Quick answer: what governs the Security Governance thesis?
Tampere University’s Security Governance specialisation is a 120 ECTS Master of Administrative Sciences route in the Master’s Programme in Security Management and Politics. The current SGY Security Governance structure allocates 40 ECTS to Master’s Thesis and seminar. The current course that most directly matches that structure is HAL.HATI.399, a 40 ECTS Administrative Sciences seminar-and-thesis course that explicitly contains Security Governance first-year and second-year English seminars in the 2026-2027 teaching schedule.
HAL.HATI.399 uses the general 0-5 course scale. Its thesis-seminar participation component is 10 ECTS and pass/fail, and the course includes a research seminar, an independent scientific thesis, and library information-search training. Students enrol separately in the seminar and information-search component; the administrative independent-study implementations are used for partial-credit recording.
A separate current SAFER.399 Master’s Thesis, 30 ECTS also exists and refers to a Master’s Thesis Seminar labelled SAFS08. This guide does not substitute that route into current Security Governance, because SGY publishes a 40 ECTS thesis-and-seminar allocation and HAL.HATI.399 directly hosts the current Security Governance English seminars. Your approved Sisu plan remains the final operational control.
1. Start with SGY and HAL.HATI.399
Security Governance is not simply the administrative version of International Security. Current SGY combines joint programme studies, 25 ECTS of advanced Security Governance, 10 ECTS of advanced International Security, electives including internship/working-life skills, and the 40 ECTS Master’s Thesis and seminar.
That structure should control the guide. Similar SAFER labels elsewhere in the curriculum are useful controls, but they should not override a specialisation page and thesis course that explicitly identify the current Security Governance route.
2. Understand the 40 ECTS seminar-and-thesis package
HAL.HATI.399 is a 40 ECTS advanced-studies course in Administrative Sciences. Tampere describes its content as a research seminar plus an independent scientific thesis that demonstrates the student’s ability to understand and apply disciplinary theory and research methods to define and address an administratively relevant problem.
The whole course uses 0-5 grading, but the seminar participation component is 10 ECTS pass/fail. Keep those grading levels separate. A pass in the seminar is not itself the final thesis grade, and the entire 40 ECTS package should not be described as pass/fail.
3. The current Security Governance seminars are explicit
The 2026-2027 HAL.HATI.399 schedule explicitly provides Security Governance, 2nd-year seminar in English across the academic year and a Security Governance, 1st-year seminar in English beginning in January 2027. This is much stronger programme-specific evidence than inferring a seminar from a generic course label.
The course also requires separate enrolment in information-searching training, and all completion-option parts are compulsory. Use the seminar sequence as a research-development pipeline rather than treating it as an administrative formality.
4. What about SAFER.399 and SAFS08?
Current SAFER.399 is a separate 30 ECTS Administrative Studies thesis object. Its completion instructions tell students to enrol in a Master’s Thesis Seminar labelled SAFS08 plus information-searching skills. That is real current evidence, but it does not automatically make SAFER.399 the governing Security Governance thesis.
For the current SGY route, the stronger match is SGY’s 40 ECTS thesis-and-seminar allocation together with HAL.HATI.399’s explicit Security Governance seminar implementations. If your personal Sisu plan shows a transitional or alternative SAFER.399 route, follow that approved plan and ask Study Services/supervision to resolve any discrepancy before registering.
5. Use SAFER.310 to define security concepts
Current SAFER.310 Introduction to Security Studies develops the shared conceptual base of the programme: security governance, international security, risk, preparedness, defence, deterrence and resilience, as well as academic writing and argumentation.
A thesis should therefore define concepts instead of using them as slogans. “Resilience”, “preparedness”, “risk” and “security governance” can mean different things across organisations and literatures. State what each concept means in your study and what observable evidence would support it.
6. Security governance is not just “what government does”
Governance often involves networks of public authorities, companies, NGOs, communities and cross-border actors rather than one hierarchical organisation. If governance is central to the thesis, define the relevant actors, decision arenas, formal authority, informal influence and coordination mechanisms.
Avoid switching between “government”, “management” and “governance” as though they are interchangeable. The difference may be the analytical contribution of the thesis, especially in networked preparedness, critical infrastructure, crisis response or multi-level policy implementation.
7. Make resilience measurable or interpretable
The programme strongly emphasises organisational and societal resilience. A resilience thesis becomes weak when the concept means only “doing well under pressure”. Define the system or organisation, the disturbance, the capability being assessed, and the relevant timeframe.
