Circular Image

J. Ubacht

info

Please Note

26 records found

A Design Science Approach to Structuring Information Transfer Between Development and Construction

Master thesis (2026) - L.J. Handgraaf, J. Ubacht, M.W. Ludema
A Dutch housing development project passes through a long, phased trajectory: from the first initiative, through successive design stages, to engineering and construction, a process that typically spans some ten years. At every phase transition, responsibility passes to a new discipline, and with it the knowledge, assumptions, and risks on which the project rests. Between independent firms, contracts discipline this transfer, but a developer-builder that combines development and construction in-house lacks this contractual boundary and depends on internal coordination. This thesis examines how that internal transfer can be structured at Bouwbedrijf Duinstede, a Dutch developer-builder with approximately 120 employees. The design objective is to develop a decision model that makes information transfer during phase transitions explicit, ensuring that responsibilities, risks, and financial insight remain structurally transparent.

The problem analysis, based on ten semi-structured interviews across all disciplines and an extensive analysis of internal documents and completed projects, reveals a developer-builder paradox: the projects with the greatest financial exposure, the company's own developments, are governed the least formally. At internal transitions, handover documents, phase budgets, and recorded risks are absent, and coordination is informal and person-bound. Three deficiencies recur: responsibility shifts without clear decision ownership, risks are not structurally assessed and transferred, and financial assumptions remain untested until they surface in a later phase. Four mechanisms explain information loss: rising external volatility rapidly outdates early assumptions; tension between commercial and technical disciplines remains uncoordinated; financial blind spots leave assumptions untested; and path dependency locks projects into costly rework. The underlying gap is the absence of a structural moment at which assumptions, risks, and responsibilities are made explicit and allocated.

The project follows the Design Science Research methodology (Johannesson & Perjons, 2021) within a single embedded case study. Four design activities were conducted: explicating the problem, defining requirements, designing the artefact, and demonstrating and evaluating it. The root causes were translated into three design principles: freedom within frameworks, phased financial transparency, and adaptive responsiveness and organisational learning, operationalised into eight functional and four non-functional requirements.

The resulting artefact is a sprint-based decision model designed as an agile hybrid. A stage-gate structure of formal Directors' Decisions marks every phase transition and is complemented by iterative, multidisciplinary sprints between the gates. Four streams carry an explicit role per phase (Leads, Decides, Advises, or Monitors), formally shifting the lead as the design matures. Every transition converges in a fixed-format gate document containing an investment proposal and handover matrix, recording who hands over what, to whom, and under which conditions. A one-time, irreversible Hard Gate ties the build commitment to criteria for pre-sales, contracts, and margin. A notification register carries early risk signals through the gates, while a central project archive and three organisational learning mechanisms convert individual experience into transferable organisational knowledge.

The model was demonstrated on De Weverij, a fictitious but realistic own-development project of 43 dwellings subjected to disturbances including soil contamination, a municipal social housing condition, and an appeal procedure. The walkthrough indicates that the model can function logically under adverse conditions, while five expert sessions indicate that it is perceived as useful and organisationally feasible, provided that administrative intensity remains limited, cashflow steering is added, and sufficient preparation capacity is secured. The resulting refinements constitute version 2 of the artefact. Given the ex-ante and artificial character of the evaluation, these findings suggest, but cannot yet prove, that the model will reduce rework and information loss in practice.

The refined model is translated into a phased implementation roadmap involving a group simulation, a pilot on three live projects, and organisation-wide scaling. Future research should measure the effect on rework and information loss, establish an evidence-based rule for the timing of the lead transition, examine portfolio-level cashflow control, and test the design at other developer-builders. The project contributes by explicating the developer-builder paradox, extending the agile-stage-gate hybrid to a context with irreversible physical and legal commitments, and adding a boundary condition to the literature on tacit knowledge. ...

Designing ethical and sustainability-driven course guidelines

Generative Artificial Intelligence (GenAI) is increasingly embedded in Science, Technology, Engineering, and Mathematics (STEM) education, offering opportunities to support learning through personalised assistance, improved efficiency, and enhanced accessibility. At the same time, its widespread adoption raises ethical, sustainability, and pedagogical challenges, including academic integrity, algorithmic bias, and the potential erosion of higher-order thinking skills. Although these challenges are widely recognised, lecturers lack practical guidance for redesigning courses to accommodate students' GenAI use. This research addresses this gap by developing ethical and sustainability-oriented design guidelines for course design. Using a Design Science Research methodology, the study combined a comprehensive literature review with two rounds of semi-structured expert interviews and an example course redesign. The research resulted in ten design guidelines that support educational institutions in changing courses to account for GenAI use by students. Central themes include rethinking foundational knowledge and skills, supporting higher-order thinking skills (HOTS), enhancing AI literacy, adopting authentic and process-oriented assessment, and ensuring fair and human-centred learning environments. The findings further demonstrate that successful implementation depends not only on course-level redesign but also on institutional governance, clear AI policy, and collaboration. This study contributes to AI in Education (AIED) by providing an artefact that supports course managers in adapting STEM courses to student GenAI use while preserving constructive alignment. By integrating ethical and sustainability considerations, the proposed guidelines offer a practical foundation for responsible GenAI adoption. ...

Designing a decision-support tool to align digital innovation with sustainability goals

Master thesis (2025) - M.I. de Gier, J. Ubacht, L.M. Kamp, L. Klaiber
The Dutch high-tech manufacturing sector is undergoing a Twin Transition: the simultaneous shift toward digital transformation and improved sustainability. This dual transition is driven by the need to maintain technological leadership while meeting national climate goals and complying with the Corporate Sustainability Reporting Directive (CSRD). Although digital technologies can support sustainability efforts, they also introduce trade-offs that make the relationship between these goals complex.

