Search
Browse By Day
Browse By Time
Browse By Person
Browse By Policy Area
Browse By Session Type
Browse By Keyword
Browse Artificial Intelligence Presentations
Program Calendar
Sign In
Search Tips
Cybercrime policy is often debated at the federal level, but many of the legal, administrative, and enforcement choices that shape prevention occur in states. This paper asks whether state cybercrime legislation and enforcement capacity are associated with measurable deterrence of cybercrime, and whether deterrence differs across types of attacks and affected sectors. The question fits a federalism problem: if states vary in legal authority, institutional capacity, political alignment, economic resources, technology capacity, and AI adoption in cybersecurity, then cybercrime risk may also vary in ways that matter for public policy and critical services.
I conduct an empirical state-level analysis using two cybercrime datasets. The first is a ransomware dataset from Comparitech, which identifies incidents and affected sectors; the second is a Distributed Denial of Service attack dataset from the Center for Applied Internet Data Analysis. I analyze ransomware and DDoS outcomes separately because they reflect different forms of cyber harm and may respond differently to state policy. The models include controls for institutional capacity, demographics, political alignment, state economic conditions, technological capacity, and state-level integration of AI into cybersecurity practice. I draw state-level covariates from FRED, BLS, BEA, and PUMS sources to account for variation in economic structure, labor-market conditions, population composition, and broader state capacity.
Preliminary results show that cybercrime exposure is uneven across states and sectors. Ransomware incidents affecting health care and other important public-service sectors reveal that cybercrime is not only a private technology problem; it also creates risks for service continuity, public administration, and citizen well-being. The findings suggest that states with deeper institutional capacity and stronger enforcement mechanisms show better deterrence-related outcomes than states with weaker administrative and enforcement capacity. Deterrence depends on whether states can translate law into credible enforcement, organizational readiness, and sector-specific protection.
The paper advances public policy research by framing cybercrime deterrence as a problem of state capacity and federalism. Its implications are direct for policymakers: improving state cyber governance requires not only adopting legal tools but also strengthening enforcement institutions, cyber workforce capacity, data systems, and AI governance in cybersecurity.