2019 年 5 月, 巴尔的摩, 马里兰州, 政府陷入混乱。网络犯罪分子封锁了该市的许多关键文件,并要求付费才能解密这些文件。该市拒绝支付赎金。此次攻击导致一系列服务, 瘫痪,包括房地产交易和账单支付,,恢复成本飙升至数百万美元。
In May 2019, the government of Baltimore, Maryland, fell into chaos. Cybercriminals had locked the city out of many of its critical files and demanded payment to decrypt them. The city refused to pay ransom. The attack incapacitated a swath of services, including real estate transactions and bill payment, and recovery costs soared into the millions.
就像法律或医疗诊所, 一样,该课程既可以为学生提供实践培训,也可以为高危社区提供无偿服务。完成教学模块并通过认证考试后,, 的学生将被分组分配给客户。到学期结束时,,每个团队都会创建一份报告,评估客户’的网络攻击漏洞,并建议改进保护的步骤。到目前为止, 该诊所已提供了 40 多项评估, 保密且免费, 主要为新英格兰市政当局和医疗保健组织提供。
Much like a legal or medical clinic, the course doubles as hands-on training for students and a pro-bono service to at-risk communities. After completing instructional modules and passing a certification exam, students are assigned in teams to a client. By the end of the semester, each team creates a report assessing the client的 vulnerabilities to cyberattack and recommending steps to improve protection. So far, the clinic has provided more than 40 assessments, confidential and free of charge, primarily for New England municipalities and health-care organizations.
2025,,FBI的 互联网犯罪投诉中心平均每天记录 2,765 起针对美国人的网络攻击。 Chun: “ 说,当这些攻击袭击城镇, 时,后果将超出财务范围, 对我们生活的各个方面产生可怕的, 级联效应。”
In 2025, the FBI的 Internet Crime Complaint Center documented an average of 2,765 cyberattacks targeting Americans every day. When these attacks strike cities and towns, the fallout goes beyond finances, says Chun: “There的 a terrifying, cascading effect on every dimension of our lives.”
In recent years, cyberattacks targeting the kinds of client communities served by MIT的 clinic have imperiled water supplies, impeded 911 and police services, and exposed citizens personal data.
Despite being gateways to essential infrastructure, many small municipalities and hospitals lack in-house staff trained in cybersecurity.当今的劳动力市场,对此类专家的需求远远超过供应,公共部门预算很少能与私营公司提供合格候选人的高薪相匹配。
Despite being gateways to essential infrastructure, many small municipalities and hospitals lack in-house staff trained in cybersecurity. Demand for such experts far exceeds supply in today的 labor market, and public sector budgets rarely can match the high salaries private companies offer qualified candidates.
根据 Comparitech,,从 2018 年到 2024 年,,针对美国政府实体, 发生了 525 起勒索软件攻击,大约每五天发生一次,,导致停机成本估计为 $10.9 亿。
According to Comparitech, from 2018 to 2024, there have been 525 ransomware attacks on U.S. government entities, approximately one every five days, leading to an estimated $1.09 billion in downtime costs.
“资金不足的公共和非营利机构需要遵循自助途径,” Susskind 说。 “这些组织可以通过免费服务诊所的一点指导来实施许多低成本举措。”
“Underfunded public and not-for-profit bodies need to follow a self-help pathway,” Susskind says. “There are many low-cost moves that these organizations can implement with a little coaching from a free-service clinic.”
Some might be surprised to find a university cybersecurity program housed outside the computer science department. Chun is an applied social scientist with expertise in public policy and planning, and Susskind is a leading scholar of conflict resolution and consensus building. They call the approach they’ve developed for the clinic “defensive social engineering” to emphasize that cybersecurity isn’t solely a technical challenge.