This research addresses a key gap in both academic literature and industry practice: the lack of a sector-specific decision-support tool that connects digital maturity with sustainability performance. Using a Design Science Research (DSR) approach, the study followed four phases: problem explication, requirements definition, design and development, and demonstration and evaluation.
1. Through expert interviews and literature reviews, ten key challenges were identified, of which four were prioritized for tool development by applying the Stacey Matrix. These include unclear returns on investment, limited visibility into sustainability impacts, the absence of sector-specific roadmaps, and a lack of methods for weighing trade-offs between digital and sustainability goals.
2. To define the tool’s requirements, a second literature review and five user interviews were conducted, resulting in functional, structural, and contextual specifications using the MoSCoW framework.
3. The resulting tool consists of three integrated components: a company-specific ESG and digital maturity survey, a Twin Transition maturity model across People, Process, and Policy dimensions, and a recommendation dashboard. This dashboard maps digital manufacturing technologies based on their sustainability impact and implementation complexity. The tool adapts an existing maturity model by aligning ESG priorities with digital transformation levels, and uses Environmentally Extended Input-Output Analysis (EEIOA) and ESG materiality mapping for impact assessment.
4. Demonstrations with consultants and a manufacturing firm showed that the tool is effective in bridging departmental silos and supporting strategic discussions. It helps companies translate high-level sustainability and digital goals into actionable steps suited to their specific context. Rather than offering prescriptive solutions, the tool serves as a structured guide for informed decision-making.

The research contributes to Twin Transition theory by providing the first integrated framework that explicitly links digital capabilities to ESG outcomes in the high-tech manufacturing sector. Methodologically, it shows how stakeholder input and quantitative analysis can be combined in a practical, industry-ready tool. While the tool offers a valuable starting point, the study also highlights its limitations, particularly in addressing the political and cultural dynamics that shape real-world change. Future research should explore how this approach can be adapted to other sectors and to small and medium-sized enterprises (SMEs). Longitudinal studies, deeper lifecycle assessments, and cross-national comparisons will also be needed to understand the broader dynamics of the Twin Transition.
...

A Decision Support Framework with a Case Study on York, Pennsylvania

Master thesis (2025) - Y. Mouhdad, J. Ubacht, J.N. Quist, Jan Westra
Global food production faces increasing challenges due to population growth, urbanization, and climate change. Even in developed countries such as the United States, a significant number of people experience food insecurity (U.S. Department of Agriculture, 2025). Therefore, alternative crop growth methods such as vertical farming are considered. Vertical farming is the practice of growing crops in an indoor facility by stacking multiple layers of production (Agritecture & CEAg World, 2025). While the vertical farming market is expected to grow yearly, multiple large bankruptcies of vertical farming companies in the U.S. in 2023 showed that it has severe drawbacks and difficulties competing with traditional farming (field farming). Therefore, a framework is needed to assess the viability of vertical farming. This led to the following research question: Which decision support framework can support the assessment of the viability of vertical farming?

The research approach used to support the development of the decision support framework is a single case study method. The case was on an ongoing project at the York State Fair in York, Pennsylvania, in the United States, which involved several stakeholders. In this research, the advantages and disadvantages of vertical farming were first compared to traditional farming in terms of economic viability. Disadvantages such as high investment costs and energy usage were found to be more financially impactful than the advantages such as no-pesticide use, and water efficiency.

It was found that multiple important stakeholders had concerns about profitability. In addition, there is potential for conflict due to different interests in what the workforce must be in the project. The most suitable solution was to include educational aspects such as hiring interns. In addition, to cope with possible external factors such as shortages in the agricultural workforce, including automation via robotics, could make the project more resilient. The business models best suited to the project are the differentiation and experience business models. Based on the factors critical to the viability of vertical farming, a financial model tool was made in Excel. This tool can calculate a vertical farm project's profitability and test how resilient the profitability is to changes in the critical parameters.

A decision support framework was created, consisting of the following six stages: “identify drivers,” “analyze business environment,” “analyze stakeholder alignment,” “develop business case,” “analyze viability,” and “implement vertical farm initiative.” The stakeholder methods that should be used include a power-interest matrix, value network analysis, and, depending on potential conflicts between stakeholders, a system diagram analysis. A Business Model Canvas can be used to develop the business case. The vertical farm's viability can be assessed using the financial model tool. If the viability is satisfactory, the vertical farming initiative can be implemented. Private organizations and public institutions can use the decision support framework to assess whether a vertical farming initiative is profitable in a specific location, what type of business model fits the vertical farm, and whether policies need to be changed to increase a vertical farm’s viability. ...

Investigating how ERP systems, like SAP, can enable automated sustainability reporting and strategic decision-making under CSRD and ESRS E1

Today, companies face increasing pressure to report their sustainability practices, particularly greenhouse gas emissions, due to new regulatory requirements such as the Corporate Sustainability Reporting Directive (CSRD) and European Sustainability Reporting Standards (ESRS). This thesis explores how Enterprise Resource Planning (ERP) systems, specifically SAP, can effectively support organizations in complying with emissions reporting under ESRS E1. An exploratory qualitative approach combining desk research, a detailed case analysis of SAP functionalities, and expert interviews was undertaken to investigate reporting requirements, data integration challenges, and best practices.

The research identified critical emission metrics required by ESRS E1 and evaluated SAP's capability to manage these metrics through its Sustainability Control Tower. Key challenges were found in the accurate and complete collection of emission data, particularly Scope 3 emissions. Furthermore, organizational and strategic obstacles, such as unclear responsibilities and viewing emissions reporting purely as compliance rather than a strategic advantage, were highlighted.

