A cybersecurity dissertation topic is only as strong as the dataset behind it — a compelling research question with no accessible data to test it against stalls by week six. Below are 35 topics across eight sub-areas, each paired with a publicly accessible dataset or source UK undergraduates can actually reach.
Why Does the Dataset Matter More Than the Topic Here?
Cybersecurity is one of the few undergraduate fields where the field’s own major public datasets (intrusion-detection traffic captures, malware sample repositories, phishing corpora) are built specifically for machine-learning and analysis research, which means a well-chosen topic can be genuinely novel in its analysis even when it reuses an established dataset. The risk runs the other way: a topic that sounds current (a named 2026 threat, a specific breach) but has no accessible underlying data behind it is unworkable inside an undergraduate timeline. Check dataset access before you commit to a topic, not after.
| Sub-area | Example research question | Named dataset/source |
|---|---|---|
| Network intrusion detection | Which machine-learning classifier best detects DDoS traffic in a labelled network capture? | CICIDS2017/2018 (Canadian Institute for Cybersecurity, University of New Brunswick) — publicly available labelled network traffic |
| Network intrusion detection | How does feature selection affect intrusion-detection accuracy on older vs newer traffic captures? | NSL-KDD — a widely used, publicly available refined version of the KDD Cup 1999 intrusion dataset |
| Network intrusion detection | How well do intrusion-detection models trained on one dataset generalise to another? | UNSW-NB15 (University of New South Wales) — publicly available labelled network traffic dataset |
| Malware analysis | What static features best distinguish malware families in a public sample set? | VirusShare / VirusTotal public feeds — publicly accessible malware sample and analysis repositories (institutional access/registration may be required) |
| Phishing and social engineering | Which URL or content features most reliably flag phishing sites in a labelled dataset? | Public phishing URL datasets hosted on Kaggle and PhishTank — openly accessible, community-maintained |
| Human factors | What UK survey evidence exists on staff susceptibility to phishing in SMEs? | DSIT/Home Office UK Cyber Security Breaches Survey (annual, most recent edition released 30 April 2026) |
| UK policy and breach trends | How has the reported prevalence of UK business cyber breaches changed year on year? | DSIT/Home Office UK Cyber Security Breaches Survey time series |
| Data protection/privacy | What do published ICO enforcement actions reveal about the most common UK data-breach causes? | Information Commissioner’s Office (ICO) published enforcement and breach report data — free, public |
| Cloud security | How effective are open-source configuration scanners at catching common cloud misconfigurations? | Open-source benchmark configurations (e.g. CIS Benchmarks) tested against a self-built cloud lab environment |
| IoT security | What authentication weaknesses are common across a sample of consumer IoT device firmware? | Publicly documented IoT vulnerability databases (e.g. NVD/CVE entries filtered for IoT-class devices) |
| Cryptography | How does a named post-quantum algorithm’s performance compare to a classical equivalent in a benchmark test? | NIST’s published post-quantum cryptography standardisation materials and reference implementations |
| AI and security | Can adversarial examples reliably fool a publicly available image classifier? | Standard public benchmark image datasets combined with open adversarial-attack toolkits |

35 Topics, Grouped by Sub-Area
Network Security and Intrusion Detection (1–6)
- Comparing supervised classifiers for DDoS detection on a labelled traffic dataset.
- Evaluating feature-selection methods for intrusion detection across CICIDS2017 vs NSL-KDD.
- Testing cross-dataset generalisation of intrusion-detection models (train on one, test on another).
- Investigating class-imbalance handling techniques for rare attack types in network traffic data.
- Comparing signature-based and anomaly-based detection approaches on the same traffic capture.
- Assessing the real-time feasibility of a chosen detection model against its offline accuracy.
Malware Analysis (7–11)
- Comparing static vs dynamic analysis features for malware family classification.
- Evaluating the resilience of a classifier to obfuscated malware samples.
- Building and testing a lightweight malware-detection model suited to resource-constrained devices.
- Investigating ransomware behavioural patterns using publicly documented sample analyses.
- Comparing open-source antivirus engine detection rates on a public sample set (via VirusTotal’s aggregated results).
Phishing and Social Engineering (12–16)
- Identifying the strongest predictive features in a labelled phishing-URL dataset.
- Comparing machine-learning and rule-based phishing detection approaches.
- A survey-based study of UK students’ ability to identify phishing emails.
- Analysing linguistic features common to phishing emails in a public corpus.
- Evaluating browser-based phishing warnings’ effectiveness through a small usability study.
UK Policy, Breach Data and SME Cybersecurity (17–21)
- What the UK Cyber Security Breaches Survey time series shows about SME breach prevalence.
- Comparing reported breach types across business size bands in the UK survey data.
- A documentary analysis of published ICO enforcement notices and their common root causes.
- Evaluating UK SMEs’ stated cybersecurity investment against survey-reported incident rates.
- How NCSC guidance for small organisations maps onto commonly reported breach types.
Cloud and Infrastructure Security (22–25)
- Auditing common cloud storage misconfigurations against a published benchmark.
- Comparing open-source cloud security scanning tools on a self-built test environment.
- Evaluating identity and access management misconfiguration risks in a lab-based cloud setup.
- Investigating container security scanning tools against known vulnerable images.
IoT and Embedded Security (26–28)
- A vulnerability audit of consumer IoT device authentication mechanisms using published CVE data.
- Comparing firmware update practices across a sample of consumer IoT device vendors.
- Evaluating network segmentation as a mitigation for compromised IoT devices in a lab environment.
Cryptography and Post-Quantum Security (29–31)
- Benchmarking a NIST-selected post-quantum algorithm against a classical equivalent.
- Investigating the practical implementation overhead of post-quantum cryptography on constrained devices.
