Cybersecurity in Elections:
Developing a Holistic Exposure and Adaptation Testing (HEAT) Process for Election Management Bodies
Preface
The International Foundation for Electoral Systems (IFES) has worked for more than 30 years in over 145
countries to support the right to free and fair elections worldwide. Securing that right once it has been
established is a major part of our work. As technology changes, countries and their election
management bodies (EMBs) must change how they conceive of security. Bad actors, whether foreign or
domestic, use technology to enhance their reach and the damage they can inflict. Battles for the
integrity of elections are increasingly waged in cyberspace, and one small flaw in technology, or in the
way it is used, can jeopardize an election. Hence, strengthening cybersecurity in democracies is
increasingly important, and IFES is continuing to expand our support to electoral cybersecurity globally.
Even as cyberattacks become more frequent, electoral processes are becoming increasingly reliant on
the kinds of technology those attacks exploit. Elections increasingly depend on technology such as digital
voter rolls and election results, biometric voter registration, and electronic voting machines. Countries
are continuing to adopt these technologies, so the need for an effective framework for protecting
against cyberthreats has never been greater. This cannot be an afterthought in the electoral process.
Rather, a discussion around the ever-changing electoral threat environment should inform the public
procurement process for any election technology. To do otherwise is to risk the possibility that actual or
perceived vulnerabilities are exploited to undermine the credibility of the process.
The balance between transparency and security is perhaps the central issue in cybersecurity in elections.
While technology needs to be sufficiently opaque to bad actors, the public can quickly lose trust in any
system that is a “black box” to non-experts. Securing this technology means more than just strong
software and hardware – it also means securing the human, political, legal and procedural aspects of an
election. A technology can only be as secure as the processes and the people around it. Building on case
studies and an extensive literature review, IFES has turned its lessons learned into a methodology to
assist EMBs in their defense against cyberattacks on the democratic process. The methodology
presented in this paper, called the Holistic Exposure and Adaptation Testing (HEAT) process, is a holistic
framework for understanding and responding to threats to electoral cybersecurity.
Drawing on an extensive literature review and our technical expertise, IFES developed this framework
with the shifting technological landscape in mind. The nature of technical innovation means that
cyberattacks cannot be wholly prevented, but they can and should be anticipated as much as is possible.
The HEAT process is designed to support EMBs in assessing and protecting against cyberthreats.
Protecting the fundamental right to free and fair elections now requires a cybersecurity strategy and
infrastructure. IFES wrote this paper to that end and will continue defending democratic electoral
processes from cyber interference in support of citizens’ right to political participation and
representation.
William R. Sweeney, Jr.
IFES President and CEO
1