To address these challenges, the study proposes a structured 12-step roadmap, emphasizing data integration, clear internal governance, and strategic alignment of emissions reporting with broader business objectives. The roadmap facilitates accurate, compliant reporting while enhancing strategic decision-making capabilities. The thesis concludes that, although further validation of this roadmap in practice is necessary, ERP systems like SAP, when properly integrated, provide robust tools for effective emissions reporting and strategic sustainability management.
...
Master thesis (2024) - A.W. van Roon, Fátima Delgado Medina, Jolien Ubacht, Marja Veentjer
As the aviation industry faces mounting pressure to mitigate its environmental impact and with zero-emissions aircraft still likely years away, it is crucial that airlines find intermediary steps to make progress in the meantime. An opportunity with massive potential is for airlines to leverage IT technologies to reduce their footprint, otherwise known as Greening by IT. Through applications such as better flight planning algorithms which could reduce 0.5-1% of annual emissions or better data oversight to more easily identify polluting elements of the operation, the ways in which Greening by IT can help airlines is numerous. Despite its promise and several demonstrated examples in the industry, airlines still seem to lag in fully implementing Greening by IT solutions and realizing its full potential. A good example of this is within KLM Dutch Royal Airlines, where most efforts to improve sustainability within IT have been put into Green IT, which consists of measures to make IT itself more sustainable. While many of these efforts are admirable, one should question why so much effort is put into reducing IT’s contribution to the total footprint, which makes up less than 1% of total emissions from KLM. When one looks closer, it is easy to see that implementing Greening by IT is more complicated, as coordination with stakeholders outside of IT is needed and the impacts of changes you make are less clear. If navigating tight resource constraints, balancing many other high priority needs, and complying with aviation’s many regulations wasn’t enough, the research on how to best implement Greening by IT is scattered and lacks concrete answers. There is a lack of an understanding in which factors influence implementation the most, which strategies can be used, and a lack of a widely-accepted adoption model which could be used by practitioners and researchers alike. Beyond this, there is a complete absence of prior research on Greening by IT’s application within airlines, nor any unique aspects which must be considered. As a result, the purpose of this study was to explore the key factors impacting Greening by IT implementation, the strategies to guide it, and to integrate these together into a decision support framework. This framework is designed to be used primarily by IT practitioners within airlines to understand the implementation process, select the barriers which impact them the most, and choose strategies which can be used to help overcome them. In order to design a framework that is relevant in practice and to understand the complex phenomena involved with Greening by IT in practice, the study was carried out together with KLM’s CIO Office. Conducting this study with KLM enabled access to important documentation and stakeholders within the company. More specifically, the use-case within KLM Information Services was defined as Data & Technology platform, which combines business and IT elements to provide IT services for several KLM-specific business streams. Three qualitative research methods were used, consisting of a literature study, desk research of KLM documents, and stakeholder interviews. The research process was broken down into five sub-questions which were used to guide the research... ...

Unveiling the potential of human-LLM collaboration in the ontology extension process

Master thesis (2024) - J. García Fernández, J. Ubacht, Oscar Oviedo-Trespalacios, N. Bharosa, Jack Verhoosel
We live in the era of data. Data stands as the new essential resource, proving crucial not only for sophisticated mathematical models but also for commonplace applications. Regardless the field or domain, data needs to be shared in order to improve these tools, which means that systems must speak the same language. To address this challenge, there is a growing popularity in utilizing ontologies. These are formal structures of knowledge that enable a common understanding of concepts related to a specific domain, both by humans and by machines. But their generation is a complex task that requires knowledge from both the domain and the ontology engineering field. Many ontologies already exist, and extending those with new concepts and paradigms is a common practice. It is also essential to promote reusability of standards and standardization, and to avoid “reinventing the wheel”.
In parallel, the fast evolution of Artificial Intelligence is leading the emergence of infinite possibilities in terms of automation of tasks that have hitherto been completely manual. In particular, the use of Large Language Models is booming, though its use to help in the extension of existing ontologies has not been exploited yet. This research proposal aims to answer the question of: How can LLMs be integrated into a semi-automated and domain-independent process for the extension of existing ontologies?
This master’s thesis, carried out in collaboration with TNO, follows the Design Science Research Approach to analyze the problems associated with ontology engineering and the integration of LLMs in the ontology extension process by interviewing 11 ontology engineers and experts in the field. The analysis of the interviews is used to generate a model of the current ontology extension process and to produce a set of 22 high-level design requirements to guide the design a process framework for human-LLM collaboration for the ontology extension process. The design prototype proposed consists of an extended version of the current ontology extension process model augmented by the assistance of LLMs on various ontology extension tasks and incorporating additional ontology engineering tools and stakeholders in the process. The design includes a set of prompt templates that can be customized by the ontology engineer to extend an ontology in any domain. The final design is demonstrated and evaluated with a real use case, which consists of extending the Common Greenhouse Ontology (CGO), developed by TNO, with the use case Semantic Explanation and Navigation System (SENS), previously executed by TNO. The demonstration and evaluation is performed using OpenAI’s model GPT-4 Omni, through the creation of a GPT Assistant.
The generated ontology extension using the process framework and the GPT assistant is similar to the manually crafted extension. Remarkably good results are achieved in tasks such as defining business scenarios and creating a glossary of terms, generating Competency Questions, formalizing the ontology (in OWL) and the CQs (in SPARQL queries), and verifying the generated ontology extension using mock data and CQs. An end-user (ontology engineer) is asked to use the proposed process framework prototype and qualitatively evaluate the tasks, concluding that this approach is very useful for ontology engineers with various level of expertise to structure and increase the quality of the current ontology extension process.
Although the proposed design holds a great potential to be implemented and integrated with the current methodologies and tools used by ontology engineers, several challenges need to be tackled before we see a wide adoption and integration of LLMs in the ontology extension process. These challenges go beyond the technical performance of the LLMs, but revolve around the societal implications of the use of this technology instead. The loss of enriching human interactions and expertise, and the environmental and ethical impact are big concerns of the ontology engineers. These must be addressed before the potential of LLMs for the ontology extension process can be unveiled. ...
In recent years, there has been a significant increase in the number of depression cases. However, only 9% of depression patients in Indonesia receive appropriate treatment. The rapid advancement of technology highlights the potential for telemedicine to close this gap. Unfortunately, the adoption of telemedicine in Indonesia remains challenging, with a small amount of the population having used this technology.

Several factors impact the adoption of telemedicine among its users. The adoption of this technology, including by healthcare professionals, will depend on these factors. To understand these factors, the adoption of telemedicine for depression care among healthcare professionals in Indonesia is explored in this study.

The Unified Theory of Acceptance and Use of Technology (UTAUT) is employed as the theoretical foundation. Performance expectancy and effort expectancy are used to find the answer to the main research question. Performance expectancy refers to the degree to which one expects a system to help them raise their job performance, while effort expectancy refers to the degree to which a system is easy to use. Eleven interviewees were interviewed for this research, of whom eight are psychologists, two are psychiatrists, and one is an academic.

In terms of performance expectancy, there are nine key factors that could contribute to the adoption of telemedicine for depression care. In terms of effort expectancy, it was found that five key factors influence healthcare professionals’ perceived ease of use towards telemedicine. As a result, it was found through deeper analysis that education and technology are two additional contributors to the UTAUT framework in telemedicine for depression care. Additionally, the findings show that current regulations are still inadequate to provide comprehensive rules related to telemedicine practices in Indonesia.

