2019 年 5 月, 巴尔的摩, 马里兰州, 政府陷入混乱。网络犯罪分子封锁了该市的许多关键文件,并要求付费才能解密这些文件。该市拒绝支付赎金。此次攻击导致一系列服务, 瘫痪,包括房地产交易和账单支付,,恢复成本飙升至数百万美元。

In May 2019, the government of Baltimore, Maryland, fell into chaos. Cybercriminals had locked the city out of many of its critical files and demanded payment to decrypt them. The city refused to pay ransom. The attack incapacitated a swath of services, including real estate transactions and bill payment, and recovery costs soared into the millions.

就像法律或医疗诊所, 一样,该课程既可以为学生提供实践培训,也可以为高危社区提供无偿服务。完成教学模块并通过认证考试后,, 的学生将被分组分配给客户。到学期结束时,,每个团队都会创建一份报告,评估客户’的网络攻击漏洞,并建议改进保护的步骤。到目前为止, 该诊所已提供了 40 多项评估, 保密且免费, 主要为新英格兰市政当局和医疗保健组织提供。

Much like a legal or medical clinic, the course doubles as hands-on training for students and a pro-bono service to at-risk communities. After completing instructional modules and passing a certification exam, students are assigned in teams to a client. By the end of the semester, each team creates a report assessing the client的 vulnerabilities to cyberattack and recommending steps to improve protection. So far, the clinic has provided more than 40 assessments, confidential and free of charge, primarily for New England municipalities and health-care organizations.

2025,,FBI的 互联网犯罪投诉中心平均每天记录 2,765 起针对美国人的网络攻击。 Chun: “ 说,当这些攻击袭击城镇, 时,其后果将超出财务范围, 对我们生活的各个方面产生可怕的, 级联效应。”

In 2025, the FBI的 Internet Crime Complaint Center documented an average of 2,765 cyberattacks targeting Americans every day. When these attacks strike cities and towns, the fallout goes beyond finances, says Chun: “There的 a terrifying, cascading effect on every dimension of our lives.” 

近年来,针对 MIT 诊所服务的各类客户社区的, 网络攻击危及了供水,,阻碍了 911 和警察服务,,并暴露了公民的个人数据。

In recent years, cyberattacks targeting the kinds of client communities served by MIT的 clinic have imperiled water supplies, impeded 911 and police services, and exposed citizens personal data.

尽管是通往重要基础设施,的门户,但许多小城市和医院缺乏接受过网络安全培训的内部工作人员。当今的劳动力市场,对此类专家的需求远远超过供应,公共部门预算很少能与私营公司提供合格候选人的高薪相匹配。

Despite being gateways to essential infrastructure, many small municipalities and hospitals lack in-house staff trained in cybersecurity. Demand for such experts far exceeds supply in today的 labor market, and public sector budgets rarely can match the high salaries private companies offer qualified candidates.

根据 Comparitech,,从 2018 年到 2024 年,,针对美国政府实体, 发生了 525 起勒索软件攻击,大约每五天发生一次,,导致停机成本估计为 $10.9 亿。

According to Comparitech, from 2018 to 2024, there have been 525 ransomware attacks on U.S. government entities, approximately one every five days, leading to an estimated $1.09 billion in downtime costs.  

“Underfunded public and not-for-profit bodies need to follow a self-help pathway,” Susskind says. “There are many low-cost moves that these organizations can implement with a little coaching from a free-service clinic.”

有些人可能会惊讶地发现大学网络安全项目位于计算机科学系之外。 Chun 是一位应用社会科学家,拥有公共政策和规划, 方面的专业知识,Susskind 是解决冲突和建立共识方面的领先学者。他们将’为诊所开发的方法称为“防御性社会工程”,以强调网络安全’不仅仅是一个技术挑战。

Some might be surprised to find a university cybersecurity program housed outside the computer science department. Chun is an applied social scientist with expertise in public policy and planning, and Susskind is a leading scholar of conflict resolution and consensus building. They call the approach they’ve developed for the clinic “defensive social engineering” to emphasize that cybersecurity isn’t solely a technical challenge.

Chun 承认,人工智能的快速发展为犯罪分子创造了令人震惊的新工具— “now AI 不仅可以识别漏洞,,还可以进行攻击本身,,这真的很可怕” — 以及不断发展的软件声称菜单可以防范这些攻击。因此, 该课程在网络安全的技术方面花费了大量时间。 “但最终,” Chun 说, “最大的攻击媒介仍然是通过人类。”

Chun acknowledges that the rapid development of artificial intelligence has created alarming new tools for criminals — “now AI can not only identify the vulnerability, but do the attack itself, which is really scary” — and an ever-evolving menu of software claims to guard against these attacks. Accordingly, the course spends considerable time on the technical aspects of cybersecurity. “But at the end of the day,” Chun says, “the biggest attack vector is still through humans.”

