International Foundation for Electoral Systems Insider attacks represent yet another attack vector that can be devastating. If an adversary has physical proximity to an election system, it may be easier to procure or install a malevolent player inside an EMB, which can inflict serious damage to election systems. An insider attack may also come from an individual acting destructively to achieve some political goal. Insider attacks may come from weak physical security of systems, inadequate vetting of contractors, or even poor hiring and employment practices. A related problem is the limited pool of experienced IT experts willing to start or continue working for EMBs. EMBs typically pay salaries comparable to the rest of the public sector, while good IT experts can earn much more in the private sector. While this may be a problem for any type of expert working with an EMB, where the responsibility is enormous and wages limited, it is even more so with IT. Incentives must be considered when evaluating human exposure. A related challenge is the requirement for even greater openness and transparency to EMB systems and platforms for stakeholders such as observers and party agents, which as seen in Kenya in 2017 may even be ordered by the courts. This presents even greater entry points for human mistakes or interference, and argues for a careful security credentialing process and oversight and monitoring of stakeholder access. c) Political Exposure There is no end to the ways in which an EMB can be exposed politically, sometimes by their own action or inaction, especially in developing democracies where checks and balances may not be in place. It takes significant time and effort to build trust in elections and the institution running an election but takes very little to lose that trust. For example, if corruption is alleged during a procurement process for new election technology, whether proven or not, this can significantly impact public perceptions of the EMB. Types of political exposure include political influence on EMBs to adopt certain types of election technology, improper influence over election technology procurement processes, and allegations of improper technology use that is designed to cast doubt on the institution, process, or outcome. Procurement of election technology can be particularly fraught, especially as technology vendors access senior political figures promising an easy fix to integrity issues, or as citizens look to technology for a solution for perceived failures in the electoral process. This can leave an EMB exposed when they face pressure to adopt a certain technology or are influenced in the procurement process to use a solesource procurement or select a preferred provider. A particular concern in the procurement process is commonly termed “vendor-lock.” As the ACE Electoral Knowledge Network notes, “[w]here technology is proprietary to a vendor, where data formats are not open, or when an EMB relies heavily on a vendor for its electoral operations, it risks being locked into a particular vendor…[a]ny such tie to one particular vendor should be avoided to make sure the EMB remains in control of the systems it uses and the costs incurred.”89 Beyond being locked into one vendor, there can be flow-on risks and costs in the vendor relationship that can leave an EMB exposed. For example, in The Gambia, in response to criticism following the 2011 election cycle, the Independent 89 ACE: The Electoral Knowledge Network, “Election Technology Vendors,” https://aceproject.org/aceen/topics/em/emia/emia03. 22

Select target paragraph3