- Comparing key-exchange protocol performance under simulated network latency.
AI, Adversarial Security and Emerging Topics (32–35)
- Testing the robustness of a public image classifier to adversarial perturbation.
- Evaluating a large language model’s susceptibility to prompt-injection attacks in a controlled test.
- Investigating data-poisoning attacks on a small, self-trained classifier.
- A comparative review of AI-assisted threat-detection tools’ claimed capabilities against independently published evaluations.

How Is a Cybersecurity Dissertation Different From a General Computer Science One?
Cybersecurity sits inside computer science departmentally at most UK universities, but the topics above differ from a general CS dissertation in a specific way: the evaluation criteria a cybersecurity dissertation is marked against usually include a threat model and an explicit discussion of real-world attacker capability, not just technical correctness. A general CS dissertation on a classifier might be marked purely on accuracy and methodology; a cybersecurity dissertation using the same classifier for, say, intrusion detection is also expected to discuss what an adversary could do to evade it, and what the false-negative rate actually costs an organisation in practice. Keep this framing explicit in your introduction and discussion chapters regardless of which of the 35 topics above you choose. Our full worked example of a computer science dissertation shows the wider chapter-by-chapter shape a cybersecurity project will still largely follow, even with this different evaluation lens.
How Do I Narrow One of These to a Testable Question?
Every topic above is a starting point, not a finished research question. Narrow it the same way any dissertation topic gets narrowed: name the specific dataset, the specific comparison or metric, and the specific scope (which attack types, which time period, which sample). “Comparing supervised classifiers for DDoS detection” becomes testable as: “Which of three supervised classifiers (Random Forest, SVM, and a neural network) achieves the highest F1-score for DDoS detection on the CICIDS2018 dataset?” — named dataset, named methods, named metric. Write this narrowed version down before you approach your supervisor; a topic proposal with the dataset, comparison and metric already named moves through approval faster than one still phrased as a general area of interest.
What Tools Will I Actually Need to Run These Analyses?
Most of the machine-learning-based topics above are workable in Python with open-source libraries (scikit-learn, pandas), which is free and the same practical route covered in our guide to the tool stack for a computer science dissertation. Lab-based cloud, IoT and network topics need whatever virtualisation or lab environment your department provides — confirm this access before finalising your proposal, and if your topic instead compares against your own prior placement or project experience, our guide to turning a placement year into your dissertation covers that route specifically.
What Access Do I Actually Need?
Most of the network-traffic and malware datasets above are publicly downloadable with registration but no fee; some malware repositories require an institutional or research-affiliation email for full sample access — check this before committing a topic to one specifically. The UK Cyber Security Breaches Survey and ICO enforcement data are entirely free and open, published under UK government licensing. Where a topic proposes a lab-based cloud, IoT or network environment, confirm your department can provide the lab access or virtual environment the design assumes before your proposal is finalised. Any topic involving real participants (phishing-susceptibility surveys, usability studies) needs the same departmental ethics approval as any other primary study — see our general guide to whether you need ethics approval for an undergraduate dissertation before assuming a technical topic is automatically exempt.
What Mistakes Cost the Most Marks Here?
- Choosing a topic with no accessible dataset behind it. A compelling-sounding 2026 threat with no public data is unworkable inside an undergraduate timeline.
- Treating an aging dataset as current. NSL-KDD and similar older datasets are still legitimate for methodological comparison work, but state their age and limitations explicitly rather than presenting findings as reflecting today’s threat landscape.
- Overclaiming from a small lab-based test. A misconfiguration audit run against one self-built environment supports a scoped claim about that environment, not a general claim about “cloud security” as a whole.
- Skipping ethics review for human-subject topics. A phishing-susceptibility survey of real participants still needs departmental ethics approval like any other primary study involving people.
- Citing a dataset without checking its current maintenance status. Some public security datasets are no longer actively updated — check and state this rather than implying a dataset is more current than it is.
- Omitting the threat-model framing a cybersecurity marker specifically expects. A purely technical evaluation with no discussion of attacker capability or real-world cost reads as a general CS project, not a cybersecurity one.
Once your topic and dataset are confirmed, Tesify drafts your dissertation chapters around the design you specify. Everything stays 100% written by you, and it is free to start.
Frequently Asked Questions
Do I need special access to use CICIDS2017 or NSL-KDD?
Both are publicly downloadable, typically with a simple registration; check the current terms on the dataset provider’s own site before building your proposal around either.
Is the UK Cyber Security Breaches Survey free to use?
Yes — it is published by the Department for Science, Innovation and Technology and the Home Office and is freely accessible, including its historical time series.
Can I run a phishing-susceptibility study on real participants?
Yes, but it needs the same departmental ethics approval as any other primary study involving human participants, including informed consent and debriefing.
Are older datasets like NSL-KDD still acceptable for a 2026 dissertation?
Yes for methodological or comparative work, provided you state their age and limitations explicitly rather than presenting findings as representative of the current threat landscape.
Do I need a lab environment for cloud or IoT security topics?
Usually yes, at least a small self-built or virtualised test environment — confirm your department can provide this before finalising a topic that assumes it.
Can I access real malware samples as an undergraduate?
Some public repositories require institutional or research-affiliation registration for full access — check this before committing to a malware-analysis topic specifically.
What makes a cybersecurity dissertation topic too broad?
Any topic naming a general area (“cloud security,” “malware”) without a specific dataset, comparison and metric attached — narrow to what you will actually measure before proposing it.
Is a purely literature-based cybersecurity dissertation acceptable?
Some departments allow a structured comparative review of published evaluations (as in topic 35) as an alternative to a hands-on technical project — check your own department’s expectations before assuming either route is default.
