CSE Connect Final Year Impact Projects for 2026-2027
Practical Cyber and Digital Resilience for Small and Medium-sized Enterprises (SMEs)
About the 2026-27 project
There are eight themes, and each forms the basis of a final year project carried out for a client.
Projects run from 12 October 2026 to 31 March 2027, spanning both terms of your final year. Students from universities across the UK take part.
You work as part of a national team while delivering an individual project artefact.
Your own university supervises and marks your project, against its own criteria, in the usual way.
CSE Connect is the client, providing the brief, the resources, the environment you work in, and access to people working in the field.
How this experience will benefit you
Deliver an artefact/deploy a solution that meets a real-world use case, held in a repository you can show to an employer.
Work to a brief set by industry (supported by government) and explain your decisions directly to key stakeholders.
Present your completed work to an audience that includes attendees from government, industry and academia.
Join a networked community of students at universities across the UK. Enhance teamworking and communication skills.
Develop authentic STARR stories, covering situation, task, action, result and reflection, that you can use to describe work-aligned experiences beyond your degree.
How you will be supported
You are not expected to start a project with expertise or knowledge of the resilience domain. You will learn about it as you work on the project.
The project opens with a session where the work is explained, and you can see what previous students produced for last year’s projects.
Practitioners working in the field join at intervals during the year and you can put questions to them.
The systems you test against are authorised, built and provided for you.
Why SMEs are an interesting case
Consider a games studio of six people whose game is already on sale to the public while still in development. Its work depends on a code repository and build pipeline that push updates to players every few weeks, a public website with player accounts and a community forum, a cloud accounting package, and a shared drive holding contracts and design documents.
One of the six employees looks after the computers and the build server, and has unofficial responsibility for cyber security, alongside a full-time role as a developer.
A large employer facing the same risks has a security team, a budget for the work and a contract with a supplier who handles it. The studio owes the same duty to the players whose accounts and personal data it holds, because data protection law attaches its obligations to the data an organisation holds rather than to the number of people it employs.
The SME Challenge?
5.5 million
SMEs in the UK, according to the National Cyber Security Centre [1]
As likely to be attacked as larger organisations. [1]
Free guidance already exists for them. The difficulty is the time, money and expertise needed to act on it. [2]
The eight project themes will explore this challenge.
How the eight project themes fit together [3]
- Anticipating what could go wrong
- Detecting when something has happened
- Responding to an incident
- Restoring the business to working order
- Confirming the remedy has been applied and continues to hold
Each project is individual and has its own outcome.
You can complete your work without waiting for another student to complete theirs.
The Eight Project Themes
-
A Closer Look at Project Themes (1-4)
You build a pipeline that runs the scanner on a schedule and uses a model to triage the results. The pipeline removes duplicates and false positives, and ranks what remains by the cost to the studio of leaving each one unfixed. [6]
-
A Closer Look at Project Themes (1-4)
You build the monitoring that watches the services the studio depends on, the alert that reaches the person able to act on it, and the notification that goes to players.
-
A Closer Look at Project Themes (1-4)
You build an automated runbook that handles one class of incident, from the first alert through to the service being restored. You then measure recovery time with the runbook and without it. [3]
-
A Closer Look at Project Themes (5-8)
You build the automation that carries the maintenance and support load of a one-person software project, from verifying and applying updates to triaging what the client sends in, and the controls that bound it. [6]
-
A Closer Look at Project Themes (5-8)
You build an application that records which suppliers and services a small organisation depends on, and what stops working when any one of them becomes unavailable. It turns that map into an ordered recovery list. [3]
-
A Closer Look at Project Themes (5-8)
You build a self-assessment that an owner completes without help, producing a prioritised risk register and an investment case that sets the cost of each recommended control against the loss it is meant to avoid. [1]
-
A Closer Look at Project Themes (5-8)
You build a self-running exercise that a small organisation can complete without a facilitator, together with the communication pack it tests, covering who decides, who is told, in what order, and what is said. [2]
What we are looking for
We are looking for students who are reliable, are willing to take ownership of their work, and are curious about learning new subjects and new skills.
How to apply
- Applications close at 23:59 on 2 October 2026.
- Apply at https://forms.cloud.microsoft/e/sfWuBis8JF
- Questions to innovate@cseconnect.org
- The project begins on 12 October 2026.
References
- [1]National Cyber Security Centre, "Cyber Action Toolkit: breaking down the barriers to resilience," 11 Nov. 2025. https://www.ncsc.gov.uk/blog-post/cat-breaking-down-resilience-barriers
- [2]National Cyber Security Centre, "Exercise in a Box." https://www.ncsc.gov.uk/section/exercise-in-a-box/overview
- [3]National Cyber Security Centre, "When cyber attacks happen: helping organisations recover," 28 Jul. 2026. https://www.ncsc.gov.uk/blogs/when-cyber-attacks-happen-helping-organisations-recover
- [4]P. Haigh and Harry G, National Cyber Security Centre, "Cyber Shield: The path to an agentic AI future for cyber defence," 7 Jul. 2026. https://www.ncsc.gov.uk/blogs/cyber-shield-the-path-to-an-agentic-ai-future-for-cyber-defence
- [5]National Cyber Security Centre, "Thinking carefully before adopting agentic AI," 15 May 2026. https://www.ncsc.gov.uk/blogs/thinking-carefully-before-adopting-agentic-ai
- [6]O. Whitehouse, National Cyber Security Centre, "Preparing for a 'vulnerability patch wave'," 1 May 2026. https://www.ncsc.gov.uk/blogs/prepare-for-vulnerability-patch-wave
- [7]National Cyber Security Centre, "Retaining defensive advantage in the age of frontier AI cyber capabilities," 15 Apr. 2026. https://www.ncsc.gov.uk/blogs/retaining-defensive-advantage-in-the-age-of-frontier-ai-cyber-capabilities
- [8]Toby W, National Cyber Security Centre, "Managing the cyber risk of agentic AI," 20 Aug. 2026. https://www.ncsc.gov.uk/blogs/managing-the-cyber-risk-of-agentic-ai