This research has several limitations. It focuses exclusively on depression care in Indonesia as a country and not specific to certain locations. Bias can arise from the small number of interviewees in this research. Future research should consider the location, gender, age, and experience of interviewees to provide more comprehensive results. Another research can be employed to ensure the validity and generalization of the suggested framework in similar cases.

The implications of this research are intended for policymakers, academic institutions, and technology providers. To ensure the proper functioning of telemedicine, policymakers supported by academic institutions should incorporate telemedicine courses into the curriculum and establish formal regulations of telemedicine in the country. For technology providers, they must ensure that telemedicine functionalities meet the needs of healthcare professionals in order for them to perform their duties. ...

A Participatory Action Research on Balinese Community

Master thesis (2024) - S. Nadhira, Fátima Delgado Medina, J. Ubacht, Els Leclercq, V.E. Scholten
This research addresses the revitalization of Balinese cultural values, which inherently embody circular economy principles and support sustainable communities. The key problem tackled is the decline in communal sharing and the shift towards individualistic behaviors, exacerbated by modernization and tourism, which undermine traditional practices and increase waste. Using a Participatory Action Research (PAR) approach, the study involved desk research, interviews, and a community workshop to co-create an intervention. A major finding is the effectiveness of a barter market intervention, which aligns with traditional values like Ngayah and Tri Hita Karana, promoting non-monetary exchanges and fostering community bonds. The study recommends employing pulling, facilitating, and matching strategies to enhance participation and integration of well-being aspects in the Circular Value Flower (CVF) framework. This research provides practical insights for fostering sustainable practices and emphasizes the need for collective responsibility in climate change adaptation, making it relevant for researcher, policymakers and community leaders aiming to promote circular economies in culturally diverse contexts. ...
The logistics industry is undergoing a significant transformation with the integration of Internet of Things (IoT) technologies. The goal is to achieve smarter, more efficient operations, such as autonomous asset tracking, workflow optimization, and predictive maintenance in real-time. These advancements promise streamlined supply chains, reduced downtime, and improved customer satisfaction by enabling faster and more accurate deliveries. IoT tools, including GPS tracking, RFID tags, and predictive maintenance systems, enhance fleet monitoring, inventory management, and equipment repairs, leading to greater operational efficiency and reduced waste.

However, despite its potential, IoT adoption in the logistics sector, particularly among third-party logistics firms (3PLs), faces several challenges. Legacy systems are often incompatible with modern IoT solutions, requiring costly upgrades and extensive integration efforts. Organizational resistance also poses a barrier, as employees accustomed to traditional methods may be hesitant to embrace new technologies, especially if the benefits are not clearly communicated. Financial constraints further complicate adoption, with high upfront costs for hardware, software, and infrastructure, as well as ongoing expenses for maintenance, data management, and training. These factors often lead to "pilot purgatory," where IoT projects remain in the testing phase due to financial and organizational limitations.

To address these challenges, the IoT Technology Adoption Framework (ITAF) was developed as a structured approach to guide companies through IoT integration. ITAF outlines a stage-gated process, starting with identifying challenges and assessing organizational capabilities. This is followed by planning, pilot testing, and ultimately, large-scale implementation. Each stage includes decision gates to evaluate progress and determine the best course of action, ensuring a systematic and informed transition. Metrics are integrated into the framework to assess the technical, organizational, and financial feasibility of IoT projects.

Expert insights, particularly from FedEx Europe, helped refine the ITAF to better address real-world complexities. These include improving system interoperability, fostering organizational buy-in, and managing financial risks. Feedback led to enhancements such as greater vendor involvement, continuous reassessment of company capabilities, and cost-benefit analyses post-launch. These refinements make the framework adaptable for various company sizes and IoT applications, from fleet management to real-time inventory tracking.

The flexibility of ITAF allows it to be tailored to the needs of different logistics providers. Smaller companies can prioritize financial considerations, while larger organizations may focus on system compatibility and scaling solutions. Its modular design also makes it applicable beyond logistics to sectors like healthcare, manufacturing, and retail, which face similar IoT integration challenges. Testing the framework across diverse industries could further validate its scalability and refine its approach for broader applicability.

As IoT technologies rapidly evolve, ITAF emphasizes the importance of continuous reassessment and updates to ensure companies remain competitive and aligned with industry standards. Clear stakeholder ownership at each stage of implementation fosters accountability and minimizes delays. By providing a practical and adaptable roadmap, ITAF addresses the complexities of IoT adoption, enabling companies to unlock its transformative potential and maintain a competitive edge in an increasingly data-driven industry. ...

A Feasibility Study for Smallholder Farmers in Ghana's Ashanti Region

Climate change is a pressing concern affecting the livelihoods of farmers in Ghana's Ashanti region due to erratic rainfall patterns, primarily impacting rain-fed agriculture. This research explores the potential of carbon credits to encourage smallholder farmers in the Ashanti region to adopt agroforestry practices as a solution. Agroforestry, if effectively implemented, not only helps combat climate change by capturing carbon but also improves soil fertility, protects crops from extreme weather, and offers various benefits to local farmers. This study delves into the complexities of this issue to propose innovative solutions benefiting both the local farming community and the global climate challenge.

The carbon-based agroforestry system consists of three main parts: the carbon credit system, the institutional system, and the socio-technical system. To study this complex system, we adopt an illustrative case study approach, focusing on the Ashanti region in Ghana. Our research follows a top-down approach, beginning with comprehensive desk research to build a foundational understanding, followed by in-depth interviews with local farmers and selected experts, including government agencies and an NGO, to gain a nuanced understanding of the Ashanti region's context.

Taking into account the carbon credit system, significant attention is devoted to crafting a project framework that aligns with rigorous carbon standards. The accumulation of carbon credits over time serves as a means to secure initial investments. Farmer involvement, particularly their commitment, assumes paramount importance in the context of the carbon credit system, given that only mature trees can generate carbon credits. Primary risks pertain to tree cutting or tree mortality. To mitigate these risks, farmers need comprehensive training and access to essential tools for tree maintenance.

