← All thesis proposals
Society & decisions · D5 · Spring 2027

Cyber risks in municipal services

Build a tool that connects IT incidents to affected services, or study how different roles prioritise risks.

Bachelor’sMaster’sProposal
Download brief ↓
Societal decision-support concept: Protect the services people need
Concept illustration · AI-generated
ONE TOPIC. TWO POSSIBLE APPROACHES.

Choose your track

Your choice is remembered in this browser.

The lists below describe what your thesis may include. Agree a feasible selection for one track, rather than completing both.

Choose one track. Master’s proposals target Spring 2027. Final scope and programme approval are agreed with the supervisor; bachelor scopes are suggested adaptations.

TRACK 01 · IMPLEMENTATION INCLUDED

Technical track

Develop a working solution and test whether it addresses the problem.

Possible research question

Can service-dependency context and interpretable risk estimates improve municipal cyber-risk prioritisation?

Suggested tasks

  • Read research on municipal cyber-risk prioritisation and compare existing solutions.
  • Identify one problem faced by municipal IT and service owners.
  • Write a research question and define what the solution should do.
  • Create a fictional list of municipal services, their IT systems and the connections between them.
  • Build a view that explains which services an IT incident could affect and helps staff prioritise a response.
  • Compare it with a list ranked only by technical risk scores. Study how users understand and explain their priorities.
  • Explain what worked, what did not, and how the results compare with earlier research.
Evaluation, degree scope and deliverables

Study and evaluation

Compare the implemented solution with a technical-score-only risk queue. Combine reproducible technical tests with an appropriate empirical evaluation.

  • Scenario-based prioritisation accuracy
  • Time to identify affected services
  • Understanding of uncertainty and dependencies

Degree scope

Bachelor’s

Build a service map with incident overlays and an explainable priority rule. Test dependency traversal and prioritisation tasks.

Master’s

Compare service-aware and score-only decisions using controlled incident scenarios and domain-reviewed consequences.

Background

  • Programming
  • Networking or cybersecurity
  • Graph modelling

Possible deliverables

  • A focused literature review, justified problem and research question
  • A working prototype with source code and setup instructions
  • A reproducible comparison and an appropriate study of use
  • A report explaining design lessons, results and limitations
TRACK 02 · NO IMPLEMENTATION REQUIRED

Non-technical track

Study existing systems, information or work practices. You do not need to develop software.

Possible research question

How does service context affect the way municipal stakeholders understand and prioritise cyber risks?

Suggested tasks

  • Read earlier studies of municipal cyber-risk prioritisation.
  • Choose one problem and write a research question the study can answer.
  • Map which roles own technical risks and the services affected by them.
  • Discuss fictional incidents with IT staff and service owners using existing risk reports.
  • Compare how each role explains priorities, dependencies and acceptable response trade-offs.
  • Analyse the interviews, observations or documents using a clearly described method. Look for disagreements as well as common patterns.
  • Explain the findings, compare them with earlier research and suggest practical improvements.
Evaluation, degree scope and deliverables

Study and evaluation

Use a bounded empirical study of municipal cyber-risk prioritisation. Justify case selection, recruitment and the analysis method. Distinguish observed behaviour from participants’ perceptions; use triangulation or a comparison where it serves the research question.

  • Differences in risk interpretation across roles
  • Governance and communication needs for service-aware prioritisation
  • Evidence for the findings, conflicting cases and limits of the study

Degree scope

Bachelor’s

Study one case or a small set of existing materials. Agree the interviews, documents or scenario tasks with the supervisor. Describe the method, analyse the findings and give practical recommendations.

Master’s

Use a clear research question and relevant IS theory. Justify the cases, participants and analysis method. Explain what the findings add to earlier research and where they may apply. No software development is required.

Background

  • Literature review and academic writing
  • Qualitative or quantitative research methods
  • Interest in municipal cyber-risk prioritisation; no programming prerequisite

Possible deliverables

  • A literature review and research question
  • A study plan and approved research material
  • An analysis supported by interviews, observations, documents or scenario results
  • A thesis with findings, recommendations and limitations

Scope and access

Use fictional infrastructure and labelled scenarios. The prototype does not assess or attack a live municipal network. These implementation-related limits apply when developing or testing a technical solution. For a non-technical study, agree access to participants or existing materials early, use approved or fictional cases where appropriate, and distinguish perceptions from observed outcomes.

Agree access to data, participants or existing materials and any required ethics or privacy review before committing. A non-technical track needs a systematic study, not a working prototype.

Full academic proposal

Working topic

Explainable Cyber-Risk Prioritisation for Municipal Services

Brief outline

This proposal examines municipal cyber-risk prioritisation in the work and information needs of municipal IT and service owners. The technical track combines a literature review and justified gap with requirements, design, implementation and evaluation of a bounded solution. The non-technical track investigates practices, experiences or organisational conditions through a systematic study of existing systems, documents or scenarios, without requiring implementation. Choose one track and agree the final research question, degree scope and contribution with the supervisor.

Programme fit

Information Systems. These are suggested research approaches, not a statement of confirmed programme policy. Agree the final title, track, degree scope and contribution with the supervisor and programme.

Shared research foundation

Review the literature; identify and justify a gap; formulate research questions; conduct a systematic study; analyse the evidence; explain the contribution relative to prior research and discuss limitations. The technical track additionally includes requirements, design, implementation and evaluation of an artifact.