English   Danish

2026/2027  KAN-CDIBO1203U  Cyber Security, Regulation, and Policy in Digital Business

English Title
Cyber Security, Regulation, and Policy in Digital Business

Course information

Language English
Course ECTS 7.5 ECTS
Type Mandatory
Level Full Degree Master
Duration One Semester
Start time of the course Autumn, Spring
Timetable Course schedule will be posted at calendar.cbs.dk
Study board
Study Board for Digitalisation, Technology and Communication
Programme Master of Science (MSc) in Business Administration and Digital Business
Course coordinator
  • Jan Lemnitzer - Department of Digitalisation (DIGI)
Main academic disciplines
  • Globalisation and international business
  • Information technology
Teaching methods
  • Blended learning
Last updated on 15-06-2026

Relevant links

Learning objectives
At the end of the semester, students should be able to:
  • Analyze the relationship between technology policy, digital business strategy, and geopolitics in contemporary global markets.
  • Evaluate major regulatory approaches to digital platforms, cloud infrastructure, and artificial intelligence, including differences between EU, US, and Chinese governance models.
  • Assess the implications of technology regulation for firms of different sizes, from startups deploying AI systems to global platform companies and cloud providers.
  • Explain the strategic importance of digital sovereignty, including debates concerning dependence on global cloud providers, critical digital infrastructure, and European technology policy.
  • Identify and assess key cybersecurity risks facing organizations, including operational, strategic, regulatory, and supply chain risks.
  • Apply core concepts of cybersecurity governance and risk management to organizational and business contexts.
  • Analyze the geopolitical dimensions of cybersecurity and digital conflict, including cyberwarfare, hybrid warfare, state-sponsored cyber operations, and the role of private technology actors in conflict environments.
  • Critically assess the role of Big Tech companies in global governance and security, including their influence on regulation, digital infrastructure, and international power relations.
  • Communicate complex policy, cybersecurity, and geopolitical issues clearly and professionally to both technical and non-technical stakeholders.
  • Reflect critically on future developments in digital business, cybersecurity, AI governance, and global technology policy, and their implications for organizations and society.
Examination
Cyber Security, Regulation, and Policy in Digital Business:
Exam ECTS 7,5
Examination form Written sit-in exam on CBS' computers
Individual or group exam Individual exam
Assignment type Written assignment
Duration 4 hours
Grading scale 7-point grading scale
Examiner(s) Internal examiner and external examiner
Exam period Summer and Winter
Aids Closed book: no aids
However, at all written sit-in exams the student has access to the basic IT application package (Microsoft Office365 (minus Excel), document camera and paper, 7-zip file manager, Adobe Reader DC, PDF24, Texlive, VLC player, Windows Media Player – ATTENTION no sound allowed), and the student is allowed to bring simple writing and drawing utensils (non-digital). PLEASE NOTE: Students are not allowed to communicate with others during the exam.
Make-up exam/re-exam
Same examination form as the ordinary exam
The number of registered candidates for the make-up examination/re-take examination may warrant that it most appropriately be held as an oral examination. The programme office will inform the students if the make-up examination/re-take examination instead is held as an oral examination including a second examiner or external examiner.
Description of the exam procedure

Students must answer questions relating to tech policy debates and cybersecurity risk management. They will be offered a choice of questions.

Course content, structure and pedagogical approach

Tech policy is no longer niche topic but the key area where the future of digital business and increasingly the future of geopolitics is being decided as we watch. Today’s business leaders need to understand the emergent security, regulatory and policy environments to guide their companies to prosperity in the middle of rapid change. Every business leader needs to understand current politics around platform regulation, Cloud providers and AI regulation. They also need to understand the cyber threats facing their business and ensure that cyber risks are managed professionally. This course is designed to ensure that every graduate of the masters degree has this vital knowledge.

The first part of the course will equip students with the knowledge and tools to analyze the most important political debates about the regulation of tech companies, from gatekeeper rules for the largest platforms to rules about managing high risk AI models that apply to the smallest companies running them. How can Europe ensure its digital sovereignty in business cloud computing, and should be buy it as a premium service from US Big Tech companies? How are the US, the EU and China going about regulating AI, and what approach is the most sensible?

The second part of the course will introduce students to the concepts and tools necessary to understand and assess the cybersecurity risks faced by companies, as well as to the security controls and procedures available to manage this risk. Students will learn how cyber risks are managed professionally, who is affected by the new NIS 2 Directive and why its implementation can be so challenging, and why supply chain cybersecurity is fast becoming a priority in the field.

The final two classes combine both strands by looking at the political side of cybersecurity and its geopolitical implications. One class studies the cyberwar in Ukraine, for example its use of western volunteers in Ukraine’s IT army, the Russian approach to hybrid warfare or the platformization of warfighting as shown in Ukraine’s new Delta platform. The final class will study the geopolitical aspects of a cybersecurity landscape caught between Big Tech’s dominance, the battle between liberal and authoritarian states in UN Cyber norms making and the EU’s attempt to establish a tech environment that is both digitally sovereign and secure.

In this way, the course provides the students with practice-oriented insights while offering reflections on current and future developments in the context of digital business cyber security, regulation, and policy, and the ways in which they will affect tech companies from the smallest to the largest.

Research-based teaching
CBS’ programmes and teaching are research-based. The following types of research-based knowledge and research-like activities are included in this course:
Research-based knowledge
  • Teacher’s own research
  • Models
  • Monitor and assess research developments in the field
Research-like activities
  • Analysis
  • Discussion, critical reflection, modelling
Description of the teaching methods
The course will use pre-recorded online lectures to introduce the subject matter and classroom discussions to explore it in more depth.
The seminars will rely on active learning methods such as simulations and role-play to facilitate a good discussion.
Feedback during the teaching period
Throughout the course students will practice the drafting of exam essays with real or mock questions and receive feedback on their approaches.
Student workload
Lectures 24 hours
Workshops/Classes 24 hours
Reading/Class Preparation 100 hours
Exam preparation 58 hours
Expected literature

The reading for this course will be shared via Canvas. Due to the fast-changing nature of the field, additions and changes will be made throughout the course – these will always be communicated via Canvas. Students do not need to purchase any reading material for this course.

Sample literature:

Mario Marinelli, Digital Economic Policy: The Economics of Digital Markets from a European Union Perspective (OUP 2022)

Shoshana Zuboff, The age of surveillance capitalism: the fight for the human future at the new frontier of power (2019) 

Recent EU legislation such as the Digital Markets Act, Digital Services Act, AI Act, the NIS 2 Directive and the Cyber Resilience Act

Filippo Gualtiero Blancato, 'The cloud sovereignty nexus: How the European Union seeks to reverse strategic dependencies in its digital ecosystem', Policy and Internet (early access 5 September 2023)

Tom Wheeler, The three challenges of AI regulation', Brookings commentary, 15 June 2023 

Matt Shehan, 'China’s AI Regulations and How They Get Made', Carnegie Endowment paper, 10 July 2023

Sean Joyce, Friso Van der Oord, Principles for Board Governance of Cyber Risk, Harvard Law School Forum on Corporate Governance, 10 June 2021

Andrew Phipps, Jason R.C. Nurse, 'Inside ransomware groups: An analysis of their origins, structures, and dynamics', Computers & Security, Volume 160, January 2026.

Iryna Fyshchuk, Mette Strange Noesgaard, Jeppe Agger Nielsen, Managing cyberattacks in wartime: The case of Ukraine, Public Administration Review, Online first 7 November 2024

 

Last updated on 15-06-2026