Who Coordinates U.S. Cyber Defense? A Co-Authorship Network Analysis of Joint Cybersecurity Advisories (2024--2025)
M. Abdullah Canbaz, Hakan Otal, Tugce Unlu, Nour Alhussein, Brian Nussbaum
TL;DR
The paper addresses how U.S. cyber defense coordination emerges from cross-agency collaboration in Joint Cybersecurity Advisories (CSAs) by constructing a co-authorship network from nine CSAs (Nov 2024–Aug 2025). It builds an undirected, weighted graph with 41 agencies and 442 ties, treating each CSA's signatories as a clique and computing metrics such as $D$, $W$, $B$, $C$, $Q$, and $k$-core to map structural roles. Key findings show a hub-centric, small-world topology anchored by CISA and FBI, with NSA, ASD-ACSC, and NCSC-UK acting as brokers and a dense inner core (22-core) that supports resilience; however, the network is vulnerable to disruption of these central hubs. The study contributes a replicable dataset and network-analysis approach for understanding跨-border cybersecurity coordination and offers policy guidance on surge playbooks, strengthening secondary bridges, and sector-specific collaboration, while proposing extensions to dynamic, predictive network models for proactive defense planning.
Abstract
Cyber threats increasingly demand joint responses, yet the organizational dynamics behind multi-agency cybersecurity collaboration remain poorly understood. Understanding who leads, who bridges, and how agencies coordinate is critical for strengthening both U.S. homeland security and allied defense efforts. In this study, we construct a co-authorship network from nine Joint Cybersecurity Advisories (CSAs) issued between November 2024 and August 2025. We map 41 agencies and 442 co-authoring ties to analyze the structure of collaboration. We find a tightly knit U.S. triad -- CISA, FBI, and NSA -- densely connected with Five Eyes and select European allies. Degree centrality identifies CISA and FBI as coordination hubs, while betweenness highlights NSA, the UK's NCSC, and Australia's ASD-ACSC as key bridges linking otherwise fragmented clusters. By releasing the first replicable dataset and network analysis of CSAs, we provide new empirical evidence on how collaborative cybersecurity signals are organized and where strategic influence is concentrated.