术语 “ 社会工程” 通常指的是操纵网络犯罪受害者损害安全的方式 (,例如, 通过向骗子, 汇款、下载恶意代码, 或泄露敏感信息)。 Susskind 和 Chun的防御性社会工程概念同样以人类心理学为基础。该方法强调网络安全必须成为每个人’, 技术或其他工作的一部分。

The term “social engineering” commonly refers to ways cybercrime victims are manipulated into compromising security (for example, by sending money to a scammer, downloading malicious code, or disclosing sensitive information). Susskind and Chun的 concept of defensive social engineering is similarly grounded in human psychology. The approach emphasizes that cybersecurity must be part of everyone的 job, technical or otherwise.

Chun 说,“It 人们知道该做什么, 人们做出了正确的选择,”。 “It的 帮助他们将现有的资源和预算用于可以持久的,,而不是仅仅花费在最新的防病毒软件上。”

“It的 about people knowing what to do, people making the right choices,” says Chun. “It的 helping them use the resources and budget they have now on things that can be long-lasting, rather than just spending on the latest antivirus software.”

“具有计算机科学背景的学生对我们对帮助客户建立组织能力的重视感到惊讶,” Susskind 说。 “学生需要了解其客户社区的领导力动态。 IT 主管不能 只做她或他想做的事。他们的预算取决于当地政府。 They need approval to hire new staff.”

“Students with computer science backgrounds are surprised by the importance we attach to helping clients build organizational capacity,” says Susskind. “Students need to understand the leadership dynamics in their client communities. The IT director can’t just do what she or he wants. They depend on the local government for their budget. They need approval to hire new staff.”

另一方面,, Susskind 表示,来自规划或社会科学背景的, 学生经常研究智慧城市创新,但没有了解太多管理相关风险所需的技术。人工智能和高级系统设计 — 的某些方面以及网络法和对网络安全至关重要的其他主题 — 是工程专业的学生在其他课程中可能不会学到的。网络安全诊所旨在完善各学科学生的知识。该课程旨在通过每学期邀请至少六位来自行业,其他大学和麻省理工学院学术部门,行业,和%2相关公共机构的客座演讲者来拓宽这些学生’的知识,。

On the other hand, Susskind says, students from planning or social science backgrounds often study smart city innovations without learning much about the technologies needed to manage the associated risks. And there are aspects of AI and advanced system design — along with cyber law and other topics critical to cybersecurity — that engineering students may not learn in their other courses. The Cybersecurity Clinic aims to round out the knowledge of students from every discipline. The course aims to broaden those students knowledge, too, by inviting at least half a dozen guest speakers each semester from industry, other universities and MIT academic departments, industry, and/or relevant public agencies.

例如,去年春天,,讲师阵容包括 Dan Ricci,,工业数据工作的创始人,,在预算有限的环境下对能源系统进行风险建模; Gus Serino, I&C Secure Inc. 总裁,,关于工业控制系统的操作技术网络安全; 以及来自 MassCyberCenter 和网络安全基础设施安全局的代表,提供各自州和联邦级别的概述 organizations programs and initiatives.

This past spring, for example, the lineup of lecturers included Dan Ricci, the founder of Industrial Data Works, on the modeling of risk in energy systems within budget-constrained environments; Gus Serino, president of I&C Secure Inc., on operational-technology cybersecurity for industrial control systems; and representatives from the MassCyberCenter and the Cybersecurity Infrastructure Security Agency providing overviews of their respective state- and federal-level organizations programs and initiatives.

“There are highly specialized things to learn, especially about the ways AI is changing cybersecurity, that we need help teaching,” Susskind says. “The rate at which the field of cybersecurity is changing means that most academics will have a very hard time keeping up.”

诊所学生在学期的前四个星期准备实地作业。一系列在线模块, 辅以课堂讨论, 概述了针对关键城市基础设施; 的网络攻击的范围和性质; 审查了与其客户类型; 最相关的23 个风险领域,并为评估过程的每个步骤提供了指导。这包括模拟棘手的客户交互。如果客户不’不认真对待学生,或未能提供必要的信息?如果他们主张接受比事实更积极的评估怎么办?

Clinic students spend the first four weeks of the semester preparing for field assignments. A series of online modules, supplemented by class discussion, outline the scope and nature of cyberattacks against critical urban infrastructure; review the 23 risk areas most relevant to their type of clients; and provide guidance for each step of the assessment process. This includes simulations of tricky client interactions. What if clients don’t take students seriously, or fail to provide the necessary information? What if they argue to receive a more positive assessment than the facts warrant?

“I 以前从未有过一门让我们为如此现实的场景做好准备的课程,” 迭戈·孔特雷拉斯, 说,他是计算机科学与工程专业的大四学生,今年春天完成了这门课程。

“I’ve never ever had a class that prepared us for such realistic scenarios before,” says Diego Contreras, a rising senior majoring in computer science and engineering who completed the course this spring.

这些模块的最终结果是学生必须在第一次尝试中通过考试才能获得现场作业。 For the remainder of the semester, they’ll receive continued support via weekly class meetings and get faculty input on their drafted reports, but the onus is on students to coordinate their team的 activities and build client trust.

