Build a contextual incident dashboard for labelled laboratory events. Test whether users can trace an alert to the affected device and service.
Security alerts for medical devices
Build a tool for reviewing device alerts, or study how healthcare IT staff prioritise incidents.

Choose your track
Your choice is remembered in this browser.
The lists below describe what your thesis may include. Agree a feasible selection for one track, rather than completing both.
Choose one track. Master’s proposals target Spring 2027. Final scope and programme approval are agreed with the supervisor; bachelor scopes are suggested adaptations.
Technical track
Develop a working solution and test whether it addresses the problem.
How can explainable anomaly detection support incident prioritisation without unnecessary disruption to healthcare services?
Suggested tasks
- Read research on healthcare device incident response and compare existing solutions.
- Identify one problem faced by healthcare IT staff.
- Write a research question and define what the solution should do.
- Create a controlled lab dataset of medical-device network activity and fictional security incidents.
- Build an alert screen showing the evidence, affected device and possible service impact. Keep response decisions with the user.
- Compare it with a list of security scores. Measure detection errors and how well users explain their response choices.
- Explain what worked, what did not, and how the results compare with earlier research.
Evaluation, degree scope and deliverables
Study and evaluation
Compare the implemented solution with a conventional score-based security alert queue. Combine reproducible technical tests with an appropriate empirical evaluation.
- Detection performance and false positives
- Prioritisation accuracy and investigation time
- Inappropriate disruption recommendations
Degree scope
Compare score-only and explanation-plus-context interfaces on controlled triage tasks, using an unchanged detector.
Background
- Programming
- Networking and basic cybersecurity
- Introductory machine learning
Possible deliverables
- A focused literature review, justified problem and research question
- A working prototype with source code and setup instructions
- A reproducible comparison and an appropriate study of use
- A report explaining design lessons, results and limitations
Non-technical track
Study existing systems, information or work practices. You do not need to develop software.
How do healthcare IT staff translate security alerts into operational priorities and proportionate response decisions?
Suggested tasks
- Read earlier studies of healthcare device incident response.
- Choose one problem and write a research question the study can answer.
- Interview incident responders about balancing security concerns with continuity of care.
- Run tabletop discussions using authorised, fictional device incidents and existing alert examples.
- Map how technical evidence, service context and uncertainty influence escalation and responsibility.
- Analyse the interviews, observations or documents using a clearly described method. Look for disagreements as well as common patterns.
- Explain the findings, compare them with earlier research and suggest practical improvements.
Evaluation, degree scope and deliverables
Study and evaluation
Use a bounded empirical study of healthcare device incident response. Justify case selection, recruitment and the analysis method. Distinguish observed behaviour from participants’ perceptions; use triangulation or a comparison where it serves the research question.
- Reasoning behind incident priorities and response choices
- Coordination and accountability across clinical and IT roles
- Evidence for the findings, conflicting cases and limits of the study
Degree scope
Study one case or a small set of existing materials. Agree the interviews, documents or scenario tasks with the supervisor. Describe the method, analyse the findings and give practical recommendations.
Use a clear research question and relevant IS theory. Justify the cases, participants and analysis method. Explain what the findings add to earlier research and where they may apply. No software development is required.
Background
- Literature review and academic writing
- Qualitative or quantitative research methods
- Interest in healthcare device incident response; no programming prerequisite
Possible deliverables
- A literature review and research question
- A study plan and approved research material
- An analysis supported by interviews, observations, documents or scenario results
- A thesis with findings, recommendations and limitations
Scope and access
Use an isolated, authorised lab. Do not connect to a hospital network or automatically disconnect devices. These implementation-related limits apply when developing or testing a technical solution. For a non-technical study, agree access to participants or existing materials early, use approved or fictional cases where appropriate, and distinguish perceptions from observed outcomes.
Agree access to data, participants or existing materials and any required ethics or privacy review before committing. A non-technical track needs a systematic study, not a working prototype.
Full academic proposal
Working topic
From Medical-Device Security Alerts to Actionable Incident Decisions
Brief outline
This proposal examines healthcare device incident response in the work and information needs of healthcare IT staff. The technical track combines a literature review and justified gap with requirements, design, implementation and evaluation of a bounded solution. The non-technical track investigates practices, experiences or organisational conditions through a systematic study of existing systems, documents or scenarios, without requiring implementation. Choose one track and agree the final research question, degree scope and contribution with the supervisor.
Programme fit
Information Systems. These are suggested research approaches, not a statement of confirmed programme policy. Agree the final title, track, degree scope and contribution with the supervisor and programme.
Shared research foundation
Review the literature; identify and justify a gap; formulate research questions; conduct a systematic study; analyse the evidence; explain the contribution relative to prior research and discuss limitations. The technical track additionally includes requirements, design, implementation and evaluation of an artifact.


