Although CYKNOW draws special attention to the importance of studying sociotechnical systems and its practices, it builds a methodological approach that allows for engaging multiple levels and structural concepts simultaneously. This framework enables an exploration of how knowledge about the digital threat landscape is produced by both strategists and engineers, how these understandings are mutually formed, and how policies and practices for cybersecurity emerge as a result.

CYKNOW will promote better understanding of cyber security, as well as develop novel theoretical and methodological tools for cybersecurity research in particular. In addition to shifting the academic research agenda around cybersecurity and international politics,

CYKNOW is designed to facilitate increased understanding between the technical and political environments, as well as to inform and expand political debates around cybersecurity and its implications.

Project Manager

Erik Reichborn-Kjennerud
Senior Research Fellow

Participants

Rita Augestad Knudsen
Senior Research Fellow
Claudia Emilie Aanonsen
Senior Research Fellow
Karsten Friis
Research Professor

External

Linda Monsees, IIR, Prague
Tim Stevens, KCL, London
Myriam Dunn Cavelty, ETHZ, Zurich

Articles

Articles
New research
Articles
New research

Why AI and Automation Do Not Equal Better Security

  • Security policy
  • Cyber
  • Intelligence
169_Nytt varslingssystem cyberangrep_Foto Ronja S Larsen_Aftenposten_NTB.jpg

New publications

Publications
Publications
Scientific article

Operationalising uncertainty: The automation of threat knowledge and situational awareness

This article examines how automated technologies produce threat knowledge in pursuit of “situational awareness”. Focusing on intrusion detection systems (IDS), it argues that searching for “anomalies” represents not only a technical shift but a sociotechnical reconfiguration. Drawing on interviews with technical operators, engineers, and institutional actors involved in Norway's national IDS, the article shows that anomaly detection does not deliver the seamless oversight or predictive control often promised by automation and Machine Learning. Instead, it produces new forms of uncertainty and interpretive labour warranted by military doctrines of “total security”. By exploring the conditions under which threats become known—a situated awareness—“omniboxing” is conceptualised as a lens to unpack the production of threat knowledge where uncertainty is not eradicated but operationalised. In contrast to Latour's black box, omniboxing acknowledges that while technical operators preserve an unyielding commitment to realising “total security”, technologies are not experienced as settled or self-evident. By foregrounding the ongoing and open-ended interpretive labour of human operators, the article demonstrates how IDS are not neutral tools of detection but are active in constituting what is seen, known, and acted upon as a threat. Situational awareness, often imagined as a means of achieving omniscient oversight, is rather a reflexive and situated process, revealing cybersecurity technologies as sociotechnical configurations rather than technical objects.

  • Defence
  • Security policy
  • Cyber
  • Intelligence
  • The Nordic countries
Security dialogue_cover.jpeg
  • Defence
  • Security policy
  • Cyber
  • Intelligence
  • The Nordic countries
Publications
Publications
Chapter

Krig i en verden av fremmed intelligens

This chapter investigates a number of issues related to the ongoing debates around artificial intelligence and its impact on the future of geopolitics and warfare. Through insights from science and technology studies (STS), the chapter seeks to question common assumptions in political science about the relationship between technology, war and politics. It will be argued that political science's treatment of these as independent elements and the subsequent simplified notions of technological and socio-political change must be altered in favor of a more inclusive way of thinking about socio-technical practices. This will improve our understanding of the war-technology relationship while providing a more fertile ground for discussing changes in the wake of the development of artificial intelligence.

  • Defence
  • Security policy
Screenshot 2022-06-17 at 14.45.12.png
  • Defence
  • Security policy
Publications
Publications
Policy brief

The power of standards in European Union digital governance

• This policy brief situates standardisation projects in the EU within global regulatory power, highlighting implications for markets, innovation, and global governance. • Standards for the production and distribution of digital products in the EU are technopolitical instruments that shape authority, legitimacy, and power, rather than neutral administrative tools for ensuring security and quality. • The EU’s regulatory power extends beyond European borders, intensifying debates about regulatory overreach, where public-interest regulation is often framed as protectionist and consequently rejected or simply ignored by major tech companies. • Standards should remain contestable, certification regimes subject to robust oversight, and expertise broadened beyond narrow technocratic communities.

  • Security policy
  • Cyber
  • Governance
  • The EU
Screenshot 2025-12-18 at 14.11.50.png
  • Security policy
  • Cyber
  • Governance
  • The EU
Publications
Publications
Book

The World According to Military Targeting

A revealing account of the prevalence—and alarming ubiquity—of military targeting, and how it has become a self-propelling worldview driven by dominance, violence, and power. The World According to Military Targeting engages directly with our grave world condition, asking how we ended up in a “closed world” made for military targeting by military targeting. In this book, NUPI researcher Erik Reichborn-Kjennerud explores how the operational logics and seductive forces of targeting produce a world in which the only ways to think about politics and security is through military supremacy, endless war, and global domination, with serious implications for social and political life. Offering a critical investigation of military targeting through the lenses of its historical formation, current operations, and future implications, the author presents an innovative investigation into targeting’s radical knowledge production, how it abstracts and brings into being new worlds, and the violence and destructive effects it generates. Through an interdisciplinary lens, the book draws attention to military doctrine and methodologies; statistical thought and practice; the mathematical and computational techniques of data production, processing, and modeling; and the so-called machine-learning algorithms and AI of today. The resulting narrative provides novel insights into how imagining the world, producing the world, and operationalizing the world are always wrapped up in each other and profoundly embedded in sociotechnical systems.

