2026/2027 KAN-CDIBO1203U Cyber Security, Regulation, and Policy in Digital Business
| English Title | |
| Cyber Security, Regulation, and Policy in Digital Business |
Course information |
|
| Language | English |
| Course ECTS | 7.5 ECTS |
| Type | Mandatory |
| Level | Full Degree Master |
| Duration | One Semester |
| Start time of the course | Autumn, Spring |
| Timetable | Course schedule will be posted at calendar.cbs.dk |
| Study board |
Study Board for Digitalisation, Technology and
Communication
|
| Programme | Master of Science (MSc) in Business Administration and Digital Business |
| Course coordinator | |
|
|
| Main academic disciplines | |
|
|
| Teaching methods | |
|
|
| Last updated on 15-06-2026 | |
Relevant links |
| Learning objectives | ||||||||||||||||||||||||
At the end of the semester, students should be
able to:
|
||||||||||||||||||||||||
| Examination | ||||||||||||||||||||||||
|
||||||||||||||||||||||||
| Course content, structure and pedagogical approach | ||||||||||||||||||||||||
|
Tech policy is no longer niche topic but the key area where the future of digital business and increasingly the future of geopolitics is being decided as we watch. Today’s business leaders need to understand the emergent security, regulatory and policy environments to guide their companies to prosperity in the middle of rapid change. Every business leader needs to understand current politics around platform regulation, Cloud providers and AI regulation. They also need to understand the cyber threats facing their business and ensure that cyber risks are managed professionally. This course is designed to ensure that every graduate of the masters degree has this vital knowledge. The first part of the course will equip students with the knowledge and tools to analyze the most important political debates about the regulation of tech companies, from gatekeeper rules for the largest platforms to rules about managing high risk AI models that apply to the smallest companies running them. How can Europe ensure its digital sovereignty in business cloud computing, and should be buy it as a premium service from US Big Tech companies? How are the US, the EU and China going about regulating AI, and what approach is the most sensible? The second part of the course will introduce students to the concepts and tools necessary to understand and assess the cybersecurity risks faced by companies, as well as to the security controls and procedures available to manage this risk. Students will learn how cyber risks are managed professionally, who is affected by the new NIS 2 Directive and why its implementation can be so challenging, and why supply chain cybersecurity is fast becoming a priority in the field. The final two classes combine both strands by looking at the political side of cybersecurity and its geopolitical implications. One class studies the cyberwar in Ukraine, for example its use of western volunteers in Ukraine’s IT army, the Russian approach to hybrid warfare or the platformization of warfighting as shown in Ukraine’s new Delta platform. The final class will study the geopolitical aspects of a cybersecurity landscape caught between Big Tech’s dominance, the battle between liberal and authoritarian states in UN Cyber norms making and the EU’s attempt to establish a tech environment that is both digitally sovereign and secure. In this way, the course provides the students with practice-oriented insights while offering reflections on current and future developments in the context of digital business cyber security, regulation, and policy, and the ways in which they will affect tech companies from the smallest to the largest. |
||||||||||||||||||||||||
| Research-based teaching | ||||||||||||||||||||||||
|
CBS’ programmes and teaching are research-based. The following
types of research-based knowledge and research-like activities are
included in this course:
Research-based knowledge
Research-like activities
|
||||||||||||||||||||||||
| Description of the teaching methods | ||||||||||||||||||||||||
| The course will use pre-recorded online lectures
to introduce the subject matter and classroom discussions to
explore it in more depth.
The seminars will rely on active learning methods such as simulations and role-play to facilitate a good discussion. |
||||||||||||||||||||||||
| Feedback during the teaching period | ||||||||||||||||||||||||
| Throughout the course students will practice the drafting of exam essays with real or mock questions and receive feedback on their approaches. | ||||||||||||||||||||||||
| Student workload | ||||||||||||||||||||||||
|
||||||||||||||||||||||||
| Expected literature | ||||||||||||||||||||||||
|
The reading for this course will be shared via Canvas. Due to the fast-changing nature of the field, additions and changes will be made throughout the course – these will always be communicated via Canvas. Students do not need to purchase any reading material for this course. Sample literature: Mario Marinelli, Digital Economic Policy: The Economics of Digital Markets from a European Union Perspective (OUP 2022) Shoshana Zuboff, The age of surveillance capitalism: the fight for the human future at the new frontier of power (2019) Recent EU legislation such as the Digital Markets Act, Digital Services Act, AI Act, the NIS 2 Directive and the Cyber Resilience Act Filippo Gualtiero Blancato, 'The cloud sovereignty nexus: How the European Union seeks to reverse strategic dependencies in its digital ecosystem', Policy and Internet (early access 5 September 2023) Tom Wheeler, The three challenges of AI regulation', Brookings commentary, 15 June 2023 Matt Shehan, 'China’s AI Regulations and How They Get Made', Carnegie Endowment paper, 10 July 2023 Sean Joyce, Friso Van der Oord, Principles for Board Governance of Cyber Risk, Harvard Law School Forum on Corporate Governance, 10 June 2021 Andrew Phipps, Jason R.C. Nurse, 'Inside ransomware groups: An analysis of their origins, structures, and dynamics', Computers & Security, Volume 160, January 2026. Iryna Fyshchuk, Mette Strange Noesgaard, Jeppe Agger Nielsen, Managing cyberattacks in wartime: The case of Ukraine, Public Administration Review, Online first 7 November 2024
|
||||||||||||||||||||||||