Recovery speed, continuity of critical functions, adaptive decision-making, redundancy, learning, network coordination and anticipatory capacity are different dimensions. Choose dimensions justified by literature and your evidence rather than combining all of them into a single vague score.
8. Risk research: separate identification, assessment and governance
Security Governance also engages risk. A risk register, perceived risk, statistical hazard, vulnerability analysis and governance response are not the same object. Define whether the thesis studies how risks are identified, quantified, prioritised, communicated, allocated or managed.
If organisations use different risk scales, do not compare colour codes or numerical scores without understanding the underlying definitions. The research contribution may lie in how actors interpret and govern risk, not merely in reproducing the organisation’s existing matrix.
9. Policy-process analysis
A policy thesis should identify what stage is being studied: agenda setting, formulation, adoption, implementation, coordination, evaluation or revision. A strategy being published does not prove that practice changed.
Trace actors, decisions, documents and implementation evidence. If the thesis claims a policy “worked”, define the outcome and comparison logic. Without criteria, an implementation report can become a description of activity rather than an evaluation of effectiveness.
10. Organisational case studies
Municipalities, ministries, emergency organisations, companies, universities, hospitals or infrastructure operators can be useful cases. Define why the case is theoretically or practically relevant and what unit of analysis you are actually studying: the whole organisation, a team, a policy process, a preparedness function or an inter-organisational relationship.
Separate formal design from practice. A written continuity plan shows intended arrangements; interviews, exercises, incident records or observations may show how arrangements work in practice. Those evidence levels should not be collapsed.
11. Governance-network research
If you study networks, define the network boundary and what a connection means. A tie could mean information exchange, contractual dependence, joint planning, authority, funding or operational coordination. Different tie definitions produce different networks.
For formal social-network analysis, document node inclusion, tie construction, missing data and metrics. For qualitative network governance, explain how relationships and coordination mechanisms are identified from interviews/documents. Do not infer power from a diagram alone.
12. Expert and official interviews
Security Governance often involves officials, managers and subject-matter experts. Define why each participant role matters, how participants were recruited and what information they can reasonably know. Organisational position can shape both access and narrative.
Use consent, secure storage and appropriate anonymisation. In small organisations, a job title or incident description can identify a person even after names are removed. Triangulate interview claims against documents or other evidence where feasible.
13. Policy documents and preparedness plans
Strategies, preparedness plans, risk assessments, audit reports and guidance documents are institutionally produced sources. They can establish formal commitments, definitions or procedures, but they do not automatically establish actual performance.
Record issuer, date/version, intended audience and legal/organisational context. If a document is confidential or security-sensitive, do not reproduce protected details in the public thesis. Design the research so that the academic argument remains reviewable from lawful evidence.
14. Evaluation research
Security Governance naturally invites evaluation: Was a preparedness reform effective? Did an exercise improve coordination? Did a new governance model reduce vulnerability? Those questions need explicit criteria.
Define the benchmark, expected mechanism and evidence before judging success. Consider alternative explanations and implementation context. A positive participant perception is evidence about perception, not automatically about objective effectiveness.
15. Crisis management and timeline discipline
Current programme material connects security governance with crisis management and resilience. Crisis research is especially vulnerable to hindsight bias. Build a chronology that distinguishes when the event occurred, when decisions were taken, when information became available and when retrospective documents were written.
If you assess decision quality, use the information available to decision-makers at the time rather than information revealed later. This protects the analysis from unfairly judging actors with knowledge they could not have possessed.
16. Comparative organisations or jurisdictions
Comparing municipalities, agencies, sectors or countries can reveal governance variation, but comparison needs a stable framework. Define selection logic and apply the same questions across cases.
If one case provides internal documents and interviews while another provides only public sources, state that asymmetry. Strong comparison does not require identical data, but the certainty of the conclusions must reflect the evidence available for each case.
17. Surveys and administrative data
Surveys can measure preparedness perceptions, risk awareness, trust, coordination experience or organisational climate. Define the target population, sampling/recruitment route, response coverage and how constructs are measured.
Administrative datasets and incident records also need stable definitions and missing-data analysis. Changes in reporting practices can look like changes in security conditions. Preserve dataset versions and transformation steps so reported figures can be reproduced.