The land tenure system in the Ashanti region is notably complex, predominantly relying on the customary framework. Insights garnered from farmer interviews underscore the pronounced tenure insecurity that impedes farmer participation in the system. Securing land tenure documents is pivotal to instilling confidence among farmers regarding the equitable distribution of system benefits. Notably, varying farmer characteristics and specific traditional areas wield varying degrees of influence over land tenure security and the complexity of acquiring such documents. For system feasibility, a targeted approach focusing on engaging landowners and dispelling misconceptions while emphasising the advantages of land tenure documents is essential. Incentivising landowners through a share of the carbon revenue may also be necessary to ensure their active participation.

Farmers in the Ashanti region grapple with diverse challenges, stemming from erratic rainfall patterns, pest infestations, weed proliferation, and soil nutrient depletion. These challenges are compounded by financial constraints, exacerbating the farmers' livelihood struggles. Notably, farmers place a higher premium on the tangible benefits of increased fruit tree yields as the primary incentive for system participation, displaying comparatively lesser interest in the intangible monetary returns from carbon credits. Effective communication with farmers necessitates addressing their immediate concerns. Consequently, the agroforestry system should be designed to incorporate intercropped fruit trees, delivering additional yields while preserving the cultural significance of existing crops and optimising the environmental advantages of the system. Given that farmers predominantly learn through visual exposure, the initiation of a pilot agroforestry system can substantially bolster their willingness to participate. Simultaneously, the development of tailored training programs and the provision of essential tools are indispensable for empowering farmers to proficiently maintain the trees.

The significance of carbon credits within the system primarily lies in compensating cooperating and financial parties, as farmers prioritise other benefits. The institutional system's challenges, particularly in securing land tenure documents, pose substantial feasibility hurdles for the system's viability. In future research on this topic, it would be valuable to seek the insights of traditional authorities. ...
Master thesis (2023) - H.D. Yeşilli, Y. Zhauniarovich, M.J.G. van Eeten, J. Ubacht, Lukas Willinge, Ruurd Boomsma
Increasing digitalization of systems bring about the grand challenge of keeping these systems secure from malicious prying eyes, and thus highlighting the need for increased Cybersecurity practices. Ransomware is among the most prevalent cybersecurity threats in our current digital era. The attacks are mainly done by advanced persistent threats (ATPs) to increase the impact done to organizations worldwide. Ransomware encrypt data using advanced cryptographic measures and lock users out of their systems to ask for a ransom that is typically paid through bitcoins. ATPs also exfiltrate sensitive data and utilize double and triple extortion methods where they either blackmail the organization with the public release or selling of their data, or they go to the customers to blackmail them, so they pressure the organization into paying the ransom. Defense against Ransomware is possible but in many cases, by the time, ransomware is detected the malicious actors already have strong access into the systems and data. All is not lost however as organizations can bring back their systems and data if there are backup & recovery policies that have been established prior. This thesis systematically explores the ransomware topic scoped on backups & recovery to identify how ransomware attack backups, what are the best practices for backups & recovery, and the corresponding challenges for organizations to produce policy recommendations. To this end, three methods are used. The methods are: semi-systematic literature review, qualitative content analysis, and semi-structured interviews. A triangulation of these methods over cybersecurity frameworks, expert knowledge and backup software provider reports establish essential insights. The main recommendations made are that organizations must ensure that they regularly must create redundant, airgapped, offline, and offsite backups that are stored in multiple storage media. Furthermore organizations must establish proper cyber hygiene practices in order to protect their backups. Lastly, organizations must ensure that they can test and maintain resilient backup & recovery policies through establishing responsibility and accountability of different stakeholders, streamlining their IT environments, and having a cybersecurity-enabling approach to organizational IT governance. The research is a rigorous and comprehensive overview of the backup & recovery topic against ransomware and is academically relevant as it fills research gaps on: how ransomware attacks target backups & recovery specifically, what the best practices offered by the most credible cybersecurity frameworks are, and why organizations still fail in setting up proper backup & recovery practices. The EPA relevance is characterized through navigating a branch of the grand challenge of cybersecurity, namely ransomware. This is a grand challenge as there are a plethora of stakeholders on an organizational level who have different opinions and views on the topic at hand where organizations are comprised of teams in different countries, subject to different regulations, etc. Therefore it is essential in this complex environment to see what could be made as policy recommendations for organizations of all levels against the treat of ransomware with respect to backup & recovery practices. ...
The EU Artificial Intelligence Act (AI Act) proposed by the European Commission is a significant legislative effort to regulate AI systems. It is the first legal framework that specifically addresses the risks associated with AI systems, aiming to ensure their trustworthiness and alignment with the values enshrined in the Charter of the Fundamental Rights of the EU and the Union values. Thus, the draft of the AI Act emphasizes the importance of fundamental rights in Europe's AI approach.

The AI Act covers various AI applications, including machine learning, logical, statistical, and knowledge-based approaches. It provides a classification framework based on the purpose and risks posed by AI applications: Prohibited/Unacceptable risk, High-Risk, Limited-Risk, and Minimal/No risk. However, there are concerns about the clarity of the classification criteria mentioned in the AI Act. Some AI systems may fall into multiple classifications, leading to ambiguity. For example, a social robot used in patient treatment could be classified as High-Risk or Limited-Risk. This ambiguity is also observed in classifying AI systems in enterprise functions, where 40{\%} of the classifications remain unclear.

Therefore, these challenges provide an opportunity to improve the classification process of AI systems under the AI Act, facilitating the classification process and accommodating emerging AI technologies. The main research question addressed in this thesis is: \textbf{"To what extent can the process of AI systems classification under the AI Act be improved?"}

The research focuses specifically on AI systems classification. It explores specific provisions of the AI Act, including Prohibited Risk, Classification Rules for High-Risk AI systems, Transparency Obligations, and Annexes II and III.

To achieve the objective of improving the classification accuracy of AI systems based on the AI Act, the study adopts the Design Science Methodology. This methodology involves systematically studying existing AI systems classifications and challenges, extracting themes to develop a framework, and evaluating the framework through feedback from AI experts.

