Cybersecurity poses significant challenges for legal theory, unsettling fundamental categories such as sovereignty, responsibility, and normativity. The modern paradigm of security, based on the idea that the State is the exclusive guarantor of public order within territorially defined boundaries, falters when confronted with cyber threats that unfold in an extraterritorial, transnational, technically opaque and (mostly) privately owned and managed domain, that is, cyberspace. In the EU, cybersecurity governance operates through a multi-level and multi-stakeholder architecture in which public and private actors, Union and Member States agencies and institutions overlap and (re)negotiate normative, executive, and adjudicative functions. Against this backdrop, this paper examines (i) how cybersecurity exposes the fragility of State power, unable to exert full control over cyberspace; (ii) the emergence and effectiveness of supranational responses at EU level; and (iii) how EU Member States are responding to this crisis. Thus, since the early 2000s, the EU has sought to enhance common resilience and security in cyberspace. Yet, national security remains an exclusive competence of Member States. The result is a (dys)functional dualism whereby the EU fosters regulatory and technical integration through its internal market competences, while States retain exclusive authority over national security. This hybrid arrangement highlights a deep legal-institutional tension and a new vulnerability in Europe’s cybersecurity governance, prompting a reconsideration of how sovereignty, coercion, and legality are being redefined in cyberspace.
Chiara, P.G. (2026). Il governo della cybersicurezza: crisi dello Stato? Potere, diritto e vulnerabilità nell’era digitale globale. JURA GENTIUM, 23(1), 99-126.
Il governo della cybersicurezza: crisi dello Stato? Potere, diritto e vulnerabilità nell’era digitale globale
Pier Giorgio Chiara
2026
Abstract
Cybersecurity poses significant challenges for legal theory, unsettling fundamental categories such as sovereignty, responsibility, and normativity. The modern paradigm of security, based on the idea that the State is the exclusive guarantor of public order within territorially defined boundaries, falters when confronted with cyber threats that unfold in an extraterritorial, transnational, technically opaque and (mostly) privately owned and managed domain, that is, cyberspace. In the EU, cybersecurity governance operates through a multi-level and multi-stakeholder architecture in which public and private actors, Union and Member States agencies and institutions overlap and (re)negotiate normative, executive, and adjudicative functions. Against this backdrop, this paper examines (i) how cybersecurity exposes the fragility of State power, unable to exert full control over cyberspace; (ii) the emergence and effectiveness of supranational responses at EU level; and (iii) how EU Member States are responding to this crisis. Thus, since the early 2000s, the EU has sought to enhance common resilience and security in cyberspace. Yet, national security remains an exclusive competence of Member States. The result is a (dys)functional dualism whereby the EU fosters regulatory and technical integration through its internal market competences, while States retain exclusive authority over national security. This hybrid arrangement highlights a deep legal-institutional tension and a new vulnerability in Europe’s cybersecurity governance, prompting a reconsideration of how sovereignty, coercion, and legality are being redefined in cyberspace.| File | Dimensione | Formato | |
|---|---|---|---|
|
JG-2026-1-Chiara.pdf
accesso aperto
Tipo:
Versione (PDF) editoriale / Version Of Record
Licenza:
Licenza per Accesso Aperto. Creative Commons Attribuzione (CCBY)
Dimensione
295.44 kB
Formato
Adobe PDF
|
295.44 kB | Adobe PDF | Visualizza/Apri |
I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.