18. Mixed methods and evidence integration
A document analysis plus interviews plus a survey is not automatically a coherent mixed-method thesis. State what each evidence stream contributes and where they are integrated.
For example, documents may establish formal governance arrangements, interviews may explain implementation mechanisms, and survey results may show how widely a pattern is experienced. If sources conflict, investigate the conflict instead of averaging it away.
19. Personal data and sensitive organisational information
Tampere requires personal-data processing to be planned before collection and agreed with the relevant supervisor. Security-governance projects can involve contact details, job roles, incident experiences, opinions or other identifiable information. Collect only what the research question requires.
Security-sensitive organisational material can create additional risks even when it is not personal data. Separate research records from the public thesis, use access controls, and agree handling with supervisors/commissioners. Publicity of the thesis means the final manuscript should not depend on hidden evidence that examiners cannot assess.
20. Supervision and research-plan control
Tampere appoints one or two supervisors, with one serving as primary supervisor. Bring decisions to meetings: unit of analysis, case boundary, interview sample, document corpus, risk/resilience definition, evaluation criteria or data-protection question.
Use the early seminar to stress-test feasibility. If access to internal plans or officials is uncertain, design a fallback using public documents, alternative participants or a literature-based route that can still answer the core research question.
21. Seminar participation, presentation and opposition
HAL.HATI.399 gives Security Governance a programme-specific seminar route, while Tampere’s general non-technical thesis framework also expects thesis presentation, peer discussion/opposition and maturity completion. Treat these as quality-control mechanisms.
A strong seminar presentation exposes the evidence chain: problem, concepts, material, method, emerging finding and limitation. Opposition teaches the same examiner-style question you need for your own work: does the conclusion actually follow from the evidence?
22. AI use in Security Governance research
Tampere allows AI support under current study guidance, but the student remains responsible for the submitted work and thesis-use principles should be agreed with the primary supervisor. AI summaries of policy documents, risk reports or organisational procedures can omit qualifiers or invent details.
Verify factual content against original sources. Do not upload confidential preparedness material, internal incident reports, personal interview data or other protected information to external AI systems unless the applicable rules permit it. Acknowledgement does not transfer analytical responsibility to the tool.
23. Maturity test and thesis language
The master’s thesis process includes a maturity test. The route depends on earlier demonstration of language skills and current degree rules. Where relevant language proficiency has already been assessed, the master’s thesis abstract can serve as the maturity test for content; where language checking is still required, a separate route applies.
Confirm your own Sisu implementation early. Do not copy another student’s route, especially where transition-era thesis courses such as SAFER.399 and HAL.HATI.399 coexist in the curriculum.
24. Turnitin, Trepo, publicity and PDF/A
After primary-supervisor permission, the final manuscript goes through Tampere’s Turnitin originality process. A similarity percentage is not an automatic plagiarism verdict. Policy language and standard administrative formulations can create legitimate matches, but sources must still be attributed correctly.
After the Similarity Report is reviewed, submit the final thesis through Trepo while registered as attending. The thesis is a public document and is permanently electronically archived. Keep confidential/security-sensitive supporting material outside the public manuscript and ensure the final file meets PDF/A requirements.
25. Assessment, response and appeal
HAL.HATI.399 uses the 0-5 course scale, while its 10 ECTS seminar component is pass/fail. Under Tampere’s general non-technical process, the normal examiner assessment window is 21 days, extended to 28 days when a separate maturity test is required as part of the process. These are examiner windows, not guarantees for the entire graduation timeline.
The examiner statement and proposed grade are sent to the student’s tuni.fi email. Current rules allow a written response within seven days and an appeal to the Faculty Council within 14 days from access to the result and information on how the criteria were applied. Once approved, the thesis is final.
26. Run a final claim-to-evidence audit
Before freezing the manuscript, map every major conclusion back to exact evidence. For governance claims, identify the actor/relationship/document or observation that supports them. For resilience claims, identify the disturbance and capability measured. For evaluation claims, identify the benchmark. For interview findings, identify the coded segment without exposing participants unnecessarily.
Then test wording strength. “The organisation has a preparedness plan” is not the same as “the organisation is prepared”; “participants perceived coordination as improved” is not the same as “coordination objectively improved”. Downgrade claims when evidence is indirect, contested or incomplete.
