Cybersecurity in Elections: Developing a Holistic Exposure and Adaptation Testing (HEAT) Process for Election Management Bodies be used in wider contexts.25 This publication offers a myriad of recommendations organized by various topics and using the five-step functional approach developed by the National Institute of Standards and Technology (NIST). Most recently, in July 2018, an EU Cooperation Group26 published a Compendium on Cyber Security of Election Technology that aims to systemize the cyber concerns and threats across the European continent and offers myriad experiences accumulated from EU member states’ elections in case studies.27 IFES argues that one of the first steps in implementing election technology is to weigh the costs and benefits of adopting a particular tool.28 IFES has found through global experience that EMBs or governments often focus on security concerns during the collection of data, and focus less on how the data will be processed, transmitted and stored. Regardless of country context, this step should always include the input of a diverse group of stakeholders, such as election officials, government leaders, political party leaders, and civil society organizations, including special needs groups. This assessment also provides an opportunity to identify the problems in the electoral process that a particular technology can help solve. IFES’ own work on guidelines states that “a specific technology should only be considered if there is a specific problem that the technology can address.”29 It is important that there be a clear need for the technology, and that technology is not introduced for technology’s sake. The technical and financial IFES has found through global experience that EMBs feasibility, potential benefit, and likelihood of acceptance by or governments often focus stakeholders of the new technology should be evaluated before on security concerns during 30 testing whether the technology is a good fit. The common practice the collection of data, and of procuring election technologies from private vendors, for example, focus less on how the data brings potential benefits, such as world-class technology expertise will be processed, and global experience, but also risks. IFES, the European Commission, transmitted and stored. and the UN Development Programme (UNDP) all note the risk of private vendors having control over EMB operations once the technology is in place, with EMBs unable to switch technology again without incurring huge costs.31 Security vetting of private contractors can also be a challenge. 25 Harvard Kennedy School’s Belfer Center, Defending Digital Democracy Project (D3), The State and Local Election Cyber-Security Playbook, https://www.belfercenter.org/publication/state-and-local-election-cybersecurityplaybook. 26 Comprising experts from the EU member states, the European Commission and ENISA. 27 EU NIS Cooperation Group, Compendium on Cyber Security of Election Technology, July 2018, https://www.ria.ee/public/Cyber_security_of_Election_Technology.pdf. 28 Ben Goldsmith and Holly Ruthrauff, Implementing and Overseeing Electronic Voting and Counting Technologies, IFES and NDI, 2013, 23-24. 29 Michael Yard, ed., Direct Democracy: Progress and Pitfalls of Election Technology, IFES, 2010, 20. 30 Ben Goldsmith, Electronic Voting and Counting Technologies, IFES, 2011, 13. 31 European Commission and UNDP, Procurement Aspects of Introducing ICTs solutions in Electoral Processes, 2010, 73; and Yard, ed., Direct Democracy: Progress and Pitfalls of Election Technology, International Foundation for Electoral Systems, 112. 9

Select target paragraph3