Cybersecurity in Elections:
Developing a Holistic Exposure and Adaptation Testing (HEAT) Process for Election Management Bodies
respect to cybersecurity in elections, and the role that privacy commissions may play with respect to
oversight of personal data in elections.
III. Types of Exposure that Can Impact Cybersecurity
Drawing on the themes, trends, and approaches that emerged from the literature review, we have
identified five different types of exposure an EMB must consider in its use of data management
technology platforms. These different types or “dimensions” of exposure have informed the
development of IFES’ HEAT process, which is outlined in the next section of this paper.
a)
Technology Exposure
Election management systems for various parts of the electoral process are becoming increasingly
automated or digitalized,78 including voter registration, voter identification and authentication on
Election Day through electronic voter lists (e-poll books), party and candidate registration, and
tabulation of election results, among others. In IFES’ experience, most countries running elections today
have automated and digitalized at least one of these processes, most commonly the tabulation of
results. Unfortunately, there are myriad ways a piece of technology or an entire system can be
misconfigured or compromised, deliberately or otherwise. While there are various applicable
international principles and guidelines, as discussed above, there are usually no country-specific
standards for employing automated or digitalized systems in elections, with some exceptions.79
The danger of cyberattacks on EMBs has become ubiquitous, and the level of sophistication of such
attacks varies. Perpetrators range from under-resourced and often young individuals, who want to
commit vandalism, gain notoriety, or make a political statement by defacing an EMB’s website, to
Advanced Persistent Threat (APT) groups, usually cyber offensive groups supported and financed by
states that want to inflict damage during elections or as part of hybrid warfare. Attacks can therefore
range from simple hacks using existing penetration testing tools (for example, Kali Linux)80 to advanced
exploitation of a hardware or software vulnerability that might not even have been documented before
the attack (known as zero-day exploits).81
78
Automation is converting to automatic operation, without the need for human assistance, while digitalization is
converting data into a digital form that can be processed by a computer.
79
In the U.S., the EAC has produced Voluntary Voting System Guidelines, which were last updated in 2015 but are
continuously developed. See “Voluntary Voting System Guidelines,” Voting Equipment, U.S. EAC,
https://www.eac.gov/voting-equipment/voluntary-voting-system-guidelines/. These are a set of specifications for
basic functionality, accessibility and security capabilities of voting as well as election management systems. While
these guidelines are non-obligatory at the federal level, except those obligations stemming from the Help America
Vote Act of 2002, a number of U.S. jurisdictions have adopted them as obligatory or introduced parts of the
standards in their state legislation. See “Help America Vote Act,” About U.S. EAC, U.S. EAC,
https://www.eac.gov/about/help-america-vote-act/.
80
Kali Linux, https://www.kali.org/.
81
There are a number of possible attack vectors from external locations, such as SQL injections, DNS hijacking,
cross-site scripting, rootkits, etc.
19