International Foundation for Electoral Systems Wide interconnectivity also creates possibilities for novel attack vectors. In 2016, for example, a botnet82 (Mirai Botnet) was discovered in a small jewelry store, and was eventually found to have compromised 25,000 CCTV cameras globally (Mirai Botnet), raising a concern that certain types of devices can be compromised even during their production.83 The so-called Internet-of-Things (IoT) – which is basically the concept of connecting any device with an on and off switch to the internet or to other devices – allows for a constant and substantial increase in the number of internet-facing devices that may be ripe for exploitation by malicious actors.84 Internet-facing systems with limited capacity that depend on their own organization’s resources to function and be maintained can also be open to distributed denial-ofservice (DDoS) attacks. In Estonia in 2007, a DDoS attack nearly shut down internet infrastructure in the country, while in Kyrgyzstan in 2009, hackers effectively took the country offline after a ten-day DDoS cyber assault, eliminating 80 percent of the country’s online capacity. DDoS attacks flood the system with numerous requests from many different locations. Due to limited resources, EMBs typically do not have the capacity to withstand persistent, powerful DDoS attacks without some external assistance. DDoS attacks will always be a threat, since they are inherent to the free design of the system. For example, election results reporting can be targeted by a DDoS attack during election night, when the interest of election stakeholders peaks in a very short period of time and the impact of denied service will therefore be significant. Beyond deliberate attacks, election technologies are also vulnerable to misconfiguration, accidental misuse, deterioration (especially in transfer or storage), and various types of hardware and software failure. For example, in the 2013 electoral process in Kenya, a significant number of voter identification kits suffered battery failures. Election technology may also require back-up satellite coverage in the event of cellphone or internet failure. It is, therefore, paramount that there are contingency procedures in place, sometimes requiring reverting back to pen and paper. b) Human Exposure The need to protect systems from cyberattacks might be obvious, but it is still off the radar of many organizations’ decision-makers. A 2018 research survey by PricewaterhouseCoopers (PwC) posited that almost half of company executives lack an overall information security strategy and that many 82 A botnet is a string of connected computers coordinated together to perform a task. See “What is a botnet?” Malware, US Norton, 2018, https://us.norton.com/internetsecurity-malware-what-is-a-botnet.html. 83 Daniel Cid, “Large CCTV Botnet Leveraged in DDoS Attacks,” Sucuriblog, June 27, 2016, https://blog.sucuri.net/2016/06/large-cctv-botnet-leveraged-ddos-attacks.html. 84 For example, this number increased by a third from 2016 to 2017. Researchers suggest that future cyberattacks are imminent and that IoT devices must have patchable firmware. Derek Hawkins, “The Cybersecurity 202: Here’s what security researchers want policymakers to know about the Internet of Things,” The Washington Post, August 10, 2018, https://www.washingtonpost.com/news/powerpost/paloma/the-cybersecurity-202/2018/08/10/thecybersecurity-202-here-s-what-security-researchers-want-policymakers-to-know-about-the-internet-ofthings/5b6c6ec91b326b020795603d. 20

Select target paragraph3