How MIT students are helping to prevent cyberattacks
Summary
The MIT Cybersecurity Clinic, launched in 2019 by Lecturer Jungwoo Chun and Professor Lawrence Susskind within the Department of Urban Studies and Planning, provides pro-bono cybersecurity vulnerability assessments to local governments and healthcare organizations. Since its inception, the clinic has delivered over 40 confidential assessments, helping clients implement low-cost measures that can prevent 80% or more of cyberattack costs. The program emphasizes "defensive social engineering," acknowledging that human factors are the primary attack vector, complementing technical solutions. Students undergo instructional modules, pass a certification exam, and work in teams to assess client vulnerabilities, recommending steps like hardware/software inventory, regular patching, multi-factor authentication, and employee training. This model is expanding, with online modules available via *MITx* and MIT co-founding a consortium of 61 cybersecurity clinics in 2021.
Key takeaway
For IT Directors or CTOs in underfunded public or non-profit organizations, this clinic model offers a proven pathway to bolster your cybersecurity posture. You can leverage external expertise, like that from a clinic, to identify vulnerabilities and secure budget approval for essential, low-cost improvements. Prioritize foundational steps such as comprehensive asset inventory, multi-factor authentication, and employee training to mitigate over 80% of potential cyberattack risks.
Key insights
Cybersecurity is a human-centric challenge requiring "defensive social engineering" and organizational capacity building, not just technical fixes.
Principles
- Human factors are the biggest attack vector.
- Low-cost measures prevent most cyberattack costs.
- Cybersecurity requires cross-disciplinary understanding.
Method
The MIT Cybersecurity Clinic's method involves instructional modules, certification, team-based client vulnerability assessments, and report generation with actionable, low-cost recommendations for improvement.
In practice
- Inventory all network hardware and software.
- Implement multi-factor authentication and data backups.
- Train employees against opening unknown attachments.
Topics
- Cybersecurity Clinics
- Defensive Social Engineering
- Ransomware Attacks
- Critical Infrastructure Security
- Public Sector Cybersecurity
- Organizational Capacity Building
Best for: IT Professional, Consultant, Policy Maker
Related on AIssential
See Counsel's argued verdicts on the open AI decisions leaders are weighing →
Editorial summary, takeaway, and curation by AIssential. Original article published by MIT News - Artificial intelligence.