MIT Cybersecurity Clinic Empowers Municipalities Against Growing Ransomware Threat

In May 2019, the city of Baltimore, Maryland, became a stark example of a growing crisis: a ransomware attack that crippled its digital infrastructure, locking down critical files and demanding a hefty payment for their release. The city’s courageous decision to refuse the ransom, while ethically sound, led to a prolonged period of disruption, impacting essential services like real estate transactions and bill payments. The ensuing recovery efforts incurred costs that ballooned into the millions, highlighting the profound financial and operational vulnerabilities faced by municipal governments in the digital age. This incident, now a central case study in MIT’s Urban Studies and Planning Department, underscores the escalating threat of ransomware attacks on public sector agencies.
To combat this pervasive danger, Lecturer Jungwoo Chun and Ford Professor of Urban and Environmental Planning Lawrence Susskind established the MIT Cybersecurity Clinic in 2019. This innovative program, offered nearly every semester since its inception, functions as a dual-purpose initiative: providing invaluable hands-on training for students while simultaneously offering pro-bono cybersecurity assessments to communities at risk. The clinic’s model, akin to legal or medical clinics, allows students to gain practical experience and contribute directly to public good.
The Clinic’s Model: Education Meets Public Service
After completing rigorous instructional modules and passing a certification exam, students are meticulously assigned to teams, each tasked with serving a specific client. Throughout the semester, these teams conduct comprehensive vulnerability assessments, meticulously documenting potential weaknesses in their client’s cybersecurity posture. The culmination of their work is a detailed report offering actionable recommendations for enhancing digital defenses. To date, the MIT Cybersecurity Clinic has delivered over 40 confidential and complimentary assessments, predominantly serving municipalities and healthcare organizations across New England.
The urgency of the clinic’s mission is underscored by alarming statistics. In 2025 alone, the FBI’s Internet Crime Complaint Center reported an average of 2,765 cyberattacks targeting Americans daily. When these attacks strike at the heart of municipal operations, the consequences extend far beyond financial losses. As Jungwoo Chun eloquently states, "There’s a terrifying, cascading effect on every dimension of our lives." Recent years have witnessed cyberattacks jeopardizing public water supplies, disrupting 911 and police services, and compromising sensitive personal data of citizens in communities served by the clinic.
The Cybersecurity Gap in Public Service
A significant contributing factor to this vulnerability is the chronic understaffing of cybersecurity expertise within many small municipalities and healthcare facilities. Despite being critical gateways to essential infrastructure, these organizations often lack dedicated in-house cybersecurity professionals. The demand for such specialists in the current labor market far outstrips the available supply. Furthermore, public sector budgets are frequently outmatched by the high salaries offered by private companies, making it exceedingly difficult for government entities to attract and retain qualified cybersecurity talent.
Compounding this issue, data from Comparitech reveals a troubling trend: between 2018 and 2024, the United States experienced 525 ransomware attacks on government entities, averaging approximately one attack every five days. These incidents resulted in an estimated $1.09 billion in downtime costs, a staggering figure that reflects the profound economic impact of these breaches.
Lawrence Susskind emphasizes the need for a self-sufficient approach for underfunded public and not-for-profit organizations. "There are many low-cost moves that these organizations can implement with a little coaching from a free-service clinic," he asserts, highlighting the clinic’s role in providing accessible guidance.
A Novel Approach: Defensive Social Engineering
The placement of a cybersecurity program within MIT’s Department of Urban Studies and Planning, rather than a traditional computer science department, is a deliberate choice that underscores its unique methodology. Jungwoo Chun, an applied social scientist with expertise in public policy and planning, and Lawrence Susskind, a renowned scholar of conflict resolution and consensus building, have pioneered an approach they term "defensive social engineering." This framework recognizes that cybersecurity is not solely a technical challenge but is deeply intertwined with human behavior and organizational dynamics.
While acknowledging the escalating sophistication of cyber threats, particularly with the advent of artificial intelligence, Chun notes, "Now AI can not only identify the vulnerability, but do the attack itself, which is really scary." The course dedicates significant attention to the technical intricacies of cybersecurity, yet Chun firmly believes, "At the end of the day, the biggest attack vector is still through humans."
The concept of "social engineering" in cybersecurity typically refers to the manipulation of individuals into compromising security protocols, such as divulging sensitive information or falling victim to phishing scams. Susskind and Chun’s "defensive social engineering" flips this on its head, leveraging an understanding of human psychology to build resilience. Their approach stresses that cybersecurity is an all-encompassing responsibility, extending beyond the purview of IT departments to every member of an organization, regardless of their technical background.
"It’s about people knowing what to do, people making the right choices," Chun explains. "It’s helping them use the resources and budget they have now on things that can be long-lasting, rather than just spending on the latest antivirus software."
Interdisciplinary Training for Holistic Security
Students entering the clinic, regardless of their disciplinary background, gain a more comprehensive understanding of cybersecurity. Susskind observes that students with computer science backgrounds are often surprised by the emphasis placed on building organizational capacity. "Students need to understand the leadership dynamics in their client communities. The IT director can’t just do what she or he wants. They depend on the local government for their budget. They need approval to hire new staff."
