Cybersecurity in Elections:
Developing a Holistic Exposure and Adaptation Testing (HEAT) Process for Election Management Bodies
executives are still beginners in data-use governance.85 This is typically a problem of vertical disconnect
between decision-makers and IT specialists, and EMBs are no exception. Most EMBs lack a dedicated
cybersecurity officer. Election commission members often do not understand or appreciate the
cybersecurity dangers associated with their decisions. When they do, they may resort to hoping their
systems are obscure, irrelevant, or beyond the reach of hackers. Given how important elections are, this
is a systemic fallacy with dire consequences.
The failure of decision-makers in EMBs to understand the importance of cyber protection usually goes
hand in hand with a lack of basic cybersecurity practices (commonly referred to as cyber hygiene) used
by staff on computers connected to sensitive networks. In some situations, this even extends to IT
staff.86 Inadequate cyber hygiene may or may not be compounded by a lack of understanding of the
social engineering aspects of a cyberattack. For example, it can require training to understand the
dangers of impersonation during unsolicited communication, as well as the difference between
requested and unsolicited conversation over the phone or other communication channels, such as
emails or chat on social networks.
Three of the major ways in which EMBs are vulnerable to human exposure are phishing attacks,
watering hole attacks, and insider attacks. Phishing attacks are cyberattacks through impersonation or
other fraudulent action, performed to gain access to systems or to some piece of information, such as
passwords. This method of attack was used by Russia in targeting the presidential campaign of Hillary
Clinton in 2016.87 A phishing attack aimed at specific personnel, such as the most vulnerable staffer who
knows the least about security or exhibits the most lax behavior, is referred to as spear-phishing. Most
adversaries target the weakest link to make such attacks affordable, so high-tech responses aren’t
necessarily the right answer.
If an attack is also aimed at high-level executives or decision-makers, it is commonly known as whaling.
One of the most common attack vectors in spear-phishing is fraudulent emails (also referred to as
spoofing) or clone-phishing (where a legitimate and previously delivered email is cloned and malware
inserted).88 In case of high-level attacks by advanced hacker organizations, emails are crafted to be
virtually indistinguishable from legitimate intra-institutional emails and may contain links with malware.
Once the victim clicks on the link, the damage may already be done, and it may take substantial effort
and training to remove the malware. Watering hole attacks are where a hacker or hacking group guesses
or observes which websites an organization’s employees often uses and infects one or more of them
with malware in order to ultimately infect the organization’s network.
85
Christopher Castelli, Revitalizing privacy and trust in a data-driven world: Key findings from The Global State of
Information Security® Survey 2018, PwC, https://www.pwc.com/us/en/cybersecurity/assets/revitalizing-privacytrust-in-data-driven-world.pdf.
86
For example, IT specialists may sometimes avoid installing anti-virus software on their workstations only to avoid
computation overhead, especially if they have to operate on outdated hardware.
87
Intelligence Community Assessment, “Assessing Russian Activities and Intentions in Recent US Elections,”
January 6, 2017, https://www.dni.gov/files/documents/ICA_2017_01.pdf.
88
Computero, “How Not to Go Phishing,” May 16, 2014, https://computerobz.wordpress.com/tag/clone-phishing/.
21