  • Defence
  • Security policy
  • Cyber
  • Conflict
  • Defence
  • Security policy
  • Cyber
  • Conflict
Articles
Articles
New research

Riskification and the production of threat: A comparison of risk assessments in cybersecurity and counter-terrorism

This article foregrounds the riskification of cybersecurity – the transition from pre-empting threat to governing risk – through a comparison of the U.S. government intrusion detection system EINSTEIN and parts of the UK counter-terrorism programme Prevent. Extensively theorised within both cybersecurity and counter-terrorism, calculating, profiling and governing risk has become the default mode of security governance, algorithmically producing subjects of insecurity. However, a closer, comparative read of the sociotechnical configurations that underpin specific modalities in risk assessment systems reveal important differences: Whereas Prevent more clearly presupposes normative subjects and standards of (in)security, EINSTEIN’s anomaly detection engenders threat not as a binary or normative distinction but as a separate category of risk. Highlighting these differences enables a deeper understanding of speculative security practices as such, and of how they may be theorised. In particular, the article shows how ‘meaning-making’ and ‘sense-making’ are processes that shape both security responses and timelines through which risk is conceptualised in different ways. Moreover, it reveals that rather than being fixed, risk and (in)security is perpetually co-produced with the tools used for assessment: The production of (in)security hence has little to do with real or imagined risk but rather emerges from a particular configuration of social, political and technological relations.

  • Security policy
  • Cyber
Screenshot 2025-05-28 at 10.39.35.png
  • Security policy
  • Cyber
Publications
Publications
Scientific article

Stuxnet, revisited (again): Producing the strategic relevance of cyber operations

More than a decade after Stuxnet hit the Natanz uranium enrichment facility in Iran, it is still discussed as the most vivid example of a cyber operation causing kinetic damage to infrastructure with implications for national security. This article shows that Stuxnet is due a revisit by arguing that the operation represents a paradigmatic shift in perceptions that continue to produce the meaning of ‘strategic relevance’ for cyber operations. The exceptional story of Operation Olympic Games and the Stuxnet malware has underpinned the way contemporary understandings of the (potential) role of cyber operations in international conflict prevail. Through a critical review of academic and policy discourse largely driven by orthodox perspectives on strategic security, the article demonstrates how these perspectives continue to influence American and Western policy objectives based on the imagined utility of cyber operations as an instrument of power. When exploring the strategic relevance of cyber operations as historically and politically produced, tied up in discursive and material interactions, it allows for scholars across the spectrum of security studies to critically consider the emergence of ‘new’ security threats and strategic capabilities.

  • Defence
  • Security policy
  • Cyber
  • Foreign policy
  • Conflict
  • Defence
  • Security policy
  • Cyber
  • Foreign policy
  • Conflict
Publications
Publications
Policy brief

Digital Borders, Global Ties: The EU’s Dual Quest for Cybersecurity and Digital Sovereignty

The EU's approach to ‘digital sovereignty’ and cybersecurity addresses concerns about geopolitical instability, data ownership, and control over critical digital infrastructure. This policy brief highlights the EU’s ambiguous claim to digital sovereignty, which is not only about controlling the internal digital space but also about navigating external dependencies. As the EU seeks to reduce reliance on external actors and increase autonomy in its digital space, it must navigate the risks of isolation from global markets. This creates a delicate balance between strengthening (cyber)security and fostering international cooperation. The forthcoming EU Cyber Resilience Act (CRA) is illustrative of this tension; while the CRA aims to strengthen digital resilience and autonomy, it underscores the need for the EU to protect its digital borders whilst integrated in the global digital economy. This push for autonomy must account for international interdependencies, especially in cybersecurity, where external partnerships remain crucial. Ultimately, the EU must adopt a nuanced approach that aligns ambitions toward digital sovereignty with the realities of an interconnected world.

  • Defence
  • Security policy
  • Cyber
Skjermbilde 2024-11-27 kl. 10.11.32.png
  • Defence
  • Security policy
  • Cyber
Publications
Publications
Chapter

Stuxnet - et paradigmeskifte?

More than a decade after Stuxnet was made publicly known, it remains the most vigorous example of a cyber attack causing both serious kinetic damage and as means to assert political pressure. Based on an analysis of the operation and its aftermath, this chapter argues that Stuxnet represents a paradigm shift. In view of advancements made to develop offensive and defensive cyber capabilities, particularly in the US, Israel and Iran, the shift refers to how states understand and use cyber capabilities during times of conflict. We illustrate how cyber operations can in certain contexts function as a supplement between diplomacy and the use of military means, but also in some cases as a substitute for conventional military force. The article is in Norwegian.

  • Cyber
cybermakt.jpg
  • Cyber

Themes

  • Defence
  • Security policy
  • Cyber
  • Globalisation
  • Diplomacy
  • Foreign policy
  • Europe
  • Governance
  • International organizations
  • The EU

Project Manager

Erik Reichborn-Kjennerud
Senior Research Fellow

Participants

Rita Augestad Knudsen
Senior Research Fellow
Claudia Emilie Aanonsen
Senior Research Fellow
Karsten Friis
Research Professor

External

Linda Monsees, IIR, Prague
Tim Stevens, KCL, London
Myriam Dunn Cavelty, ETHZ, Zurich