Teaching critical infrastructure risks gives students a practical way to connect cybersecurity with systems they already depend on: water, power, healthcare, transportation, and manufacturing. This lesson plan is designed for upper elementary, middle school, or early high school learners, with the depth adjusted by grade level. The goal is not to teach offensive techniques. Students evaluate evidence, identify weak points in a simplified system diagram, and recommend safer operating practices based on documented infrastructure incidents.
Critical Infrastructure Risks Driving The Case Study
Start with a clear definition. Critical infrastructure includes systems whose disruption can affect public health, safety, economic activity, or daily services. In a classroom, that definition should stay concrete. A water plant pumps and treats drinking water. A hospital needs patient systems and backup power. A manufacturing site may depend on programmable logic controllers, often called PLCs, to operate pumps, valves, conveyors, or other physical equipment.
Use a short evidence brief rather than a dramatic scenario. The FBI Internet Crime Complaint Center reported more than 2,100 ransomware incidents in 2025 affecting U.S. critical infrastructure sectors, including healthcare, energy, and manufacturing, according to FBI ransomware reporting. That fact is enough to establish why a risk lesson is valid without overstating what every incident did or did not cause.
What Students Should And Should Not Conclude
Students should understand that cybersecurity risk is not limited to stolen files. In industrial environments, a cyber incident can interfere with scheduling, monitoring, billing, maintenance, or physical processes. They should also learn caution: not every ransomware event reaches operational technology, and not every exposed device causes a public service failure. The class should separate confirmed facts from assumptions.
A useful teacher prompt is: “What do we know, what do we infer, and what would we need to verify?” That structure keeps the lesson evidence-based. It also helps students avoid treating all attacks as identical. A hospital billing disruption, a manufacturing outage, and an exposed PLC at a utility site involve different technical controls and different public impacts.
Lesson Structure And Materials
Classroom Setup
The activity works best as a 60- to 90-minute lesson. Students work in teams of three or four. Each team receives a simplified infrastructure diagram showing a public-facing office network, a maintenance workstation, a PLC network, remote access, backup storage, and an operator console. Keep the diagram intentionally simple. The purpose is systems thinking, not industrial engineering certification.
- Printed system diagram with labeled assets and connections
- Incident brief with two verified facts and two unknowns
- Risk scoring sheet using likelihood, impact, and uncertainty
- Sticky notes or index cards for controls and open questions
- Teacher slide defining ransomware, PLC, segmentation, patching, and backup
Before group work begins, review vocabulary. Ransomware is malware used to encrypt or block access to systems, often paired with extortion. A PLC is an industrial controller used to automate equipment. Network segmentation separates systems so that compromise in one area is less likely to spread. Patching means applying software updates that address known issues. Backups are copies of data or configurations used for recovery, but they must be protected and tested.
Using Evidence Without Teaching Attack Steps
Avoid asking students to describe how an attacker gains access. Instead, ask them to identify defensive concerns visible in the diagram. Is remote access separated from controller equipment? Are backups connected to the same network as ordinary user devices? Is there a plan for manual operation if monitoring tools fail? These questions keep the task constructive and age-appropriate.
For enrichment, students can compare straightforward technology discussions from Abacus News with formal incident summaries. This exercise can help them understand the role of language in cybersecurity reporting, emphasizing media literacy by showing how headlines may simplify issues while technical reports are more detailed and precise.
Evidence-Based Risk Evaluation
Scoring Critical Infrastructure Risks In Teams
Each team scores three risks: ransomware on office computers, exposed remote access to equipment, and outdated software on a controller workstation. Use a three-level scale for younger learners: low, medium, and high. Older students can use numeric scoring from 1 to 5. Require every score to include a reason and one uncertainty. This prevents students from giving high scores to every item without analysis.
| Risk Item | Likely Student Evidence | Defensive Control To Discuss |
|---|---|---|
| Ransomware on office network | Incident reports show ransomware affects infrastructure sectors | Backups, user training, access limits, recovery planning |
| Internet-exposed PLC | External access to controllers can create operational concern | Remove direct exposure, require controlled remote access, monitor changes |
| Legacy or unpatched equipment | Older systems may be harder to update or replace | Inventory, compensating controls, planned maintenance windows |
A second evidence point can extend the discussion. A database report described Iranian-affiliated activity since March 2026 involving internet-exposed PLCs in U.S. critical infrastructure and associated operational disruption and financial loss; use the source as a defensive case study, not as a technical playbook, through the PLC disruption report. For students, the practical lesson is simple: equipment connected to the internet needs strict access control, monitoring, and ownership.
Connecting The Case To Water Systems
Water systems make the topic concrete because pumps, treatment processes, billing systems, and operator workstations are easier for students to picture than abstract networks. If your class is studying public utilities, a related explanation of water system cyberattacks can help connect PLC access, authentication gaps, and defensive controls. Keep the classroom focus on risk reduction: inventory devices, reduce unnecessary exposure, separate business and control networks, and prepare recovery procedures.
This is also where students can see cost and maintenance tradeoffs. Replacing older equipment may be expensive and disruptive. Patching may require scheduled downtime. Operators may need remote access for legitimate maintenance. A good student answer recognizes those constraints instead of pretending that every control is free or instant.
Assessment And Student Deliverables

Risk Memo Format
Each team writes a one-page memo to a fictional city operations manager. The memo should identify the top two risks, explain the evidence, name one uncertainty, and recommend two defensive actions. Require precise wording. For example, students should write “reduce direct internet exposure for controller equipment” rather than “make everything secure.” Specific language shows whether they understand the system.
Assessment can use four criteria: evidence use, technical accuracy, understanding of impact, and practicality of controls. A strong response cites the ransomware and PLC evidence, avoids unsupported claims, and distinguishes between information systems and operational equipment. A weaker response may list controls without explaining what problem each control reduces.
Discussion Questions For Reflection
After memos are submitted, ask students which risk was hardest to score and why. Many will find uncertainty challenging. That is useful. Real infrastructure security decisions often involve incomplete information, aging systems, budget limits, and safety requirements. The classroom version should model responsible reasoning: act on known risks, document unknowns, and avoid claims the evidence does not support.
For younger learners, the reflection can be oral. For older learners, ask for a short written paragraph explaining how cyber and physical systems connect. Students should be able to say that a computer problem can affect real-world services when the computer is part of monitoring, control, scheduling, or recovery.
Teaching Critical Infrastructure Risks With Care
Keeping The Lesson Accurate And Safe
A lesson on critical infrastructure risks should build civic and technical understanding without fear. Keep examples defensive, avoid exploit details, and remind students that infrastructure operators include engineers, technicians, public servants, and vendors working under real constraints. The best classroom outcome is not alarm. It is disciplined analysis: identify assets, consider impact, weigh uncertainty, and recommend controls that match the system.
This approach also supports electronics and engineering instruction. Students see that sensors, controllers, networks, and human procedures are connected. A PLC is not just a black box. It is part of a larger operating environment that needs maintenance, access rules, and recovery planning. That is the core teaching value: cybersecurity becomes a practical engineering problem, not an isolated computer topic.