Chun 承认,人工智能的快速发展为犯罪分子创造了令人震惊的新工具— “now AI 不仅可以识别漏洞,,还可以进行攻击本身,,这真的很可怕” — 以及不断发展的软件声称菜单可以防范这些攻击。 Accordingly, the course spends considerable time on the technical aspects of cybersecurity. “But at the end of the day,” Chun says, “the biggest attack vector is still through humans.”
Chun acknowledges that the rapid development of artificial intelligence has created alarming new tools for criminals — “now AI can not only identify the vulnerability, but do the attack itself, which is really scary” — and an ever-evolving menu of software claims to guard against these attacks. Accordingly, the course spends considerable time on the technical aspects of cybersecurity. “But at the end of the day,” Chun says, “the biggest attack vector is still through humans.”
The term “social engineering” commonly refers to ways cybercrime victims are manipulated into compromising security (for example, by sending money to a scammer, downloading malicious code, or disclosing sensitive information). Susskind 和 Chun的防御性社会工程概念同样以人类心理学为基础。该方法强调网络安全必须成为每个人’, 技术或其他工作的一部分。
The term “social engineering” commonly refers to ways cybercrime victims are manipulated into compromising security (for example, by sending money to a scammer, downloading malicious code, or disclosing sensitive information). Susskind and Chun的 concept of defensive social engineering is similarly grounded in human psychology. The approach emphasizes that cybersecurity must be part of everyone的 job, technical or otherwise.
Chun 说,“It 人们知道该做什么, 人们做出了正确的选择,”。 “It的 帮助他们将现有的资源和预算用于可以持久的,,而不是仅仅花费在最新的防病毒软件上。”
“It的 about people knowing what to do, people making the right choices,” says Chun. “It的 helping them use the resources and budget they have now on things that can be long-lasting, rather than just spending on the latest antivirus software.”
“Students with computer science backgrounds are surprised by the importance we attach to helping clients build organizational capacity,” says Susskind. “Students need to understand the leadership dynamics in their client communities. The IT director can’t just do what she or he wants. They depend on the local government for their budget. They need approval to hire new staff.”
On the other hand, Susskind says, students from planning or social science backgrounds often study smart city innovations without learning much about the technologies needed to manage the associated risks. And there are aspects of AI and advanced system design — along with cyber law and other topics critical to cybersecurity — that engineering students may not learn in their other courses.网络安全诊所旨在完善各学科学生的知识。 The course aims to broaden those students knowledge, too, by inviting at least half a dozen guest speakers each semester from industry, other universities and MIT academic departments, industry, and/or relevant public agencies.
On the other hand, Susskind says, students from planning or social science backgrounds often study smart city innovations without learning much about the technologies needed to manage the associated risks. And there are aspects of AI and advanced system design — along with cyber law and other topics critical to cybersecurity — that engineering students may not learn in their other courses. The Cybersecurity Clinic aims to round out the knowledge of students from every discipline. The course aims to broaden those students knowledge, too, by inviting at least half a dozen guest speakers each semester from industry, other universities and MIT academic departments, industry, and/or relevant public agencies.
This past spring, for example, the lineup of lecturers included Dan Ricci, the founder of Industrial Data Works, on the modeling of risk in energy systems within budget-constrained environments; Gus Serino, president of I&C Secure Inc., on operational-technology cybersecurity for industrial control systems; and representatives from the MassCyberCenter and the Cybersecurity Infrastructure Security Agency providing overviews of their respective state- and federal-level organizations programs and initiatives.
“There are highly specialized things to learn, especially about the ways AI is changing cybersecurity, that we need help teaching,” Susskind says. “The rate at which the field of cybersecurity is changing means that most academics will have a very hard time keeping up.”
诊所学生在学期的前四个星期准备实地作业。 A series of online modules, supplemented by class discussion, outline the scope and nature of cyberattacks against critical urban infrastructure; review the 23 risk areas most relevant to their type of clients; and provide guidance for each step of the assessment process.这包括模拟棘手的客户交互。 What if clients don’t take students seriously, or fail to provide the necessary information? What if they argue to receive a more positive assessment than the facts warrant?