Conversely, students from planning or social science disciplines, who might be drawn to "smart city" initiatives, may lack a deep understanding of the technologies required to manage associated risks. Engineering students, too, may not encounter crucial aspects of cybersecurity, such as cyber law, advanced system design, or the nuances of AI in their other coursework. The MIT Cybersecurity Clinic aims to bridge these knowledge gaps, fostering a well-rounded understanding for all participants. To further enrich the learning experience, the course regularly hosts guest speakers from industry, academia, and relevant public agencies, offering diverse perspectives on the ever-evolving cybersecurity landscape.
This past spring, for instance, the clinic featured distinguished speakers such as Dan Ricci, founder of Industrial Data Works, who discussed risk modeling in budget-constrained energy systems; Gus Serino, president of I&C Secure Inc., on operational technology cybersecurity for industrial control systems; and representatives from the MassCyberCenter and the Cybersecurity and Infrastructure Security Agency, who provided overviews of state and federal programs.
Susskind acknowledges the necessity of external expertise, particularly regarding the impact of AI on cybersecurity. "There are highly specialized things to learn, especially about the ways AI is changing cybersecurity, that we need help teaching," he states. "The rate at which the field of cybersecurity is changing means that most academics will have a very hard time keeping up."
A Structured Roadmap for Enhanced Security
The clinic’s pedagogical structure is designed to prepare students thoroughly for their fieldwork. The initial four weeks are dedicated to intensive preparation through online modules and class discussions. These modules delve into the nature of cyberattacks targeting critical urban infrastructure, explore 23 key risk areas relevant to client organizations, and provide step-by-step guidance for conducting vulnerability assessments. Crucially, the curriculum includes simulations of challenging client interactions, preparing students for scenarios where clients may be skeptical, uncooperative, or attempt to downplay security risks.
Diego Contreras, a rising senior majoring in computer science and engineering who completed the course, found the preparation to be exceptionally realistic. "I’ve never ever had a class that prepared us for such realistic scenarios before," he remarked.
Upon successfully passing a first-attempt certification exam, students are eligible for field assignments. For the remainder of the semester, they receive ongoing support through weekly meetings and faculty feedback on their draft reports. However, the responsibility for coordinating team activities and cultivating client trust rests squarely on the students’ shoulders.
"You represent MIT, and that is quite the responsibility," Contreras shared. "This course has given me people skills I wouldn’t have developed in any other context."
Zev Moore ’26, a student studying mathematical economics and finance who took the class last fall, highlighted the delicate art of delivering critical feedback. "The most delicate aspect of the project was balancing our assessment findings," he explained. "Our approach was to provide important feedback while simultaneously validating the positive security measures our client already had in place, which ensured our report felt like a collaborative roadmap for improvement."
Common Recommendations for Broad Impact
Across the majority of their assessment reports, the clinic’s students consistently recommend a core set of actionable security measures. These include:
- Asset Inventory: Maintaining a comprehensive inventory of all hardware and software connected to the network, along with tracking user access.
- Regular Patching and Backups: Implementing consistent software patching schedules and robust data backup protocols.
- Multi-Factor Authentication (MFA) and Password Policies: Mandating MFA and enforcing frequent password updates.
- Employee Training: Educating staff to be vigilant against suspicious email attachments and links.
- Incident Response Planning: Developing a clear attack response plan that outlines lines of authority and the organization’s stance on ransom payments.
- Vendor Vetting: Ensuring that all third-party vendors adhere to strong cybersecurity practices.
"None of these items is costly," Susskind emphasizes. "Together, they will probably avoid 80 percent or more of the possible cost and danger of cyberattacks."
Disseminating the Model and Fostering a Network
The MIT Cybersecurity Clinic has made a significant impact, with over 120 students completing the full course. The preparatory online modules are freely accessible to the public as a Massive Open Online Course (MOOC) on MITx, titled "Cybersecurity for Critical Urban Infrastructure," attracting tens of thousands of learners. Furthermore, the modules are being adopted by universities establishing their own cybersecurity clinics. This growing network is bolstered by a consortium co-founded by MIT in 2021 with the University of California at Berkeley, Indiana University, and the University of Alabama, which now comprises 61 member institutions.
While most student teams conclude their client engagements after delivering their reports, some have volunteered to provide ongoing support for implementation. Susskind and Chun maintain contact with clients for at least two years post-engagement, offering continued guidance.
"We often hear of the vulnerability assessment report serving as the organization’s blueprint for their short-term, mid-term, and long-term agenda to be more prepared for future attacks," says Chun. He notes that many IT directors and chief technology officers have used the MIT reports as leverage to secure necessary budget allocations or specific line items from their leadership. "They were using the student report as leverage to say, ‘it’s not just me saying it. We have a credible team who dedicated their time and these are the findings.’"
Chun concludes with a sentiment of profound satisfaction: "It’s really a humbling experience when some of our past clients reach out to us again after some time to say: ‘Now we have different people, we just purchased new equipment. Can we do this all over again?’" This recurring engagement speaks volumes about the enduring value and trust placed in the clinic’s work.







