نوع مقاله : مقاله پژوهشی
عنوان مقاله English
1. Introduction
In the twenty-first century, cyberspace has emerged as one of the most critical arenas of national and international power. This domain simultaneously offers vast opportunities for economic, cultural, scientific, and diplomatic development while posing serious threats to national security, social cohesion, cultural identity, and political independence of nations. For the Islamic Republic of Iran, which operates in a complex geopolitical environment, faces extensive international sanctions, and is continually targeted by hybrid operations, cognitive warfare, organized cyberattacks, and foreign media-informational campaigns, strategic management of cyberspace is no longer merely a technical or cultural issue; rather, it constitutes a dual strategic imperative. First, ensuring the sustainability of national security against cyber threats, informational infiltration, and soft warfare; second, intelligently harnessing the potential of this space to enhance soft power, improve the country's global image, and advance diplomatic objectives through digital diplomacy. Despite numerous policy-making efforts in recent years, a persistent gap remains: the absence of an integrated strategic model capable of pursuing these two overarching goals in a synergistic manner. Many prior approaches have been either excessively security-oriented and restrictive or entirely open and inattentive to hybrid threats. The present study aims to address this theoretical and practical lacuna by developing an indigenous, multidimensional model for cyberspace governance in Iran that establishes a dynamic balance between security imperatives and opportunity creation.
2. Theoretical Framework
The theoretical framework of this study conceptualizes cyberspace as a multidimensional arena for redefining power, identity, security, and international interactions. Accordingly, an integrated framework is developed based on three complementary theoretical pillars: Cyber Governance Theory, Securitization Theory, and Soft Power and Digital Diplomacy Theory. Cyber Governance Theory provides the structural and institutional perspective, emphasizing the need to strengthen domestic infrastructures, establish integrated governance structures, enhance media literacy and cognitive resilience, and participate strategically in global cyber governance (Alkan, 2012; Fischerkeller et al., 2022). Securitization Theory explains how cyberspace is constructed as a security issue through threat-oriented discourse and how excessive securitization may lead to restrictive policies, international isolation, and weakened soft power (Buzan, Wæver & de Wilde, 1998; Betz, 2017; Lehto, 2022). Finally, Soft Power and Digital Diplomacy Theory highlights cyberspace as an arena for attraction, cultural influence, international image-building, diplomatic interaction, and trust-building (Nye, 2004; Bjola & Holmes, 2015; Maurer, 2020). Together, these dimensions provide the theoretical basis for simultaneously strengthening national security and sustainable international relations.
3. Methodology
This applied research employed a mixed-methods sequential exploratory design (qualitative followed by quantitative). In the qualitative phase, data were collected through semi-structured interviews with 15 senior managers and policymakers from the fields of national security, information technology, media, and international relations. Additionally, Delphi sessions and focused group discussions (FGD) were conducted with 15 other experts and specialists. Qualitative data were analyzed using thematic content analysis and systematic coding (open, axial, and selective). In the quantitative phase, the classic SWOT framework was utilized to identify and categorize internal factors (strengths and weaknesses) and external factors (opportunities and threats). Subsequently, the strategies derived from the qualitative phase were prioritized using the Quantitative Strategic Planning Matrix (QSPM) based on attractiveness scores. Instrument validity was confirmed through expert content evaluation, and reliability was established via Cronbach's alpha (≥ 0.7).
4. Results & Discussion
Internal environmental analysis revealed that Iran's cyberspace governance possesses notable strengths: highly skilled and experienced human resources in cybersecurity, relatively resilient security infrastructure, active monitoring systems, secure data centers, and proven success in managing and containing domestic cyber crises. Nevertheless, deep structural weaknesses limit the full exploitation of these strengths: a historically negative and predominantly threat-centric perception of cyberspace, the absence of a unified management structure and weak inter-institutional coordination, legal gaps and fragmented policymaking, heavy dependence on foreign technology and software, and—most critically—significant deficiencies in public digital and media literacy as well as a shortage of attractive, competitive, nationally identity-based content.
Externally, substantial opportunities were identified: prospects for expanding international and regional cooperation in cybersecurity, rapid growth of the digital economy and online services, advancement of e-government, high domestic innovation capacity and knowledge-based enterprises, and the potential to leverage emerging technologies (particularly artificial intelligence) in cybersecurity. In contrast, external threats were assessed as highly serious: organized cyberattacks by state and non-state actors, digital espionage and sabotage operations, extensive information warfare, infiltration and incitement via social networks, and the spillover of geopolitical and political tensions into the cyber domain. The results of the Internal Factors Evaluation (IFE = 3.91) and External Factors Evaluation (EFE = 3.55) matrices indicate that the overall factor scores exceed the average (2.5), signifying that strengths and opportunities collectively outweigh weaknesses and threats, thereby creating favorable conditions for adopting development-oriented and offensive strategies rather than purely defensive ones.
5. Conclusions & Suggestions
Based on the prioritization conducted via the QSPM matrix, the strategies with the highest attractiveness scores were determined as follows:
1. Maximizing the utilization of existing specialized human capital for dual purposes: widespread education in digital literacy and cybersecurity across societal levels and managerial cadres, and fostering educational, research, and experiential exchange collaborations with aligned countries and international organizations.
2. Transforming successful experiences in managing domestic cyber crises into a driving force for indigenous technology development and gradual reduction of dependence on foreign suppliers.
3. Systematically enhancing awareness, security skills, and digital literacy among users, organizations, and policymakers.
4. Strengthening predictive, preventive, and rapid-response capabilities against external cyberattacks by leveraging existing specialized expertise.
5. Improving macro-level crisis management to mitigate the adverse impacts of political and geopolitical tensions on cybersecurity and national social stability.
The proposed model rests on three synergistic pillars:
1. Technical pillar: secure infrastructure, indigenous technology, advanced warning and monitoring systems;
2. Cognitive pillar: high media and digital literacy, societal cognitive resilience against soft warfare and misinformation;
3. Cultural-diplomatic pillar: production of attractive and credible content rooted in national-Islamic identity, proactive digital diplomacy, and intelligent participation in global internet governance discourses.
کلیدواژهها English