A decision tree is designed as the proposed framework. It is evaluated on 16 respondents from two different backgrounds: legal and non-legal. In order to obtain comprehensive insights, the evaluation is designed to incorporate an experiment where respondents are tasked to classify AI systems to the risk level with the AI Act only. Then in the second experiment, they have to classify AI systems using the proposed decision tree framework. It is important to note that the study acknowledges the possibility of overestimating or underestimating respondents' ability to classify AI systems due to their diverse backgrounds and levels of understanding of the AI Act. Furthermore, a semi-structured interview is conducted to strengthen the analysis.

Based on the evaluation, the decision tree's performance revealed higher accuracy than the classification approach without the decision tree. However, the overall accuracy remained low, indicating room for improvement. Challenges identified include the need for additional context and understanding of terms, definitions, and examples in the decision tree and the potential for misclassification due to vague definitions and assumptions. Respondents also expressed the need for more detailed information about AI system use cases to improve classification accuracy.

The decision tree's performance varied between obvious and non-obvious use cases, with non-obvious cases presenting challenges in accurate classification. The accuracy for obvious cases was higher, highlighting the difficulty of distinguishing between High-Risk and Unacceptable Risk categories. Lack of clarity in terms and definitions and limited contextual information contributed to the challenges faced in classifying non-obvious cases.

Legal experts demonstrated higher accuracy than non-legal respondents, indicating familiarity with legal terminology and the AI Act. However, legal and non-legal respondents encountered difficulties classifying non-obvious cases, emphasizing the need for clearer frameworks and tools to enhance clarity and streamline the classification process. Greater clarity in the AI Act and an interdisciplinary approach were recommended to address these challenges and facilitate understanding of the risks associated with AI systems.

Based on the analysis, several areas for improving AI systems classification under the AI Act have been identified. The current classification process faces challenges related to ambiguities in definitions, lack of contextual information, and difficulties in distinguishing between different risk levels.

To address these challenges and enhance the classification process, it is recommended to introduce clearer guidelines and refine the decision tree used for classification. The decision tree should incorporate additional criteria and features that provide more clarity and context. It is important to consider biases, subjective interpretations, clarity, and the dynamic nature of AI technologies in these improvements.

The study has certain limitations. The small sample size of respondents may impact the generalizability of the findings. The number of participants might not be representative of the entire population. Additionally, the limited number of use cases utilized in the research may limit the comprehensiveness of the classification framework. The study is based on the latest amendment of a policy proposal, and there is a potential for changes in the regulation's details, which may affect the effectiveness of the results. Finally, potential biases may exist in the development of the research, such as in making the decision tree and selecting the use cases.

Future research should explore the continuity of the decision tree's performance over time and its evaluation. There should be more research on non-obvious cases in specific domains or industries. It is crucial to focus on potential issues in classifying certain risk levels in the AI Act that hinder classification accuracy. Understanding the differences between legal and non-legal perspectives on the AI Act is also important to establish standardized understanding among stakeholders. Additionally, conducting quantitative research with larger and more diverse respondents from industrial backgrounds can further evaluate the proposed framework. ...

The impact of onboard sensors on road logistics to improve the estimation accuracy of emission factors

Master thesis (2023) - N. Will, L.A. Tavasszy, J.A. Annema, J. Ubacht, Tobias Bohnhoff
The transport sector is one of the most significant contributors to European GHG emissions and is expected to grow even further in the coming years. The target of the European Union to reduce transport-related GHG emissions by 55% by 2030 seems to be a challenging task, keeping in mind the projected growth rates of the sector. In order to achieve the set-out targets, transparent and standardised GHG emissions quantification methodologies and reporting schemes must exist to monitor the GHG emissions of vehicles and reduce them where possible. Vehicle emissions used to be approximated with standard emission factors per vehicle class. However, the accuracy of these traditional emission factors is limited, especially on a larger scale, such as the European Union, leading to inaccurate vehicle emissions. Thus, primary fuel consumption data could be used to calculate the emissions of vehicles accurately by collecting the primary data via onboard sensors. The combination of data management structures for primary data in road logistics with the possibility of improving the accuracy of emissions calculations and reporting from a socio-technical perspective is currently not sufficiently addressed in scientific literature. The study is also highly relevant from a private interest, as new legislative decisions force private companies to declare their emissions on only validated and correct emissions factors.

The research aimed to investigate the current practices of using vehicles’ primary data to improve GHG emissions’ accuracy by creating a system architecture for the data flow from the vehicle to the final visualisation of the GHG emissions. For that, the design science research methodology (DSRM) approach was chosen to answer the main research question of:

”What onboard sensor systems architecture can enable road logistics operators to gather primary data from their fleet to accurately determine their vehicle emissions?”

Four sub-questions were formulated in line with the used DSRM design cycle to answer the main research question and to contribute to the existing body of knowledge via a socio-technical analysis, system requirements, system architecture, and an evaluation.

The research utilised interviews, scientific literature, and informal conversations with industry players as the main knowledge source. The expert interviews were first used during the design process to understand the environment, derive system requirements for the later design, and to create a stakeholder overview. In the second phase of the research, the experts were utilised to evaluate the created design. Interview partners were selected based on their role in the system and potential expertise to help steer the design and evaluation. The feedback received was directly implemented in the designs.
The first step of the analysis was the socio-technical analysis. It revealed the first requirements and design principles for the later design phase, based on the institutional setting and stakeholder demands derived from interviews and the available literature. It also showcased the active and influencing role of the EU in the system, which underlined the need for a socio-technical analysis. Lastly, the stakeholder overview visualised the transport sector’s highly fragmented and multi-stakeholder domain, which industry experts evaluated and approved.

The complete system requirements were established and finalised in the second phase of the research. They were separated into three clusters: institutional, stakeholder, and technical-related requirements and were further categorised into functional and non-functional system requirements. Design principles were also created to steer the design process. Six functional and ten non-function system requirements were derived and four design principles. The requirements were evaluated and approved by the expert interviews and were used as the main input for the design phase. The main conclusion was the stakeholder-specific characteristic of some of the requirements due to the different needs of logistical actors and related IT companies that calculated GHG emissions.

