International Foundation for Electoral Systems It also means looking at cybersecurity holistically, as one type of vulnerability may be addressed in isolation while another is exploited instead. Or, different types of cybersecurity exposure may compound to produce a unique vulnerability that can result in significant problems, whether through malpractice (negligence or mistake) or fraud (deliberate exploitation).6 While existing guidelines on cybersecurity, discussed in the literature review below, provide sound guidance on mitigating technological exposure in elections (for example, by ensuring sound cyber hygiene practices and implementing two-factor authentication), they may not consider other types of exposure, such as restrictive laws, weak procedures or untrained staff, that can undercut cybersecurity frameworks and lead to breakdowns in the electoral process or in public trust of electoral outcomes. Types of Cybersecurity Exposure in Elections Technology Exposure – for example, through hacking or system failure Human Exposure – for example, through poorly trained or malevolent officials using data systems Political Exposure – for example, through improper influence over the procurement process for election technology Legal Exposure – for example, through poorly drafted or manipulated laws that restrict EMB independence or leave the process vulnerable to litigation Procedural Exposure – for example, through poorly designed procedures that create vulnerabilities in how data is managed Given all these considerations, how can EMBs secure systems from technical vulnerabilities that leave them exposed and may lead to post-election challenges, while at the same time protecting principles of open data and transparency? In this paper, the International Foundation for Electoral Systems (IFES) outlines strategies for EMBs to strengthen their technology and procedures to resist vulnerabilities, by following what we have termed a Holistic Exposure and Adaptation Testing (HEAT) process. While no electoral process or technology is infallible, the HEAT process aims to secure automated or digitalized electoral processes – as far as possible – against unanticipated threats, illicit incursions, system failures, or unfounded legal challenges. As the name suggests, the HEAT process focuses on the types of exposure an EMB may face when implementing different types of technology systems (technology, human, political, legal and procedural 6 IFES has defined these terms further in Chad Vickery and Erica Shein, Assessing Electoral Fraud in New Democracies: Refining the Vocabulary, May 2012, http://www.ifes.org/sites/default/files/assessing_electoral_fraud_series_vickery_shein.pdf. Electoral fraud differs from electoral malpractice along several key dimensions. The range of possible actors is wider for fraud, as it can include any person or group with a stake in the election result. This may include voters, political parties, state officials with election-related duties, candidates and the media, in addition to election workers. Malpractice, on the other hand, is largely analyzed in the context of election officials (permanent and ad hoc staff), though other actors (e.g., political parties, the media) can breach their duty of care as it relates to codes of conduct, guidelines, or internationally accepted best practice. The nature of the action and the presence of intent is most significant: fraud is committed deliberately and with intent to interfere with the electoral process (manifested as either an action or an omission, in the case of an actor with official election responsibilities), while malpractice results from carelessness or neglect. 4

Select target paragraph3