Cybersecurity in Elections: Developing a Holistic Exposure and Adaptation Testing (HEAT) Process for Election Management Bodies executives are still beginners in data-use governance.85 This is typically a problem of vertical disconnect between decision-makers and IT specialists, and EMBs are no exception. Most EMBs lack a dedicated cybersecurity officer. Election commission members often do not understand or appreciate the cybersecurity dangers associated with their decisions. When they do, they may resort to hoping their systems are obscure, irrelevant, or beyond the reach of hackers. Given how important elections are, this is a systemic fallacy with dire consequences. The failure of decision-makers in EMBs to understand the importance of cyber protection usually goes hand in hand with a lack of basic cybersecurity practices (commonly referred to as cyber hygiene) used by staff on computers connected to sensitive networks. In some situations, this even extends to IT staff.86 Inadequate cyber hygiene may or may not be compounded by a lack of understanding of the social engineering aspects of a cyberattack. For example, it can require training to understand the dangers of impersonation during unsolicited communication, as well as the difference between requested and unsolicited conversation over the phone or other communication channels, such as emails or chat on social networks. Three of the major ways in which EMBs are vulnerable to human exposure are phishing attacks, watering hole attacks, and insider attacks. Phishing attacks are cyberattacks through impersonation or other fraudulent action, performed to gain access to systems or to some piece of information, such as passwords. This method of attack was used by Russia in targeting the presidential campaign of Hillary Clinton in 2016.87 A phishing attack aimed at specific personnel, such as the most vulnerable staffer who knows the least about security or exhibits the most lax behavior, is referred to as spear-phishing. Most adversaries target the weakest link to make such attacks affordable, so high-tech responses aren’t necessarily the right answer. If an attack is also aimed at high-level executives or decision-makers, it is commonly known as whaling. One of the most common attack vectors in spear-phishing is fraudulent emails (also referred to as spoofing) or clone-phishing (where a legitimate and previously delivered email is cloned and malware inserted).88 In case of high-level attacks by advanced hacker organizations, emails are crafted to be virtually indistinguishable from legitimate intra-institutional emails and may contain links with malware. Once the victim clicks on the link, the damage may already be done, and it may take substantial effort and training to remove the malware. Watering hole attacks are where a hacker or hacking group guesses or observes which websites an organization’s employees often uses and infects one or more of them with malware in order to ultimately infect the organization’s network. 85 Christopher Castelli, Revitalizing privacy and trust in a data-driven world: Key findings from The Global State of Information Security® Survey 2018, PwC, https://www.pwc.com/us/en/cybersecurity/assets/revitalizing-privacytrust-in-data-driven-world.pdf. 86 For example, IT specialists may sometimes avoid installing anti-virus software on their workstations only to avoid computation overhead, especially if they have to operate on outdated hardware. 87 Intelligence Community Assessment, “Assessing Russian Activities and Intentions in Recent US Elections,” January 6, 2017, https://www.dni.gov/files/documents/ICA_2017_01.pdf. 88 Computero, “How Not to Go Phishing,” May 16, 2014, https://computerobz.wordpress.com/tag/clone-phishing/. 21

Select target paragraph3