The third phase was the designing of the system architecture. It was separated into two parts. First, the creation of a list of possible design options to address the derived system requirements with another evaluation round with the expert. Second, the creation of the system architecture by creating system architecture components, which incorporate the most fundamental design options from the design phase. The experts again evaluated these system architecture components before they were incorporated into stakeholder-specific system architecture, which captured the overarching processes and data flows of an IT company that specialised in the quantification of GHG emissions of vehicles in road logistics. The main conclusion was that, due to the diversity of system stakeholders, a general system architecture that adresses all stakeholder needs is less feasible than the creation of stakeholder-specific system architectures.

The fourth phase was the evaluation, which happened throughout all stages of this research, and concluded the general correctness of the derived stakeholder-specific system architecture by the experts. It also pointed out potential limitations of the designs. The specific knowledge needed to validate such designs of the technical domain (data management structures), the policy and institutional knowledge, and the specific details of state-of-the-art GHG quantification methodologies makes evaluating the entire system more challenging. Thus, a broad sample of interview partners was needed. Moreover, selecting a design option, especially in the perception and physical layer of the system architecture, can create path dependencies and narrow down the design space. The evaluation phase was concluded by addressing the general success factors of the proposed design. Here the willingness of the logistical operators to adopt the GHG emissions reporting, the importance of methodology alignments and the need for truly value-adding services were especially highlighted as success factors of the system architecture.

The research concluded by recognising the great potential of primary data to improve the accuracy of emission factors in road logistics. Seven main conclusions and contributions to the field of logistics were made:
1. The inclusion of a multi-domain designer perspective when designing an abstract system architecture in the logistical sector - should be mandatory in the scoping of any project.
2. The identification of relevant stakeholder clusters and an abstract stakeholder analysis to be considered when designing in the socio-technical environment.
3. The categorization of systems requirements into institutional, stakeholder and technical requirements to represent the multi-domain character of the system.
4. The need for financial quantification tools of the CO2 reduction for logistical operators to validate their investment decisions.
5. Compliance with leading European GHG emissions quantification methodologies and data regulations - should also be implemented, e.g. in the EU taxonomy.
6. A stakeholder cluster-specific system architecture, which incorporated the derived requirements and outlined business relationships and data flows in the system, evaluated and approved by industry experts.
7. The issue of the stakeholder-specific requirements for the system leading to multiple co-existing system architecture specifications.


Finally, the research concluded with a short and long-term outlook of how the sector might develop and presented potential future research topics, such as the possibility of using other forms of data sharing, such as data spaces or blockchain applications, for secure and trusted data sharing. ...
Master thesis (2023) - E. Nieuwlaar, J.A. Pouwelse, C. Lofi, J. Ubacht
The European Commission is developing a European Digital Identity (EDI), which will enable a trustworthy digital proof of identity for its citizens. We present a proof of identity in combination with cryptographic evidence of the natural person being authorized to act on behalf of a legal entity. Our study achieves this by connecting users of our system with trusted issuers, the European Blockchain Services Infrastructure (EBSI), and verifiers. Accordingly, we provide a zero-trust architecture for legal entity representation, making trust portable by providing irrefutable proof of a natural person acting as a legal representative of an organization. Our zerotrust architecture aims to change how we represent legal entities and delegate authorizations with powers of attorney (PoA) as a legal primitive, making trust portable and secure. With government assistance, we conducted a pilot deployment of our prototype with live connectivity to the legal source of truth, the Kamer van Koophandel (KVK). In our pilot, a commercial business-only retailer acted as the verifier of the PoA. We shorten legally binding delegation that is cross-border, decentralized, verifiable, and revokable from a week-long process to mere seconds. ...

Designing policy recommendations for public blockchains to transition towards a quantum-safe environment

Since Bitcoin’s genesis block validated the concept of blockchain technology, the domain has experienced rapid growth and innovation. While mass adoption remains a challenge, numerous applications have demonstrated substantial potential, establishing blockchain as a leading frontier of technological advancement. Originally emphasizing decentralization and individual freedom without external interference, the space is gradually shifting due to mainstream institutional adoption and increasing retail and institutional investments. Consequently, the debate around regulation has intensified, raising the central question: “For what reasons, and to what extent, should one regulate the blockchain domain?”

This research addresses this question within the context of the emerging quantum threat to blockchain. Quantum computing capabilities are progressing exponentially, surpassing Moore’s Law in computational growth, and are expected to reach the level of Cryptographically Relevant Quantum Computers (CRQCs) within the coming decade(s). At this stage, quantum algorithms such as Shor’s and Grover’s will threaten existing public-key cryptography, including blockchain security. Failure to transition to quantum-safe protocols risks undermining trust, destabilizing infrastructure, and compromising user funds. Therefore, preparing for a quantum-secure blockchain environment is critical.

The objective of this research is to provide an overview of recommendations that support blockchain’s timely transition to quantum safety. Recommendations encompass regulatory and policy guidance, technical strategies, and community engagement approaches. The methodology combines literature review, secondary data analysis, market analysis, case studies, and expert interviews. The technical chapter explores post-quantum cryptography options, evaluating trade-offs and considerations for integration into existing blockchain architectures, culminating in a technical framework for practitioners.

The organizational perspective analyzes blockchain governance, including decentralized change mechanisms and stakeholder influence. A market analysis of the top 100 cryptocurrency projects assessed their quantum-awareness, research activities, and adoption of mitigation strategies, forming the basis of the N.A.R.A.Q. framework. Additionally, 30 interviews with blockchain founders, project leads, CEOs, CTOs, cybersecurity experts, and post-quantum cryptosystem designers provided insights into the perceived threats, regulatory perspectives, barriers, and enablers for transitioning to quantum safety.

The study integrates these findings into actionable recommendations, proposing the Quantum-Secure Stamp of Approval (QSSA) and an enhanced N.A.R.A.Q. framework. The implications for Non-Quantum-Secure Blockchain Technologies (NQSBTs) are addressed, alongside policy recommendations targeting regulators, stakeholders, and the broader blockchain community. The research emphasizes collaborative efforts and external institutional support while analyzing key obstacles and barriers to adoption.

