Cybersecurity in Elections:
Developing a Holistic Exposure and Adaptation Testing (HEAT) Process for Election Management Bodies
In terms of human exposure, measures against insider attacks are often self-explanatory – such as
monitoring physical access to servers – but sometimes additional action may be required. This can entail
doubling up IT experts when logging in to sensitive servers, never using wireless networks for sensitive
LANs to avoid close-proximity, fraudulent Wi-Fi access attacks (so-called evil twin attacks). Control
systems must be in place to ensure accessibility is strictly compartmentalized, logs created, and logs
regularly reviewed by ICT supervisors for compliance and abuse. Vetting personnel when hiring is a good
practice but needs to be conducted carefully to avoid nepotism or discrimination and to avoid
introducing new problems, such as potential bureaucratic delays. A good EMB should also have a data
security strategy to avoid having outdated, obsolete, or underutilized election systems that can lead to
inefficient data management.
For political exposure, EMBs should carefully plan and execute procurement processes for election
technology, and develop sound communication and consultation mechanisms on cybersecurity issues.
Specific measures may also need to be put in place to strengthen the de jure or de facto independence
of the EMB and its leadership. At the same time, greater collaboration may be required with law
enforcement personnel and intelligence agencies, depending on the nature of the cyberthreat. This
would need to be done carefully, recognizing the need for the EMB to also maintain independence both
in practice and in terms of public perceptions. For legal and procedural exposure, various legal or
regulatory amendments or reforms may be required, along with the development or refinement of
strategy documents, operational plans, training materials, or other manuals and guidelines.
The EMB may have certain cybersecurity practices in place, but those might be scattered in multiple
documents, informal files kept by IT specialists, or not even recorded in written form, but only employed
in practice. The HEAT team should encourage the EMB to consolidate and lay down all their security
practices and assumption in one place; in this way, they will be more accessible, transparent to the EMB,
and possible to be challenged (for example, if the system does not place any constraints on the size and
structure of passwords, this can be highly problematic). This, if formalized, can become the EMB’s
cybersecurity strategy. The establishment of such a strategy will increase the EMB’s resilience against
cyberattacks.
Ultimately, the goals of the HEAT process are to holistically test specific election technology systems for
vulnerabilities, to directly involve relevant EMB officials in the process and ensure it can be an exercise
in capacity development, and to identify adaptations that the EMB can lead or influence to reduce
cybersecurity exposure levels.
V. Conclusions
As identified at the outset of this paper, EMBs increasingly rely on complex technology in electoral
processes. This has created new security challenges related to protection and safekeeping of election
data in digital form and related computerized systems. Most countries now automate and digitalize at
least part of their elections, from the use of e-voting to electronic voter databases. The issues around
cybersecurity in elections are therefore increasingly universal and are becoming more complex.
33