Cybersecurity in Elections: Developing a Holistic Exposure and Adaptation Testing (HEAT) Process for Election Management Bodies respect to cybersecurity in elections, and the role that privacy commissions may play with respect to oversight of personal data in elections. III. Types of Exposure that Can Impact Cybersecurity Drawing on the themes, trends, and approaches that emerged from the literature review, we have identified five different types of exposure an EMB must consider in its use of data management technology platforms. These different types or “dimensions” of exposure have informed the development of IFES’ HEAT process, which is outlined in the next section of this paper. a) Technology Exposure Election management systems for various parts of the electoral process are becoming increasingly automated or digitalized,78 including voter registration, voter identification and authentication on Election Day through electronic voter lists (e-poll books), party and candidate registration, and tabulation of election results, among others. In IFES’ experience, most countries running elections today have automated and digitalized at least one of these processes, most commonly the tabulation of results. Unfortunately, there are myriad ways a piece of technology or an entire system can be misconfigured or compromised, deliberately or otherwise. While there are various applicable international principles and guidelines, as discussed above, there are usually no country-specific standards for employing automated or digitalized systems in elections, with some exceptions.79 The danger of cyberattacks on EMBs has become ubiquitous, and the level of sophistication of such attacks varies. Perpetrators range from under-resourced and often young individuals, who want to commit vandalism, gain notoriety, or make a political statement by defacing an EMB’s website, to Advanced Persistent Threat (APT) groups, usually cyber offensive groups supported and financed by states that want to inflict damage during elections or as part of hybrid warfare. Attacks can therefore range from simple hacks using existing penetration testing tools (for example, Kali Linux)80 to advanced exploitation of a hardware or software vulnerability that might not even have been documented before the attack (known as zero-day exploits).81 78 Automation is converting to automatic operation, without the need for human assistance, while digitalization is converting data into a digital form that can be processed by a computer. 79 In the U.S., the EAC has produced Voluntary Voting System Guidelines, which were last updated in 2015 but are continuously developed. See “Voluntary Voting System Guidelines,” Voting Equipment, U.S. EAC, https://www.eac.gov/voting-equipment/voluntary-voting-system-guidelines/. These are a set of specifications for basic functionality, accessibility and security capabilities of voting as well as election management systems. While these guidelines are non-obligatory at the federal level, except those obligations stemming from the Help America Vote Act of 2002, a number of U.S. jurisdictions have adopted them as obligatory or introduced parts of the standards in their state legislation. See “Help America Vote Act,” About U.S. EAC, U.S. EAC, https://www.eac.gov/about/help-america-vote-act/. 80 Kali Linux, https://www.kali.org/. 81 There are a number of possible attack vectors from external locations, such as SQL injections, DNS hijacking, cross-site scripting, rootkits, etc. 19

Select target paragraph3