27. Exercises, after-action reviews and learning claims
Preparedness exercises and after-action reviews can be excellent Security Governance evidence, but they need careful interpretation. An exercise is a designed scenario with artificial constraints, known objectives and often unusually high participant attention. Performance during an exercise therefore does not automatically predict performance during a real crisis. Record the scenario, participating organisations, exercise objectives, evaluator criteria and what information participants had during the exercise.
After-action reports are also institutional products. They may prioritise learning, accountability, reputation or compliance differently. If the thesis uses them to claim that an organisation learned or improved, look for evidence of implemented corrective actions, changed procedures, later exercises or follow-up measures. Distinguish identification of a lesson from institutionalisation of that lesson. A recommendation appearing in a report is not proof that capability changed.
28. Commissioned theses and academic independence
Security Governance projects are often attractive to ministries, municipalities, companies and other organisations because they can address real preparedness, risk or governance problems. A commissioner can provide access and a practical problem, but the thesis still needs an academic research question, transparent method and university assessment. Agree early which materials can be used, who controls personal data, what can be quoted and which details must stay outside the public manuscript.
Do not let the commissioner determine the conclusion. If the evidence contradicts the organisation’s preferred narrative, report the finding academically and discuss publication/confidentiality boundaries with the supervisor. Recommendations should follow from the evidence and should distinguish feasibility, values and organisational constraints from empirical findings. This separation protects both the student’s independence and the usefulness of the final work.
29. Final Security Governance checklist
Before starting, verify SGY, HAL.HATI.399, your current Security Governance seminar group, supervisor(s), information-search training and maturity route in Sisu. Treat SAFER.399/SAFS08 as a separate curriculum control unless your own approved plan explicitly places you there.
Before submission, confirm the research puzzle is bounded; governance/risk/resilience concepts are defined; case/network/corpus boundaries are explicit; formal policy and actual practice are not conflated; personal and security-sensitive data are protected; AI-assisted material is verified; major claims trace to evidence; maturity requirements are complete; Turnitin is reviewed; the final PDF/A is valid; Trepo submission is complete; and enough time remains for examination and graduation administration.
A strong Security Governance thesis does not need access to secret operational material. It needs an administratively relevant research problem, disciplined concepts, transparent evidence and a defensible link from governance theory and method to findings about organisations, networks, policies, risks or resilience. The final manuscript should make uncertainty visible as well: distinguish what is directly documented, what comes from participant perception, what is inferred from patterns, and what remains unknown because access or data are limited. That transparency is especially important when evaluating preparedness or resilience, where formal plans can create an appearance of capability that only exercises, incidents, implementation evidence or carefully bounded expert testimony can substantiate. Keep those evidence levels explicit in the final discussion and limitations section.
Sources and verification
Links are preserved so readers can inspect the controlling documentation or underlying research.
- Security Governance, Security Management and PoliticsTampere UniversityAccessed 31 August 2026
- Master's Programme in Security Management and Politics, 120 crTampere UniversityAccessed 31 August 2026
- SGY Security GovernanceTampere UniversityAccessed 31 August 2026
- SAFER.SG-S01 Advanced Studies in Security GovernanceTampere UniversityAccessed 31 August 2026
- HAL.HATI.399 Pro gradu seminar and thesis, Administrative SciencesTampere UniversityAccessed 31 August 2026
- SAFER.399 Master’s ThesisTampere UniversityAccessed 31 August 2026
- SAFER.310 Introduction to Security StudiesTampere UniversityAccessed 31 August 2026
- POL.KV.343 Strategy and Crisis ManagementTampere UniversityAccessed 31 August 2026
- Master's thesisTampere UniversityAccessed 31 August 2026
- Maturity test and demonstration of language skills in degreesTampere UniversityAccessed 31 August 2026
- How to use AI in studiesTampere UniversityAccessed 31 August 2026
- Instructions for students concerning data protectionTampere UniversityAccessed 31 August 2026
- Assessing originality of thesisTampere UniversityAccessed 31 August 2026
- Publicity of thesisTampere UniversityAccessed 31 August 2026
- Archiving thesisTampere UniversityAccessed 31 August 2026
- Graduation schedulesTampere UniversityAccessed 31 August 2026
Copy a formatted citation
Select the required referencing style, review the generated citation and copy it without leaving the guide.
PT Writers Editorial Team. (2026). Tampere University Security Governance Master's Thesis Guide: HAL.HATI.399 40 ECTS, Seminar and Trepo. PT Writers. https://ptwriters.org/blog/tampere-university-security-governance-masters-thesis/