{"id":63316,"date":"2026-07-14T08:33:00","date_gmt":"2026-07-14T12:33:00","guid":{"rendered":"https:\/\/overcentral.com\/en\/?p=63316"},"modified":"2026-07-14T08:33:00","modified_gmt":"2026-07-14T12:33:00","slug":"mit-cybersecurity-clinic-ransomware-defense","status":"publish","type":"post","link":"https:\/\/overcentral.com\/en\/mit-cybersecurity-clinic-ransomware-defense\/","title":{"rendered":"MIT Students Defend Municipalities from Ransomware Attacks"},"content":{"rendered":"<p>When ransomware locked the city of Baltimore out of its critical systems in May 2019, the resulting chaos shut down real estate transactions and bill payments, ultimately costing millions in recovery. That case study is now a core teaching tool at <a href=\"https:\/\/overcentral.com\/en\/mit-music-technology-showcase\/\" title=\"MIT Music Technology Program Presents Inaugural Research Showcase\" data-iacss-internal=\"1\">MIT<\/a>, where a unique program has turned the fight against municipal cyberattacks into a live, semester-long clinic. The <a href=\"https:\/\/dusp.mit.edu\/\" target=\"_blank\" rel=\"noopener noreferrer\" data-iacss-external=\"1\">MIT Cybersecurity Clinic<\/a>, housed within the Department of Urban Studies and Planning (DUSP), has since provided over 40 free, confidential vulnerability assessments to New England municipalities and healthcare organizations, demonstrating that the most effective defense against digital extortion often begins not with code, but with human psychology and organizational structure.<\/p>\n<h2>The Rise of Ransomware in the Public Sector<\/h2>\n<p>The threat landscape for local governments is stark. In 2025, the <a href=\"https:\/\/overcentral.com\/en\/fbi-seizes-netnut-popabotnet\/\" title=\"FBI Seizes NetNut Proxy Platform, Popa Botnet\" data-iacss-internal=\"1\">FBI<\/a>\u2019s Internet Crime Complaint Center recorded an average of 2,765 cyberattacks targeting <a href=\"https:\/\/overcentral.com\/en\/imposter-scams-cost-americans-billions\/\" title=\"Imposter scams cost Americans $3.5 billion, worsening in 2025\" data-iacss-internal=\"1\">Americans<\/a> every single day. For small cities and towns, these attacks create cascading failures that threaten water supplies, disrupt 911 services, and expose citizens\u2019 personal data. According to Comparitech, 525 ransomware attacks on U.S. government entities occurred between 2018 and 2024\u2014roughly one every five days\u2014leading to an estimated $1.09 billion in downtime costs.<\/p>\n<p>The core problem is a critical resource gap: the public sector cannot compete with private industry for cybersecurity talent. While a hospital or town hall might have an IT director, they rarely have a dedicated security team. \u201cUnderfunded public and not-for-profit bodies need to follow a self-help pathway,\u201d explains MIT Ford Professor Lawrence Susskind. \u201cThere are many low-cost moves that these organizations can implement with a little coaching from a free-service clinic.\u201d<\/p>\n<h2>Defensive Social Engineering: A New Approach to Cybersecurity<\/h2>\n<p>What makes the MIT Cybersecurity Clinic distinctive is its academic home. It is not run by the computer science department but by DUSP, led by Lecturer Jungwoo Chun, an applied social scientist, and Susskind, a leading scholar in conflict resolution. They have termed their methodology \u201cdefensive social engineering.\u201d This framework acknowledges that while the technical arms race is accelerating\u2014AI can now identify vulnerabilities and execute attacks autonomously\u2014the largest attack vector remains the human one.<\/p>\n<p>The concept inverts the typical hacker tactic of social engineering (manipulating people into compromising security). Instead, defensive social engineering trains everyone in an organization to be a security asset. \u201cIt\u2019s about people knowing what to do, people making the right choices,\u201d says Chun. \u201cIt\u2019s helping them use the resources and budget they have now on things that can be long-lasting, rather than just spending on the latest antivirus software.\u201d This lens forces students to understand the political and budgetary realities their clients face. An IT director cannot simply demand new staff or software; they must convince a city council to allocate funds, often using the clinic\u2019s report as leverage.<\/p>\n<h2>How the MIT Cybersecurity Clinic Operates<\/h2>\n<p>The course, known as 11.074\/11.274 (Cybersecurity Clinic), functions like a legal or medical clinic. For the first four weeks, students complete instructional modules, covering the 23 most relevant risk areas for their clients, and must pass a certification exam. The curriculum includes simulations of difficult client interactions, such as being dismissed for being a student or managing expectations for a report\u2019s findings.<\/p>\n<p>Once certified, student teams are assigned to real clients, such as a small town government or a community hospital. The onus is on the students to coordinate, build trust, and conduct the assessment. \u201cYou represent MIT, and that is quite the responsibility,\u201d says Diego Contreras, a computer science and engineering senior who completed the course. \u201cThis course has given me people skills I wouldn\u2019t have developed in any other context.