Clinic students spend the first four weeks of the semester preparing for field assignments. A series of online modules, supplemented by class discussion, outline the scope and nature of cyberattacks against critical urban infrastructure; review the 23 risk areas most relevant to their type of clients; and provide guidance for each step of the assessment process. This includes simulations of tricky client interactions. What if clients don’t take students seriously, or fail to provide the necessary information? What if they argue to receive a more positive assessment than the facts warrant?
“I’ve never ever had a class that prepared us for such realistic scenarios before,” says Diego Contreras, a rising senior majoring in computer science and engineering who completed the course this spring.
The modules culminate in an exam students must pass on their first try to receive a field assignment. For the remainder of the semester, they’ll receive continued support via weekly class meetings and get faculty input on their drafted reports, but the onus is on students to coordinate their team的 activities and build client trust.
“You represent MIT, and that is quite the responsibility,” Contreras says. “This course has given me people skills I wouldn’t have developed in any other context.”
“ 该项目最微妙的方面是平衡我们的评估结果,” 泽夫摩尔 ’26, 说,他去年秋天作为一名高级学生学习数学经济学和金融学。 “我们的方法是提供重要反馈,同时验证我们的客户已经采取的积极安全措施,,这确保我们的报告感觉像是一个改进的协作路线图。”
“The most delicate aspect of the project was balancing our assessment findings,” says Zev Moore ’26, who took the class last fall as a senior studying mathematical economics and finance. “Our approach was to provide important feedback while simultaneously validating the positive security measures our client already had in place, which ensured our report felt like a collaborative roadmap for improvement.”
Certain key recommendations show up in the majority of reports.例如, 建议客户清点与其网络相关的所有硬件和软件,并跟踪谁可以访问; 补丁软件并定期备份数据; 需要多重身份验证和频繁的密码更新; 培训员工不要打开来自未知方的附件; 准备一份攻击响应计划,明确权限并包括组织的 对支付赎金的立场; 并且仅使用具有良好网络安全卫生状况的供应商。
Certain key recommendations show up in the majority of reports. For example, clients are advised to inventory all hardware and software tied into their network and track who has access; patch software and back up data regularly; require multi-factor authentication and frequent password updates; train employees not to open attachments from unknown parties; prepare an attack response plan that clarifies lines of authority and includes the organization的 stance on paying ransoms; and only use vendors with good cybersecurity hygiene.
“None of these items is costly,” Susskind says. “Together, they will probably avoid 80 percent or more of the possible cost and danger of cyberattacks.”
To date, more than 120 students have completed the full course at MIT. The online modules that prepare students for certification are freely available to the public as a massive open online course on MITx called Cybersecurity for Critical Urban Infrastructure, which has attracted tens of thousands of learners. The modules are also used by universities with their own cybersecurity clinics — a growing cohort, thanks in part to a consortium (with 61 member institutions and counting) co-founded by MIT in 2021 with the University of California at Berkeley, Indiana University, and the University of Alabama.
Most student teams wrap up client work after finalizing their recommendations; a few have volunteered to stay on after semester的 end to advise on implementation. In either case, Susskind and Chun check in periodically with clients for at least two years following each engagement.
“We often hear of the vulnerability assessment report serving as the organization的 blueprint for their short-term, mid-term, and long-term agenda to be more prepared for future attacks,” says Chun. “We primarily work with IT directors or chief technology officers, and many of them have been telling us post-engagement that they shared the MIT report with the city or town leadership and were able to convince them they needed extra budget or a specific line item. They were using the student report as leverage to say, ‘it的 not just me saying it. We have a credible team who dedicated their time and these are the findings.’
“It的 really a humbling experience,” Chun adds, “when some of our past clients reach out to us again after some time to say: ‘Now we have different people, we just purchased new equipment. Can we do this all over again?’”