Ultimately, the study highlights the delicate balance between regulation and innovation. While regulatory frameworks can protect users and investors, overregulation or lack of technological understanding may hinder innovation. The findings aim to guide policymakers and blockchain stakeholders in facilitating a smooth transition to a quantum-safe environment, ensuring security, trust, and continued technological progress. By providing a foundation for discussion, this research contributes to strategic planning for the future of blockchain in a post-quantum era. ...
Master thesis (2022) - A. Chen, E.J.L. Chappin, J. Ubacht
As the Earth's temperature rises, it is critical that countries address and adapt to climate change. The European Union (EU) is committed to achieving carbon neutrality by 2050 (European Commission, 2018).The cornerstone of the EU’s climate policy to combat climate change is the EU Emission Trading System (ETS). It is the world’s first major compliance carbon market and remains the biggest one. Currently, the focus of the EU is to strengthen the market of the EU ETS for the next decade and beyond (European Commission, 2022-a). An important development in this phase is the recognition of global carbon markets to reduce global GHG emissions effectively. Three main challenges of ETSs are identified in this research: lack of system compatibility to link with other ETSs, security issues, and (manual) monitoring of transactions. To realize the full potential of ETSs, the added value of a blockchain-based architecture to support the carbon trading market and counteract the current deficiencies is explored. Although the reviewed literature is useful to identify the possibilities of blockchain solutions to address the current challenges in ETSs, it is not clear how the current EU compliance market could allow extension by providing a large, transparent, verifiable, interoperable, and robust carbon system. Research about blockchain-based EU ETSs would contribute so that the development of global carbon markets could happen. This results in the following main research question: What blockchain-based design can be used by the European Union to improve the technical design of the EU ETS while allowing for the extension to other Emission Trading Systems?. For this research project, a Design Science Research (DSR) approach is taken to ensure a discipline-oriented creation of a successful design that addresses the challenges in the EU ETS. This research proposes a blockchain-based solution that is able to cover the core functions of the system while actively improving system compatibility, preventing security issues and non-transparency, and enable automatized monitoring of transactions. It is concluded that the proposed design is able to improve the current system by enabling extension to other ETSs, automatizing manual processes, providing data security through encryption, and providing transparency in the narket and trade of emission allowances. Additionally, this research provides a blockchain governance framework to align policy and stakeholder interests with governance and technical blockchain control points in the emission trading sector. Besides contributing to closing a gap in a growing research field, the use of the architecture offers a technological solution in which systems can be integrated with each other without having to throw away the existing principles. This is beneficial because these existing principles have been developed after a great amount of learnings, investments, and experience. Also, the design enables more authorities to join a system that is already running while also able to have a say in the governance. This could lead to convergence of market mechanisms and prices where as a result, a more efficient and unified carbon market will emerge. ...

Solving IoT vulnerabilities through governance

Master thesis (2021) - T. de Roon, S.E. Parkin, M.J.G. van Eeten, J. Ubacht, R. Krenn
Connecting ‘things’ like a doorbell, webcam, lamp, or other objects to the web to provide a service or control is called the Internet of Things (IoT). These devices contain vulnerabilities that form risks for the device user and possibly the network owner through their heterogeneity. The identified knowledge gap is the need for more IoT governance but no specification on governance options and means to reach specific stakeholders. Using a dataset of network scan data of The Hague as the empirical context for the defined knowledge gap, this research aims to look into the vulnerabilities IoT devices carry, and then look into relevant stakeholders to see what they can do through governance and why they are not doing this. To answer the main research question: How can the municipality of The Hague use governance instruments to decrease cyber vulnerabilities in IoT devices?
Using a literature study to define IoT concepts and the governance of IoT and current governance examples, background information is provided for the rest of this research. The database of 1649 IP addresses of network scan data from the area of The Hague is then used to find what vulnerabilities are present and what stakeholders are identifiable from this data. Exploring this network scan data showed only 191 devices are fully identifiable from the total number of IP addresses. These devices all carry vulnerabilities for the user of these devices, and being visible is by itself a vulnerability. No device owners could be directly identified, only the providers of the networks these devices are found in. This results in the identifiable stakeholders from the dataset: ISPs and device manufacturers.
Governance options are defined for these stakeholders (e.g. security-by-design, informing users etc.). These options are assessed on viability and validity through semi-structured interviews with three ISPs and the municipality.
The conclusion found is that the most viable action to take is informing device users since secure configuration and usage of a device would take away vulnerabilities while waiting for European legislation to be implemented. This legislation will force more security-by-design. The recommendation for the municipality is to take the role of leading actor, provide a better problematization with the data available, and use this to generate more urgency with other stakeholders. Starting public-private partnerships (with ISPs, device vendors, universities, other municipalities: different perspectives to progress the problem) and starting information campaigns and therefore try to reach as many people as possible. Even though ISPs can not provide in reaching vulnerable users directly, they can help in general information campaigns. Increasing security practices on the user side while waiting for legislation on the manufacturer's side.
...
Master thesis (2020) - Diego Valdivia, J.H.R. van Duin, J. Ubacht, L.A. Tavasszy, Bernd van Dijk
The rise of e-commerce has led to a congested last-mile delivery paradigm. Increasing customer expectations have pushed carriers into a delivery market with diminishing profitability. Furthermore, the current state of last-mile delivery has high societal costs in congestion and environmental impact. To address these challenges, scientists in the logistics field have proposed multimodal transport and collaborative delivery. However, current centralized logistics planning systems are unable to cope with the complexity that these solutions pose. For this reason, Thymo Vlot developed a Self-Organizing Logistics algorithm that leverages decentralization to enable multimodal transport and collaborative delivery. However, the logistics planning system that would utilize this algorithm was left undeveloped, which motivates this thesis project. The first step to develop a software project is to define its architecture. In this thesis project, I analyze Thymo Vlot’s algorithm and develop the software architecture of a logistics planning system that would use it. The main design tool consisted of the selection and application of architectural patterns, which are documented solutions to commonplace problems in software development, drawn from the literature and modern distributed systems. The result of this project is an event-driven microservices architecture, which is highly granular, modifiable, and scalable. These characteristics give the project significant commercial value, as the architecture can be applied to different use cases with different algorithms. The project also leaves behind an architecture with small components, which eases the development cycle of the logistics planning system, thus addressing important managerial challenges. Finally, this project makes significant scientific contributions by developing a software solution that addresses managerial, societal, and environmental challenges of last-mile delivery, thus providing a stepping stone for further research that bridges the gap between the logistics and computer science fields. ...