\u201d Teams produce a final deliverable: a confidential report that acts as a \u201croadmap for improvement,\u201d balancing critical feedback with validation of existing security measures.<\/p>\n<h3>Common, Low-Cost Recommendations That Make a High Impact<\/h3>\n<p>While every report is tailored, many share a core set of recommendations because they address fundamental vulnerabilities common to under-resourced organizations. These low-cost actions form the foundation of what Susskind calls a self-help pathway:<\/p>\n<ul>\n<li><strong>Hardware and software inventory:<\/strong> Track every device and application on the network, along with who has access.<\/li>\n<li><strong>Regular patching and backups:<\/strong> Ensure software is up to date and data is backed up in a way that cannot be encrypted by ransomware.<\/li>\n<li><strong>Multi-factor authentication:<\/strong> Mandate it across the board, along with frequent password updates.<\/li>\n<li><strong>Employee training:<\/strong> Teach staff not to open attachments from unknown sources and to recognize phishing attempts.<\/li>\n<li><strong>Incident response plan:<\/strong> Clarify lines of authority and establish a clear policy on paying ransoms (the clinic\u2019s guidance aligns with the standard advice: do not pay).<\/li>\n<\/ul>\n<p>Susskind estimates that these simple, affordable changes can prevent 80% or more of the potential cost and danger of cyberattacks.<\/p>\n<h2>How Does the Clinic Help Clients Implement Change?<\/h2>\n<p>The relationship does not end with the report. Faculty members follow up with clients for at least two years after each engagement. Many IT directors use the campus report as a formal document to convince city leadership to allocate a specific budget line item for cybersecurity. \u201cWe often hear of the vulnerability assessment report serving as the organization&#8217;s blueprint for their short-term, mid-term, and long-term agenda,\u201d says Chun. The clinic\u2019s credibility, borrowed from MIT, provides the external validation that many internal advocates need to secure funding for improvements.<\/p>\n<h2>Building a Scalable Model for Cybersecurity Education<\/h2>\n<p>The impact of the clinic extends beyond MIT. The online modules used for student certification are freely available as a massive open online course (MOOC) on MITx, titled <em>Cybersecurity for Critical Urban Infrastructure<\/em>, which has already attracted tens of thousands of learners. Furthermore, MIT co-founded a consortium (the <a href=\"https:\/\/cybersecurityclinic.org\/\" target=\"_blank\" rel=\"noopener noreferrer\" data-iacss-external=\"1\">Cybersecurity Clinics Consortium<\/a>) in 2021 alongside UC Berkeley, Indiana University, and the University of Alabama. The consortium now has 61 member institutions, all of which are adopting the model to start their own clinics, creating a scalable pipeline of free, high-quality cybersecurity assistance for vulnerable communities across the country.<\/p>\n<h2>What This Means for Municipalities and Other At-Risk Organizations<\/h2>\n<p>The MIT Cybersecurity Clinic proves that significant cyber resilience is achievable without massive technical investment. The program\u2019s success hinges on recognizing that cybersecurity is fundamentally a governance and human-management problem. For any small municipality or healthcare organization currently feeling exposed, the actionable takeaway is clear: start with the low-cost, high-impact items. Inventory your systems, enforce multi-factor authentication, and train your staff. For those looking for expert guidance, the clinic\u2019s free assessment model is a proven path, and organizations should consider contacting the consortium or exploring similar programs if they are in its service area. The best time to harden defenses against ransomware is before the demand arrives, not after the files are locked.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>When ransomware locked the city of Baltimore out of its critical systems in May 2019, the resulting chaos shut down real estate transactions and bill payments, ultimately costing millions in recovery. That case study is now a core teaching tool at MIT, where a unique program has turned the fight against municipal cyberattacks into a [&hellip;]<\/p>\n","protected":false},"author":7,"featured_media":74567,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/iili.io\/CG3vlhg.jpg","fifu_image_alt":"MIT Students Defend Municipalities from Ransomware Attacks","footnotes":""},"categories":[349],"tags":[],"class_list":["post-63316","post","type-post","status-publish","format-standard","has-post-thumbnail","category-articles"],"fifu_image_url":"https:\/\/iili.io\/CG3vlhg.jpg","fifu_image_alt":"MIT Students Defend Municipalities from Ransomware Attacks","_links":{"self":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts\/63316","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/comments?post=63316"}],"version-history":[{"count":0,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts\/63316\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/media\/74567"}],"wp:attachment":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/media?parent=63316"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/categories?post=63316"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/tags?post=63316"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}