Cybersecurity in Elections:
Developing a Holistic Exposure and Adaptation Testing (HEAT) Process for Election Management Bodies
be used in wider contexts.25 This publication offers a myriad of recommendations organized by various
topics and using the five-step functional approach developed by the National Institute of Standards and
Technology (NIST). Most recently, in July 2018, an EU Cooperation Group26 published a Compendium on
Cyber Security of Election Technology that aims to systemize the cyber concerns and threats across the
European continent and offers myriad experiences accumulated from EU member states’ elections in
case studies.27
IFES argues that one of the first steps in implementing election technology is to weigh the costs and
benefits of adopting a particular tool.28 IFES has found through global experience that EMBs or
governments often focus on security concerns during the collection of data, and focus less on how the
data will be processed, transmitted and stored. Regardless of country context, this step should always
include the input of a diverse group of stakeholders, such as election officials, government leaders,
political party leaders, and civil society organizations, including special needs groups. This assessment
also provides an opportunity to identify the problems in the electoral process that a particular
technology can help solve. IFES’ own work on guidelines states that “a specific technology should only
be considered if there is a specific problem that the technology can address.”29 It is important that there
be a clear need for the technology, and that technology is not
introduced for technology’s sake. The technical and financial
IFES has found through
global
experience that EMBs
feasibility, potential benefit, and likelihood of acceptance by
or governments often focus
stakeholders of the new technology should be evaluated before
on security concerns during
30
testing whether the technology is a good fit. The common practice
the collection of data, and
of procuring election technologies from private vendors, for example,
focus less on how the data
brings potential benefits, such as world-class technology expertise
will be processed,
and global experience, but also risks. IFES, the European Commission,
transmitted and stored.
and the UN Development Programme (UNDP) all note the risk of
private vendors having control over EMB operations once the technology is in place, with EMBs unable
to switch technology again without incurring huge costs.31 Security vetting of private contractors can
also be a challenge.
25
Harvard Kennedy School’s Belfer Center, Defending Digital Democracy Project (D3), The State and Local Election
Cyber-Security Playbook, https://www.belfercenter.org/publication/state-and-local-election-cybersecurityplaybook.
26
Comprising experts from the EU member states, the European Commission and ENISA.
27
EU NIS Cooperation Group, Compendium on Cyber Security of Election Technology, July 2018,
https://www.ria.ee/public/Cyber_security_of_Election_Technology.pdf.
28
Ben Goldsmith and Holly Ruthrauff, Implementing and Overseeing Electronic Voting and Counting Technologies,
IFES and NDI, 2013, 23-24.
29
Michael Yard, ed., Direct Democracy: Progress and Pitfalls of Election Technology, IFES, 2010, 20.
30
Ben Goldsmith, Electronic Voting and Counting Technologies, IFES, 2011, 13.
31
European Commission and UNDP, Procurement Aspects of Introducing ICTs solutions in Electoral Processes, 2010,
73; and Yard, ed., Direct Democracy: Progress and Pitfalls of Election Technology, International Foundation for
Electoral Systems, 112.
9