The modules culminate in an exam students must pass on their first try to receive a field assignment. For the remainder of the semester, they’ll receive continued support via weekly class meetings and get faculty input on their drafted reports, but the onus is on students to coordinate their team的 activities and build client trust.

“You represent MIT, and that is quite the responsibility,” Contreras says. “This course has given me people skills I wouldn’t have developed in any other context.”

“ 该项目最微妙的方面是平衡我们的评估结果,” Zev Moore ’26, 说,他去年秋天作为一名高级学生学习数学经济学和金融学。 “我们的方法是提供重要反馈,同时验证我们的客户已经采取的积极安全措施,,这确保我们的报告感觉像是一个改进的协作路线图。”

“The most delicate aspect of the project was balancing our assessment findings,” says Zev Moore ’26, who took the class last fall as a senior studying mathematical economics and finance. “Our approach was to provide important feedback while simultaneously validating the positive security measures our client already had in place, which ensured our report felt like a collaborative roadmap for improvement.”

某些关键建议出现在大多数报告中。例如, 建议客户清点与其网络相关的所有硬件和软件,并跟踪谁可以访问; 补丁软件并定期备份数据; 需要多重身份验证和频繁的密码更新; 培训员工不要打开来自未知方的附件; 准备一份攻击响应计划,明确权限并包括组织的 对支付赎金的立场; 并且仅使用具有良好网络安全卫生状况的供应商。

Certain key recommendations show up in the majority of reports. For example, clients are advised to inventory all hardware and software tied into their network and track who has access; patch software and back up data regularly; require multi-factor authentication and frequent password updates; train employees not to open attachments from unknown parties; prepare an attack response plan that clarifies lines of authority and includes the organization的 stance on paying ransoms; and only use vendors with good cybersecurity hygiene.

“这些物品都不贵,” Susskind 说。 “在一起,,他们可能会避免 80% 或更多的网络攻击可能造成的成本和危险。”

“None of these items is costly,” Susskind says. “Together, they will probably avoid 80 percent or more of the possible cost and danger of cyberattacks.”

迄今为止, 已有 120 多名学生完成了麻省理工学院的全部课程。为学生准备认证的在线模块作为 MITx 上的大型开放在线课程免费向公众开放,名为“关键城市基础设施网络安全,”,吸引了数万名学习者。拥有自己的网络安全诊所的大学也使用这些模块 — 不断增长的群体,,部分归功于麻省理工学院于 2021 年与加州大学伯克利分校, 印第安纳大学, 和阿拉巴马大学共同创立的联盟 (,该联盟拥有 61 个成员机构,数量)。

To date, more than 120 students have completed the full course at MIT. The online modules that prepare students for certification are freely available to the public as a massive open online course on MITx called Cybersecurity for Critical Urban Infrastructure, which has attracted tens of thousands of learners. The modules are also used by universities with their own cybersecurity clinics — a growing cohort, thanks in part to a consortium (with 61 member institutions and counting) co-founded by MIT in 2021 with the University of California at Berkeley, Indiana University, and the University of Alabama.

大多数学生团队在最终确定建议后都会结束客户工作;,少数人自愿在学期结束后留下来的 提供实施建议。无论哪种情况,, Susskind 和 Chun 在每次合作后至少两年内定期与客户进行检查。

Most student teams wrap up client work after finalizing their recommendations; a few have volunteered to stay on after semester的 end to advise on implementation. In either case, Susskind and Chun check in periodically with clients for at least two years following each engagement.

“我们经常听说漏洞评估报告充当组织'的短期,中期,和长期议程的蓝图,以便为未来的攻击做好更充分的准备,” Chun 说。 “我们主要与 IT 总监或首席技术官合作,,他们中的许多人在参与后告诉我们,他们与城市或城镇领导层分享了 MIT 报告,并能够说服他们需要额外预算或特定项目。他们利用学生报告作为杠杆来说, ‘it的,而不仅仅是我这么说。我们拥有一支值得信赖的团队,他们投入了时间,这些就是调查结果。’

“We often hear of the vulnerability assessment report serving as the organization的 blueprint for their short-term, mid-term, and long-term agenda to be more prepared for future attacks,” says Chun. “We primarily work with IT directors or chief technology officers, and many of them have been telling us post-engagement that they shared the MIT report with the city or town leadership and were able to convince them they needed extra budget or a specific line item. They were using the student report as leverage to say, ‘it的 not just me saying it. We have a credible team who dedicated their time and these are the findings.’

“It的 确实是一次令人谦卑的经历,” Chun 补充道, “ 当我们的一些过去的客户在一段时间后再次联系我们说: ‘现在我们有不同的人, 我们刚刚购买了新设备。我们可以重来一次吗?’”

“It的 really a humbling experience,” Chun adds, “when some of our past clients reach out to us again after some time to say: ‘Now we have different people, we just purchased new equipment. Can we do this all over again?’”